Lines 46-86json
52 "start": "electron-vite preview",
53 "app:headless": "LOCAL_OPERATOR_NO_NOTIFICATIONS=1 LOCAL_OPERATOR_UI_TELEMETRY=off LOCAL_OPERATOR_UI_WINDOW_MODE=headless electron . --window-mode=headless",
54 "//app:headless": "The agent-driven launch, so it carries the notification kill switch (scripts/notifications-off.mjs) AND the telemetry switch (scripts/telemetry-off.mjs). `headless` silences this app's OWN banner and cannot reach the backend's: the app spawns a backend, and that backend's parked-gate announcement ends at `osascript` on macOS, whose banner lands in the operator's real Notification Center attributed to Script Editor. The telemetry switch matters because a run of this line boots the real app against the live PostHog project key its build carries, in BOTH processes - main co ...
55 "//dev": "The `.env` loader is `dotenv-cli`, whose default is NOT to overwrite a variable that is already in the environment - and that non-override is load-bearing rather than incidental. `dev` used to be `npx dotenv-cli -e .env -- bash -c 'export $(grep -v '^#' .env | xargs) && electron-vite dev'`, added so a checkout's `.env` would beat variables a Cursor/vscode terminal injects; that inner re-export runs AFTER any prefix the caller put on the line, so `pnpm dev:headless` (whose whole guarantee is the launch-side switch) could be re-armed by a `.env` line reading LOCAL_OPERATOR_UI_TELEM ...
56 "dev": "npx dotenv-cli -e .env -- electron-vite dev",
57 "//dev:headless": "The env var is the only channel this launch can carry a mode on. electron-vite dev spawns Electron itself from its OWN option parser and forwards nothing extra: measured, neither an appended argument nor its shipped ELECTRON_CLI_ARGS passthrough reaches the app's argv (the run reported the default 1380x900 when the passthrough asked for 1024x768). It does not need the flag: a second launch forwards the mode it resolved to the instance holding the lock (src/main/window-raise.ts), which is the channel this env var already feeds.",
58 "dev:headless": "LOCAL_OPERATOR_NO_NOTIFICATIONS=1 LOCAL_OPERATOR_UI_TELEMETRY=off LOCAL_OPERATOR_UI_WINDOW_MODE=headless pnpm dev",
59 "build": "electron-vite build",
60 "//prebuild": "The build compiles main/preload to V8 bytecode for the pinned Electron, so it needs a real node_modules/electron/dist before electron-vite runs. Since Electron 42 nothing fetches that during an install except our own postinstall, so this hook covers the trees that hook cannot reach (--ignore-scripts, or a dist/ removed by hand) and fails the build by name instead of letting it die inside the bytecode step with an ENOENT. build:npm needs no runtime: it deliberately emits plain JS (LOCAL_OPERATOR_UI_NO_BYTECODE=true).",
61 "prebuild": "node ./bin/ensure-electron.js",
62 "prebuild:npm": "rm -rf out/main out/preload",
63 "build:npm": "LOCAL_OPERATOR_UI_NO_BYTECODE=true electron-vite build",
64 "postbuild:npm": "chmod +x ./bin/local-operator-ui.js",
65 "postbuild": "chmod +x ./bin/local-operator-ui.js",
66 "postinstall": "node ./bin/postinstall.js",
HighInstall Time Lifecycle Scripts
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L66 MediumAmbiguous Install Lifecycle Script
Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L66 67 "lint": "pnpm biome check src bin scripts/linux-sandbox.test.mjs",
68 "lint:fix": "pnpm biome check --write src bin scripts/linux-sandbox.test.mjs",
69 "//lint:scripts": "`pnpm lint` names the paths it checks by hand, so the whole of `scripts/` - the proof harnesses, evidence rigs and release gates - sat outside the lint and formatter contracts, and a formatter error rode into a merged pull request green. This gate runs the same `biome check` over the `scripts/` files a change touches against a base ref (`origin/main` locally, the merge commit's first parent in CI), so a violation cannot ride in with the diff that introduces it, while the tree's 106 pre-existing offenders are burnt down file by file rather than turned red at once. Widenin ...
70 "lint:scripts": "node scripts/check-scripts-lint.mjs",
71 "format": "pnpm biome format src",
72 "format:fix": "pnpm biome format --write src",
73 "prepack": "pnpm run build:npm",
74 "check-types:main": "tsc --noEmit -p tsconfig.node.json",
75 "check-types:renderer": "tsc --noEmit -p tsconfig.app.json",
76 "check-types": "pnpm run check-types:main && pnpm run check-types:renderer",
77 "check-changed": "node scripts/ci-scope.mjs --since \"$(git merge-base origin/main HEAD)\" --run",
78 "test:session-cookies": "node scripts/session-cookie-electron.test.mjs",
79 "test:desktop": "node scripts/run-desktop-tests.mjs scripts/update-fleet-drain.test.mjs scripts/at-mentions.test.mjs scripts/directory-listing.test.mjs scripts/slash-token.test.mjs scripts/slash-rank.test.mjs scripts/slash-submit.test.mjs scripts/slash-highlight.test.mjs scripts/slash-contract.test.mjs scripts/slash-row-format.test.mjs scripts/owned-serve-lifecycle.test.mjs scripts/launcher-watch.test.mjs scripts/linux-sandbox.test.mjs scripts/capture-evidence.test.mjs scripts/desktop-contract.test.mjs scripts/transcript-reducer.test.mjs scripts/tool-compose-lifecycle.test.mjs scripts/tran ...
80 "check-themes": "node scripts/generate-theme-css.mjs --check && node scripts/contrast-contract.mjs",
81 "check-vendored": "node scripts/check-vendored.mjs",
82 "check-evidence": "node scripts/check-evidence.mjs",
83 "check-evidence:parity": "node scripts/evidence-histogram-parity.mjs",
84 "check-edit-diffs": "node scripts/check-edit-diffs.mjs",
85 "check-runtime-deps": "node scripts/check-runtime-deps.mjs",
86 "gen-themes": "node scripts/generate-theme-css.mjs",
Long lines were clipped for display.