Skip to content
View yunaremaia's full-sized avatar

Block or report yunaremaia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
yunaremaia/README.md

Yunare Maia 🇧🇷

Open-source developer from Mossoró, Rio Grande do Norte - Brazil. I build driftcheck — a CLI that catches version drift between docs and toolchain files before your contributors hit a build failure. I also contribute to agent runtimes, security scanners, and developer tooling: AI-policy classification, vulnerability reporting, CLI ergonomics, and the CI hygiene that keeps big repos mergeable. Steady, reproducible, reviewed — one focused PR at a time.

driftcheck Apache Maka Modular Mojo anchore/syft LMCache fmt VoiceStudio Merged PRs Open to collaboration

GitHub stats Contribution streak

Now

  • Open PRs: open pull requests across developer tooling, security scanners, and upstream reproducibility — including driftcheck lint hardening, Go lint pass, and GitHub Actions CI hygiene. Currently in flight:
    • yunaremaia/driftcheck#160 — add ruff and mypy linting to CI workflow (fixes #148)
    • anchore/syft#5302 — skip docker:// references in github-actions PURL generation
    • LMCache/LMCache#5211 — remove stale G004 ignores for clean connector adapters
    • karmada-io/karmada#7898 — remove retired Go Report Card badge from README
    • ray-project/kuberay#5286 — remove unused DecompressStream to clear gosec G110
  • Recently merged: browse the live search or see the highlights below.

Featured contributions

  • 🔍 yunaremaia/driftcheck — my own project. Detects version drift between docs and toolchain files (README vs Dockerfile, build.gradle, pom.xml, versions.tf, .circleci/config.yml, .gitlab-ci.yml, GitHub Actions versions, Kubernetes manifests, Helm charts, Taskfiles, and more). 64 detector modules, 1198+ tests, 25+ drift types.
  • 🛡️ yunaremaia/aipr — AI-policy pre-screening for contributors: classifies CONTRIBUTING/AI_POLICY/AGENTS docs and flags repos that require human-in-the-loop disclosure before you invest hours building a PR.
  • ⚡ yunaremaia/agentcost — track and compare LLM API pricing across 20+ models with SQLite persistence for historical cost analysis.
  • 🏛️ apache/maka (ASF agent runtime) - five merged PRs in one week: permission-mode refactor, usage-limit billing paths, humanized retry delays, DeepSeek V4 Flash metadata, and a desktop flake fix.
  • 📦 anchore/syft — Syft is the open-source SBOM generator. Contributed PURL generation fixes for GitHub Actions packages (skip docker:// references to prevent malformed package URLs).
  • 🔐 decionis/agent-safe-pipeline - cryptographic-agility docs, TLS verification posture, and Unicode edge-case conformance vectors (#56, #55, #23).
  • 🧠 LMCache/LMCache — KV-cache acceleration for LLM inference. Lint hygiene pass removing stale gosec suppresses now that connector adapters are clean.

What I work on

  • 🔍 Drift detection — version drift between docs and toolchain files (Dockerfile, build.gradle, pom.xml, versions.tf, CircleCI, GitLab CI, GitHub Actions, Kubernetes, Helm, Taskfiles, and more)
  • 🤖 AI policy tooling — automated pre-screening of AI contribution policies so contributors know before building whether a repo accepts autonomous PRs
  • 💰 LLM cost tracking — pricing APIs, historical cost analysis, model comparison
  • 🔬 Test infrastructure & CI hygiene — flake elimination, conformance vectors, reproducible pipelines (Rust, Python, Mojo, Go, C++)
  • 📦 Software composition analysis — SBOM generation, PURL correctness, vulnerability reporting
  • 🔤 Encoding & Unicode correctness — UTF-8 sanitization, Windows code-page edge cases, std::error_code formatter robustness (C++)
  • 🤖 AI agent safety — policy-as-code permissions (agent-guard), security scanning for AI-generated code (vibeguard), MCP server audits (mcp-guard), memory health monitoring (memwatch), CLI output filtering (leanpipe)
  • 🔄 Agent state & observability — checkpoint/recovery (agent-checkpoint), session memory (context-bridge), token tracking (agentcost), worktree isolation (agent-workspace), tool-call rollback (agent-undo)

Recent merged work

When Where What
2026-09-29 yunaremaia/driftcheck feat: detect Python target drift inside pyproject.toml tool tables (+9 more)
2026-09-27 yunaremaia/ci-test-gate ci: update github-script to v8 for Node 24 runner compatibility
2026-09-27 yunaremaia/agent-undo feat: add rollback simulation/dry-run mode with diff preview and command list (#
2026-09-27 yunaremaia/gfi feat: add persistent seen-issue tracking with URL-based dedup and deterministic (+1 more)
2026-09-26 yunaremaia/agent-guard security: add path traversal protection to _normalize_path
2026-09-26 yunaremaia/aipr fix(ci): update GitHub Actions to known-stable versions

Stack

TypeScript Python Rust Mojo C++ Go Bash · Node · git-first workflows · schema-driven pipelines · distributed test runners · drift detection · AI policy tooling · LLM cost tracking

Support

If my open-source work saves you time, you can support it here:

  • Solana / cbBTC: Eeztv1nCYUt1fwGWpzKC948gaWfjejYCAuLtUMgzDWbW
  • Or collaborate: pick an open issue I maintain, or ping me below.

Featured Projects

Project What it does Stack Tests
driftcheck 61 detectors for version drift between docs and toolchain files — Dockerfile, go.mod, rust-toolchain, package.json, Taskfile, Gradle, .NET/C#, Node 20→24 Actions, and more. --fix mode + SARIF output Python · pytest 1308
taintrace Typosquat detector for package managers — catches malicious lookalike names before they reach your lockfile Python · rapidfuzz 116
agent-guard Policy-as-code for AI agent permissions — define bounded permissions in YAML, enforce at runtime with shell injection, ReDoS, and symlink path-traversal prevention Python · YAML —
agentcost Token usage tracker for multi-agent AI sessions — per-agent, per-run cost breakdowns with SQLite persistence Python · SQLite 64
depscan Multi-ecosystem dependency scanner (PyPI, npm, Cargo, Go, PHP) with vulnerability and typosquat detection Python 13
ci-test-gate LLM-powered test selection for CI — runs only tests relevant to the semantic diff, cutting CI minutes Python 157
diff-contract Deterministic guardrails for AI-generated diffs — block changes to protected paths, enforce contract boundaries Python 59
aipr AI contribution policy scanner for repositories — CI exit codes for humans and agents; detects AI policy gates pre-flight Python 37
vibeguard Security scanner for AI-generated code — shell injection, ReDoS, symlink traversal detection Python —
mcp-guard Security scanner for MCP servers — audit capabilities, detect risks, generate SARIF reports Python —
agent-undo Record and rollback AI agent operations — file writes, shell commands, git ops, API calls. Time-machine for AI agent actions Python —
agent-checkpoint Crash recovery preserving exact AI agent state — decisions, reasoning log, accumulated context — with deterministic resume Python —
agent-workspace Git worktree manager for parallel AI agents Python —
context-bridge Universal session memory for AI agents — capture, index, recall across any AI coding agent Python —
leanpipe CLI output filter for AI agents — strip noise, keep signal, save tokens Python —
memwatch Agent Memory Health Monitor — scan AI agent memory stores for rot, contradictions, and duplicates Python —
ghstats GitHub Stats Dashboard — visualize contributions, PRs, and activity from the terminal Python —
gfi Good First Issue finder — search and filter GitHub issues for contributors Python —
a2a-drift Detect A2A (Agent2Agent) protocol compliance drift — agent cards, endpoints, spec versions, JSON-RPC conformance Python —
agent-behavior-drift Detect behavioral drift in AI agent sessions — tool-call patterns, output quality, decision anomalies Python —
ci-sandbox Local CI pipeline simulator — see what runs and what skips without executing anything Python —
cli-shim Universal Agent-Native CLI Adapter — makes legacy CLIs agent-friendly Python —
mcp-reconcile Cross-tool MCP configuration drift detection and reconciliation Python —
oss-contribution-finder Find open-source contribution opportunities via GitHub API Python —
agent-capability-attestation Capability attestation for AI agents — verify declared capabilities against observed behavior Python —
env-drift Environment variable drift detection — .env vs actual runtime config Python —
prompt-drift Prompt template drift detection — detect changes in prompt chains across versions Python —
proto-drift Protobuf/gRPC schema drift detection — breaking changes in .proto files Python —
license-drift License header drift detection — missing or stale SPDX headers in source files Python —
dotfiles-drift Dotfiles configuration drift detection — sync dotfiles across machines Python —
ci-gate-watch CI gate drift watch — detect when required CI checks change or disappear Python —
mcp-response-guard MCP response guard — validate MCP server responses against declared schemas Python —
agent-memory Structured memory for AI agents — persistent key-value with TTL and namespaces Python —
agent-call-graph Call graph visualization for AI agent tool invocations Python —
ai-reputation-guard Reputation scoring for AI-generated contributions — detect low-effort patterns Python —
tool-call-retry Retry logic with backoff for AI agent tool calls Python —
migrate-safe Safe migration runner for AI agent state across versions Python —
org-policy-drift Organization policy drift detection — enforce consistency across repos Python —
acc-mcp MCP server for accessibility testing Python —
sandbox-ffi-layers FFI sandboxing layers for secure AI agent execution Rust —
git-api Git API wrapper for AI agents Python —

