Documentation
¶
Overview ¶
Package checker runs the detection rules against one package name and produces a verdict: allow it, warn and allow it, or block it.
Index ¶
Constants ¶
View Source
const NewPackageAge = 72 * time.Hour
NewPackageAge is the threshold from the project pitch: a package first published less than this long ago is treated as suspicious on its own, since a supply-chain drop is typically live for hours before takedown.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Checker ¶
Checker holds the loaded rule data and registry adapters so repeated checks (one per package on an install line) do not re-read embedded data or reconstruct HTTP clients each time.
type Level ¶
type Level string
Level is the outcome severity. Block stops the install, Warn lets it through with a printed reason, Allow is silent.
Click to show internal directories.
Click to hide internal directories.