Skip to content

Compatibility

codeArbiter’s requirements are deliberately narrow: Claude Code, Codex, or Pi, plus Python 3 on PATH. All three hosts share .codearbiter/; see the Claude Code + Codex evidence for the verified boundary and the Pi install page for the ca-pi install flow.

RequirementWhat’s neededNotes
Claude CodeAny version with plugin supportplugin.json states no explicit minimum version; the plugin uses standard hook events (SessionStart, PreToolUse, PostToolUse) and the plugin/marketplace install commands documented in Install.
CodexMinimum 0.143.0; live-verified on 0.144.1ca-codex uses one OS-specific handler per event and a Codex adapter that converts the shared guard verdict to structured deny output. Trust the hook set through /hooks.
Pi0.80.5 or 0.80.10 (this release line)ca-pi is a Feature Forge preview, available and welcomed for real use while broader testing continues before stable status or a claim of 100% validation. Install it Git-only: pi install git:github.com/arbiterForge/codeArbiter@ca-pi-v<version>. Also requires Node.js 22.19+. Requires an affirmative project-trust decision before repository-aware startup. Its human-readable generated catalog is plugins/ca-pi/SKILLS.md. See Install for Pi.
PythonPython 3, stdlib only, resolvable as python3 or python on PATHEvery hook is registered twice in hooks.json — once under python3, once under a python3 -c "" || python fallback — so it runs on a machine where only python resolves. No third-party Python packages are ever installed or imported (ADR-0004: database-free, stdlib-only architecture). On Pi, a missing interpreter blocks mutating calls and surfaces an interpreter breadcrumb rather than failing silently.
Operating systemWindows, macOS, or LinuxHooks are pure Python stdlib and carry no OS-specific code path beyond the interpreter-name fallback above. The .git/hooks backstop shim is a POSIX sh script; on Windows this runs under Git for Windows’ bundled sh.exe, which ships with every standard Git install. Windows is also a promoted, tested platform for ca-pi; see Windows notes.
gitAny reasonably current gitRequired regardless of codeArbiter — the plugin reads repo state (git config user.email, branch, diff) via subprocess calls to your existing git binary, and installs the .git/hooks backstop through it.
Node.jsNot required for Claude Code or CodexNode is required for ca-pi (22.19+) and is only otherwise needed to build or develop this documentation site (site/) and the optional pluggable-execution-farm TypeScript dispatcher (plugins/ca/tools/) if you use /ca:sprint --farm. Node is not a runtime dependency of the Claude Code/Codex enforcement hooks themselves.
Network accessNot required for enforcementSee Network Calls below — the gate-enforcement hook chain makes zero network calls; two clearly-scoped, opt-in-by-default exceptions exist outside that chain.
SurfaceClaude CodeCodexPi
Entry commands/ca:<name>$ca-<name>/ca-<name> (generated alias); /skill:ca-<name> fallback
Plugincaca-codexca-pi (Feature Forge preview)
DistributionMarketplace + npm-backed releaseMarketplace + npm-backed releaseGit tags only (ca-pi-v<version>); no npm release
Trust/approvalClaude Code plugin trust flowReview through /hooks; start a fresh threadAffirmative project-trust decision, then a fresh session
Statusline / footerAvailableNo statusline surfaceRich footer in every interactive parent repository; governance row only when enabled and affirmatively trusted; rate-window telemetry is omitted
Mutation permissionHost permission flow plus gatesCodex approval plus gatesExecute mode asks before governed mutations or external side effects; hard blocks deny first
Plan modeHost plan workflowRead-only collaboration modePlan mode is read-only except for the current canonical spec, plan, and plan ledger
Background jobsHost managedHost managedBounded session-only jobs, never restored from Pi session entries; unverified cleanup blocks later launches with /ca-doctor direction
/ca:sprint --farmpreview, shared farm.js backendpreview, shared farm.js backendpreview, same shared farm.js backend through the trusted parent extension; no Pi-native farm engine
Subagent/child dispatchPlugin agents dispatched directlyRoles run inline (packaging pending)Fresh child Pi processes via the parent-only codearbiter_dispatch EXEC tool; single/chain/parallel modes share bounded depth, concurrency, timeout, cancellation, and process-tree cleanup
Transcript pruning / compactionClaude transcript-pruning engineNo transcript pruning; host-neutral staleness warningNative Pi compaction event; codeArbiter does not rewrite Pi session JSONL
Project stateShared .codearbiter/ storeShared .codearbiter/ storeShared .codearbiter/ store

The full exception ledger with status and evidence for every host delta lives in docs/parity.md.

The Pi platform aggregate has a cold prerequisite: if the tools workspace lacks its resolved Vitest binary, it returns missing_prerequisite before fixtures start and directs the operator to npm --prefix plugins/ca-pi/tools ci --ignore-scripts. It never installs on the verification path. Footer, permission UI, plan UI, and background jobs are parent-interactive only and absent from JSON, RPC, print, and hardened children.

Confirm both before installing, per Install:

  • Python 3 on PATH. Without it, the gates and the session-startup injection silently do not run — /ca:doctor catches this as an interpreter-resolution failure.
  • git config user.email set. Overrides and ADRs are attributed to this identity; an unset email is asked for once, interactively, rather than silently defaulting.

Grepping every file under plugins/ca/hooks/ for network-capable stdlib usage (urllib, http.client, socket) turns up exactly one file that actually opens a connection: _updatelib.py. (_ledgerlib.py matches a naive text search only because it uses the English word “requests” to mean tool-call records — it imports nothing network-capable.)

  • The gate-enforcement hookspre-bash.py, pre-write.py, pre-edit.py, pre-read.py, post-write-edit.py, and session-start.py’s activation/briefing logic — make zero network calls. Every check is a local file read, a local git subprocess call against your own repo, or an in-process regex/parse. This is the enforcement chain compatibility and security actually depend on.
  • The update-available notifier (_updatelib.py) is a separate, non-blocking mechanism: a best-effort, once-a-day, fail-silent, unauthenticated HTTPS GET against GitHub’s public Releases API (api.github.com), run as a detached background process off the SessionStart hot path so a slow or unreachable network never delays a session. It only ever displays a one-line notice; it never applies an update. This ships on by default but is easy to make fully offline — see Staying up to date in the project README for the opt-out.
  • The pluggable execution farm (/ca:sprint --farm, opt-in, requires FARM_API_KEY) sends byte-capped, secret-redacted task context to an OpenAI-compatible HTTP provider you configure. This is a separate, explicitly opt-in feature, not part of the gate chain, and inert unless you pass --farm.

No hook writes anything off your machine as a side effect of enforcement. docs/hooks.md documents the same invariant per-hook, plus the one local, read-only git fetch session-start.py runs in the background against your own configured remote (the repo-hygiene briefing).

Zero, for the plugin itself. plugins/ca/hooks/*.py import only the Python standard library — no pip install, no requirements.txt, no compiled binaries (ADR-0004). The one TypeScript toolchain in the repo, plugins/ca/tools/ (the farm dispatcher), carries its own devDependencies for its own build and test — those are irrelevant to whether the enforcement hooks run, since the hooks never import from that package.

The docs site (site/) has its own, larger package.json (Astro, Starlight, vitest) — that’s a dependency surface for building this website, never for using the plugin.