Developers · v0.50.0

Put RuleOak in front of one consequential action

Distribution boundary: the public source repository is the canonical source release. npm-specific commands apply only after the exact @ruleoak/*@0.50.0 packages are publicly available and verified.

Start with one supported execution path where incorrect autonomous behavior would matter. Verify the boundary before broadening scope.

Source checkout

git clone https://github.com/ruleoak/ruleoak.git
cd ruleoak
git checkout v0.50.0
npm ci --ignore-scripts
npm run check:publish
Source checkout works independently of npm publication. When npm packages are published, use exact @0.50.0 versions and verify packed contents against the release evidence.

Package roles

PackageRole
@ruleoak/protocolSchemas, validators, conformance vectors and stable integration formats.
@ruleoak/coreAuthority, policy, approval, execution and evidence runtime.
@ruleoak/cliProtection, diagnostics, approvals, inspection, evidence, reliability and governed-development workflows.

Minimal Node SDK pattern

import { createRuleOak } from '@ruleoak/core'

const ruleoak = await createRuleOak({
  workspace: '.ruleoak',
  policy: { policyVersion: 2, defaultAction: 'deny', rules: [] }
})

const guarded = ruleoak.guardFunction({
  name: 'filesystem.read',
  category: 'file',
  operation: 'read',
  resource: ([path]) => path,
  execute: async (path) => /* your implementation */ path
})

The SDK guards only calls routed through the guarded function/tool. It does not intercept unrelated process behavior.

Integration paths

Before production-like use