{"_id":"@antihero/nodenet","_rev":"9-aaa7d44f2996447547edf6462128c01e","name":"@antihero/nodenet","dist-tags":{"latest":"0.6.0"},"versions":{"0.1.0":{"name":"@antihero/nodenet","version":"0.1.0","keywords":["graph","code-graph","ownership","authority","governance","living-context","lcdd","impact-analysis","reviewers","ai-agents"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.1.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"e50d4d5bb55265825ac7e7a0f76e8f625a0c8bbe","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.1.0.tgz","fileCount":96,"integrity":"sha512-QEgv4AJ6EUdQlBOkrV4CqHqLXffdbTQSNkbRXJCb9n2w/AUrwo+k+zwaEXd87eI21gPH/KC8NOV252fKbhAQdg==","signatures":[{"sig":"MEUCIQC93HQOspo+2v0T5pkr3JobiPQoJw/qcpWk3C7Pe32GmgIgBqvndbf947S0yRy29CO+9ZeTwQgI58qujEkJ00l/PaM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":458028},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"af70ade6e8c55b1d4a7736f4430f7a53589aec8b","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run test && npm run build"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, context, ownership, and authority into an explainable graph so humans and AI can safely understand the impact of software changes.","directories":{},"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","typescript":"^5.6.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.1.0_1786111551708_0.19147144493535206","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@antihero/nodenet","version":"0.2.0","keywords":["graph","code-graph","ownership","authority","governance","living-context","lcdd","impact-analysis","reviewers","ai-agents"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.2.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"e9a9fc5d65919fd02d88cbb2cd67698fe2e828e0","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.2.0.tgz","fileCount":111,"integrity":"sha512-SvoH1inajwPNZAkAcpJb8kQP6CU0sQFd1+LXVPIVg12kwiLkyco0DmkDZJWY3AjhpBDVpnJKHnJKNibAq2Gk4A==","signatures":[{"sig":"MEYCIQDbWwDkwWLGcg9mNYjedK9rv/VPEbw5AA+p48bO3GVExgIhAJ1GeCcP68NjHHRjm8Kj1CPZk/WHHTjeNn4gtRN6wDvj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":529946},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"af70ade6e8c55b1d4a7736f4430f7a53589aec8b","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run test && npm run build"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, context, ownership, and authority into an explainable graph so humans and AI can safely understand the impact of software changes.","directories":{},"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","typescript":"^5.6.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.2.0_1786112746860_0.4202166128308291","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@antihero/nodenet","version":"0.3.0","keywords":["graph","code-graph","ownership","authority","governance","living-context","lcdd","impact-analysis","reviewers","ai-agents"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.3.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"9ccc899c72cd94a9c2471410188d332dc7833bf6","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.3.0.tgz","fileCount":120,"integrity":"sha512-X1LutmWRX/iOxCnVIaUVAq4OboaHHh49/+NQrlKvvvMHsgFF74E2W7f03WCtY9RvKnXXUbdgmXzyT9yyBWHzuw==","signatures":[{"sig":"MEUCIQDKZm5ruh7fGQgSAq8VGPdgCZoNvvmP7DwOWiPPfR7OlQIgPVFqugRHyKyznbFmnyOKPYBNcTBQ1tFGlbb+J1HQdBo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":590347},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"aa611c86d425b9168c9a863d0f31fc522fd07281","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run test && npm run build"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, context, ownership, and authority into an explainable graph so humans and AI can safely understand the impact of software changes.","directories":{},"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","typescript":"^5.6.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.3.0_1786114441105_0.0885070277486375","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@antihero/nodenet","version":"0.4.0","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.4.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"36042d8e729dedcf78fee5d849b1b915e0d57dac","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.4.0.tgz","fileCount":156,"integrity":"sha512-3sSioB50lejaFtU0VIK94fOrDICmI5SpK93tkYUd0UpusFMCHYSpGg9ZM/8hNfU9jTg+R9IuUBzgbo96l03J2w==","signatures":[{"sig":"MEUCIC+WybgZN9qZCqe8vXtDbtb5BGAI6WX31GOBAvAQH5T8AiEA/XILT84YvJfn37JW9MrNAeTqW//xaObyVRZi855axDw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":798313},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"1fa5ad34baedfeab1df0515efd60e82cb4b3de03","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run test && npm run build"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, living context, ownership, and authority into an explainable graph — so humans and AI know what a change affects and who must review it. Deterministic, local-first, zero LLM/vector dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","@lcdd/core":"0.6.0","typescript":"^5.6.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.4.0_1786201808217_0.74069340325398","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@antihero/nodenet","version":"0.5.0","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.5.