- scripts/check-phase10.sh with --self-test, --go, --security, --postgres,
--spa, --openapi, --dist, --hygiene, --evidence and --all
- phase10_detect refuses failed, skipped, zero-test, non-JSON and build-failed
go test runs and named tests that did not pass
- the two known fonoteka parity failures are the only allow-listed ones and
refuse the gate once they pass again
- hygiene enforces the framework/app boundary, SC-4 alias-only API types,
typed-client-only HTTP, no raw HTML, same-origin dist, named lucide imports,
no retired admin prefix routes and a test import for every SPA module