惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
罗磊的独立博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
T
Tailwind CSS Blog
美团技术团队
Y
Y Combinator Blog
I
InfoQ
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
GRAHAM CLULEY
爱范儿
爱范儿
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
A
Arctic Wolf
Hugging Face - Blog
Hugging Face - Blog
S
Security Affairs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
云风的 BLOG
云风的 BLOG
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
H
Heimdal Security Blog
博客园 - 司徒正美
Latest news
Latest news
H
Hacker News: Front Page
H
Help Net Security
Know Your Adversary
Know Your Adversary
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Secure Thoughts
AWS News Blog
AWS News Blog
V
Vulnerabilities – Threatpost
NISL@THU
NISL@THU
C
Cyber Attacks, Cyber Crime and Cyber Security
L
LangChain Blog
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
The Cloudflare Blog
I
Intezer
N
News and Events Feed by Topic

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
GitHub - janitor-security/the-janitor: A deterministic, zero-copy structural firewall. Mathematically neutralize Agentic Swarms, supply-chain injections, and architectural necrosis.
GhrammR · 2026-05-18 · via Hacker News - Newest: "AI"

The Janitor: The Mathematical Firewall Against Autonomous AI

v10.2.2 — Rust-Native. Zero-Copy. Dual-PQC Attestation. SLSA Level 4 Reproducible Builds.

Integrity Status

*Attested by The Janitor v10.2.2

Research Foundation

For grant reviewers and academic collaborators: The Janitor implements three formally verified layers — IFDS interprocedural taint analysis across 23 language grammars, Kani-proven Boolean predicates for detection correctness, and Z3 SMT exploit witness synthesis. Full research brief: docs/grant-research-brief.md.


: Zero-Upload, FIPS 204 + FIPS 205 Compliant.*


Sonar finds style violations. The Janitor enforces structural integrity.

82% of open Godot Engine pull requests contain no issue link. 20% introduce language antipatterns. Zero comment scanners caught it. The Janitor did — across 50 live PRs, in under 90 seconds.


The Problem: Mythos-Class Autonomous Injection

The Veracode 2025 State of Software Security report established the baseline: AI-assisted code contains 36% more high-severity vulnerabilities than human-written equivalents. But the threat has evolved from Copilot assistance to 'Mythos-class' autonomous AI agents that inject vulnerabilities and orchestrate attack chains across microservices. Your linter passes agentic output. Your SAST tool uploads it to a cloud pipeline. By the time the report arrives, the PR is merged.

The threat model has changed. Your enforcement layer has not. The Janitor is the only deterministic defense against 'Mythos-class' AI agents, mathematically verifying intent before code enters the repository. Looking ahead, our decadal roadmap pioneers Zero-Knowledge AST proofs and Labyrinth Deception to neutralize adversarial agents at the structural level.

Researchers and grant reviewers: The Janitor's formal methods foundation — IFDS taint analysis, Kani-proven Boolean predicates, and Z3 SMT exploit witness synthesis — is documented in docs/grant-research-brief.md.

Zero-Friction GitHub Integration

Janitor Sentinel Demo

Janitor Sentinel automatically downgrades vetoes when it detects safe patterns (e.g., Dependabot).

The Enforcement Layer

The Janitor is not a linter. It is a structural firewall that runs on your hardware, on every pull request — before the merge button is available.

Actuarial Risk Matrix

The Janitor doesn't just find vulnerabilities — it generates a financial ledger. Every intercepted threat is categorized and billed:

  • Critical Threat (security antipattern or Swarm collision): $150/incident — CI pipeline poisoned, supply-chain injection vector, or coordinated Agentic Swarm clone.
  • Necrotic GC (dead-code ghost, bot-closeable): $20/PR — automated garbage collection, no human triage required.
  • Total Economic Impact = sum of all categorical billings across the audit window.

Audited 33,000 PRs across 22 enterprise repositories on an 8 GB laptop. The ledger is machine-generated, per-PR, and appended to .janitor/bounce_log.ndjson atomically on every merge event.

