# vouch: explicit trust as a response to AI-slop contributions

> vouch is a community trust management system by Mitchell Hashimoto: contributors must be explicitly vouched for by trusted members before interacting with configurable parts of a project, and can be denounced to be blocked. The ledger is a single flat file, enforcement ships as seven GitHub Actions, and the CLI is a Nushell module with no other dependencies. The system is experimental and in use by the Ghostty project.

**mitchellh/vouch** — A community trust management system based on explicit vouches to participate.

- Repository: https://github.com/mitchellh/vouch
- Stars: 5,113 · Forks: 92
- Language: Nushell
- License: MIT
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/mitchellh-vouch

## The broken filter of effort

The README's argument for vouch is one of the more articulate statements of a problem the maintainers of popular repositories all recognize. Open source has always run on trust and verify, and historically the effort required to understand a codebase, implement a change and submit it for review was itself a filter that kept out low-quality contributions from unqualified people, sufficient for over twenty years. The landscape changed with AI tools that let anyone trivially create plausible-looking but extremely low-quality contributions with little or no true understanding, so the minimal barrier of submitting a change no longer implies good faith or competence. The proposed correction keeps trust but makes it explicit, every project already has a definite set of trusted individuals, its maintainers, and a larger set of probably trusted ones, its active community, so let those people vouch for newcomers, and let the vouched contribute. The system is labeled experimental and is in use by Ghostty, with continued iteration promised from experience.

## A flat file as the ledger

The trust data lives in a single flat file using a minimal format, chosen so it can be trivially parsed with standard POSIX tools and any programming language without external libraries, and an example, VOUCHED.example.td, ships in the repository. That decision carries the whole audit posture of the project: the trust list is greppable, diffable in pull requests, blameable through git history, and readable by scripts that have never heard of vouch. No database, no API, no lock-in, the source of truth is text under version control, which means changes to community membership are themselves reviewed changes. The implementation is generic enough for any project on any code forge, with GitHub integration provided out of the box, so the flat file remains portable even where the automation is not.

## Seven GitHub Actions, mixed to taste

GitHub enforcement arrives as a set of provided Actions, and the integration strategy is explicitly compositional, by choosing which actions to use, a project fully controls how users are vouched and what they can or cannot do. check-issue runs on issues, verifying the author is vouched on open or reopen, automatically allowing bots and collaborators with write access, with optional auto-close and lock for the unvouched or denounced. check-pr does the same for pull requests, and check-user tests any user's standing with an allow-fail option for reporting only. The management side is conversational, manage-by-issue and manage-by-discussion let collaborators vouch, denounce or unvouch people via comments, updating the file and committing the change. sync-codeowners imports CODEOWNERS into the vouch list, and setup-vouch installs the CLI, bringing Nushell along automatically if it is missing. The repository itself fully integrates vouch, so the docs describe a running instance of their own product.

## A CLI that is nothing but Nushell

The command-line interface is implemented as a Nushell module and requires only Nushell, with no other external dependencies, an unusual and deliberate choice that makes the whole system inspectable by anyone who can read shell code. Being Nushell, it carries integrated help:

```nu
use vouch *
help add
help check
help denounce
help gh-check-issue
help gh-check-pr
help gh-manage-by-issue
```

Local operation is three verbs. Checking status uses exit codes as the contract, zero for vouched, one for denounced, two for unknown:

```bash
vouch check <username>
```

Adding and denouncing preview the new file contents by default and only write with --write, so mistakes surface before they land, and denounce accepts a reason:

```bash
vouch denounce badactor --reason "Submitted AI slop"
```

## The tool refuses to write your policy

The most consequential design decision is a refusal, who and how someone is vouched or denounced, and what consequences vouching or denouncing carries, are left entirely to the integrating project. The tooling enforces a file format and provides gates, but the policy, whether vouching requires one sponsor or three, whether denouncement is permanent or appealable, whether the gated surface is issues only or pull requests too, is community law the community must write. This is the difference between infrastructure and governance, and the repository documents the boundary rather than papering over it. Supporting material is shaped accordingly, an FAQ for the questions that recur, a Cookbook of integration patterns, and a contributing guide, all describing how to operate the machinery rather than what your rules should be.

## From the Pi project, through Ghostty

vouch is candid about its lineage: it is based on the already successful system in use by the Pi project, whose maintainer's approach the author extracted into a more generalizable form with additional changes. That origin matters for evaluation, because the model has survived contact with a real community rather than being designed in the abstract, and the generalization preserves the parts that worked while making the ledger format and tooling reusable anywhere. Ghostty, the terminal emulator, is the flagship adopter named in the warning block, which doubles as the project's own statement of seriousness and of immaturity, an experiment running in production on a popular project, gathering the experience the README promises will shape improvements. The author is Mitchell Hashimoto, and the repository carries the polish of someone who has shipped developer infrastructure at scale before.

## Small, pinned and deliberately unfinished

The operational footprint is small and carefully pinned. Nix users get a flake and shell.nix, .pinact.yaml keeps GitHub Actions references at exact versions, tests cover the module, and a HACKING.md describes the development workflow alongside AGENTS.md for coding assistants. Releases are measured, v1.4.1 and v1.4.2 on the same February 2026 day, v1.5.0 on 2026-07-12, with the last push on 2026-08-23. The honest framing throughout is that this is a bet on how open source moderation will have to work, a filter of explicit trust replacing a filter of effort, and the README's warning label, we'll continue to improve the system based on experience and feedback, is the correct register for infrastructure that governs who may speak.

## Conclusion

Adopt vouch if your project is drowning in plausible-looking but low-effort contributions and you want an explicit, file-based trust ledger your collaborators actually control, with GitHub enforcement available off the shelf. Skip it if your contribution volume is low enough that maintainer attention still scales, or if an application threshold would discourage the casual good-faith contributors you want. Verify first that you can define a vouching policy your community accepts, since the tool deliberately leaves who, how and consequences to the project, and treat it as what it declares itself to be, an experimental system still being improved from experience.

## FAQ

### What is vouch, the trust system?

vouch is a community trust management system: contributors must be explicitly vouched for by trusted members before interacting with configurable parts of a project, and can be denounced to be blocked. The vouch list lives in a single flat file, and GitHub integration ships as Actions plus a Nushell CLI.

### How does vouch integrate with GitHub?

Through seven provided GitHub Actions: check-issue and check-pr gate new issues and pull requests on author vouch status, check-user reports a user's standing, manage-by-issue and manage-by-discussion let collaborators vouch or denounce via comments, sync-codeowners imports CODEOWNERS, and setup-vouch installs the CLI.

### What file format does vouch use for its ledger?

A single flat file in a minimal format that can be trivially parsed with standard POSIX tools and any programming language without external libraries. An example file, VOUCHED.example.td, is included in the repository.

## Sources

- [Issues](https://github.com/mitchellh/vouch/issues)
- [License: MIT](https://github.com/mitchellh/vouch/blob/main/LICENSE)
- [mitchellh/vouch on GitHub](https://github.com/mitchellh/vouch)
- [README](https://github.com/mitchellh/vouch/blob/main/README.md)
- [Releases](https://github.com/mitchellh/vouch/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mitchellh-vouch
