claudeers.
// Other

claude-governance

Claude Code governance templates by tech stack : CLAUDE.md, scoped rules, architecture docs, cost control & dev-level adaptation

// Other[ api ][ web ][ mobile ][ claude ]#claude#agentflow4j#claude-ai#claude-api#claude-code#copilot#finops#governance#otherMIT$open-sourceupdated 2 months ago
Repository unavailable
0/100
last commit 2 months ago
last release none
releases 0
open issues 8

Install with your AI

This project is repository unavailable — not recommended for automated install, so we don't generate an auto-install prompt for it. Read the repo and decide for yourself.

// compatibility

Platformsapi, web, mobile
Operating systems
AI compatibilityclaude
LicenseMIT
Pricingopen-source
LanguageJava

Claude Code Governance Templates

Ready-to-use governance templates for Claude Code, organized by tech stack. Rules load automatically on every session: no prompting required.

If this saves you time, consider giving it a ⭐: it helps others find the project.

image

Why this exists

Without structure, Claude Code generates inconsistent code, ignores your conventions, and repeats the same mistakes across sessions. This project fixes that with a hierarchy of CLAUDE.md files that load automatically: no prompting required.

What you get:

  • Consistent code that respects your architecture and naming conventions
  • Security rules enforced by default (no IDOR, no raw SQL, no hardcoded secrets)
  • Cost control: precise diffs instead of full rewrites, right model for the right task
  • Behavior adapted to the developer's experience level (Junior → Tech Lead)

Installation

Via plugin marketplace (recommended):

/plugin marketplace add datallmhub/claude-governance
/plugin install claude-governance

Then run /setup in any project: select your stack, governance files are copied automatically, and rules inject at every session start.

Local / development:

git clone https://github.com/datallmhub/claude-governance.git
claude --plugin-dir /path/to/claude-governance

Manual (no plugin):

  1. Copy the stack folder into your project root
  2. Update CLAUDE.md with your project name and stack versions
  3. Copy CLAUDE.local.md.exampleCLAUDE.local.md (do not commit)
  4. Set your experience level in dev-level.md

Available stacks

Java

StackFolderStatus
Java (Spring Boot) + React (TypeScript)java-react/✅ Ready
Java (Spring Boot) + Angularjava-angular/🔜 Coming
Java (Spring Boot) + Vue.jsjava-vue/🔜 Coming
Java (Spring Boot) API onlyjava-only/🔜 Coming

JavaScript / TypeScript

StackFolderStatus
React / TypeScript onlyreact-only/✅ Ready
Angular onlyangular-only/✅ Ready
Vue.js onlyvue-only/✅ Ready
Next.js (full-stack)nextjs/✅ Ready
Node.js (Express) + Reactnode-express-react/🔜 Coming
Node.js (NestJS) + Reactnestjs-react/✅ Ready

Python

StackFolderStatus
Python (FastAPI) + Reactpython-fastapi-react/✅ Ready
Python (Django) + Reactpython-django-react/🔜 Coming
Python (FastAPI) API onlypython-fastapi-only/🔜 Coming

.NET / Go / PHP

StackFolderStatus
.NET (ASP.NET Core) + Reactdotnet-react/🔜 Coming
Go (Gin / Echo) + Reactgo-react/🔜 Coming
Laravel + Reactlaravel-react/🔜 Coming
Symfony + Reactsymfony-react/🔜 Coming

What's inside each template

<stack>/
├── CLAUDE.md                    # Project context: always loaded
├── CLAUDE.local.md.example      # Personal overrides (copy locally, never commit)
├── .claude/
│   ├── settings.json            # SessionStart hook: injects rules at session start
│   ├── rules/
│   │   ├── backend.md           # Backend rules: scoped to backend files only
│   │   ├── frontend.md          # Frontend rules: scoped to frontend files only
│   │   ├── database.md          # DB / migration rules
│   │   ├── testing.md           # Testing standards
│   │   ├── security.md          # Security rules: loaded on every file
│   │   ├── governance.md        # Git, PR, versioning, release process
│   │   └── dev-level.md         # Behavior by experience level
│   └── architecture/
│       ├── overview.md          # System architecture + key decisions
│       ├── api.md               # REST API contract
│       └── data-model.md        # Database schema
└── samples/                     # Code examples applying all the rules