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"f4c85eaa962add85b976a73907b948b6e134c3b0","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.5.0.tgz","fileCount":226,"integrity":"sha512-i+B8vS2eaqaBBRJvdSvTOfHO6nzAWYpv1oanyKXX+YA09krUx83oJ/TDZskuO+2BusPRKRR9/UCVvHTbqN53kQ==","signatures":[{"sig":"MEYCIQD9x+toYBGQq9lbjfsZU79mLdgngnSv2VXDJOJpollP7wIhAOrr8RX82XovG0uJmFLAxMV03dyedMJf8dYfW1dBGN+Q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1157596},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b93251d2282928733d00e31ec24834a2646b8d86","scripts":{"test":"vitest run","build":"npm run clean && tsc -p tsconfig.json","clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run test && npm run build"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, living context, ownership, and authority into an explainable graph — so humans and AI know what a change affects and who must review it. Deterministic, local-first, zero LLM/vector dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","@lcdd/core":"0.6.0","typescript":"^5.6.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.5.0_1786262871078_0.9046262393896454","host":"s3://npm-registry-packages-npm-production"}},"0.6.0-beta.1":{"name":"@antihero/nodenet","version":"0.6.0-beta.1","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.6.0-beta.1","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"e14d267216cf1f513fb8c368ca47e94aeb017919","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.6.0-beta.1.tgz","fileCount":244,"integrity":"sha512-HFjTHotCWKMhhYOymmnnxulb+++RsQka4xq+i0d4zIEdk2W7kwscQUYgX3qEGimsYR5vz1OMtEMYlEUIOZxy+A==","signatures":[{"sig":"MEYCIQCmnc540sYFFoA6kO93WS08sQIZCfREpS7yzwOaDHH0bAIhAIGOJoVq0zRKpgD9xP2BhLh1TMM0i46/Astl+Y77Yp3G","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1278324},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"5df1f571495672f7379264ef25d164c2257627a1","scripts":{"test":"vitest run","build":"npm run clean && tsc -p tsconfig.json","clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:e2e:self":"node scripts/e2e-self.mjs","prepublishOnly":"npm run typecheck && npm run test && npm run build","benchmark:languages":"node dist/cli/cli.js benchmark-languages --json","benchmark:governance":"node scripts/benchmark-governance-fixture.mjs"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"NodeNet maps code, living context, ownership, and authority into an explainable graph — so humans and AI know what a change affects and who must review it. Deterministic, local-first, zero LLM/vector dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","@lcdd/core":"0.6.0","typescript":"^5.6.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.6.0-beta.1_1786272615032_0.5874291301327021","host":"s3://npm-registry-packages-npm-production"}},"0.6.0-beta.2":{"name":"@antihero/nodenet","version":"0.6.0-beta.2","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.6.0-beta.2","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"e3b10b7497939d2da759c7c5f3f73cd0e840bab8","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.6.0-beta.2.tgz","fileCount":265,"integrity":"sha512-B5Au2crjCX0XA+biauhCn35yphCvafKe0oI+UYuzr56qS6pZsdIVTpp25+sZ28ovQ76zFEYBIwqTFBU0RrxVhQ==","signatures":[{"sig":"MEQCIFQLesnNYXtXLZZBy69SWVVsHT/iCN9L4MI0CeSoyjKbAiBUcjHYUiuGG1lWKq5gFE1RoHzQvcjDqVHFLSgEGaxggA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1396165},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"5df1f571495672f7379264ef25d164c2257627a1","scripts":{"test":"vitest run","build":"npm run clean && tsc -p tsconfig.json","clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:e2e:self":"node scripts/e2e-self.mjs","prepublishOnly":"npm run typecheck && npm run test && npm run build","benchmark:languages":"node dist/cli/cli.js benchmark-languages --json","benchmark:governance":"node scripts/benchmark-governance-fixture.mjs","experiment:token-tasks":"npm run build && node scripts/e2e-self.mjs","experiment:score-governed-ab":"node scripts/score-governed-change-ab.mjs"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"Governance-aware repository intelligence for AI agents: route changes, explain impact, and resolve the right reviewers. Deterministic and local-first.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","@lcdd/core":"0.6.0","typescript":"^5.6.3"},"publishConfig":{"tag":"beta","access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.6.0-beta.2_1786292163989_0.7035468858336162","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@antihero/nodenet","version":"0.6.0","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","_id":"@antihero/nodenet@0.6.0","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"homepage":"https://github.com/Lelianto/nodenet#readme","bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"bin":{"nodenet":"dist/cli/cli.js"},"dist":{"shasum":"493bd90a9b866e254a8a857da33c25f86852c27b","tarball":"https://registry.npmjs.org/@antihero/nodenet/-/nodenet-0.6.0.tgz","fileCount":265,"integrity":"sha512-r4rxW+Q6HhHY4gw2IcAo8HdeFaNv0vflPWHX+zPNP4PRwu47ncyJfZWTLU5eDkajnbZgcjEH+y9pQvK0CKh4iA==","signatures":[{"sig":"MEUCIQCyWqnSTNM2CWld8FeIJownFeIc7EmeecLKbi23jcmrsQIgTu40oU0YaDlZRyKaOe/htrehnRYaGRJwRR8Vn+ldZuw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1396561},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b6907e8e369c5ee8a93091b43a4899308f588187","scripts":{"test":"vitest run","build":"npm run clean && tsc -p tsconfig.json","clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:e2e:self":"node scripts/e2e-self.mjs","prepublishOnly":"npm run typecheck && npm run test && npm run build","benchmark:languages":"node dist/cli/cli.js benchmark-languages --json","benchmark:governance":"node scripts/benchmark-governance-fixture.mjs","experiment:token-tasks":"npm run build && node scripts/e2e-self.mjs","experiment:score-governed-ab":"node scripts/score-governed-change-ab.mjs"},"_npmUser":{"name":"antihero","email":"lelianto.eko@gmail.com"},"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"_npmVersion":"10.8.2","description":"Governance-aware repository intelligence for AI agents: route changes, explain impact, and resolve the right reviewers. Deterministic and local-first.