checker

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: MIT Imports: 6 Imported by: 0

Documentation

Overview

Package checker runs the detection rules against one package name and produces a verdict: allow it, warn and allow it, or block it.

Index

Constants

View Source
const NewPackageAge = 72 * time.Hour

NewPackageAge is the threshold from the project pitch: a package first published less than this long ago is treated as suspicious on its own, since a supply-chain drop is typically live for hours before takedown.

Variables

This section is empty.

Functions

This section is empty.

Types

type Checker

type Checker struct {
	Now func() time.Time
	// contains filtered or unexported fields
}

Checker holds the loaded rule data and registry adapters so repeated checks (one per package on an install line) do not re-read embedded data or reconstruct HTTP clients each time.

func New

func New() (*Checker, error)

func (*Checker) Check

func (c *Checker) Check(ctx context.Context, eco rules.Ecosystem, name string) Verdict

Check evaluates one package name for one ecosystem.

func (*Checker) WithRegistry

func (c *Checker) WithRegistry(eco rules.Ecosystem, reg registry.Registry)

WithRegistry overrides the adapter for one ecosystem. Used by tests to point at a fake HTTP server instead of the real registry.

type Level

type Level string

Level is the outcome severity. Block stops the install, Warn lets it through with a printed reason, Allow is silent.

const (
	Allow Level = "allow"
	Warn  Level = "warn"
	Block Level = "block"
)

type Reason

type Reason struct {
	Rule    string `json:"rule"`
	Level   Level  `json:"level"`
	Message string `json:"message"`
	Source  string `json:"source,omitempty"`
}

Reason is one rule result. Multiple reasons can fire for one package.

type Verdict

type Verdict struct {
	Ecosystem rules.Ecosystem `json:"ecosystem"`
	Package   string          `json:"package"`
	Level     Level           `json:"level"`
	Reasons   []Reason        `json:"reasons"`
}

Verdict is the combined result for one package name.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL