OPEN SOURCE / MIT Trust starts with inspection
The verifier
is open.
MaruCheck judges whether code has enough evidence to ship. You should be able to read how that judgment is made, run it locally, and change it with the community.
01 — RUN THE SAME VERIFIER
No black-box gate between your code and release.
$ npm install --save-dev --save-exact marucheck@0.5.0$ npx --no-install maru verify --diff02 — TWO REPOSITORIES / ONE PROOF LOOP
Separate release cycles. Shared contracts.
The local CLI and hosted application remain independent projects so either can evolve without hiding the boundary between local execution and shared evidence.
03 — CONTRIBUTE TO THE FAILURE PATH
Bring the case the happy path missed.
Report a false pass. Tighten a contract rule. Add an adapter. Improve the evidence a developer sees when a release is blocked. Focused issues and pull requests are welcome.
COMMON QUESTIONS
Common questions
- What license does MaruCheck use?
- MaruCheck is released under the MIT license. You may read, run, modify, self-host, and redistribute it, including commercially. The verifier and the web application are maintained as two public repositories so you can inspect exactly what runs before putting it in a release path.
- Where is the MaruCheck source code?
- MaruCheck is split into two repositories. Kidus-M/MaruCheck holds the CLI: Quality Contracts, risk analysis, verification plans, evidence, QA Memory, semantic drift, MCP, and CI. Kidus-M/MaruCheck-Web holds the public site, authenticated dashboard, project connections, report ingestion, and production feedback.
- Can I contribute to MaruCheck?
- Yes. MaruCheck accepts focused contributions through its public CONTRIBUTING guide, which describes the expected workflow, checks, and review expectations. Reading the verifier's source before adopting it is encouraged — an independent check is only worth running if you can audit what it actually does.