Still Systems, LLC — TreeResolve product site (stillsystems.github.io/treeresolve-community)
Enterprise Guide
This document provides technical, architectural, and security details for enterprise engineering organizations, InfoSec assessment teams, and IT administrators evaluating or deploying TreeResolve.
1. Executive Summary
TreeResolve is an offline-first, deterministic 3-way merge conflict resolution engine for VS Code and Git workflows. Unlike generative AI coding assistants, TreeResolve uses mathematical syntax-tree reconciliation to eliminate merge conflicts without code hallucination or data egress.
Core Value Proposition for Enterprises
- Source code stays local: Parsing, AST analysis, micro-diffing, and resolution run on developer workstations or internal CI runners. Source code is not transmitted. The table in §2.1 lists what else can leave the machine.
- Deterministic merges: Only disjoint, non-colliding syntax is auto-resolved. Collisions stay for review.
- Offline license keys: An already-issued offline key validates on the machine with no network call.
- Seamless Fleet Rollout: Deployable silently via Microsoft Intune, Jamf Pro, Munki, or Ansible, with repository-level governance via
.treeresolverc.
2. Security & Compliance Architecture
2.1. What is transmitted
- Data Category: Source Code — Transmitted Over Network?: NO — Destination: Never leaves local workstation memory.
- Data Category: Concrete Syntax Trees (CST / AST) — Transmitted Over Network?: NO — Destination: Kept in local worker threads; never stored or sent.
- Data Category: File Names & File Paths — Transmitted Over Network?: NO — Destination: Never transmitted or logged.
- Data Category: Git Repositories, Branches & Commits — Transmitted Over Network?: NO — Destination: Handled purely through local Git plumbing.
- Data Category: Device Fingerprint (Trial/Floating Leases) — Transmitted Over Network?: Conditional — Destination: SHA-256 hash (
platform:arch:machineId, 32 hex chars derived from VS Code machine ID or anonymous UUID; zero PII, no usernames/hostnames) sent only on reverse trial issuance or floating lease renewals. Offline wildcard enterprise keys bypass network requests entirely. - Data Category: Anonymous Aggregate Metrics — Transmitted Over Network?: Optional — Destination: Only if telemetry is explicitly enabled (can be disabled).
2.2. Deterministic AST Analysis vs. Generative AI
Traditional line-based merge tools frequently fail on trivial disjoint changes, while generative AI merge tools carry substantial risks:
- Hallucination Risk: LLMs can invent arguments, omit security guards, or subtly alter logic during conflict reconciliation.
- Intellectual Property Leakage: Cloud LLM prompts expose proprietary source code to external servers and third-party models.
- Non-Deterministic Merges: The same conflict resolved twice by an LLM can yield different code.
TreeResolve's Approach: TreeResolve parses source files into concrete syntax trees using pre-compiled, sandboxed WebAssembly grammars (@vscode/tree-sitter-wasm). Changes are merged using formal set-difference logic against the common ancestor (Base). If an operation cannot be proven syntactically disjoint, TreeResolve preserves the conflict for human review.
2.3. WebAssembly Sandboxing & CSP Enforcement
- Sandboxed Execution: Language grammars execute within isolated WebAssembly virtual environments with strict memory boundaries.
- Webview Security: The 3-way visual merge canvas enforces a strict Content Security Policy (CSP):
``text default-src 'none'; connect-src 'none'; object-src 'none'; frame-ancestors 'none'; ``
The editor webview cannot initiate outbound network requests, run arbitrary remote scripts, or leak buffer contents.
3. Enterprise Licensing Architecture
TreeResolve uses an offline-first cryptographic licensing model that eliminates the requirement for continuous internet connectivity.
3.1. Ed25519 Asymmetric Verification
- Licenses and trial tokens are issued as JSON Web Tokens (JWT) signed by Still Systems using an Ed25519 private key.
- The VS Code extension verifies signatures locally using the bundled Ed25519 public key.
- Air-Gapped Operation: Developer machines never need to connect to Still Systems servers to validate an enterprise license.
3.2. License Tiers & Binding Model
- Pro (per person): One purchaser license usable in any repository on up to 3 machines (
binding: person,domainId: '*',maxMachines: 3). No per-repo activation after purchase. - Enterprise (seats + org wildcards): Seat budget for concurrent machines/people (
binding: org) with optional organization wildcard (domainId: '*') or legacy domain lock. - 90-Day Offline Hard-Cap: Person/org wildcard leases carry a maximum offline validity window of 90 days (renew via floating lease when online).
- Revocation Manifests: The extension periodically checks edge-cached revocation manifests when network connectivity is available, immediately disabling revoked tokens (
jti).
3.3. Internal Gateway / Proxy Deployment & Air-Gapped Environments
For enterprises operating within strict egress-restricted VPCs, corporate TLS-intercepting forward proxies, or air-gapped enclaves:
- Air-Gapped Workstations & Offline Keys:
- Organizations running completely disconnected networks can bypass all outbound telemetry and ticket requests by installing an offline enterprise wildcard license key.
- In VS Code, run
TreeResolve: Install License Key(treeresolve.installLicense) or provision via CLI:
``bash npx treeresolve license <JWT_TOKEN> ``
- The Ed25519 asymmetric signature is verified purely in-process; zero outbound network calls are attempted once an offline license is activated.
- Corporate Forward Proxies (
HTTPS_PROXY/ TLS Interception):
- If floating trial leases or telemetry are enabled in an enterprise environment using TLS-inspecting forward proxies, ensure developers or MDM profiles define standard proxy environment variables (
HTTPS_PROXY/HTTP_PROXY). - When using corporate private Certificate Authorities (CAs), launch VS Code with standard corporate root trust or configure
NODE_EXTRA_CA_CERTS/--use-openssl-caso outbound license verification cleanly traverses the proxy without TLS negotiation failures. - Network requests feature strict 3–4 second bounded timeouts via
AbortControllerto guarantee no editor hanging or command degradation in restrictive network topologies.
- Internal Licensing Mirror:
- Deploy an internal instance of the TreeResolve enterprise licensing service or an HTTP reverse proxy within your corporate intranet.
- Configure the enterprise endpoint via MDM or VS Code configuration:
``json { "treeresolve.licensingEndpoint": "https://treeresolve-licensing.internal.company.com" } ``
3.4. Workstation Migration, Salt Invalidation & Floating Seat Reconciliation
To eliminate repository name leakage under network inspection, TreeResolve derives domain identifiers using a local 32-byte installation salt stored in VS Code secretsStorage (or ~/.treeresolve/installation_salt).
- Workstation Migration & Salt Regeneration: If an engineer migrates laptops, re-images an operating system, or clears local application storage, a new random installation salt is generated. This alters the locally derived repository
domainId. - Enterprise Mitigation:
- **Organization Wildcard Licenses (
domainId: '*')**: Enterprise accounts are authenticated at the organization tier and are completely unaffected by local salt rotation across developer laptops. - Floating Lease Reclaiming: After a machine migration or salt reset, reclaim a 30-day floating lease for the new
domainId:
```bash # CLI npx treeresolve reclaim <licenseKey>
# VS Code Command Palette TreeResolve: Reclaim Floating Lease (Machine Migration) ```
This calls POST /api/v1/lease/reclaim on the licensing worker and stores the new lease for offline verification.
- Self-Serve Billing Portal: Pro subscribers can open invoices, update payment methods, or cancel via:
``bash npx treeresolve portal [licenseKey] ``
Or in VS Code: TreeResolve: Open Billing Portal (routes through GET /api/v1/portal?licenseKey=).
4. Fleet Management & Automated Deployment
4.1. Silent Installation via MDM
TreeResolve is on the VS Code Marketplace as still-systems.ss-treeresolve. For air-gapped fleets, distribute a verified offline VSIX (SHA-256 + Sigstore) from a GitHub Release, or provision the CLI via npm (treeresolve@1.0.2) for headless / mergetool workflows. Full steps and AllowedExtensions allow-list examples: docs/trust/offline-vsix.md.
Microsoft Intune / Windows MDM
Deploy via PowerShell script or Intune Win32 App:
# Install extension silently for all users
code --install-extension still-systems.ss-treeresolve --force
Jamf Pro / macOS Fleet
Deploy via Jamf shell policy:
#!/bin/bash
# Install extension silently under current logged-in user
sudo -u $(stat -f "%Su" /dev/console) code --install-extension still-systems.ss-treeresolve --force
4.2. Centralized VS Code Settings Configuration
IT administrators can push global default settings to /etc/vscode/settings.json (Linux), C:\ProgramData\Code\settings.json (Windows), or via MDM profiles:
{
"treeresolve.autoMergeImports": true,
"treeresolve.stageOnSave": true,
"treeresolve.enableTelemetry": false,
"treeresolve.licensingEndpoint": "https://treeresolve-licensing.internal.company.com"
}
4.3. Repository-Level Policy Governance (.treeresolverc)
Security and platform teams can check a .treeresolverc or treeresolve.json file into the root of any repository to enforce uniform conflict handling:
{
"$schema": "https://stillsystems.github.io/treeresolve-community/schema/treeresolverc.json",
"autoMergeImports": true,
"stageOnSave": false,
"rules": [
{
"pattern": "**/package-lock.json",
"autoMerge": true,
"stageOnSave": true
},
{
"pattern": "security/auth/**",
"autoMerge": false,
"stageOnSave": false
}
]
}
The $schema URL is hosted on Still Systems–controlled GitHub Pages (stillsystems.github.io). Do not point editors at third-party domains for this schema.
