Skip to content

Community review

Plugin approvals, takedowns and reviewer changes are decided by votes from registered reviewers and recorded in a public, append-only ledger. 0 of 504 listed plugins are community verified.

How it works

  1. Propose. Anyone with a GitHub account older than 30 days opens a pull request that appends one entry to registry/ledger.jsonl, for example npm run ledger -- approve <plugin> --by <you>.
  2. Vote. Registered reviewers read the code (npm run ledger -- inspect <plugin> downloads and unpacks the exact zip) and approve or request changes on the pull request.
  3. Count. A check counts approvals on the latest commit from reviewers whose GitHub accounts are at least 180 days old. Your own pull request and plugins from a repo you own never count. A single request for changes from a reviewer blocks it.
  4. Record. Once merged, the entry becomes part of the ledger and the site updates on the next build.

Votes needed

ChangeApprovals
Approve a plugin version2
Revoke a plugin (malware, abuse)1
Add a source2
Remove a source (spam)2
Add or remove a reviewer2 / 2
Change the site's code2
Change these rules or the vote counter3

Every change needs at least two people: the one proposing it and someone else approving it. While there are fewer reviewers than a quorum, every eligible reviewer must approve. The numbers live in registry/governance.json, and changing them takes 3 approvals.

What "verified" means

An approval pins the SHA-256 of each package zip, the same hash Stash checks when it installs. If the author publishes new code, the hash changes and the plugin shows Changed since review until reviewers approve the new version. A revoke hides a plugin and its install snippets right away, and it keeps them hidden until a new version is approved.

Ledger integrity

Each ledger entry records the SHA-256 hash of the entry before it. Changing or removing an earlier entry changes its hash and invalidates every entry after it, so any copy of the ledger can be checked for tampering. Every clone and fork of the repository holds the full history. Votes are GitHub pull request reviews from registered accounts.

Current head: d5f33b57678a96cf460c36688df390a66a3bfca9042d5ab9932097b159bc91c4
To verify, download ledger.jsonl and run npm run ledger -- verify ledger.jsonl from a clone of this repo.

Reviewers (1)

To become a reviewer, open a pull request created with npm run ledger -- add-reviewer <your-login> --by <your-login> and describe your experience. Existing reviewers vote on it.

Needs review

No approved plugins have changed since review.

493 plugins have not been reviewed yet. Any of them can be proposed for approval from the plugin list.

Ledger

#DecisionProposed byDateHash
0Ledger started with reviewers SudoMedic
Bootstrap reviewer. Add more with add-reviewer pull requests.
-Oct 10, 2026d5f33b57678a