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.6","dependencies":{"valibot":"^1.0.0","commander":"^12.1.0","@lcdd/core":"0.6.0","typescript":"^5.6.3"},"publishConfig":{"tag":"latest","access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.4","fast-check":"^3.21.0","@types/node":"^20.16.0"},"_npmOperationalInternal":{"tmp":"tmp/nodenet_0.6.0_1786327354667_0.4052460003291498","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-08-07T14:05:51.391Z","modified":"2026-08-10T02:04:15.243Z","0.1.0":"2026-08-07T14:05:51.839Z","0.2.0":"2026-08-07T14:25:46.998Z","0.3.0":"2026-08-07T14:54:01.271Z","0.4.0":"2026-08-08T15:10:08.376Z","0.5.0":"2026-08-09T08:07:51.250Z","0.6.0-beta.1":"2026-08-09T10:50:15.196Z","0.6.0-beta.2":"2026-08-09T16:16:04.151Z","0.6.0":"2026-08-10T02:02:34.889Z"},"bugs":{"url":"https://github.com/Lelianto/nodenet/issues"},"author":{"name":"Lelianto Pradana"},"license":"Apache-2.0","homepage":"https://github.com/Lelianto/nodenet#readme","keywords":["graph","code-graph","knowledge-graph","dependency-graph","static-analysis","multi-language","typescript","javascript","python","golang","java","csharp","php","ownership","authority","governance","living-context","lcdd","codeowners","impact-analysis","change-impact","reviewers","code-review","merge-policy","ai-agents","mcp","model-context-protocol","claude-code","codex","developer-tools","cli","visualization","graph-visualization"],"repository":{"url":"git+https://github.com/Lelianto/nodenet.git","type":"git"},"description":"Governance-aware repository intelligence for AI agents: route changes, explain impact, and resolve the right reviewers. Deterministic and local-first.","maintainers":[{"name":"antihero","email":"lelianto.eko@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"docs/logo.svg\" alt=\"NodeNet\" width=\"320\" />\n</p>\n\n<p align=\"center\">\n  <strong>Governance-aware repository intelligence for AI agents.</strong>\n</p>\n\n<p align=\"center\">\n  <img src=\"docs/language-support.svg\" alt=\"NodeNet supports seven full and three basic programming languages\" width=\"900\" />\n</p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@antihero/nodenet\"><img src=\"https://img.shields.io/npm/v/@antihero/nodenet?logo=npm&label=version\" alt=\"npm version\" /></a>\n  <a href=\"https://www.npmjs.com/package/@antihero/nodenet\"><img src=\"https://img.shields.io/npm/dm/@antihero/nodenet\" alt=\"npm downloads\" /></a>\n  <a href=\"LICENSE\"><img src=\"https://img.shields.io/npm/l/@antihero/nodenet\" alt=\"license\" /></a>\n  <a href=\"package.json\"><img src=\"https://img.shields.io/badge/node-%3E%3D20-339933?logo=node.js\" alt=\"Node.js >= 20\" /></a>\n  <a href=\"tsconfig.json\"><img src=\"https://img.shields.io/badge/TypeScript-strict-3178C6?logo=typescript\" alt=\"TypeScript strict\" /></a>\n  <a href=\"https://github.com/Lelianto/nodenet/actions\"><img src=\"https://img.shields.io/github/actions/workflow/status/Lelianto/nodenet/ci.yml?label=ci\" alt=\"CI\" /></a>\n  <a href=\"https://github.com/Lelianto/nodenet\"><img src=\"https://img.shields.io/github/stars/Lelianto/nodenet?style=social\" alt=\"GitHub stars\" /></a>\n</p>\n\nAI coding agents can search code. They do not automatically know which rules\ngovern a change, who owns it, what its blast radius is, or when human approval\nis mandatory. Software is more than code —\narchitecture decisions, business rules, ownership boundaries, security\npolicies, and team responsibilities determine whether a change should be made\nand who should review it.\n\n**NodeNet connects code structure, living context, ownership, authority, and\nthe actual Git change so an AI agent can route work, respect constraints, and\nrequest the right review before changing code.** It is deterministic,\nlocal-first, and requires no LLM or vector store for core analysis. Network\naccess is reserved for explicit integrations such as GitHub.\n\nIt is the practical reference implementation of **Living Context Driven\nDevelopment (LCDD)** — context treated as a living, versioned, governed\nartifact ([living-context-driven-development](https://github.com/Lelianto/living-context-driven-development)).\n\n---\n\n## Contents\n\n- [What it does](#what-it-does)\n- [The problem it solves](#the-problem-it-solves)\n- [How it works](#how-it-works)\n- [See it in action](#see-it-in-action)\n- [Why NodeNet (vs Graphify & co)](#why-nodenet-vs-graphify--co)\n- [Measured evidence](#measured-evidence)\n- [Requirements](#requirements)\n- [Install](#install)\n- [Quick start](#quick-start)\n- [CLI reference](#cli-reference)\n- [How governance is declared](#how-governance-is-declared)\n- [Configuration](#configuration)\n- [GitHub pull-request integration](#github-pull-request-integration)\n- [AI assistant integration (MCP)](#ai-assistant-integration-mcp)\n- [Team setup](#team-setup)\n- [Example project](#example-project)\n- [Security & privacy](#security--privacy)\n- [Documentation](#documentation)\n- [Testing](#testing)\n- [Roadmap](#roadmap)\n- [Troubleshooting & FAQ](#troubleshooting--faq)\n- [License](#license)\n\n---\n\n## What it does\n\n| Capability | What you get |\n| --- | --- |\n| **Explainable code graph** | Typed nodes + edges with provenance — every connection says *why* it exists |\n| **Bounded repository intelligence** | Lean file-ranked `ask`, hypothetical `affected`, and progressive `route` → `map` → `evidence` → `source` context keep governed retrieval scoped |\n| **Living context** | Rules (business, security, compliance) as versioned artifacts with a lifecycle and freshness decay |\n| **Ownership & authority** | Who owns code, who approves changes, ranked from LCDD > NodeNet > CODEOWNERS > git history |\n| **Change impact** | A git diff becomes a symbol-level report: severity, affected code, ownership boundaries |\n| **Review governance** | Deterministic reviewers: `suggested` / `required` / `authorityRequired`, deduplicated, with reasons |\n| **AI context bundles (MSC)** | Minimum Sufficient Context for AI agents, secret-scanned, provenance-marked |\n| **MCP server** | The whole graph as MCP tools for Claude Code, Codex, and any MCP client |\n| **GitHub PR integration** | Post the impact comment and request reviewers on a PR |\n| **Interactive visualization** | Force-directed `graph.html` with communities, search, and filters — plus static SVG export |\n| **Local-first & deterministic** | Core analysis uses no LLM, vector store, network, or repository-code execution; identical input produces identical output |\n\nLatest reproducible evidence: [medium-repository feature verification and live\nA/B](docs/experiments/nodenet-ab-medium-feature-verification-2026-08-09.md),\n[self-repository E2E dogfooding](docs/e2e-self-benchmark-2026-08-09.md), and\nthe [governed-change A/B protocol](docs/experiments/governed-change-ab-protocol.md).