{"_id":"@cerbi/winston-governance","name":"@cerbi/winston-governance","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@cerbi/winston-governance","version":"0.1.0","description":"Cerbi governance evaluator for Winston transports","main":"dist/src/index.js","types":"dist/src/index.d.ts","scripts":{"build":"tsc -p tsconfig.json","test":"npm run build && node dist/test/fixtures.test.js"},"keywords":["cerbi","winston","governance"],"author":"","license":"MIT","type":"commonjs","devDependencies":{"@types/node":"^20.19.41","typescript":"^6.0.3","winston-transport":"^4.9.0"},"gitHead":"507ccf3fd7872714c2d3d75236f1714f6743030d","_id":"@cerbi/winston-governance@0.1.0","_nodeVersion":"24.13.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-65J6wFotgkewr9OLPY+3aKHYuPW1LRp1HNmtUjsHLvozyY4d93X2xUNNdWxArqZHyOsadRKGrKtX2IXewtzcdQ==","shasum":"6258ab2321444e48f9ffb3885bb75923b60b9e0c","tarball":"https://registry.npmjs.org/@cerbi/winston-governance/-/winston-governance-0.1.0.tgz","fileCount":44,"unpackedSize":39132,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEZ/vVyAsdtrMQ+eelaGlw/V25onqfd447WdwyPORX2UAiEAlePHMh+1G5k7MzWTxcWbDTCaZzKJ8RaGO3Qmz5R5QLI="}]},"_npmUser":{"name":"hellocerbi","email":"hello@cerbi.io"},"directories":{},"maintainers":[{"name":"hellocerbi","email":"hello@cerbi.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/winston-governance_0.1.0_1779252109897_0.7029363936489366"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-20T04:41:49.691Z","0.1.0":"2026-05-20T04:41:50.068Z","modified":"2026-05-20T04:41:50.369Z"},"maintainers":[{"name":"hellocerbi","email":"hello@cerbi.io"}],"description":"Cerbi governance evaluator for Winston transports","keywords":["cerbi","winston","governance"],"license":"MIT","readme":"# @cerbi/winston-governance\r\n\r\nA lightweight Winston transport that applies Cerbi governance rules to each log event. Governance logic is fully contained in the evaluator and loader modules; the transport is a thin wrapper.\r\n\r\n## Features\r\n\r\n- Evaluates events against JSON rulesets defined by `governance-plugin-contract.md`.\r\n- Emits canonical governance tags (mode, profile, violations, score impact).\r\n- Optional hot reload of rulesets via polling the ruleset file mtime.\r\n- Never blocks logging when configuration is missing or invalid.\r\n\r\n## Usage\r\n\r\nInstall the package alongside `winston` and provide a ruleset JSON file. Each emitted event is tagged with\r\n`CerbiEventId`, `CerbiEventTimeUtc`, `AppName`, and `Environment` (set defaults in evaluator options if not present on the input).\r\n\r\n```ts\r\nimport winston from \"winston\";\r\nimport { CerbiGovernanceTransport } from \"@cerbi/winston-governance\";\r\n\r\nconst logger = winston.createLogger({\r\n  level: \"info\",\r\n  transports: [\r\n    new CerbiGovernanceTransport({\r\n      rulesetPath: \"./ruleset.json\",\r\n      pollIntervalMs: 2000, // hot reload ruleset every 2s\r\n      evaluatorOptions: {\r\n        defaults: { appName: \"my-service\", environment: \"prod\" },\r\n        serializeStructuredFields: false,\r\n      },\r\n    }),\r\n    new winston.transports.Console(),\r\n  ],\r\n});\r\n\r\nlogger.info(\"user signup\", { userId: \"123\", password: \"plaintext\" });\r\n```\r\n\r\nIf you already have a parsed ruleset object you can pass it directly:\r\n\r\n```ts\r\nimport { createCerbiEvaluator } from \"@cerbi/winston-governance\";\r\nimport ruleset from \"./ruleset.json\";\r\n\r\nconst evaluate = createCerbiEvaluator(ruleset);\r\nconst output = evaluate({ level: \"info\", message: \"hello\", password: \"123\" });\r\nconsole.log(output.GovernanceViolations);\r\n```\r\n\r\n## Development\r\n\r\n- `npm run build` compiles TypeScript to `dist/`.\r\n- `npm test` builds then runs the golden fixture test harness.\r\n\r\nGolden fixtures in `golden-fixtures/` define the contract expectations. Each folder contains `ruleset.json`, `event_in.json`, and `event_out.json` that must match after evaluation.\r\n\r\n## Hot reload behavior\r\n\r\nWhen `pollIntervalMs` is provided, the transport polls the ruleset file mtime. A valid ruleset replaces the current ruleset; parse errors or missing files leave the previous valid copy in place while emitting `error` events for observability.\r\n","readmeFilename":"README.md","_rev":"1-ae7ebeed54ab053fd78f3b4bf481e5a0"}