Integrity Dashboard (WOPR)

janitor dashboard <repo>

Visualize C/C++ compile-time blast radius and track structural Swarm clones in real-time. The WOPR (War Operations Plan Response) dashboard renders the top-10 #include dependency silos ranked by transitive reach — the files whose modification ripples furthest through the compile graph. Built from in-memory libgit2 tree walks; no filesystem checkout required.

The Vibe-Check Gate

The Vibe-Check Gate compresses every patch blob via zstd and measures compressed_len / raw_len. Vibe-coded PRs — generated by prompting an AI without authoring the implementation — are statistically self-similar: the same scaffolding, the same docstring patterns, the same structural repetition. They compress below ratio 0.15. Any blob crossing that threshold triggers antipattern:ncd_anomaly (+10 points) before tree-sitter parses a single node.

Two complementary shields eliminate false positives on legitimate non-application content:

  • Null-Vector Collision Shield — IaC bypass (.nix, .lock, .json, .toml, .yaml, .yml, .csv) + 256-byte size guard + DOMAIN_VENDORED router. CVE vendor patches touching thirdparty/ score zero by construction. No legitimate infrastructure change can produce a spurious non-zero score.
  • Net-Negative Exemption — All score multipliers act exclusively on newly introduced symbols and patterns. Deletion-dominant patches — boilerplate purges, dead API removal, deprecated-code cleanup — mathematically cannot trigger any scoring signal. Score=0 is a proof, not a heuristic.

Zero-Copy Execution

Every analysis executes via memory-mapped file access. No network call is made during the dead-symbol pipeline.

Zero-Upload Guarantee — both deployment models:

Model Where analysis runs Source code leaves your environment?
CLI + GitHub Action (action.yml) Your GitHub Actions runner Never
Janitor Sentinel (GitHub App) Your GitHub Actions runner Never — Governor receives only the score

The Janitor engine runs entirely inside your own runner in both modes. The Governor (Sentinel's backend) receives a signed analysis result — not your source code. No server-side clone. No SAST upload.

Benchmark: Sustained 6.7 seconds per Pull Request on the 3.5M-line Godot Engine codebase (C++, C#, GDScript, Python) — featuring full Cross-File Taint Analysis and Wasm Governance. 58 MB peak RAM. On a standard CI runner. Zero panics.

Zombie Dependency Detection

AI generators hallucinate package imports. The Janitor scans package.json, Cargo.toml, requirements.txt, spin.toml, and wrangler.toml against the live symbol reference graph. A package that appears in your manifest but never appears in a reachable import path is a zombie dependency — flagged before merge.

Cryptographic Integrity Bonds

When a pull request clears the slop gate, Janitor Sentinel — our GitHub App — automatically issues a CycloneDX v1.6 CBOM (Cryptography Bill of Materials) for the merge event. The CBOM records every cryptographic operation performed during the scan: the Dual-PQC attestation signature (ML-DSA-65 NIST FIPS 204 + SLH-DSA NIST FIPS 205), the SHA-384 structural hashes, and the per-symbol audit entries covering {timestamp}{file_path}{sha256_pre_cleanup}. No token flag. No manual step. The proof is issued on a clean merge — a chain of custody for every line of code removed from production.

SLSA Level 4 Reproducible Builds

Every release binary is built with deterministic compiler flags (--build-id=none, LTO, single codegen unit) and verified via Docker-based dual-build comparison. The verify-reproducible recipe proves bit-for-bit identity across independent build environments — satisfying SLSA Build Level 4 for supply chain integrity.

Jira ASPM Deduplication

The Janitor integrates natively with Jira for Application Security Posture Management. Findings are synced as Jira issues with automatic deduplication — the first bounce creates a ticket; subsequent bounces with the same fingerprint skip creation. Credential preflight validates JANITOR_JIRA_USER and JANITOR_JIRA_TOKEN before attempting sync, gracefully degrading to local-only mode when credentials are absent.

Native SCM Support

Commit-status publishing works out of the box for GitHub, GitLab, and Azure DevOps. The Janitor auto-detects your CI environment and publishes pass/fail verdicts to the correct API — no additional configuration beyond standard CI tokens.


Competitive Moat

On-Device vs. Cloud Fabric

The market is filling with "AI Security Fabrics" — cloud-hosted LLM pipelines that ingest your source code, run probabilistic analysis, and return a verdict four minutes later. They are slow. They exfiltrate your code to a third-party inference cluster. Your diffs become training data.

The Janitor is the opposite architecture: an on-device structural firewall — a Rust binary that memory-maps your diffs, applies deterministic analysis, and exits. No network call during the analysis path. Proven at 6.7 seconds per Pull Request on a 3.5M-line C++ codebase, on an 8 GB laptop. Code never leaves your runner in either deployment model.

Deterministic vs. Heuristic

LLM-based code review tools cannot prove anything. They emit confidence scores against training distributions. A novel adversarial input — well-structured but semantically dangerous — is invisible to a heuristic system trained on pre-AI codebases.

The Janitor does not guess. It uses tree-sitter ASTs to prove structural identity, SHA-384 hashing to prove audit integrity, BLAKE3 to prove clone equivalence, and Dual-PQC (ML-DSA-65 FIPS 204 + SLH-DSA FIPS 205) to prove chain of custody. The gate passes or it blocks. There is no confidence interval. There is no false-positive budget. When a PR clears the gate, Janitor Sentinel issues a CycloneDX v1.6 CBOM: a cryptographically signed bond you can present to a SOC 2 auditor — not a report, a proof.

Air-Gap and Sovereign Deployment

Veracode, Checkmarx, and SonarQube require cloud connectivity. Their analysis pipelines send your source to remote clusters. For IL5/IL6 environments — classified networks, air-gapped DoD infrastructure, sovereign cloud mandates — this is a hard disqualifier.

The Janitor ships Air-Gap Intel Transfer Capsules: SHA-384-hashed, Ed25519-signed wisdom bundles that can be physically transported and cryptographically verified offline. Import a capsule, verify the signature chain, and the engine is operational with full threat intelligence — no network ever required.

Private Governance Modules (Wasm BYOR)

Veracode and Checkmarx enforce their rule sets. You cannot mount your own.

The Janitor supports Wasm BYOR (Bring Your Own Rules): private governance modules compiled to WebAssembly, fuel-bounded, memory-limited, and executed with deterministic provenance receipts. Every Wasm rule is pinned with BLAKE3 (janitor wasm-pin) and verified at load time. Every execution is sealed into the CBOM — auditable, reproducible, offline-verifiable.

Hallucinated Package Detection (Slopsquatting)

AI code generators hallucinate package names. py-react-vsc, django-tailwind-fast, node-express-secure-template — packages that do not exist in any registry but sound plausible enough to install if a threat actor registers them first.

The Janitor maintains a BLAKE3-seeded Bloom filter (SlopsquatFilter) seeded from the wisdom feed. Every package import in a PR is checked against the filter before it can reach the merge gate. Slopsquatting is stopped before it reaches production.

Replayable Decision Capsules

No tool in the SAST market can prove, offline and without network access, exactly why a PR was blocked. The Janitor can.

Every bounce decision is sealed into a DecisionCapsule — a tamper-evident record of the exact CST mutation roots, Wasm rule receipts, and analysis score that produced the verdict. A CISO can replay the capsule 18 months later, on an air-gapped machine, and cryptographically verify the chain of custody to the original diff.

Agentic-Ready

AI coding assistants are becoming autonomous agents — systems that open PRs without human authorship, coordinate across accounts, and submit structurally identical changes at a rate no human review queue can absorb. Current toolchains have no concept of a non-human contributor operating at machine velocity and no mechanism to detect coordinated structural injection.

The Janitor is the deterministic enforcement gate that applies your architectural rules to non-human developers. The same rules, at the same threshold, whether the author is a human engineer, a Copilot agent, or an autonomous Swarm. The janitor.toml governance manifest is version-controlled policy-as-code: your rules, enforced at the diff level, before the merge button is available.

When your team deploys AI engineers, the gate does not move.

Decadal Roadmap: The Next Frontier

The current engine intercepts threats at the static structural level — provably, at machine speed, offline. The decadal horizon pushes the frontier into mathematically certified territory that no competitor can reach without rebuilding the entire stack:

  • Zero-Knowledge AST Enclaves — Proving that a codebase satisfies all 200 governance rules without revealing a single line of source. A zk-SNARK attests the engine's verdict; the auditor verifies the proof in milliseconds. No code exfiltration. No trust boundary. The compliance answer exists on-chain without the source ever leaving your environment.
  • The Labyrinth Deception Plane — A runtime honeypot layer that presents adversarial agents with a structurally valid but semantically poisoned codebase, trapping autonomous attackers mid-campaign and extracting their full attack graph before they know they have been detected.

