Three ways in → same local check → review pack → human review. Optional drafts never replace check.
Building a product? For builders · Reviewing a supplier? For reviewers (trust table) · Receiving a pack? Receiving submissions · In-repo triage? curbpack review --repo (same method; see for reviewers) · Authority or auditor? For authorities.
Not conformity assessment. Not CE marking. Not a notified-body opinion.
check in GitHub Actions anytime. No draft step.Bring and CI go straight to check; Write adds draft choice first. Every path ends in a review pack for a human to judge.
A rule pack is a JSON checklist of structural gates. You pick which packs to run. Frozen catalog today:
house-policy — default cold start (house documentation / dependency hygiene)cra-baseline — Cyber Resilience Act (CRA)–shaped annex draft structure (informational)medtech-iec62304 — IEC 62304–shaped overlay (composes with CRA when selected)Packs are checklists shaped like regulatory annex drafts, not the law itself. Green gates mean the pack rules passed on this tree. Compose with curbpack init --packs … or .curbpack.json.
Assistants propose Option A and Option B, state Recommended: A or B with a few reasons, then stop for you. Optional allowlisted research brief informs cites; it never changes check pass/fail. After you pick, run cite-check before owning the prose. Bring and CI skip this stage.
curbpack init then curbpack check evaluates the chosen packs on disk. Dual output: machine-readable findings (JSON) and a short markdown report. Exit 0 = gates passed on this tree; 1 = findings remain. Daily check does not write the buyer one-pager.
On red: curbpack check --heal, then curbpack ask … --propose, then re-check — never invent green.
After green: curbpack share is the handoff verb (check → context-pack → buyer-questions → prepare-release). It writes a review pack: gate JSON, action report, executive summary, optional SBOM/VEX drafts, and a buyer one-pager HTML. That is the artifact you hand over. Front = findings. Back = provenance, optional allowlisted Sources (informational — not a gate input), and human sign-off status.
A person judges the evidence. When you are ready to bind a hash, run curbpack attest into Git Notes (ssh-agent signed when possible). Unsigned ≠ verified. After attest, you can open the local proof/index.html page and compare the bound hash from the evidence pointer—still human judgment, not conformity assessment.
| Signal | Meaning |
|---|---|
| Exit 0 | Gates passed on this tree—for human review, not certification |
| Exit 1 | Findings remain or operational error |
| Exit 2 | Usage / environment |
| Unsigned attest | Capsule present; not cryptographically verified |
| ssh-agent-signed | Real SSH signature produced |
Curbpack evaluates local rule-pack checks. Humans decide what to claim. Tutors propose only and must re-check; they never greenlight or attest.
Committed sample (front + back): samples/onepager.html. Optional writer aid: research brief sample. Buyer trust table: for reviewers. Authorities path: for authorities. Go deeper: white paper. Pack authoring: write your own pack.