\n\nNodeNet has three product outcomes: **Route** to the smallest relevant change\nsurface, **Govern** with applicable constraints and authority, and **Verify**\nthe real diff for impact and reviewers. Token efficiency is a constraint, not\nthe primary promise: required governance is never hidden to make a payload\nlook smaller.\n\nMedia files are indexed as local, non-authoritative retrieval candidates. An\noptional bounded `<media-file>.nodenet.json` sidecar may provide a `summary` and\n`concepts`; these inferred concepts improve discovery but can never create\ngovernance authority or a blocking decision by themselves.\n\n## The problem it solves\n\nA normal dependency graph can tell you:\n\n> `CheckoutForm → PaymentService`\n\nNodeNet understands:\n\n> `CheckoutForm` **calls** `PaymentService`, which is **owned by** `Payment Team`,\n> which is **governed by** `PAYMENT-003`, which requires **approval from**\n> `Finance Team`.\n\nSo when the Checkout Team changes `CheckoutService`:\n\n- **Impact:** HIGH — the change crosses an ownership boundary.\n- **Required review:** `@payment-team`\n- **Authority review:** `@finance-team`\n- **Why:** `CheckoutService` modifies behavior dependent on `PaymentService`, which is governed by `PAYMENT-003`.\n\nThis is the core value: **not just what is connected, but what governs it, who\nowns it, and who must review a change.**\n\n## How it works\n\n`nodenet build` runs a deterministic, offline pipeline (see\n[ARCHITECTURE.md](ARCHITECTURE.md)):\n\n<p align=\"center\">\n  <img src=\"docs/how-it-works.svg\" alt=\"NodeNet turns repository signals and LCDD governance into explainable change decisions\" width=\"1000\" />\n</p>\n\nAnalysis commands (`query`, `related`, `trace`, `impact`, `reviewers`, `health`,\n...) load the persisted graph, re-validate it at runtime, and answer from one\nunified, explainable model. Only explicitly networked workflows such as GitHub\nintegration send data off the machine.\n\n## See it in action\n\nReal output from the [example project](examples/payments-demo):\n\n```\n$ nodenet owner src/payment/PaymentService.ts\nsrc/payment/PaymentService.ts → payment-team (source: lcdd, confidence: AUTHORITATIVE)\n\n$ nodenet trace runCheckout saveSettlement\nrunCheckout() @ src/checkout/CheckoutFlow.ts:10\n  --calls--> checkout() @ src/checkout/CheckoutService.ts:4\n  --calls--> createSettlement() @ src/payment/PaymentService.ts:4\n  --calls--> saveSettlement() @ src/payment/SettlementRepository.ts:3\n\n$ nodenet governed-by src/payment/PaymentService.ts\nContexts governing src/payment/PaymentService.ts:\n  PAYMENT-003 [ACTIVE] STANDARD — Settlement Processing Rule (approvers: finance-team)\n  SEC-009 [ACTIVE] HARDENED — PCI Payment Data Validation (approvers: security-team)\n\n$ nodenet impact --base main\nImpact: HIGH\nOwnership boundary crossed: checkout-team → payment-team (via PaymentService)\nAffected living context: PAYMENT-003 [ACTIVE] STANDARD, SEC-009 [ACTIVE] HARDENED\nReview required: payment-team\nAuthority review: finance-team, security-team\n\n$ nodenet reviewers --base main\nAuthority approval required:\n  finance-team\n    because: PAYMENT-003 requires approval from finance-team (STANDARD, status ACTIVE)\n  security-team\n    because: SEC-009 requires approval from security-team (HARDENED, status ACTIVE)\n```\n\nOpen the [interactive graph](examples/payments-demo/.nodenet/graph.html) from the\nexample project to explore the Graphify-style governance map: switch between\nArchitecture, Governance, and Change views; pan/zoom; inspect evidence paths;\nand filter by community, semantic layer, or relationship type.\n\n## Why NodeNet (vs Graphify & co)\n\nCode-graph tools such as [Graphify](https://github.com/Graphify-Labs/graphify)\nexcel at *understanding* a codebase — mapping code/docs into a queryable graph\nfor AI assistants. NodeNet does that too, but its focus is the other half of\nthe job: **governing how code changes**.\n\n| | NodeNet | Graphify & code-graph tools |\n| --- | --- | --- |\n| Local, deterministic code graph (no LLM, no vector store) | ✅ | ✅ |\n| Interactive visualization + communities | ✅ | ✅ |\n| AI / MCP integration | ✅ | ✅ |\n| **Living context as governed, versioned artifacts** | ✅ | ⚠️ passive extraction only |\n| **Ownership ranking (LCDD > NodeNet > CODEOWNERS)** | ✅ | ❌ |\n| **Authority levels + lifecycle (DRAFT → ACTIVE → ARCHIVED)** | ✅ | ❌ |\n| **Symbol-level change impact + severity** | ✅ | partial (PR dashboard) |\n| **Deterministic reviewer resolution with reasons** | ✅ | ❌ (AI triage) |\n| **Merge-policy gating on hardened/mandatory rules** | ✅ | ❌ |\n| **AI context bundles, secret-scanned** | ✅ | ❌ |\n| Multi-language parsing | 10 languages: 7 full + 3 basic | 36+ |\n| Markdown/ADR/OpenAPI/SQL/Terraform ingestion | ✅ deterministic | ✅ |\n\n**NodeNet is the governance layer for AI-driven development.** It answers\n*\"who decides, and what may an AI agent change?\"* — not just *\"what is\nconnected?\"* It treats rules as living, owned, approved artifacts, and it can\nautomate review requests and CI gating from that governance. Graphify helps AI\nunderstand code; NodeNet helps teams keep code changeable, safely.\n\n## Measured evidence\n\nThe latest medium-repository verification used 1,236 graph nodes, six living\ncontexts, frozen hidden acceptance tests, and real `cl100k`/`o200k` tokenizer\ncounts. These are observed results, not universal guarantees:\n\n| Measurement | Observed result |\n| --- | ---: |\n| Lean `ask` vs full graph result | **130 vs 5,338 tokens** (o200k), identical recommended files |\n| Governed `route` context | **157 tokens** (o200k) |\n| Progressive evidence | route 157 → map 716 → evidence 842 tokens |\n| Deterministic retrieval evaluation | **10/10 gates**, 100% mandatory-context recall |\n| Live medium-repo task A/B (n=1) | control ~1,028 vs NodeNet ~1,129 task-input tokens; both acceptance and regression suites passed |\n| Retrieval quality in that live task | direct target, zero decoys, plus impact/reviewer evidence |\n\nThe honest conclusion is that NodeNet reduces exploration waste and adds\ngovernance evidence. It does **not** yet claim universal end-to-end token\nsavings or a repository-size break-even threshold. A public task-token claim\nis gated on at least ten identical paired tasks, provider telemetry, quality\nnon-inferiority, 100% mandatory-context/reviewer recall, and a bootstrap 95%\nconfidence interval. See the [positioning](docs/product-positioning.md) and\n[A/B protocol](docs/experiments/governed-change-ab-protocol.md).\n\n## Requirements\n\n| Requirement | Minimum | Check |\n| --- | --- | --- |\n| Node.js | 20+ | `node --version` |\n| git | any | `git --version` (needed for `impact` / `reviewers` / `update`) |\n\n## Install\n\n```bash\nnpm install -g @antihero/nodenet\n```\n\nOr from source:\n\n```bash\ngit clone https://github.com/Lelianto/nodenet.git\ncd nodenet\nnpm install\nnpm run build\n```\n\nThen run it inside any repository you want to map:\n\n```bash\nnodenet init      # creates nodenet.config.json + .nodenet/\nnodenet build     # scan, parse, analyze, persist the unified graph\nnodenet graph     # interactive visualization (.nodenet/graph.html)\n```\n\n## Quick start\n\n```bash\nnodenet init             # creates nodenet.config.json + .nodenet/\nnodenet build            # scan, parse, analyze, persist the unified graph\nnodenet query PaymentService\nnodenet ask \"what connects checkout to settlement?\" --json # lean routing default\nnodenet ask \"what connects checkout to settlement?\" --full --json\nnodenet affected PaymentService --depth 2\nnodenet trace LoginForm AuthService\nnodenet governed-by PaymentService\nnodenet owner src/payment/PaymentService.ts\nnodenet owner src/payment/PaymentService.ts --explain\nnodenet context PaymentService --detail route  # files + owner + governance\nnodenet context PaymentService --detail evidence\nnodenet context PaymentService --detail source # bounded, secret-scanned snippets\nnodenet impact --base main                    # analyze the current change\nnodenet reviewers --base main                 # who should review it\nnodenet report                                # highlights: god nodes, communities, governance\nnodenet health                                # context health report\nnodenet health --uncovered                    # list files missing ownership\nnodenet snapshot -o .nodenet/snapshot.json   # record graph state for CI\nnodenet diff-snapshot .nodenet/snapshot.json # exit 2 when graph drift exists\nnodenet graph                                 # interactive HTML visualization\nnodenet graph --change --base main            # overlay impact + governance decision\nnodenet graph -f svg -o graph.svg             # static SVG image\nnodenet changes --base main --refs feature-a feature-b # local multi-branch collision triage\nnodenet install --platform codex              # query-first project guidance\nnodenet serve --port 7341                     # MCP Streamable HTTP\nnodenet serve --token \"$TOKEN\" --scopes graph:read,context:read\n```\n\nIncremental builds reuse unchanged local parse results. Built-in deterministic\nadapters cover ten major languages. Every Markdown file (README, guides, ADRs,\nRFCs, docs), OpenAPI specs, SQL schemas, and Terraform resources is added to\nthe same graph without an LLM or paid service. Every relationship is classified as\n`EXTRACTED`, `DECLARED`, `INFERRED`, `AMBIGUOUS`, or `OBSERVED`.\n\n| Support | Languages | Extraction contract |\n|---|---|---|\n| Full | TypeScript, JavaScript, Python, Go, Java, C#, PHP | declarations, imports/dependencies, visibility/exports, classes and methods, language-specific structural relationships |\n| Basic | Rust, Ruby, Kotlin | files, primary declarations, and imports/dependencies |\n\nRun `nodenet languages` or `nodenet languages --json` to inspect the exact\nadapter and capability matrix installed in the current NodeNet version.\nFull per-language examples and access methods are documented in\n[docs/languages.md](docs/languages.md).\n\nMachine-readable output: append `--json` to `build`, `query`, `related`,\n`trace`, `context`, `explain`, `owner`, `governed-by`, `impact`, `reviewers`,\n`conflicts`, `health`. Run `nodenet --help` or `nodenet <command> --help` for\nthe full option reference.\n\n## CLI reference\n\n| Command | Description |\n| --- | --- |\n| `init` | Create `nodenet.config.json` and the `.nodenet/` directory |\n| `build` | Scan, parse, analyze and persist the unified graph |\n| `update` | Incremental rebuild from changed files (fingerprint-based) |\n| `watch` | Rebuild on file changes |\n| `query <name>` | Find nodes by name |\n| `ask <question>` | Lean intent-aware routing; add `--full` for matches, connections, and ranking evidence |\n| `affected <target>` | Hypothetical graph blast radius before a change exists |\n| `related <name>` | Show direct neighbors of a node |\n| `trace <from> <to>` | Shortest explainable path between two nodes |\n| `context [target]` | List contexts or build progressive `route`, `map`, `evidence`, or bounded `source` MSC output; `--compat v1` restores the beta.1 wire shape |\n| `feedback --query-id ... --outcome ...