Focus Areas

  • Drift Detection — version drift between documentation and actual toolchain files across 14+ ecosystems (Maven, Terraform, CircleCI, GitLab CI, GitHub Actions, Kubernetes, Helm, Docker Compose, Dependabot, .NET/C#, Taskfile, Gradle, pip, npm, Node 20→24 Actions migration, A2A protocol)
  • Dependency Security — typosquat detection (taintrace), multi-ecosystem vulnerability scanning (depscan), supply-chain risk analysis, license drift detection
  • AI Agent Safety — policy-as-code permissions with runtime enforcement (agent-guard), security scanning for AI-generated code (vibeguard), MCP server audits (mcp-guard), memory health monitoring (memwatch), CLI output filtering (leanpipe)
  • CI/CD Intelligence — LLM-powered test selection (ci-test-gate), deterministic diff guardrails (diff-contract), AI policy gates for CI (aipr), local CI simulation (ci-sandbox), CI gate drift watch (ci-gate-watch)
  • Agent Observability & State — token usage tracking (agentcost), universal CLI adapters (cli-shim), session memory bridging (context-bridge), crash recovery with state preservation (agent-checkpoint), worktree isolation (agent-workspace), tool-call rollback (agent-undo), behavioral drift detection (agent-behavior-drift), capability attestation (agent-capability-attestation)
  • Protocol & Standards Compliance — A2A protocol drift detection (a2a-drift), MCP configuration reconciliation (mcp-reconcile), MCP response guard (mcp-response-guard), protobuf/gRPC drift (proto-drift)
  • Developer Experience — good first issue finder (gfi), GitHub stats dashboard (ghstats), OSS contribution finder (oss-contribution-finder), prompt drift detection (prompt-drift), env drift detection (env-drift)

Stats

Metric Value
Public repos 137
Original projects
Merged PRs
Total tests 1750+
Stars received 29
Followers 57
Current streak see card below
Primary language Python

Contribution Streak

Contribution streak card — self-hosted, always fresh


Upstream Contributions

Contributions to apache/maka, modular/modular, sharkdp/bat, biopython/biopython, SeaQL/sea-orm, upscayl/upscayl, anchore/syft, LMCache/LMCache, karmada-io/karmada, ray-project/kuberay, and several others. Focus on actionable fixes: version drift, docs sync, test improvements, and CI hardening.


Toolchain

  • Python (primary) — pytest, click, rich, rapidfuzz, SQLite
  • Rust — FFI layers, sandboxing primitives, proc-macro security
  • GitHub API — GraphQL + REST, Actions, CI integration
  • CLI-first — every tool installable via pip install git+https://..., designed for scripting and automation

Reach Me

  • GitHub issues and PRs are the fastest channel for anything project-related
  • Email: yunare@gmail.com
  • Operating agreement: inicio.md (public-facing identity and contributor rules)

For Contributors

  • All projects are open source first — PRs welcome in any repo above
  • Check each repo's CONTRIBUTING.md and AI policy before contributing (use aipr to auto-detect policy gates)
  • Issues labeled good first issue are actively maintained — claim before opening a PR
  • Public artifacts (PRs, commits, issues) are English only

Bio and stats refreshed automatically by github-profile-keeper cron.

Python Tests Merged PRs Followers Open source first

Popular repositories Loading

  1. driftcheck driftcheck Public

    Detect version drift between docs and toolchain files (README vs rust-toolchain.toml etc.)

    Python 3 14

  2. agent-guard agent-guard Public

    Policy-as-code for AI agent permissions. Define bounded permissions in YAML, enforce at runtime.

    Python 3 9

  3. oss-contribution-finder oss-contribution-finder Public

    Find open-source contribution opportunities via GitHub API

    Python 2 8

  4. agentcost agentcost Public

    Token usage tracker for multi-agent AI sessions

    Python 2 10

  5. depscan depscan Public

    Multi-ecosystem dependency scanner with typosquat detection

    Python 2 9

  6. yunaremaia yunaremaia Public

    Python 1 1