Paraphe 0.0.1
dotnet tool install --global Paraphe --version 0.0.1
dotnet new tool-manifest
dotnet tool install --local Paraphe --version 0.0.1
#tool dotnet:?package=Paraphe&version=0.0.1
nuke :add-package Paraphe --version 0.0.1
Paraphe
Review git branches locally, independent of any forge. Review state is stored in git itself, so it survives rebases and travels over the remote your team already has.
Status: design stage. No functionality is implemented.
The artifact in this repository is the design brief, PARAPHE.md. It records what has been settled, why, and what is deliberately still open.
A
Paraphepackage exists on NuGet, but only to hold the id. Installing it gets you a command that prints this status and nothing else — it does not read your repositories or write any refs. Do not install it expecting a tool.
Install
dotnet tool install --global Paraphe
paraphe
Requires the .NET 10 SDK or runtime.
Paraphe ships as a dotnet tool and will not be published as a library. That is
a licensing decision rather than a packaging one — see
section 9 of the brief.
The name
Paraphe (pronounced "pa-RAF") is the French word for the initials you put on every page of a contract to attest that you have read it.
That is exactly the model: per-page attestation, made by a named person, against a specific version. Not a checkbox — a signature on a particular piece of paper.
What it is meant to do
- Watch several local repositories at once, persistently.
- Show what changed on a branch relative to a configurable base. Not
hardcoded to
main— the case that motivated this isdevelop/4.x. - Track a per-file review status per person, with drift detection when a file changes after you looked at it.
- Store all of it in git, under
refs/paraphe/*, shared over the existing remote. No hosted service, no database, no account.
Two front doors over one set of UI components: the paraphe CLI reviews the
repo you are standing in and serves its UI to your browser from a loopback
server, and a desktop app lets you pick repository, branch and base and watch
several repos at once. Blazor throughout — WebAssembly in the browser, Photino
on the desktop — on a Fluent 2 base.
Explicit non-goals: it is not a forge, not a PR platform, not a CI system, not an IDE, and not an AI agent host. It does not fetch, push, commit or edit your repository content beyond its own refs.
What is actually different about it
Every comparable tool stores review state as (path, reviewed: bool) — a
private, local, single-user flag.
Paraphe stores an append-only log of immutable attestations, each recording the blob SHA of the version actually looked at. That one change buys, all at once:
- Diff since approval. Show me what changed between the version I approved and what is there now. As far as we can tell, no existing local review tool can answer that question, because none of them recorded enough to.
- Free drift detection — the current blob simply is not the attested blob.
- Survives rebase, force-push, cherry-pick and branch renames, because blob SHAs are content-addressed and indifferent to commit topology.
- Multi-user by set union. One git ref per person means two reviewers never write the same ref, so there is no merge, no conflict, and no merge driver to install.
The feature falls out of the data model rather than being bolted onto it. That is the whole bet.
Reading order
| Document | What is in it |
|---|---|
| PARAPHE.md | The design brief. Data model, git storage layout, the full event model, security posture, licensing rationale, open questions. |
| CONTRIBUTING.md | How to contribute, how to sign the CLA, file headers, third-party code policy. |
| CLA.md | The Contributor License Agreement, individual and corporate. |
| RELEASING.md | Release runbook: NuGet key setup, cutting a release, verifying it. |
| LICENSE | GNU Affero General Public License v3.0. |
Status and what has been validated
Design stage. The highest-risk assumption in the whole design has been tested
and cleared: Azure DevOps accepts, stores, reports and deletes refs outside
refs/heads and refs/tags. Review data can be pushed to a real ADO remote
without it being silently dropped and without firing CI triggers. Details in
section 6 of the brief.
Everything else is unbuilt.
License
Paraphe is licensed under the GNU Affero General Public License v3.0 only
(AGPL-3.0-only). See LICENSE.
Contributions are accepted under a Contributor License Agreement — see CLA.md for the agreement and the rationale for an honest account of what it asks and what the project commits to in return. You keep your copyright; it is a license, not an assignment.
Your review data is not covered by the AGPL
This is the first thing a compliance-minded colleague will ask, so it is worth answering plainly.
The AGPL covers Paraphe's own source code. The events Paraphe writes into
refs/paraphe/* are your data, produced by running the tool, in the same way a
document produced by a text editor belongs to whoever wrote it. The license has
nothing to say about your repository, your source code, or your review records.
An AGPL tool does not infect the repository it operates on.
The name is not licensed by the AGPL
"Paraphe" and paraphe.dev are project identity, not code. The license grants
rights to the source; it does not grant permission to present a fork as Paraphe.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.0.1 | 103 | 9/6/2026 |