2,004,887 packages matching “code-governance”

@haverstack/commons

v0.34.0 · 3 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Canonical Schema Commons type definitions for Haverstack — register commons types exactly as written

325Downloads across all versions in the last 7 days, from the official npm downloads API.CC0-1.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.34.0 (the latest release), from the OSV.dev database.

pi-daddy

v0.43.1 · 2 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Capability governance for pi sub-agents: spawn Agent Skills (SKILL.md) definitions whose allowed-tools becomes a grant that can only narrow going down a delegation tree, enforced by pi's own --tools allowlist, with an append-only ledger.

2.2KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.43.1 (the latest release), from the OSV.dev database.

@lssm-tech/lib.companyos-spec

v3.0.5 · 13 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Contract-first CompanyOS V0/V1 specifications for bounded company operations.

4.5KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v3.0.5 (the latest release), from the OSV.dev database.

@deepseek-ai/dsh-client-modules

v0.0.1-rc.1 · 1 month ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Client module system, dual-face: node half composes the __DSH_BOOT__ entry graph (incremental dsh.client scan, bundle route, index tap, webPlugins service); browser half is the lazy-CJS module table the vendored cordis Loader consumes as its internal seam

509.4KDownloads across all versions in the last 7 days, from the official npm downloads API.BSD-3-ClauseLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.0.1-rc.1 (the latest release), from the OSV.dev database.

@recallnet/docs-governance-policy

v0.3.1 · 6 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Shared policy loader and path resolution helpers for docs governance remark plugins.

365Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.3.1 (the latest release), from the OSV.dev database.

@flowfuse/flowfuse

v3.1.0 · 7 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

An open source low-code development platform

4.3KDownloads across all versions in the last 7 days, from the official npm downloads API.SEE LICENSE IN ./LICENSELicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v3.1.0 (the latest release), from the OSV.dev database.

trackfw

v9.1.0 · 2 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Governance CLI for AI-native software delivery and AI coding agents. Enforces traceability: ADR → REQ → ROADMAP → kanban. Native support for Codex, Claude Code, Gemini CLI, Cursor, Copilot, Windsurf, Amazon Q, OpenCode, and Kiro.

690Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v9.1.0 (the latest release), from the OSV.dev database.

@rigour-labs/core

v6.5.4 · 33 minutes ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Rigour's review engine: deterministic gates on changed lines, rules and lessons learned from your team's fixes, and per-check precision from what you fix versus dismiss, across TypeScript, JavaScript, Python, Go, Ruby and C#.

2.8KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v6.5.4 (the latest release), from the OSV.dev database.

@11ai/execution-governance

v0.4.2 · 14 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.

94Downloads across all versions in the last 7 days, from the official npm downloads API.Apache-2.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.4.2 (the latest release), from the OSV.dev database.

@salesforce/capg-client

v1.4.1 · 1 month ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

TypeScript client library for CAPG (Coding Agent Policy Governance) data fetching

830Downloads across all versions in the last 7 days, from the official npm downloads API.SEE LICENSE IN LICENSE.txtLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.4.1 (the latest release), from the OSV.dev database.

@nexusclawhq/cli

v0.3.72 · 4 hours ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

NexusClaw CLI - 元数据管理命令行工具

513Downloads across all versions in the last 7 days, from the official npm downloads API.AGPL-3.0-onlyLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.3.72 (the latest release), from the OSV.dev database.

@aragon/gov-ui-kit

v2.11.4 · 23 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Implementation of the Aragon's Governance UI Kit

245Downloads across all versions in the last 7 days, from the official npm downloads API.GPL-3.0License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v2.11.4 (the latest release), from the OSV.dev database.

@claudexor/policy

v3.17.2 · 1 day ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Typed risk classifier + thin policy (path guard, require-human, deny lists). No keyword-regex governance.

1.9KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v3.17.2 (the latest release), from the OSV.dev database.

@qijenchen/governance

v0.1.0-beta.96 · 2 months ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Provider-neutral DS-author control plane for deterministic snapshots, adapters, checks, and evidence manifests.

676Downloads across all versions in the last 7 days, from the official npm downloads API.UNLICENSEDLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.0-beta.96 (the latest release), from the OSV.dev database.

@rigour-labs/cli

v6.5.4 · 32 minutes ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Code review that happens while your agent writes: deterministic checks on the lines it changed, quiet unless it can prove a defect, and learning from your team's fixes and dismissals. Works with Claude Code, Cursor, Codex, Cline and Windsurf.

2.5KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v6.5.4 (the latest release), from the OSV.dev database.

@axosoft/nan

v2.22.0-gk.1 · 1 year ago

95
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Native Abstractions for Node.js: C++ header for Node 0.8 -> 22 compatibility

10.0KDownloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v2.22.0-gk.1 (the latest release), from the OSV.dev database.

@innleaders/mcp

v1.1.14 · 14 hours ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

MCP server da biblioteca de governança InnLeaders — expõe políticas, agentes, marcas e o design system (governance:// + brand://) para qualquer IA, sem acesso ao repo

87Downloads across all versions in the last 7 days, from the official npm downloads API.UNLICENSEDLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.1.14 (the latest release), from the OSV.dev database.

@duckcodeailabs/dql-plugin-api

v1.17.2 · 15 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Stable plugin contracts for DQL — connectors, chart renderers, governance rule packs. Frozen at v1.0.

137Downloads across all versions in the last 7 days, from the official npm downloads API.MITLicense declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v1.17.2 (the latest release), from the OSV.dev database.

@xemahq/resource-governance-internal-api-client

v0.1.30 · 10 hours ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

<!-- Generated by @xemahq/api-client-generator. Do not edit by hand. --> <p align="center"> <svg width="680" height="120" viewBox="0 0 680 120" fill="none" xmlns="http://www.w3.org/2000/svg" role="img" aria-label="@xemahq/resource-governance-internal-api-

211Downloads across all versions in the last 7 days, from the official npm downloads API.LicenseRef-Xema-BSL-1.1License declared in the package manifest.

No known vulnerabilities

Known vulnerabilities affecting v0.1.30 (the latest release), from the OSV.dev database.

@warpgogol/werkstatt-typescript

v3.1.0 · 14 days ago

100
0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.

Werkstatt TypeScript plugin — generic TypeScript TurboRepo stack with best-practice validators.

25.7KDownloads across all versions in the last 7 days, from the official npm downloads API.

No known vulnerabilities

Known vulnerabilities affecting v3.1.0 (the latest release), from the OSV.dev database.