rules

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func EditDistance

func EditDistance(a, b string, cap int) int

EditDistance computes the distance between a and b allowing insertion, deletion, substitution, and transposition of two adjacent characters (the "optimal string alignment" variant of Damerau-Levenshtein).

Transposition has to count as one edit here, not two: the single most common typosquat pattern is two adjacent letters swapped, for example "reqeusts" for "requests". Under plain Levenshtein that is distance 2 (two substitutions) and would slip past a "distance 1" typosquat check entirely.

The result is capped at cap+1: once the true distance is known to exceed cap, the function may return cap+1 instead of computing the exact value.

Types

type Ecosystem

type Ecosystem string

Ecosystem identifies a package registry.

const (
	NPM      Ecosystem = "npm"
	PyPI     Ecosystem = "pypi"
	RubyGems Ecosystem = "rubygems"
	Crates   Ecosystem = "crates"
)

type Indicator

type Indicator struct {
	Ecosystem string `json:"ecosystem"`
	Name      string `json:"name"`
	Source    string `json:"source"`
	Note      string `json:"note"`
}

Indicator is one published, named example of a malicious or removed package. Every entry must cite the advisory or write-up it came from. Nothing in this list is guessed: see data/malicious.json.

func LoadMalicious

func LoadMalicious() ([]Indicator, error)

LoadMalicious reads the embedded known-malicious indicator list.

type MaliciousIndex

type MaliciousIndex map[Ecosystem]map[string]Indicator

MaliciousIndex indexes indicators by ecosystem and lowercase name for O(1) exact-match lookups.

func IndexMalicious

func IndexMalicious(list []Indicator) MaliciousIndex

func (MaliciousIndex) Lookup

func (m MaliciousIndex) Lookup(eco Ecosystem, name string) (Indicator, bool)

type PopularNames

type PopularNames struct {
	Ecosystem Ecosystem
	Ordered   []string
	// contains filtered or unexported fields
}

PopularNames is the list of well known package names for one registry, used as the typosquat comparison set. Names lowercased, order preserved (most downloaded first, per the source data).

func LoadPopular

func LoadPopular(eco Ecosystem) (*PopularNames, error)

LoadPopular reads the embedded top-name list for one ecosystem.

func (*PopularNames) Has

func (p *PopularNames) Has(name string) bool

func (*PopularNames) Nearest

func (p *PopularNames) Nearest(name string) string

Nearest returns the first popular name within edit distance 1 of name, excluding an exact match. Empty string if none found.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL