Skip to content

Instantly share code, notes, and snippets.

@loganlinn
Created September 25, 2026 00:10
Show Gist options
  • Select an option

  • Save loganlinn/796d1ca7dc0ea200bedccdaf50eb7d4e to your computer and use it in GitHub Desktop.

Select an option

Save loganlinn/796d1ca7dc0ea200bedccdaf50eb7d4e to your computer and use it in GitHub Desktop.
Jev (TypeSafe System One) projects for Infrastructure, DevOps & SRE — scouted Sep 2026

Jev for Infrastructure, DevOps & SRE — Project Scout

Scope: Open-source projects using TypeSafe's Jev (System One decision model) for infrastructure, DevOps, SRE, or platform engineering work. Sourced from GitHub repo search, code search, topic pages, and two community awesome-lists. Star counts are point-in-time (Sep 24, 2026). Filtered for serious projects — no tutorial repos, no empty scaffolds, no AI-generated slop.


Tier 1 — Built for SRE / Platform Engineering

Repo Lang ★ What it does
kiwi0719/jev-edge Lua/Go 34 Typed-judgment admission control at the traffic edge. Sits in nginx/OpenResty, APISIX, Kong; works behind Envoy, Istio, HAProxy, Traefik, Caddy; also Cloudflare Workers, Lambda@Edge, LiteLLM proxy. Asks one question about incoming requests: what is this request trying to do to my service? Catches prompt injection and abuse at the gateway before requests reach your backend. Fail-open, cached, hot-reloadable. Apache 2.0. Has benchmarks, Docker compose demo. Explicitly built for SREs, not agent authors.
jbt95/jev-toolkit TS 1 MCP-first Jev toolkit with Prometheus impact metrics + Grafana dashboard. One stdio MCP server, local JSONL event log, jev meter serve exposes Prometheus series on 127.0.0.1:8788. Ships a Grafana dashboard + install script. Built with Effect v4 RC (services, layers, typed errors, schema-validated boundaries). Triage packs for CI failures with a semantic loop breaker. launchd jobs for always-on meter + nightly audit/label runs. Early (created Sep 21) but architecturally serious.
eaisdevelopment/jevmcp Python 0 SDLC tooling: spec-drift, CI triage, code audit. ci-triage reads a failed GitHub Actions pipeline (via your own gh) and says what actually broke: for each distinct failure, whether the change under test caused it, the error line, and the next step. spec-drift checks code against its design spec. code-audit screens a codebase against its own rules (CLAUDE.md, AGENTS.md, CONTRIBUTING). One MCP server, one API key, each tool is its own skill. Very early but the CI triage concept is directly DevOps-relevant.

Tier 2 — Agent Guardrails & Security (SRE-adjacent)

Repo Lang ★ What it does
leepokai/jev-guard TS 33 Security hook for coding agents. Risk-scores every tool call with session context — deny/ask/allow. Flags prompt injection in tool results. Scans skills and plugins for malicious instructions. Works with Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, ACP. Zero dependencies, one fetch to TypeSafe or Vercel AI Gateway. check and scan commands for CI calibration. Verified end-to-end against live API (blocked a wrangler deploy --env production).
keiffff/jev-kit TS 1 Engineering-grade decision boundary for Jev. Versioned decision contracts with SHA-256 fingerprints, runtime response validation, explicit routing (allow/defer), calibration + holdout fixtures for measuring false-allow/false-defer rates. Agent review pipeline normalizes Codex/Claude Code/custom payloads. Credential preflight before model call. This is the most rigorously engineered Jev wrapper — treats the model call as a component to be validated, not magic.
luantak/is-malicious TS 24 Codebase scanner for malicious behavior. Scans source, config, build, and CI files with Jev. --diff-from origin/main scans only changed files for PR review. GitHub Actions examples for PR checks and report comments. Two-pass scan (full chunk → focused line windows). Reports token usage and cost. Supports custom TypeSafe-compatible endpoints.
shiftynick/jev-axi TS 21 Agent-ergonomic CLI with git hooks. Pre-commit, commit-msg, and pre-push hooks that judge diffs. Pre-push judges the entire push range — flags migrations without rollback notes, sensitive-area changes (auth/crypto/credentials), hand-edited generated files, and WIP leftovers. GitHub Action available. 68 commits, actively developed (update 11h ago). Credential redaction, cache by range to avoid repetitive warnings.