4.4. Headless CI/CD & CLI Deployment
For headless build systems, containerized CI runners, and terminal merge workflows:
- CI/CD Credential Injection: Provide the license token via the
TREERESOLVE_LICENSEenvironment variable. In GitHub Actions, configure as a repository or organization secret:
```yaml
- name: Auto-Resolve Git Conflicts
env: TREERESOLVE_LICENSE: ${{ secrets.TREERESOLVE_LICENSE }} run: npx treeresolve auto ```
- Automated Git Merge Driver Setup: In runner base images or developer setup scripts, run:
``bash npx treeresolve setup-driver ``
This configures Git's native 5-parameter merge driver (merge.treeresolve.driver) globally.
- Workstation Credential Provisioning: Install license tokens using:
``bash npx treeresolve license <token> ``
Credentials are saved to ~/.treeresolve/license.json with restricted file permissions (0o600).
- Anti-Tamper Monotonic Clock Guard: Monotonic execution watermarks are persisted to
~/.treeresolve/state.json, ensuring local clock tampering cannot circumvent license expiration.
4.5. Headless CI/CD Runner Prerequisites & Node.js Runtime Isolation
The standalone TreeResolve CLI executable (bin/treeresolve.js) runs natively in headless environments without requiring VS Code:
- Node.js Runtime Requirement: The CLI bundle targets Node.js 20+ runtime environments (
node >= 20.0.0) to utilize native cryptographic subroutines (crypto.subtle,crypto.createHmac) and modern WebAssembly features. Ensure CI/CD runner container base images provide Node.js 20.x LTS or higher. - Hermetic Environment Shims: When executed outside the VS Code Extension Host, the CLI automatically provides isolated mock shims to maintain deterministic parsing, diffing, and merge driver compatibility without external editor dependencies.
5. Trust Pack (vendor risk, zero-cost)
TreeResolve does not ship a paid SOC 2 report. For InfoSec review, use the Trust Pack:
- Artifact: Index — Link: docs/trust/README.md
- Artifact: Data-flow (local merge; honest licensing/telemetry egress) — Link: docs/trust/data-flow.md
- Artifact: CSA CAIQ (lite, solo-honest) — Link: docs/trust/caiq-lite.md
- Artifact: Offline VSIX +
AllowedExtensions— Link: docs/trust/offline-vsix.md - Artifact: VDP / security.txt — Link: SECURITY.md, docs/security.txt
- Artifact: SBOM + SHA-256 + Sigstore per release — Link: GitHub Actions workflow
Release artifacts(tagv*orworkflow_dispatch) - Artifact: OpenSSF Scorecard — Link: Public repo
stillsystems/treeresolve-community
Quick claims buyers usually need:
- Source code never leaves the machine for merge resolution (see data-flow).
- Air-gapped path: offline VSIX + offline wildcard JWT + telemetry off.
- Supply chain: CycloneDX SBOM and Sigstore-signed VSIX on tagged releases.
6. Procurement & Commercial Terms
Still Systems (solo-operated LLC) offers honest, deliverable procurement paths for enterprise buyers:
- Payment Methods: Self-serve card checkout via Paddle (Merchant of Record). For qualifying fleet quotes, Paddle invoices the buyer. Net-30 may be offered case-by-case after quote acceptance. Extended Net-60 (or longer) terms are not a standard offering. Still Systems does not invoice buyers or collect payment directly.
- Volume Seat Tiering: Discounted seat pricing discussed starting around 50 developer seats (see list pricing footnotes in the product README).
- Agreements: Purchases are governed by the TreeResolve EULA plus a short written order / quote for fleet deals. Custom MSA or Security Addendum language can be reviewed case-by-case; it is not a turnkey packaged deliverable. Vendor risk questionnaires can start from the CAIQ lite above.
- Support Targets: Enterprise inquiries aim for next-business-day acknowledgment (US Central). Security disclosures follow the 48-hour ack in SECURITY.md. There is no separate uptime SLA for the local extension (merge work runs on the customer's machines). Community / Pro GitHub issues remain best-effort.
- Custom Grammar Normalizers: Available only as scoped, quoted engineering work when capacity allows—not included by default in Enterprise seat pricing.
For enterprise evaluations, custom quotes, or security reviews, submit an inquiry via the Enterprise Portal or open a thread on the TreeResolve Community Tracker.