These are not roadmap promises — they are the logical next tier of a deterministic engine that already proves reachability via IFDS and path-feasibility via Z3. The mathematical foundation is live today.


PR Gate: Live Results

Repos audited         : 22 enterprise repositories (godot, nixpkgs, vscode,
                        k8s, pytorch, kafka, rust-lang/rust, tauri, redis,
                        next.js, home-assistant, ansible, workers-sdk,
                        langchain, deno, rails, laravel, apple/swift,
                        aspnetcore, okhttp, terraform, neovim)
PRs analyzed          : 33,000+  (live production PRs — no synthetic benchmarks)
Hardware              : 8 GB laptop
Engine panics         : 0
OOM events            : 0

Godot Engine alone (50 PRs, Feb 2026): 82% unlinked, 20% antipatterns. Zero false positives.


How It Works

  1. Scan — Static reference graph + 6-stage heuristic pipeline identifies every dead symbol.
  2. Simulate — Shadow Tree overlays links to dead files. Your test suite runs against simulated deletion.
  3. Remove — Tests pass? Byte-precise surgical removal, bottom-to-top. Tests fail? Full rollback, zero corruption.

Quick Start

→ 30-Second Sentinel Setup (copy-paste guide)

# Detect dead code (free)
janitor scan ./src

# Find duplicate functions (free)
janitor dedup ./src

# PR enforcement gate — score a diff (free)
janitor bounce ./src --patch diff.patch

# Shadow-simulate + remove dead code (free)
janitor clean ./src --force-purge

Language Support

Language Dead Functions Dead Classes Dead Files Duplicate Logic
Python
Rust
JavaScript / TypeScript
C++
Go
C# / Java

Runtime Architecture

Subsystem Technology Property
AST Engine Tree-sitter (23 grammars) O(n) CST construction; byte-range precision per token
Reference Graph Petgraph directed digraph Topological dead-symbol filter; in-degree = 0 → candidate
Pattern Matching Aho-Corasick (single automaton per group) O(n+m) multi-pattern scan; zero allocation in hot path
Registry Persistence rkyv + memmap2 mmap-direct deserialization; no heap allocation for reads
Structural Hashing BLAKE3 (alpha-normalized AST) Logic-clone detection across identifier rename boundaries
Audit Integrity SHA-384 (FIPS 180-4) HMAC-SHA-384 ledger proving; release asset hashing
Fuzzy Dedup AstSimHasher (SimHash over CST tokens) Classified as Refactor, Zombie, or NewCode
Vibe-Check Gate zstd level-3 compression ratio O(N) vibe-code detector; fires before AST parse; ratio < 0.15 → antipattern:ncd_anomaly (+10 pts)
PR Quality Gate MinHash LSH (64 hashes, 8-band index) Lock-free ArcSwap index; sub-linear collision detection
Deletion Engine Bottom-to-top byte-range splice UTF-8 char-boundary hardened; zero re-parse overhead
Simulation Layer Symlink overlay (Shadow Tree) Zero additional disk usage; tests run against simulated state
Audit Attestation Dual-PQC: ML-DSA-65 (FIPS 204) + SLH-DSA (FIPS 205) CycloneDX v1.6 CBOMs — quantum-safe chain-of-custody provenance
Air-Gap Intel Transfer IntelTransferCapsule — SHA-384 + Ed25519 offline verify Signed wisdom feed bundles for IL5/IL6 environments
Wasm BYOR Rules Wasmtime (fuel + memory bounded) BLAKE3-pinned private governance modules; deterministic provenance receipts
Slopsquatting Filter BLAKE3-seeded Bloom filter (SlopsquatFilter) Flags hallucinated package names; seeded from update-wisdom
Replayable Decision Capsules DecisionCapsule + WasmPolicyReceipt Offline audit replay — CBOM-sealed, Ed25519 signed
Reproducible Builds SLSA Level 4 (lld + --build-id=none + LTO) Bit-for-bit deterministic release binaries
ASPM Integration Jira dedup sync + credential preflight Fingerprint-based dedup; graceful degradation without credentials
SCM Publishing GitHub + GitLab + Azure DevOps Native commit-status verdicts; auto-detected from CI environment

