About.

Who operates GIVO, what the registry sees and stores, how to verify its guarantees without trusting them, and how to report abuse.

Operator

GIVO is built and operated by Danthur Lice as a Tree Combinator project. Contact: dev (at) treecombinator.com.

Source

The givo CLI, the code that runs on your machine, is open source: github.com/treecombinator/givo-cli (also linked from the package's repository field). The registry service itself is not published, the same model npm uses: open client, closed service. What the service guarantees is verifiable from the outside; see below.

What the registry sees and stores

Verify, do not trust

The full trade-off, written for skeptics (human and machine), is in AGENTS.md and in the docs.

Operational expectations

GIVO is operated best effort by one person; there is no paid SLA. What holds regardless of the operator's day: released versions are immutable, everything that ever resolved through GIVO keeps installing during an npmjs outage, every package's write history is public at /npm/-/givo/audit/<pkg>, and leaving takes one line. Liveness: https://registry.givo.dev/ answers {"ok": true}.

Abuse

Malicious package, compromised release, name squatting: see givo.dev/abuse. Verified reports get the version tombstoned (downloads answer 410, the record stays as evidence) and the publishing token revoked.