Tier 3 — Code Review & Ship Gates (DevOps-adjacent)

Repo Lang ★ What it does
devagrawal09/jev-review TS 599 Staged code-review workflow + local dashboard. Reviews git diffs or scans complete codebases. Jev pipeline: noul risk matrix → file profiles → evidence selection → mechanism classification → severity scoring → reviewer routing. Screens correctness, security, reliability, compatibility, test coverage. Dashboard on 127.0.0.1:4317.
abhishekswe/agent-fastpath TS 3 Ship gates, risk checks, file triage. ship_gate preset returns READY_TO_SHIP / NEEDS_REVIEW / BLOCKED for CI and test logs. risk preset flags rm -rf, git push --force, DROP TABLE. Deterministic rules first (sub-ms), then Jev for the rest. Headless browser with SSRF protection. Server-side file triage keeps files out of agent context (408 vs 35,256 tokens in benchmark). Published on npm. Setup guides for 12 agents.
burnigtm/jev-mcp TS 48 MCP server with 9 typed tools. jev_step routes next step + selects prepared call in one request. jev_gate combines patch review + claim verification. jev_screen filters untrusted content. jev_coding_loop decides whether a partner model is needed. Reduces partner-model turns by policy. Comprehensive docs (architecture, tools, install, configuration). CI on Node 20/22, Windows + Linux.
devagrawal09/stanley-code TS 114 Self-improving Jev-first coding agent. Routes requests to deterministic workflows (built-in or repo-defined). When no workflow fits, falls back to Pi agent, then writes and validates a new workflow for next time. Checks diffs against task, project rules, acceptance criteria. Finds test gaps, security regressions.

Tier 4 — Infrastructure-Adjacent / Data

Repo Lang ★ What it does
juspay/neurolink TS 139 Universal AI integration platform. One interface for 30+ LLM providers. MCP-native. Includes Jev as a "calibrated decide" inference type alongside generate and stream. Production-origin: powers Tara, Yama, and Clairvoyance at Juspay (payments infra). Not Jev-specific but is the most production-hardened Jev consumer.
realZachi/pg-jev SQL/Python 333 PostgreSQL extension for typed semantic questions over table data. jev(table, question) runs per-row Jev judgments in SQL. Streaming read-ahead, persistent HTTPS, batch concurrency. jev_prob() exposes raw probabilities. Use for data classification, churn risk, content moderation at the database layer.
tamaratran/jev-pruner TS 145 Trims long Bash output before the model sees it. Claude Code plugin + Codex wrapper. Categories for build/test/install vs search vs whole-document. Archives full output to .claude/fast-jev-output/. 10k token gate, history-aware partitioning. Directly relevant to agent ops in CI-heavy workflows.

Recommended Stack for Infra/DevOps/SRE

For SRE / platform engineering (protecting LLM-backed services at the edge):

  • jev-edge is the only project that runs Jev at the gateway, not on the developer's machine. It's the SRE answer to prompt injection.

For CI/CD pipeline integration:

  • jev-axi for git-hook-level gates (pre-commit, pre-push)
  • is-malicious for PR diff scanning in GitHub Actions
  • jevmcp (eaisdevelopment) for CI failure triage
  • agent-fastpath for ship-gate decisions on test/CI logs

For agent safety in production:

  • jev-guard for multi-agent tool-call risk scoring
  • jev-kit if you need calibrated, versioned, contract-based decision boundaries with measured false-allow/false-defer rates

For observability of Jev itself:

  • jev-toolkit (jbt95) for Prometheus metrics + Grafana dashboard on your Jev usage

Methodology

Searched via gh search repos with 16 query variants (jev + terraform/infrastructure/devops/sre/aws/kubernetes/cicd/pipeline/monitoring/prometheus/cloud/hook/safety/gate/compaction/routing), gh api search/code for code-level usage, GitHub topic pages (typesafe-jev, typesafe-ai), and two community awesome-lists (Anil-matcha/awesome-jev-by-typesafe, AbdelStark/awesome-typesafe-jev). Top candidates verified via README extraction. Filtered out: tutorial repos, empty scaffolds, AI-generated boilerplate, projects with no README, and projects unrelated to infra/DevOps/SRE (games, robotics, ad blockers, discography tools). Star counts are approximate, captured Sep 24, 2026.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment