
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@nacre.work/core
Advanced tools
The data model, the permission resolver and the shared types behind Nacre — a self-hosted knowledge index with fine-grained access control.
Most people do not install this. Applications install
@nacre.work/sdk, people run
@nacre.work/cli, and
operators run the container. This package is here because the API, the MCP
server and the worker all depend on it — and because a commercial module has to
resolve the host's copy of it, which needs it on the registry.
The permission resolver and its reference implementation, the schema and its forward-only migrations, the Qdrant filter builder, the BM25 producer both sides of search share, configuration loading, the extension registry, and the types everything else is written against.
Six invariants hold across every consumer, and breaking one is a security incident rather than a bug:
top_k returns k permitted results.404, never
403, including the wording.write does not imply read. admin implies both. This is the opposite
of most permission systems and is not a thing to fix.A commercial module registers into these from its module body while
loadModules is running:
registerAuthProvider(provider)
registerAuthzResolver(resolver)
registerAuditSink(sink)
registerIngestGate(gate)
mountAdminRoutes(...routes)
The registry is module-level state, so it belongs to whichever copy of this package was loaded. A module that resolves a second copy registers into a registry the host never reads — which is why every module declares this as a peer dependency rather than an ordinary one.
0.x, and the packages ship together referencing each other by exact version.
A minor bump can move an interface; the
extension contract
says which parts are load-bearing for a module author.
Apache 2.0. The permission model in full: github.com/nacre-work/nacre.
FAQs
Nacre core: data model, permission resolver, and shared types
The npm package @nacre.work/core receives a total of 5 weekly downloads. As such, @nacre.work/core popularity was classified as not popular.
We found that @nacre.work/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.