Enterprise Integrations

Every critical_threat bounce fires an outbound webhook — HMAC-SHA256 signed, with X-Janitor-Signature-256 and X-Janitor-Event headers. Wire to Slack, Microsoft Teams, Datadog, Splunk, or any HTTPS endpoint:

# janitor.toml
[webhook]
url    = "https://hooks.slack.com/services/..."
secret = "env:JANITOR_WEBHOOK_SECRET"
events = ["critical_threat", "necrotic_flag"]

Test without a live PR:

janitor webhook-test --repo .

Commercial Utility

Bug Bounty Utility

The Janitor accelerates offensive operations with Automated Exploit Generation (AEG). It synthesizes actionable, working Proof-of-Concepts—from AEG HTML harnesses to Z3 SMT minimal strings—empowering security researchers to prove impact without violating Terms of Service via automated network requests.

Enterprise Tiers

The enforcement is free. The attestation is the product.

Tier Cost What You Get
Free (Community) $0 Unlimited scan, clean, dedup, bounce, dashboard, report. 23 grammar spine. IFDS taint solver. Z3 SMT path feasibility. AEG curl synthesis. No signed logs.
Team Tier $499/yr Unlimited Seats. All free features + Dual-PQC Integrity Bonds (ML-DSA-65 FIPS 204 + SLH-DSA FIPS 205) + CycloneDX v1.6 CBOMs + CI/CD Compliance Attestation + Janitor Sentinel GitHub App + Financial PII taint guard with regulatory regime annotations (GLBA, EU AI Act Art. 10, NYDFS 500.11).
Sovereign / Air-Gap Tier Custom (Starting at $49,900/yr) SLSA L4 reproducible build verification, Offline PQC validation, Governor Control Plane, Wasm BYOR rule mounting, Air-Gap Intel Transfer Capsules, Mesh Topology Discovery (docker-compose + K8s service graph).
Industrial Tier Custom OT/ICS/SCADA pack. On-Premises Token Server + Keypair Rotation Protocol + SOC 2 Audit Support + Enterprise SLA + Dedicated threat intelligence briefings.

→ Get Janitor Sentinel — $499/yr

API token delivered by email within seconds of payment. No per-seat limits.

CI Integration

# PR slop gate — runs on every pull request (free)
- id: janitor
  uses: janitor-security/the-janitor@v10
  with:
    token: ${{ secrets.GITHUB_TOKEN }}

# Outputs available downstream:
# steps.janitor.outputs.slop_score
# steps.janitor.outputs.antipatterns

Commands

# Structural dead symbol audit
janitor scan <path> [--library] [--format json]

# PR enforcement gate
janitor bounce <path> --patch <file> --pr-number <n> --author <handle> --pr-body "$BODY"

# Zombie dependency detection (output includes zombie_deps)
janitor scan <path> --format json

# Structural clone detection
janitor dedup <path>

# Shadow-simulate → test → remove dead code
janitor clean <path> --force-purge

# Historical slop / clone / zombie intelligence report
janitor report [--repo <path>] [--top <n>] [--format markdown|json]

# Long-lived daemon (Unix socket, Physarum backpressure)
janitor serve [--socket <path>] [--registry <file>]

# Ratatui TUI dashboard
janitor dashboard <path>

Installation

From source (Rust 1.91+, just required):

git clone https://github.com/janitor-security/the-janitor
cd the-janitor
just build
# Binary: target/release/janitor

Pre-built binary:

# Download from Releases, then:
chmod +x janitor && sudo mv janitor /usr/local/bin/

The Proof

3.5 million lines. 6.7 seconds per PR. 58 megabytes. Zero panics.

Read the Godot Engine Autopsy →

License

Business Source License 1.1 (BUSL-1.1) — Source Available. Converts to MIT on 2030-02-15.

Scan, cleanup, dedup, bounce, and dashboard are permanently free. Integrity attestation is issued by Janitor Sentinel (Team tier).