* Mitigate axios supply-chain compromise (CVE-2026-03-31)
Pin axios to 1.13.5 via overrides to prevent resolution of compromised
1.14.1/0.30.4 versions. Add bunfig.toml with minimumReleaseAge=604800
(7 days) and .npmrc min-release-age=7 as defense-in-depth against
future supply-chain attacks.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Add changeset for axios supply-chain mitigation
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- rename package names/imports/docs/scripts to @grimoirelabs/*
- keep CLI bin name as grimoire
- update publish docs for new scope
- fix formatting in venue tests