Load order

~/.claude/CLAUDE.md       ← personal preferences (your machine)
./CLAUDE.md               ← project rules (committed, shared)
./CLAUDE.local.md         ← personal overrides (gitignored)
.claude/rules/*.md        ← scoped rules (loaded per file path)

Security

security.md loads on every file automatically. It enforces:

  • No IDOR: public_id UUID in all URLs, never internal sequential IDs
  • No hardcoded secrets: all credentials via environment variables
  • Safe tokens: JWT in memory, refresh token in HttpOnly; Secure cookie
  • Injection prevention: parameterized queries, input validated at system boundary
  • CORS locked down: explicit origin whitelist, never allowedOrigins("*")

Developer Experience Levels

One setting in dev-level.md: Claude adapts its verbosity automatically.

LevelBehavior
JUNIORStep-by-step, full context, pitfalls flagged
SENIORSolution-first, 3 sentences max per concept
EXPERTCode only, no explanations unless asked
TECH_LEAD1 sentence max, no prose, no fundamentals

GovEval: Validate your governance

GovEval is to governance rules what unit tests are to code.

It does not test Claude in isolation. It tests Claude as configured by this repoCLAUDE.md + .claude/rules/ + dev-level + everything else loaded automatically.

The developer prompt never repeats the rules:

Developer request → Claude Code runtime (rules loaded silently) → Generated code → Judge → PASS / FAIL

Example — SEC-01:

StepResult
Prompt"Create GET /tasks"
GeneratedorganizationId read from JWT, not the request
JudgeMistral Large — isolation verified
Result✅ PASS — 100/100

The judge (Mistral Large) is a different model family than the generator (Claude), so it isn't grading its own work.

/gov-eval                          # all scenarios
/gov-eval --category security      # one category
/gov-eval --scenario SEC-01        # one scenario

Requires MISTRAL_API_KEY. See java-react/tests/ for full details.

Run it on a schedule, not just once. A rule that passes today can silently break after a model update, even with no changes to CLAUDE.md. Re-run GovEval on every PR touching .claude/rules/, and periodically (e.g. every 2 weeks) to catch drift from model updates.


Contributing

See CONTRIBUTING.md for the full guide.

Pick an open new-stack issue: each one is a self-contained task with clear acceptance criteria.

// faq

What is claude-governance?

Claude Code governance templates by tech stack : CLAUDE.md, scoped rules, architecture docs, cost control & dev-level adaptation. It is open-source on GitHub.

Is claude-governance free to use?

claude-governance is open-source under the MIT license, so it is free to use.

What category does claude-governance belong to?

claude-governance is listed under other in the Claudeers registry of Claude-compatible tools.

0 views
96 stars
unclaimed
updated 2 months ago

// embed badge

claude-governance on Claudeers
[![Claudeers](https://claudeers.com/api/badge/claude-governance.svg)](https://claudeers.com/claude-governance)

// retro hit counter

claude-governance hit counter
[![Hits](https://claudeers.com/api/counter/claude-governance.svg)](https://claudeers.com/claude-governance)

// reviews

// guestbook

0/500

// related in Other

🔓

符合nature论文学术表达和科研绘图的Skill

// otherYuan1z0825/Python36,535Apache-2.0[ claude ]
🔓

Open source Ghostty-based macOS terminal with vertical tabs and notifications for AI coding agents. Built for multitasking, organization, and programmability.

// othermanaflow-ai/Swift26,069NOASSERTION[ claude ]
🔓

Anti-AI-slop design skill for Claude Code, Cursor, and Codex.

// otherNutlope/CSS25,307MIT[ claude ]
🔓

Huashu Design · HTML-native design skill for Claude Code · Claude Code 里 HTML 原生的设计 skill · 高保真原型 / 幻灯片 / 动画 + 20 设计哲学 + 5 维评审 + MP4 导出 · Agent-agnostic

// otheralchaincyf/HTML23,151MIT[ claude ]
→ see how claude-governance connects across the ecosystem