Skip to content

Latest commit

 

History

162 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

GitPin

Validate License: MIT Node.js Version MCP Protocol npm

Make agent-authored changes show exact evidence before merge.

GitPin is an agent-delivery assurance gate with a local evidence MCP. It makes material PR claims cover the actual diff and point to exact committed line slices. The local MCP supplies index-free, read-only, multi-repo evidence that humans and CI can re-check with git show.

Agent claim
    → pin.search_*   (candidates only)
    → pin.prove      (evidence pack: path + line + full SHA + content hash)
    → pin.verify     (git show re-check; HEAD match report)
    → you run: git show <sha>:<path>
Crowded category GitPin product
Vector / SQLite “repo context” servers No embeddings, no DB, no reindex
Filesystem MCP (writes) Never writes indexed repos
One-shot repo dumps Live prove → verify MCP loop
Grep hits as “the answer” Candidates → evidence pack → verification report
GitHub platform MCP Local Git roots (private/offline)

Formerly RepoContext 0.3.x. See migration.

Required PR evidence gate

gitpin gate --base <full-base-sha> --head <full-head-sha>

The gate reads policy only from the trusted base commit, reads the submitted manifest only from the head commit, compares the merge-base diff, and verifies exact line-slice hashes. It never executes PR code and never labels a locator match as proof of semantic correctness. Use the GitPin GitHub Action setup to make it a required check. That guide also documents an optional, separate CrewScore check for teams that want written-control coverage alongside GitPin evidence verification.

Current release: GitPin 0.6.3 is verified on npm, the MCP Registry, GitHub Releases, and Pages. Install with npx -y gitpin@0.6.3. Node 20+.

GitPin is maintained by Sarosh Hussain, who leads the project's technical direction. Pendoah is his company and operating context; GitPin remains the product and repository.

Five-minute path

# From a committed Git repository
npx -y gitpin@0.6.3 init --client codex

init creates ~/.gitpin/repositories.yaml outside the repo, runs doctor, prints a first evidence line with full SHA, and paste-ready MCP config. It never edits the indexed repository.

# Independently verify any claim (same contract as pin.verify)
npx -y gitpin@0.6.3 verify \
  --repository my-service \
  --path docs/architecture.md \
  --line 42 \
  --sha <full-or-short-hex>

Product job

When agents invent file contents, mix dirty worktrees, or cite the wrong branch
You want every fact re-checkable with git show <sha>:<path>
GitPin registers local Git roots, serves HEAD-only docs/code, flags stale tracked docs, returns path / line / SHA, and closes the loop with pin.verify.

Agent tool surface (pin.*) — 12 read-only tools

Job Tools
Discover pin.catalog
Find candidates pin.search_docs, pin.search_code
Prove pin.prove (primary), pin.prove_set (1–8 cites), pin.get_doc, pin.read
Verify pin.verify, pin.verify_set
Decide pin.analyzeEvidenceBrief
Inspect / diff pin.inspect, pin.compare

Resource: gitpin://catalog. Prompt: prove-with-git-head (forces the product loop).
Cite formats: docs/cite-spec.md. Agent skill template: templates/gitpin-skill.md.

Functionality that is the pivot (not a rename)

  • Evidence pack (pin.prove): claim binding, line slice, full SHA, contentSha256, citation.cite / handle, next-step verify.
  • Multi-cite sets (pin.prove_set / pin.verify_set): stable evidenceSetId for multi-repo answers and CI.
  • Verification report (pin.verify / CLI): independent git show; optional mustContain claim-text; status includes contradicted.
  • Candidates, not claims: search returns kind: evidence-candidates with forced next: pin.prove.
  • EvidenceBrief: multi-repo knownFacts / gaps / stable evidenceSetId (schema v2).
  • Dirty exclusion: uncommitted work is never cited as HEAD evidence.

Explicit non-goals

  • Semantic / embedding search
  • Writing, committing, or pushing
  • Replacing GitHub Issues/PRs automation
  • Indexing non-Git umbrella folders as one “repo”

Configuration

Variable Purpose
GITPIN_REGISTRY Registry YAML path (legacy compatibility alias: REPOCONTEXT_REGISTRY)
GITPIN_MCP_TOKEN HTTP bearer token (legacy compatibility alias: REPOCONTEXT_MCP_TOKEN)
GITPIN_ALLOWED_HOSTS HTTP host allowlist (legacy compatibility alias: REPOCONTEXT_ALLOWED_HOSTS)

Default registry: ~/.gitpin/repositories.yaml (legacy compatibility fallback: ~/.repocontext/... if present).

Docs

Tools · Compare · FAQ · Migration · Clients · Architecture · Competitive landscape

Site: shmindmaster.github.io/gitpin. GitPin is the canonical product and repository name; legacy repocontext references exist only for migration compatibility.

Development

corepack enable
pnpm install --frozen-lockfile
pnpm validate
pnpm build
pnpm verify:package
pnpm site:test

License

MIT

About

Require exact PR evidence before agent-authored changes merge. Local evidence MCP + base-trusted gate.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages