Record format

@flashyos/shiplog

shipped/1 — the past tense of a record. One sealed entry per thing that shipped, derived from first-parent commit history, emitted per repository, never edited after sealing.

version 0.1.0 · audit of 2026-10-04 · source: flashyos/packages/shiplog

npm i @flashyos/shiplog

The log is derived --first-parent and an emit is a union, never a replacement: a commit stops being first-parent the moment its branch is merged, so overwriting the fragment silently deletes entries for work that shipped. An id already present keeps its sealed entry; only new ids are added.

Classification reads the subject through a declared lexicon; where the subject cannot say what a commit was, a Kind: trailer beats both the prefix and the lexicon — the author saying so, not the machine inferring.

Edge cases — each one paid for once

--rederive is destructive and kinds.json cannot fix history

An entry is sealed once; its digest covers its kind. Run on main, --rederive took a 293-entry log to 90, because merged branches stop being first-parent. Record classification decisions for what has not been emitted yet; for what has, the classification is final.

Read the emitter id from config; never derive it from the slug

slug + "-ci" was wrong in two of ten repositories (claimyour.gold-ci vs a slug of claimyour-gold). Every structural check passed while the declared agent matched no signature anywhere.

Emitted commits carry [skip ci] or they eat the deploy budget

On one day, 54% of 594 estate commits were emitters refreshing their own fragments — against a 100/day account-wide build limit. Nothing was red; every property was just always slightly stale.

held.json: a repository publishes; an entry can still be held

An entry that maps an exploitation route stays in the repository’s own sealed record and out of the served projection. Holding is not remediation — only rotation fixes a leaked secret.

← Full catalog · The doctrine behind the tools · Adopt one