Open source from ROSH™ Company Labs
The libraries we publish, free for anyone to use. MIT licence, no runtime dependencies, tests and benchmarks in the repository, and a changelog that says what was wrong rather than only what is new.
What we publish and keep maintained
One project so far. New ones appear here as they are released.
What we found while building it
The problems worth writing down, with the sources for every claim.
The standard these are held to
- MIT licence. Use it commercially, in closed-source work, without asking anyone.
- No runtime dependencies where the work allows it, so nothing else enters your dependency tree with it.
- Released from CI with a provenance attestation, so the published tarball can be traced back to the workflow and the commit that built it.
- Tests and benchmarks live in the repository, and every number we publish comes from running them — including the ones that are unflattering.
- The changelog says what was wrong, where the report came from and what it cost, not only what is new.
- A way past a guard is the most useful report we can get. Every project listed here has a SECURITY.md explaining how to send one privately.
The same standard applies to the client work — the difference is that here you can read it.
Questions about these libraries
Can I use these commercially?
Yes. The MIT licence allows commercial use, modification and redistribution, including inside closed-source products. Keep the licence text with the copy you ship.
Who maintains them?
Redouane — ROSH™ Company Labs. Bugs and feature requests go to GitHub issues on the project itself; anything that gets past a guard should go through SECURITY.md instead, privately.
Do you accept contributions?
Yes, with two rules that matter more than usual here: no real value of any kind in a diff — no credential, card number, personal address, machine path or username — and a pull request has to pass the tests and the precision gate, which fails on a single false positive.
Will these stay free?
A version published under MIT cannot be taken back: whatever is released stays usable under that licence, by anyone, permanently. That is a property of the licence, not a promise from us.
How do these relate to the paid services?
They are separate. The libraries are free and self-contained, and nothing on this page is an upsell. They exist because the problems were in our way, and publishing them is how the standard behind the client work becomes something you can inspect instead of something we assert.
Are these production-ready?
Read the project page before deciding. Each one states its version, its test count, what it does not do and what has been fixed since launch. They are young, they are tested in the open, and the honest answer for any one of them is on its own page rather than here.
Back the work that stays free
Everything here is MIT-licensed and free to use — no paid tier, no telemetry, no account. GitHub Sponsors is what keeps it that way.