Skip to main content

Works with

Each row names one surface, the sentence measured for it, and where that sentence stops.

GitHub

On GitHub, a required check refuses the merge until a receipt for that diff verifies on the runner; the receipt names the operation it was granted for (merge, deploy, publish or a tool call) and expires.

a check is a lock only when it is required on the default branch, bound to the right app, bypass closed, SHA pinned — without all four it is a comment

https://github.com/marketplace/coderifts

https://github.com/marketplace/actions/coderifts-contract-gate

Claude Code

The coderifts marketplace lists plugin api-governance at version 1.1.2, and that plugin carries the skill.

The same marketplace also lists agent-hooks at version 0.2.0, which is the PreToolUse hook the install page installs.

A search of the Claude marketplace for coderifts on 2026-10-03 returned the heading No plugins for those filters.

https://github.com/coderifts/api-governance

https://claude.com/marketplace/plugins?q=coderifts

Cursor

The Cursor plugin coderifts-api-governance at version 1.0.1 is in the same repository. cursor.directory returned HTTP 429 on 2026-10-03, so this page does not say that directory lists it.

https://github.com/coderifts/api-governance/tree/main/plugins/api-governance-cursor

OpenAI

Measured 2026-09-29, ChatGPT Plus, in the EU. A personal MCP app connected to https://app.coderifts.com/mcp with no authentication. One analyze call came back. No receipt was issued.

Authorize was not called.

The Codex plugin manifest api-governance-openai at version 1.0.1 is in the repository. This round did not call Codex.

https://chatgpt.com/

/docs/hosts/chatgpt/

plugins/api-governance-openai

oasdiff

Built on oasdiff for OpenAPI; we add the grant at a required check, and the same gate for MCP tool manifests.

The OpenAPI 3.1 path selects oasdiff 1.11.11. The upstream LICENSE is Apache-2.0. The app THIRD_PARTY_NOTICES.md does not name oasdiff.

https://github.com/Tufin/oasdiff

https://www.oasdiff.com/pricing

/compare/oasdiff/

Kyverno

The Kyverno policy at examples/kyverno-decision.yaml is an example in coderifts/contract-gate. This round did not measure another installation.

examples/kyverno-decision.yaml

Sigstore and in-toto

Provenance says how it was built; the receipt says whether it was allowed.

No DSSE or in-toto envelope is emitted by any published artifact.

The layout in examples/decision.layout does not verify until a second distinct public key is added.

The predicate type in examples/attest-decision.yml is https://coderifts.com/attestations/decision/v1.

examples/attest-decision.yml

examples/decision.layout

Alongside

CodeRabbit runs oasdiff version 1.32.1 and reports supported breaking API changes as review comments. oasdiff is enabled by default.

CodeRabbit comments on a breaking OpenAPI change; a required CodeRifts check keeps it from merging.

The CodeRabbit page posts findings as review comments. It does not say a CodeRabbit comment blocks the merge.

https://docs.coderabbit.ai/tools/oasdiff