
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@codragraph/org
Advanced tools
Multi-tenant orgs, SSO, RBAC, and tamper-evident audit logging for the CodraGraph platform.
Multi-tenant orgs, SSO, RBAC, and tamper-evident audit logging for the CodraGraph platform.
This is Phase 5 of the CodraGraph roadmap: the org-features layer that turns the local-first OSS into something that can be operated for multiple teams or customers under one server.
Use this package when you are wrapping the local-first @codragraph/cli
indexing workers, FeatureCluster context packs, and graphstore snapshots in
tenant, RBAC, and audit boundaries for a hosted or enterprise deployment.
| Module | What it does |
|---|---|
tenancy | withTenant / requireTenant AsyncLocalStorage scoping. Path helpers that refuse to escape the org root. |
rbac | viewer < member < admin < owner. Default policy covers repos, FeatureCluster context packs/impact, graphstore, recipes, audit, and org administration; integrators extend by composing additional entries. |
audit | Append-only, tamper-evident log. Each event is a content-addressed object (sha256 of canonical JSON = the id). Re-hashing verifies. Re-uses @codragraph/graphstore's CAS for storage. |
auth | Provider-agnostic SsoProvider interface. Includes InMemorySsoProvider for tests. OIDC and SAML reference impls land in follow-ups. |
npm install @codragraph/org
import {
CasAuditLogger,
DEFAULT_POLICY,
checkPermission,
makeOrgId,
makeUserId,
withTenant,
} from "@codragraph/org";
import { FsCAS } from "@codragraph/graphstore/dist/cas/fs-cas.js";
const cas = new FsCAS({ root: "/var/codragraph/cas" });
const audit = new CasAuditLogger(cas, "/var/codragraph/audit");
await withTenant({ orgId: makeOrgId("org_acme") }, async () => {
if (!checkPermission(DEFAULT_POLICY, "member", "repo.analyze")) return;
// ... do work ...
await audit.record({
ts: new Date().toISOString(),
orgId: makeOrgId("org_acme"),
actor: { kind: "user", userId: makeUserId("user_alice") },
action: "repo.analyze",
resource: { type: "repo", id: "demo" },
result: "success",
});
});
Apache-2.0. You can use, modify, redistribute, bundle, and host this package commercially, subject to the Apache-2.0 notice and attribution requirements.
FAQs
Multi-tenant orgs, SSO, RBAC, and tamper-evident audit logging for the CodraGraph platform.
The npm package @codragraph/org receives a total of 1 weekly downloads. As such, @codragraph/org popularity was classified as not popular.
We found that @codragraph/org demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.