` | Record local opt-in retrieval outcomes without changing authority |\n| `explain <name>` | A node and every relationship with provenance |\n| `owner <path-or-symbol> [--explain]` | Who owns a file or symbol, optionally with the full resolution chain |\n| `governed-by <name>` | Living contexts governing a node |\n| `impact [--base <ref>]` | Analyze the current change (git diff) for impact |\n| `reviewers [--base <ref>]` | Resolve reviewers (suggested / required / authorityRequired) |\n| `conflicts` | List conflicting living contexts |\n| `health [--uncovered]` | Living context health report, optionally listing files without ownership |\n| `report` | Deterministic highlights report: god nodes, surprising connections, communities, governance, suggested questions |\n| `snapshot [-o <file>]` | Persist a stable, sorted graph snapshot for CI |\n| `diff-snapshot <file>` | Compare the current graph with a snapshot; exit `2` on drift |\n| `graph [-o <file>] [-f html\\|svg]` | Generate an interactive HTML viewer or static SVG image with communities |\n| `open [--change] [--base <ref>]` | Open the interactive graph in one command and hot-reload when repository files change |\n| `languages [--json]` | Show the ten-language support tier and capability matrix |\n| `changes --base <ref> --refs <refs...>` | Compare local branches for graph, context, and ownership collisions |\n| `bootstrap [--github]` | Create starter config, canonical LCDD policy, and optional GitHub workflow without overwriting files |\n| `benchmark --dataset <file>` | Measure reviewer precision/recall, false blocks, missed impacts, accuracy, and p50/p95 latency |\n| `benchmark-languages` | Execute positive and false-positive contracts across all ten adapters |\n| `benchmark-retrieval --dataset <file>` | Execute labeled questions against `ask` and MSC |\n| `benchmark-governance --dataset <file>` | Execute impact, reviewers, and decisions against labeled git-base scenarios |\n| `eval import-github` | Import historical GitHub PR/review metadata into a private local dataset |\n| `eval run` | Replay NodeNet safely against exact historical base/head commits |\n| `eval label` | Open the loopback-only blind-labeling Decision Lab |\n| `eval report` / `eval gate` | Compare labels with replay decisions and enforce quality thresholds |\n| `doctor [--json] [--fix]` | Report readiness and optionally install safe missing starter/workflow files |\n| `github pr [options]` | Analyze a PR; update an idempotent Check Run, comment, request reviewers, and audit the decision |\n| `mcp` | Run the MCP server over stdio for AI assistants |\n| `serve [--host] [--port] [--token] [--scopes] [--rate-capacity] [--rate-refill] [--reload-interval] [--no-reload]` | MCP Streamable HTTP with sessions, scopes, rate limits, and atomic reload |\n| `audit-verify [--json]` | Verify the tamper-evident local audit hash chain |\n| `install --platform <name>` | Install query-first guidance for Codex, Claude, Cursor, or Agent Skills |\n\n## How governance is declared\n\nLiving Context uses the canonical **LCDD 0.6.0 Registry** under\n`.lcdd/contexts/**/*.yaml`. NodeNet validates these artifacts with the pinned\n`@lcdd/core@0.6.0` SDK and retains the complete canonical object while deriving\nthe graph view it needs:\n\n```yaml\nid: PAYMENT-003\nversion: 1\ntitle: Settlement Processing Rule\ndescription: Settlement creation must be idempotent and auditable.\nsource:\n  type: documentation\n  location: docs/adr/003-settlement.md\nauthority:\n  source: { type: organization, id: finance-team, name: Finance Team }\n  level: 3\ncategory: domainRule\napplies_to: [src/payment/**]\nlifecycle: active\ngovernance:\n  classification: hardened-standard\n  approval_required: true\n  approvers: [finance-team]\neffective_date: 2026-08-08T00:00:00.000Z\nowner: payment-team\nenforcement:\n  mode: block\n```\n\nThe legacy `.nodenet/context.json` format remains readable for compatibility\nbut emits a deprecation warning. Preview and write a canonical migration with:\n\n```bash\nnodenet context --migrate\nnodenet context --migrate --write\n```\n\nOwnership can come from:\n\n1. **LCDD context metadata** (highest authority)\n2. **NodeNet explicit ownership** — `.nodenet/ownership.json` + `nodenet.config.json` overrides\n3. **CODEOWNERS**\n4. **Git history** — *suggestion only*, never a required reviewer\n\nSee [docs/concepts/living-context.md](docs/concepts/living-context.md) for the\nlifecycle (`draft → candidate → approved → active → …`) and\n[docs/concepts/ownership.md](docs/concepts/ownership.md) for the source ranking.\n\n## Configuration\n\n`nodenet init` writes a starter `nodenet.config.json`. Configuration is **data\nonly** — never executable code, and it is runtime-validated on every load:\n\n```json\n{\n  \"ignore\": [\"dist\", \"build\", \"coverage\", \".next\", \"out\"],\n  \"limits\": {\n    \"maxFileSizeBytes\": 1048576,\n    \"maxFiles\": 10000,\n    \"maxGraphNodes\": 100000,\n    \"maxGraphEdges\": 300000\n  },\n  \"reviewPolicy\": { \"LOW\": \"informational\", \"MEDIUM\": \"comment\", \"HIGH\": \"request\", \"CRITICAL\": \"approval\" },\n  \"contextFreshness\": { \"architecture\": \"180d\", \"security\": \"90d\", \"businessRule\": \"180d\", \"default\": \"180d\" },\n  \"ownership\": {\n    \"teams\": {\n      \"payment-team\": { \"name\": \"Payment Team\" },\n      \"checkout-team\": { \"name\": \"Checkout Team\" }\n    },\n    \"overrides\": []\n  },\n  \"developer\": { \"handle\": \"your-gh-handle\", \"team\": \"checkout-team\" },\n  \"relationships\": [\n    {\n      \"from\": \"CheckoutApi.submit\",\n      \"to\": \"SettlementProcessor.settle\",\n      \"relation\": \"calls\",\n      \"rationale\": \"POST /payments is implemented by the Python settlement service\"\n    }\n  ]\n}\n```\n\nKey sections: `ignore`, `limits` (resource limits that fail safely),\n`reviewPolicy` (severity → action), `contextFreshness` (decay durations),\n`ownership.teams` + `ownership.overrides`, `developer`, `secretPatterns` and\n`suppressions`, and `relationships`. Declared relationships model boundaries\nthat static parsing cannot observe (HTTP, queues, RPC, generated clients, and\ncross-language calls). They retain `config` provenance and are never inferred\nmerely because two files share a governance context. Schema reference:\n[src/config/config.ts](src/config/config.ts).\n\n## GitHub pull-request integration\n\n`nodenet github pr` runs inside a GitHub Actions checkout of the PR head and\nproduces the same deterministic impact + review report, optionally posting it:\n\n```bash\nnodenet github pr --repo owner/name --pr 42 --base main \\\n  --comment --request-reviewers --check --sha \"$GITHUB_SHA\" --mode warn\n```\n\n- `--comment` posts the impact + reviewers comment to the PR.\n- `--request-reviewers` requests **declared** reviewers only (required +\n  authority-required) — git-history suggestions are never auto-requested.\n- `--mode observe|warn|enforce` controls rollout. A blocking hardened/mandatory\n  decision exits with code `2` only in `enforce` mode, so the command can be a\n  required status check. `--json` emits the stable Governance Decision v1.\n- `--check --sha <commit>` creates or updates the named GitHub Check Run,\n  includes file annotations, retries transient API failures, and works for\n  `pull_request` and `merge_group` workflows.\n- Every execution records a source-free event in `.nodenet/audit.jsonl`.\n  Time-bounded emergency overrides require the exact decision ID, actor,\n  reason, and expiry; see [decision quality](docs/decision-quality.md).\n- Auth via `GITHUB_TOKEN` (least privilege: `contents: read`,\n  `checks: write`, `pull-requests: write`); `GITHUB_REPOSITORY` / `GITHUB_REF` /\n  `GITHUB_BASE_REF` are read automatically in Actions.\n- Design: [docs/adr/004-github-integration.md](docs/adr/004-github-integration.md).\n\n## Live graph and historical Decision Lab\n\nOpen the governance graph without finding generated files manually:\n\n```bash\nnodenet open\nnodenet open --change --base main\n```\n\nNodeNet starts a loopback-only server, opens the browser, watches source and\ngovernance files, incrementally rebuilds, and sends hot-reload events. Use\n`--no-open` for terminal/remote workflows and `--port 7342` for a fixed port.\nThe viewer defaults to the audit-friendly 2D map and includes a dependency-free\n**3D view** toggle. In 3D, drag to rotate, Shift+drag to pan, and scroll to zoom;\nuse the on-canvas arrow pad to move the camera and its center button to reset\nthe view. The keyboard arrow keys provide the same navigation, `Shift + Arrow`\nmoves faster, and `Home` or `0` resets the camera. These shortcuts are disabled\nwhile typing in search. Switch back to 2D whenever labels and evidence paths\nare the priority.\n\nHistorical evaluation can import GitHub PR metadata, replay exact commits in\nisolated temporary worktrees, blind-label results locally, and apply CI quality\nthresholds. See [historical decision evaluation](docs/evaluation.md).\n\n## AI assistant integration (MCP)\n\n`nodenet mcp` runs a Model Context Protocol server over stdio, exposing the\ngraph, living context, ownership, authority, impact and reviewers as tools for\nAI coding assistants (Claude Code, Codex, and any MCP client):\n\n```bash\nnodenet mcp                       # core retrieval preset\nnodenet mcp --tools governance    # governance-focused schemas\nnodenet mcp --tools all           # complete tool surface\n```\n\nTools: `ask`, `affected`, `query`, `related`, `trace`, `context` (Minimum Sufficient Context —\nsecret-scanned), `explain`, `governed_by`, `owner`, `impact`, `reviewers`,\n`health`, `graph`. All results are deterministic and provenance-backed.\nDesign: [docs/adr/005-mcp-server.md](docs/adr/005-mcp-server.md). Deployment and\ntroubleshooting: [docs/mcp-operations.md](docs/mcp-operations.md).\n\n## Team setup\n\nCanonical governance artifacts and the generated viewer are committed. The\nmachine graph remains generated and is rebuilt locally or in CI:\n\n```\n# commit these\n.lcdd/contexts/*.yaml      # canonical LCDD 0.6 Living Context Registry\n.nodenet/ownership.json    # authored explicit ownership\nnodenet.config.json        # review policy, teams, limits\n.nodenet/graph.html        # interactive visualization\n```\n\nRecommended workflow:\n\n1. One person runs `nodenet init` + `nodenet build` and commits the authored artifacts and viewer.\n2. Everyone pulls and runs `nodenet build` (or `nodenet open`) before `query`/`trace`/`impact`.\n3. `nodenet impact --base main` runs in CI on every PR (and `github pr` posts\n   the comment and requests reviewers).\n4. When rules change, edit `.lcdd/contexts/*.yaml` and commit — the lifecycle\n   and audit log keep the change explainable.\n\nThe [example project](examples/payments-demo) demonstrates the whole flow.\n\n## Example project\n\nSee [examples/payments-demo](examples/payments-demo) — a ready-made checkout →\npayment project with living context, ownership, authority and a cross-team PR\nscenario. It ships a pre-built interactive\n[graph.html](examples/payments-demo/.nodenet/graph.html) and a\n[README](examples/payments-demo/README.md):\n\n```bash\nnpm run build\ncd examples/payments-demo\n./demo.sh          # build, visualize, query, impact + reviewers\n```\n\n## Security & privacy\n\n- The repository is untrusted input. NodeNet never executes repository code.