Skip to content
Kesavaraja67Public

About

The zero-trust, local-only codebase packager. Surgically strips node_modules, build junk & caches, actively screens for hardcoded secrets, and exports pristine .zip archives or LLM text digests in one click. 100% air-gapped with zero cloud telemetry.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Xipper

The zero-trust, local-only codebase packager for developers and AI workflows.

License: MIT Build & Release

Xipper takes a project folder, automatically detects its technology stack, applies smart exclusions for dependencies and caches, actively screens for hardcoded secrets, and produces a clean .zip archive or LLM-friendly text digest in one action.


Key Features

  • 100% Local-Only / Zero Data Egress: All directory walking, secret scanning, and compression run strictly on your local machine. No cloud telemetry, no analytics, no phone-home.
  • Smart Stack Detection: Automatically recognizes Node.js/TypeScript, Python, Go, Rust, Java/Kotlin, .NET, Ruby, PHP, and monorepo configurations.
  • Deterministic 6-Layer Exclusion:
    1. Universal defaults (.git, .DS_Store, *.log, tmp/, .cache)
    2. Detected stack defaults (node_modules, venv, target, build, bin/obj, etc.)
    3. Root .gitignore parsing
    4. Nested .gitignore scoping across monorepo packages
    5. Sensitive filename screening (.env*, *.pem, id_rsa, credentials.json)
    6. Reusable user exclusion profiles
  • Two-Layer Content Secret Scanner: Inspects non-binary text files for AWS keys, GCP service accounts, Azure connection strings, GitHub tokens, Stripe/OpenAI keys, private key headers, JWTs, and high Shannon entropy literals.
  • LLM Text Digest Mode: Generates structured Markdown containing an ASCII directory tree and syntax-highlighted code blocks formatted for Claude, Gemini, or ChatGPT context windows.
  • Streaming & High Performance: Non-blocking asynchronous directory walker and streaming archiver pipeline capable of handling 50,000+ files with live progress tracking and cancel rollback.

Monorepo Architecture

xipper/
├── packages/
│   └── engine-core/       # Pure, framework-agnostic TypeScript core engine
│       ├── src/
│       │   ├── detect.ts  # Stack marker detection
│       │   ├── exclude.ts # 6-layer exclusion & gitignore engine
│       │   ├── secrets.ts # Secret regex & Shannon entropy heuristics
│       │   ├── walk.ts    # Async walker, symlinks & edge cases
│       │   ├── zip.ts     # Streaming archiver & cancellation
│       │   ├── digest.ts  # Markdown text digest generator
│       │   └── logger.ts  # Local rotating diagnostic logger
│       └── tests/         # Comprehensive Vitest test suites
├── apps/
│   ├── desktop/           # Electron + React 18 + TypeScript + Tailwind desktop app
│   │   ├── src/main/      # Electron main process & IPC handlers
│   │   ├── src/preload/   # Strictly isolated contextBridge API
│   │   └── src/renderer/  # React control panel UI & design system
│   └── web/               # Next.js static landing page & docs
└── .github/workflows/     # CI/CD multi-platform packaging

Security Model & Electron Guardrails

  • contextIsolation: true
  • nodeIntegration: false
  • sandbox: true
  • Privileged filesystem operations exist exclusively in the main process, exposed to the renderer through a narrow, strongly-typed contextBridge API (window.xipper.*).
  • Matched secret candidate strings are never rendered or logged — only the file path, line number, and rule category are reported.

Development Setup

Prerequisites

  • Node.js >= 20.0.0
  • pnpm >= 9.0.0

Installation

# Clone the repository
git clone https://github.com/Kesavaraja67/xipper.git
cd xipper

# Install workspace dependencies
pnpm install

# Run core engine tests
pnpm test

Running the Desktop App in Development

pnpm dev:desktop

Running the Web Landing Page

pnpm dev:web

Building All Packages

pnpm build

Packaging Desktop Installers

# Build desktop installer for current OS
pnpm package:desktop

Edge Case Handling Matrix

Scenario Handled Behavior
No .gitignore present Degrades gracefully to universal and stack defaults; never requires git.
Unknown project type Falls back to universal default exclusion list (.git, *.log, .tmp, etc.).
Nested .gitignore files Scoped accurately to subdirectories per gitignore specifications.
Symlinks Detected and excluded by default; prevents recursive loops and escaping project root.
Inaccessible files Non-blocking warning recorded; walker continues smoothly without crashing.
Windows MAX_PATH (>240 chars) Handled with \\?\ prefix normalization on Windows.
Cancellation mid-export Immediately aborts archiver stream and removes partial .zip from disk.
Disk full / write errors Catches ENOSPC, removes partial file, and surfaces clear diagnostic warning.

License

MIT © 2026 Xipper Contributors.

About

The zero-trust, local-only codebase packager. Surgically strips node_modules, build junk & caches, actively screens for hardcoded secrets, and exports pristine .zip archives or LLM text digests in one click. 100% air-gapped with zero cloud telemetry.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages