Skip to content
View tombruno-korext's full-sized avatar

Organizations

@Korext

Block or report tombruno-korext

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tombruno-korext/README.md
Tom Bruno: Open standards for AI code governance

Korext Open Source Korext Followers Org Stars


Hello

I'm Tom. I build infrastructure for software accountability.

I'm the creator and lead maintainer of Korext Open Source: seven open standards for making AI generated code traceable, licensable, and accountable across software supply chains. The work focuses on a future where AI writes more code than humans can review, and where the discipline of governance has to keep pace.

Alongside the open standards, I'm Founder of Korext, the commercial governance runtime that enforces these standards inside regulated industries (banks, defense primes, healthcare systems).


Open Standards

The seven packages I design, maintain, and ship.

StandardWhat it doesVersion
ai-attestation Verifiable provenance for the leading AI coding tools version
supply-chain-attestation Adapters across the leading SBOM and signature ecosystems version
ai-license Licensing framework for AI generated code version
ai-incident-registry Public incident taxonomy and registry for AI code failures version
ai-code-radar Detection pattern library for AI authored code version
ai-regression-database Regression fingerprinting for AI code patterns version
commit-carbon Emissions accounting for software changes version

Specifications: CC0 (public domain). Code: Apache 2.0. Data: CC BY 4.0. Zero legal friction for adopters to build on the standards or contribute back.


Korext Platform

The commercial governance runtime.

Korext is the enforcement layer for the open standards: it sits inside regulated industry development workflows and enforces policy, sovereignty, and audit at the moment code is written. Banks, defense primes, and healthcare systems cannot legally adopt autonomous coding tools without provable controls over what the AI writes, where the data sits, and who attests to the output.

The standards are the substrate. The platform is the runtime.

korext.com →


Day Job

Product and Platform Strategy Lead at Google, where my work centers on Chrome's AI platform, web ecosystem, and developer surfaces.


Education

UC Berkeley HEC Paris TU Dublin


Activity

GitHub Stats Top Languages



Activity Graph

Connect

LinkedIn Korext OSS Email



The next decade of software gets written faster than humans can review it. Infrastructure for accountability has to ship at the same pace as the agents producing the code.

Pinned Loading

  1. Korext/ai-attestation Korext/ai-attestation Public

    Track AI generated code in your repository. Open standard. Detects 19 AI coding tools. CC0 spec.

    JavaScript 23 3

  2. Korext/ai-code-radar Korext/ai-code-radar Public

    Live data on AI code adoption across open source. Public API. Embeddable charts. Weekly reports.

    JavaScript 4

  3. Korext/ai-incident-registry Korext/ai-incident-registry Public

    Public registry for AI code failures. AICI identifiers. Detection rule mapping. Vendor notification.

    JavaScript 4

  4. Korext/commit-carbon Korext/commit-carbon Public

    Carbon footprint of AI assisted commits. CSRD, SEC, CDP compatible. Peer reviewed methodology.

    JavaScript 4

  5. Korext/enforce-action Korext/enforce-action Public

    GitHub Action for AI code governance. Scan pull requests. Block violations. Signed proof bundles.

    TypeScript 4

  6. Korext/supply-chain-attestation Korext/supply-chain-attestation Public

    AI provenance across your dependency tree. 14 ecosystems. CycloneDX and SPDX integration. Private registry.

    JavaScript 6 1