
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@decantr/core
Advanced tools
Support status: core-supported
Release channel: stable
Low-level Decantr compiler and execution-pack foundation.
Most teams should use @decantr/cli, @decantr/content, or @decantr/mcp-server directly. @decantr/core is part of the supported Decantr public foundation surface, but it is intentionally lower-level than the usual integration entrypoints. @decantr/registry remains only for Decantr 3.x compatibility imports.
npm install @decantr/core
@decantr/core is published for advanced package consumers that need low-level execution-pack primitives. It is stable in the Decantr 3 line for the documented exports in this package, but it is still not the recommended first integration surface for most Decantr adopters.
GraphStore adapterIn the current workflow architecture, @decantr/core owns the canonical adapter labels used by compiled packs, while runnable greenfield bootstrap adapters are resolved in the CLI on top of those labels.
The graph exports establish the storage boundary, typed schema shape, temporal snapshot/diff shape, payload-filterable node queries, hybrid route-context ranking, hybrid node/source impact traversal, and provider-neutral contract capsule shape for CLI, MCP, verifier, Studio, and CI integration. Ranking blends deterministic weighted traversal with local personalized PageRank and optional task-text boosts, so central graph nodes and task-relevant nodes both surface without introducing a graph database dependency. Behavior obligations remain app-owned local law in .decantr/local-patterns.json; higher-level packages project accepted obligations into existing LocalRule graph nodes with payload.kind = "behavior-obligation" instead of adding a new graph node type. Evidence Bundles, runtime probes, visual manifests, repair plans, and proof reports are ingested through existing graph node/edge shapes where possible; generated health-baseline diffs are excluded to avoid circular graph invalidation, and TEST_COVERS_NODE edges act as verification hints rather than proof of production UI behavior. The capsule keeps the contract cache key stable while listing bounded SourceArtifact paths agents can use for file-impact follow-up queries. The core package remains pure library code: filesystem graph persistence belongs in higher-level packages such as the CLI.
Most teams should start with the CLI rather than this low-level package:
npx @decantr/cli new my-app
npx @decantr/cli analyze
npx @decantr/cli check
For common setup, brownfield, Studio, migration, CI, and agent-alignment questions, see the user-facing Decantr FAQ.
import {
buildReviewPack,
renderExecutionPackMarkdown,
resolvePackAdapter,
} from '@decantr/core';
const pack = buildReviewPack({
projectName: 'Acme Console',
target: 'react',
routeCount: 4,
sections: ['overview', 'settings'],
});
const adapter = resolvePackAdapter('react', 'spa');
const markdown = renderExecutionPackMarkdown(pack);
This package publishes execution-pack schemas under:
@decantr/core/schema/scaffold-pack.v1.json@decantr/core/schema/section-pack.v1.json@decantr/core/schema/page-pack.v1.json@decantr/core/schema/mutation-pack.v1.json@decantr/core/schema/review-pack.v1.json@decantr/core/schema/pack-manifest.v1.json@decantr/core/schema/execution-pack-bundle.v1.json@decantr/core/schema/selected-execution-pack.v1.jsonIt also publishes the draft Decantr 3 typed graph artifact schemas:
@decantr/core/schema/graph.common.v1.json@decantr/core/schema/graph-snapshot.v1.json@decantr/core/schema/graph-manifest.v1.json@decantr/core/schema/graph-diff.v1.json@decantr/core/schema/contract-capsule.v1.json@decantr/core is a local execution-pack compiler and type/schema package. It does not read or write project files, call the network, spawn processes, emit telemetry, or upload source by itself. The draft graph exports include pure builders and an in-memory adapter only; filesystem graph persistence belongs in higher-level CLI/verifier wiring. Schema URLs in emitted packs are identifiers, not network calls. See security permissions.
MIT
FAQs
Decantr core — execution-pack, typed graph, and Contract capsule primitives
The npm package @decantr/core receives a total of 415 weekly downloads. As such, @decantr/core popularity was classified as not popular.
We found that @decantr/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.