\n- Paths are validated (`SafeRelativePath`) and symlink-escapes are rejected.\n- Resource limits are configurable and fail safely.\n- Secret-like files are never scanned; AI context output is secret-scanned.\n- Git is invoked with argument arrays only (no shell concatenation).\n- Core analysis is local and has no telemetry. Network access occurs only for\n  explicit integrations such as GitHub metadata/import and PR automation.\n- Least-privilege GitHub integration requests only the permissions needed for\n  the selected operation (`contents: read`, and when enabled `checks: write`\n  and/or `pull-requests: write`).\n\nSee [SECURITY.md](SECURITY.md) and\n[docs/security/threat-model.md](docs/security/threat-model.md).\n\n## Documentation\n\n- [ARCHITECTURE.md](ARCHITECTURE.md) — layering, data flow, design decisions\n- [docs/](docs/) — full documentation index\n  - [docs/concepts/](docs/concepts/) — graph, living context, ownership, authority, change impact, review governance\n  - [docs/adr/](docs/adr/) — architecture decision records (parser, runtime validation, graph storage, GitHub, MCP, visualization)\n  - [docs/security/threat-model.md](docs/security/threat-model.md)\n- [SECURITY.md](SECURITY.md) — security guarantees and reporting\n- [CONTRIBUTING.md](CONTRIBUTING.md) — how to contribute\n- [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md) — community participation standards\n- [CHANGELOG.md](CHANGELOG.md) — release history\n- [Decision quality and auditability](docs/decision-quality.md) — eval dataset,\n  metrics, decision audit, and bounded overrides\n- [Design-partner pilot playbook](docs/design-partner-playbook.md) — staged\n  rollout, weekly review, and validation gates\n- [Glossary](docs/glossary.md) — plain-language definitions for NodeNet, LCDD,\n  evaluation, identity, GitHub enforcement, and override terms\n- [Historical evaluation](docs/evaluation.md) — GitHub import, safe replay,\n  Decision Lab, metrics, and regression gates\n- [Verified overrides](docs/verified-overrides.md) — numeric GitHub identity,\n  RBAC scope, and signed override verification\n- [Product positioning](docs/product-positioning.md) — supported promise,\n  evidence boundaries, and competitive frame\n- [Token-efficient defaults](docs/token-efficiency-v2.md) — lean output,\n  profiles, accounting, and compatibility\n- [Governed-change A/B protocol](docs/experiments/governed-change-ab-protocol.md) —\n  paired task design and publishable-claim gates\n\n## Testing\n\n```bash\nnpm run typecheck\nnpm test\nnpm run build\nnpm pack --dry-run\n```\n\nTests cover the declared extraction contract for all ten supported languages,\nReact, a monorepo,\nthe cross-team MVP scenario, CODEOWNERS, circular dependencies, malformed\nsource, and a malicious repository. Property-based tests cover lifecycle\ntransitions, traversal termination, glob matching and path safety. CI runs on\nNode 20 and 22.\n\n## Roadmap\n\n- **Phase 1 (done):** code graph — `build`, `query`, `trace`, `related`\n- **Phase 2 (done):** living context — `governed-by`, `conflicts`, `health`\n- **Phase 3 (done):** ownership — `owner`\n- **Phase 4 (done):** change impact — `impact` (symbol-level)\n- **Phase 5 (done):** review governance — `reviewers`\n- **Phase 6 (done):** production GitHub enforcement — idempotent Check Run,\n  annotations, retry, merge queue, rollout modes, comments, and review requests\n- **Phase 7 (done):** AI integration — MSC output + `mcp` server\n- **Phase 8 (done):** richer visualization — interactive force-directed graph with communities (`graph`, `graph -f svg`)\n- **Quick win (done):** highlights report — `report` (god nodes, surprising connections, communities, governance)\n- **Phase 9 (done):** ten-language parsing — seven full and three basic adapters\n- **Phase 10 (done):** decision benchmark, audit events, expiring overrides,\n  readiness doctor, bootstrap wizard, and design-partner pilot kit\n- **Phase 11 (done):** intent-aware retrieval, hypothetical affected analysis,\n  progressive source evidence, safe cache/feedback, executable benchmarks,\n  and MCP Streamable HTTP\n- **Validation-gated:** organization installation, multi-repository governance,\n  centralized Contexts, identity mapping, audit/history UI, and billing\n\nThe full prioritized development plan (gap audit, three rounds, recommended\norder) lives in [docs/roadmap.md](docs/roadmap.md).\n\n## Troubleshooting & FAQ\n\n**`nodenet: command not found`**\nThe bin directory isn't on your `PATH`. With npm global installs on macOS,\nensure `$(npm config get prefix)/bin` is in your `PATH`, then open a new\nterminal.\n\n**`impact` says \"Not inside a git repository\"**\n`impact`/`reviewers` need a git checkout and a base ref. Run `nodenet impact --base main`\ninside the repo, or use `nodenet build` + `nodenet query` which don't need git.\n\n**The graph.html canvas looks empty**\nHard-reload (Cmd/Ctrl+Shift+R). Node labels only render when zoomed in enough\n(`scale > 0.45`) — scroll to zoom. If it still renders nothing, open it in a\ncurrent Chrome/Firefox.\n\n**Why is the package name `@antihero/nodenet`?**\nThe unscoped name `nodenet` is blocked on npm as too similar to an existing\npackage. The CLI command is still `nodenet`.\n\n**How do I change a hardened context?**\nYou can't silently. Run `nodenet context propose <id>` to record a Context\nChange Proposal; it never modifies the active context and requires human\nreview and approval.\n\n**What if my repo is not TypeScript?**\nRun `nodenet languages`. NodeNet supports TypeScript, JavaScript, Python, Go,\nJava, C#, PHP, Rust, Ruby, and Kotlin. Governance at file level also works for\nunparsed repository artifacts; see [language support](docs/languages.md) for\nthe exact full/basic contract.\n\n## License\n\n[Apache-2.0](LICENSE)\n","readmeFilename":"README.md"}