manak.

The hackathon workspace

About

Zen engineering mascot

Manak runs a hackathon end to end: teams register, submit a project against a deadline, judges score what they are assigned against a published rubric, and the organizer gets a ranking that has been corrected for the fact that judges are not calibrated to each other. One container, one port, one file on disk.

It is built to be self-hosted by somebody who does not want to become its administrator. There is nothing to configure before it starts, no relay to reach, no second service to keep alive, and no asset pipeline - a page works with scripting switched off because there is no script anywhere in the product to switch on.

Version
0.1.0
Written by
Sai Ram (Hardik) Dash
Source
https://github.com/ewwhardik
Licence
MIT

What it is made of

Dependencies
0 packages
Operations
102 operations
Runtime
Node's standard library. TypeScript is stripped at load; there is no build step.
Storage
One SQLite file through node:sqlite, in write-ahead mode, with strict tables.
Client-side script
none, and the policy header forbids it

Claims, and how to check them

Each row is something this project says about itself. The right-hand column is where you settle it without reading the source.

ClaimWhere it is settled
There are no dependencies. Not few — none.package.json declares no dependencies of any kind, and there is no lock file.
Every operation is both a JSON route and a page, from one declaration./api/docs lists them; the same path without /api renders the page.
No operation can reach production without an access decision./api/capabilities publishes the matrix; boot refuses a command without one.
An event's data is invisible to anybody outside it — not found, not forbidden.docs/proof/isolation.md is generated by sending every operation over a socket.
Nothing is written without an entry in a hash-chained ledger./api/healthz publishes the chain's length and head hash on every request.
Judge leniency and severity are corrected for, and the correction is shown.docs/proof/normalization.md re-derives the numbers from a seed and nothing else.
A published ranking states how much of itself the evidence supports.A rubric fit puts a 95% range on every score and cuts the field into the tiers those ranges separate rather than into a list of places. A pairwise-only event has no interval to give, so the page drops the column and says why.
A public results page names no judge, in any field, in either rendering.tests/publish.test.ts searches the whole body for every roster id and address; the per-judge and per-criterion analysis is on the organizer's dashboard only.
No page needs client-side JavaScript, because there is none to need.The Content Security Policy on every response forbids script outright.
Everything on every page can be reached with a keyboard alone.Each table sits in a named, focusable scroll region, so a column past the edge of a narrow window is reachable without a mouse; tests/view.test.ts holds it.
Your data can leave: the whole database exports as text and imports back intact.docs/proof/roundtrip.md exports, imports and re-exports, then compares the bytes.

See for yourself

The three proof documents named in the table above are generated by scripts in the source tree and committed alongside it, so a reviewer can re-run any one of them and compare the output with what was shipped. Two of the three take no measurement at all, which is what lets them be compared byte for byte rather than read for vibes.