Skip to content
View yunaremaia's full-sized avatar

Block or report yunaremaia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yunaremaia/README.md

Yunare Maia 🇧🇷

Open-source developer from Mossoró, Rio Grande do Norte — Brazil. I build tools that keep repositories honest: driftcheck catches version drift between documentation and the files that actually build the project, taintrace catches typosquatted package names, and a family of small guardrails keeps generated changes inside the lines you drew.

448 merged PRs — 394 in my own projects, 54 upstream across 32 repositories. Five tools are on PyPI. driftcheck and aipr carry a -py suffix because the PyPI names driftcheck and aipr are permanently taken by unrelated projects; the import name and the command are unchanged in both cases.

Merged PRs Upstream Python Open to collaboration apache/maka anchore/syft LMCache ORAS

GitHub stats Contribution streak

Start here

I want to… Use
catch version drift before CI does pip install driftcheck-py → driftcheck
catch typosquatted dependencies pip install taintrace → taintrace
block out-of-scope changes to protected paths pip install diff-contract → diff-contract
run only the CI tests a change actually affects pip install ci-test-gate → ci-test-gate
check a repo's AI policy before contributing pip install aipr-py → aipr
track token cost across agent runs pip install git+https://github.com/yunaremaia/agentcost.git → agentcost
enforce bounded agent permissions pip install git+https://github.com/yunaremaia/agent-guard.git → agent-guard
scan dependencies across ecosystems pip install git+https://github.com/yunaremaia/depscan.git → depscan

Every tool is MIT-licensed and runs on Python 3.10+.

Featured work

driftcheck · 2404 tests

Your README promises Node 18, your package.json says 24, and a new contributor discovers it as a build failure. driftcheck catches it in CI instead.

86 detector modules across Maven, Gradle, Terraform, CircleCI, GitLab CI, GitHub Actions, Kubernetes, Helm, Docker Compose, Dependabot, .NET/C#, Taskfile, Rust toolchain files, Go modules, npm/pnpm/yarn lockfiles, proto schemas, SPDX license headers, dotfiles, .env, and the A2A agent protocol. --fix rewrites the documentation side; --sarif emits SARIF 2.1.0 for GitHub code scanning.

2404 tests, green on Python 3.10–3.14 across Linux, macOS and Windows.

taintrace · 444 tests

reqeusts instead of requests is one character away from a malicious package. Detects typosquat lookalikes across Cargo, Go, npm and PyPI before they reach a lockfile.

A generated snippet with a hardcoded API key or an unparameterized query ships before anyone reads it. vibeguard scans generated code for hardcoded secrets, SQL injection, dangerous eval/exec and CORS wildcards before it ships.

Upstream contributions · 54 merged PRs across 32 repos

Defects with an actual reproduction, not drive-by changes:

Plus merged work in MisakaNet, semantica, agent-safe-pipeline, Agentrace, OpenMAIC, cratestack, neural-trees, tealtiger, Prism-platform, and others.

Now

21 PRs open. The ones worth a maintainer's attention:

  • goreleaser/nfpm#1145 — the ipk packager writes a raw os.FileInfo.Mode() into the tar header, so type bits like fs.ModeDir overflow the octal field and archive/tar silently re-encodes that header as GNU base-256. apk got normalizeFileMode in #1113; ipk was left behind.
  • anchore/syft#5373 — keep same-name packages apart when resolving Python dependencies, so two distributions sharing a name no longer collide
  • pypa/packaging#1437 — merge a partial environment over defaults in select(), instead of letting an empty field clear a declared one
  • fastapi/typer#1970 — skip hidden commands in typer utils docs output

Browse the full list.

Recent merged work

When Where What
2026-10-03 yunaremaia/driftcheck fix(sarif): stop silently dropping detectors from SARIF output (+1 more)
2026-10-02 BasedHardware/omi fix(cli): coerce loosely typed records in conversations_to_sqlite ($25 bounty pr
2026-10-03 yunaremaia/taintrace chore(release): 0.2.2 -- improve PyPI discovery metadata (+1 more)
2026-10-03 yunaremaia/oss-contribution-finder refactor: extract build_parser() from main()
2026-10-03 yunaremaia/agent-capability-attestation fix: verify_signature raised TypeError instead of verifying (fixes #10)
2026-10-03 yunaremaia/prompt-drift ci: replace the fail-open test gate and make it impossible to reintroduce (+1 more)

What I work on

Drift detection — the recurring theme. When a value is declared in two places, something will eventually make them disagree, and the failure surfaces to a user as a confusing build error instead of the configuration mismatch it actually is. driftcheck (86 detectors), plus a2a-drift — agent-card and spec-version compliance, env-drift — .env files that disagree across environments, license-drift — SPDX headers that do not match the manifest, dotfiles-drift — the same setting committed with two different values.

