codeburn/packages/core
Resham Joshi de536cf55c
Merge pull request #1074 from getagentseal/fix/core-model-bound-guard-landing
fix(core): bound the model field at the observation boundary, and make the privacy guards prove it
2026-08-21 11:03:59 -07:00
..
schemas fix(core): bound the model field at the observation boundary 2026-08-21 10:18:58 -07:00
scripts build(core): stop shipping sourcemaps, expose schemas, tighten the barrel 2026-08-05 03:49:47 +03:00
src Merge pull request #1074 from getagentseal/fix/core-model-bound-guard-landing 2026-08-21 11:03:59 -07:00
tests fix(core): reject an empty privacy key in copilot's JetBrains digest 2026-08-21 10:48:21 -07:00
package.json chore: hold workspace versions at 0.9.20, defer the bump to release 2026-08-21 10:38:17 -07:00
README.md docs(core): replace Phase 1 skeleton README; bump core to 0.9.20 for republish 2026-07-27 10:52:38 -07:00
tsconfig.build.json chore: stop emitting declaration maps 2026-07-27 15:22:15 -07:00
tsconfig.json feat(core): observation schema, contracts, fingerprints, guardrail harnesses (phase 2) 2026-07-26 10:43:21 -07:00
tsup.config.ts build(core): stop shipping sourcemaps, expose schemas, tighten the barrel 2026-08-05 03:49:47 +03:00
vitest.config.ts feat(core): observation schema, contracts, fingerprints, guardrail harnesses (phase 2) 2026-07-26 10:43:21 -07:00

@codeburn/core

The pure decode/detect engine behind CodeBurn: provider session-log decoding for 36 AI coding tools, content-minimized observation envelopes, and detector contracts.

Status: 0.x. The engine is complete and battle-tested (it is the same code the CodeBurn CLI runs, proven byte-identical to the pre-extraction implementation on a frozen real-world corpus), but the public API may still change between 0.x minor versions. Pin accordingly.

What it does

  • Decode: each provider module (@codeburn/core/providers/<name>) turns that tool's raw session records into structured call data — tokens, models, timing, tool usage — with the provider's exact dedup and skip semantics.
  • Observations: toObservations maps rich decode output into a strict, content-minimized envelope: only fingerprints, enums, numbers, timestamps, dedup keys, and canonical tool names cross the boundary. Enforced by an architecture gate and per-provider content-smuggling tests.
  • Detectors: contracts for waste/optimization findings over fingerprinted data.

What it deliberately does NOT do

No file or network I/O, no environment access, no clock reads, no pricing. Hosts (the CodeBurn CLI, apps, or your own tooling) supply the records and apply their own pricing. The only runtime dependency is zod.

Usage

import { decodeQwen } from '@codeburn/core/providers/qwen'
import { toObservations } from '@codeburn/core/providers/qwen'
import { OBSERVATION_SCHEMA_VERSION } from '@codeburn/core/schema'

const { calls, diagnostics } = decodeQwen({ records, seenKeys })

Each provider is its own subpath export; see package.json#exports for the full list. JSON Schemas for the observation envelope ship under schemas/.

Part of the CodeBurn core extraction (RFC #796, tracking #809). MIT.