Supply-chain security — taintrace (typosquat detection for Cargo/Go/npm/PyPI), depscan (multi-ecosystem vulnerability scanning), ai-reputation-guard.

Guardrails for generated changes — the premise: a large diff is fine; a silent out-of-scope one is not. diff-contract fails a run that touches protected paths, aipr surfaces a repo's AI policy before you build, agent-guard enforces bounded permissions at runtime, vibeguard and mcp-guard scan generated code and MCP servers, ai-reputation-guard scores contributions that look low-effort.

CI intelligence — ci-test-gate (semantic test selection), ci-sandbox (see what a pipeline would run without running it), ci-gate-watch (declared branch protection vs the protection actually set), gfi (good-first-issue finder).

Agent observability — agentcost (token spend), memwatch (memory rot detection), context-bridge (session memory), agent-undo (rollback), agent-workspace (worktree isolation), leanpipe (CLI output filtering), acc-mcp (Agent Capability Contract enforcement at the MCP gateway).

Install

# Published on PyPI
pip install driftcheck-py    # version drift across 86 detectors
pip install taintrace        # typosquat detection
pip install diff-contract    # diff guardrails
pip install ci-test-gate     # semantic CI test selection
pip install aipr-py          # AI contribution policy detection

Everything else installs from source. This is deliberate, not a gap: for agentcost, agent-guard, depscan and the rest the short PyPI name belongs to an unrelated project, so a pip install <name> would silently fetch someone else's software. Install from Git so pip cannot resolve the wrong package:

pip install git+https://github.com/yunaremaia/agent-guard.git  # agent permission policy
pip install git+https://github.com/yunaremaia/agentcost.git  # LLM token cost tracking
pip install git+https://github.com/yunaremaia/depscan.git  # multi-ecosystem scanning

Source, issues and PRs live in the yunaremaia/* repos above.

Stack

Python Rust C++ Go TypeScript Mojo Bash · pytest · GitHub Actions · SARIF · SQLite · rapidfuzz · CLI-first, scriptable, no daemon

Stats

Metric Value
Merged PRs 448
— in my own projects 394
— upstream, across 32 repos 54
Own projects 44
Public repos 167
— of which forks of other people's work 123
Tests across featured tools 2848+
Packages on PyPI 5
Stars 23
Followers 58
Primary language Python

Contributing

PRs are welcome in any repo above. Before you open one:

  • Read the repo's CONTRIBUTING.md and any AI policy — aipr detects those gates automatically
  • Issues labeled good first issue are actively maintained — claim before starting
  • All public artifacts (PRs, commits, issues, comments) are in English

Support

If this saves you time, you can support it:

  • Solana / cbBTC: Eeztv1nCYUt1fwGWpzKC948gaWfjejYCAuLtUMgzDWbW
  • Or collaborate — pick an open issue in a project above

Reach me

  • Email: [email protected]
  • GitHub issues and PRs — fastest channel for anything project-related
  • Operating agreement: inicio.md — public identity and contributor rules

Numbers verified against the GitHub API.

Popular repositories Loading

  1. driftcheck driftcheck Public

    Detect version drift between docs and toolchain files (README vs rust-toolchain.toml etc.)

    Python 3 15

  2. agent-guard agent-guard Public

    Policy-as-code for AI agent permissions. Define bounded permissions in YAML, enforce at runtime.

    Python 3 9

  3. agentcost agentcost Public

    Token usage tracker for multi-agent AI sessions

    Python 2 15

  4. depscan depscan Public

    Find typosquatted package names in Cargo, npm, PyPI and Go lockfiles using Levenshtein similarity

    Python 2 11

  5. yunaremaia yunaremaia Public

    Open-source developer from Mossoró, Brazil. Detects version drift, typosquatting, leaked secrets and CI gate drift — driftcheck, taintrace, vibeguard, depscan.

    Python 1 2

  6. aipr aipr Public

    Read an open-source repository's AI contribution policy before you (or your agent) contribute. Exit codes for CI/agents.

    Python 1 7