Documentation
¶
Index ¶
- type BehaviorStore
- type ForgesFetcher
- type NPMFetcher
- type OSSFFetcher
- type ScoreService
- func (s *ScoreService) Close()
- func (s *ScoreService) Score(ctx context.Context, username, repo, planName string, trustedOrgs []string) (*model.ScoreResponse, error)
- func (s *ScoreService) SetBehaviorStore(bs BehaviorStore)
- func (s *ScoreService) SetClaudeClient(c *claude.Client)
- func (s *ScoreService) SetForgesFetcher(f ForgesFetcher)
- func (s *ScoreService) SetNPMFetcher(f NPMFetcher)
- func (s *ScoreService) SetOSSFFetcher(f OSSFFetcher)
- func (s *ScoreService) SetStackOverflowFetcher(f StackOverflowFetcher)
- type StackOverflowFetcher
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type BehaviorStore ¶
type BehaviorStore interface {
GetBehavioralSignals(ctx context.Context, username, provider string) (*model.Behavior, error)
GetLifetimeActivity(ctx context.Context, username, provider string) (*model.LifetimeActivity, error)
GetTopContributedRepos(ctx context.Context, username, provider string, limit int) ([]model.RepoContribution, error)
GetRepoSummary(ctx context.Context, username, provider string) (*model.OwnedRepos, time.Time, error)
SaveRepoSummary(ctx context.Context, username, provider string, summary *model.OwnedRepos) error
GetSecurityCredits(ctx context.Context, username, provider string) (*model.SecurityCredits, time.Time, error)
SaveSecurityCredits(ctx context.Context, username, provider string, credits []model.SecurityCredit) error
GetOSSFScorecard(ctx context.Context, provider, owner, repo string) (*model.OSSFScorecard, time.Time, error)
SaveOSSFScorecard(ctx context.Context, provider, owner, repo string, card *model.OSSFScorecard) error
GetPublisherProfile(ctx context.Context, provider, username, registry string) (*model.RegistryProfile, time.Time, error)
SavePublisherProfile(ctx context.Context, provider, username, registry string, profile *model.RegistryProfile) error
GetStackOverflowProfile(ctx context.Context, provider, username string) (*model.StackOverflow, time.Time, error)
SaveStackOverflowProfile(ctx context.Context, provider, username string, profile *model.StackOverflow) error
GetCrossVCS(ctx context.Context, provider, username string) (*model.CrossVCS, time.Time, error)
SaveCrossVCS(ctx context.Context, provider, username string, summary *model.CrossVCS) error
}
BehaviorStore provides behavioral signal data from contributor activity. GetLifetimeActivity returns aggregate lifetime counts; nil when no data exists. GetTopContributedRepos returns the top-N repos ranked by active-hour count. GetRepoSummary / SaveRepoSummary cache the contributor's owned-repos aggregate for 24h to amortize the cost of GitHub /users/{u}/repos calls. GetSecurityCredits / SaveSecurityCredits cache the contributor's GHSA advisory credits with a TTL governed by config.SecurityCreditTTL.
type ForgesFetcher ¶
type ForgesFetcher interface {
FetchSSHFingerprints(ctx context.Context, forge forges.Forge, username string) ([]string, error)
}
ForgesFetcher is the subset of the forges client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server. Returns the SHA-256 SSH-key fingerprints published by the user on the given forge.
type NPMFetcher ¶
type NPMFetcher interface {
FetchUserPackages(ctx context.Context, username string, topLimit int) (int, []registry.Package, error)
}
NPMFetcher is the subset of the npm registry client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server. Returns (total, top, err) where total is the unbounded count and top is the display-capped list.
type OSSFFetcher ¶
type OSSFFetcher interface {
Fetch(ctx context.Context, owner, repo string) (*ossf.Scorecard, error)
}
OSSFFetcher is the subset of the OSSF Scorecard client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server.
type ScoreService ¶
type ScoreService struct {
// contains filtered or unexported fields
}
ScoreService orchestrates signal fetching, scoring, and response enrichment.
func NewScoreService ¶
func NewScoreService(gh ghclient.Client, version string) *ScoreService
NewScoreService returns a ScoreService wired to the given GitHub client. The OSSF Scorecard, npm publisher, Stack Overflow, and forges fetchers are initialized to defaults; pass the matching SetXxxFetcher methods to override (e.g., test mocks or to disable a fetcher entirely).
func (*ScoreService) Close ¶
func (s *ScoreService) Close()
Close stops background goroutines (e.g., cache eviction).
func (*ScoreService) Score ¶
func (s *ScoreService) Score(ctx context.Context, username, repo, planName string, trustedOrgs []string) (*model.ScoreResponse, error)
Score fetches signals, computes a reputation score, and builds a plan-aware response. Results are cached to avoid redundant GitHub API calls.
func (*ScoreService) SetBehaviorStore ¶
func (s *ScoreService) SetBehaviorStore(bs BehaviorStore)
SetBehaviorStore sets an optional store for behavioral signal enrichment.
func (*ScoreService) SetClaudeClient ¶
func (s *ScoreService) SetClaudeClient(c *claude.Client)
SetClaudeClient sets an optional Claude client for AI-powered risk narratives.
func (*ScoreService) SetForgesFetcher ¶
func (s *ScoreService) SetForgesFetcher(f ForgesFetcher)
SetForgesFetcher overrides the default forges client. Pass nil to disable cross-VCS enrichment entirely.
func (*ScoreService) SetNPMFetcher ¶
func (s *ScoreService) SetNPMFetcher(f NPMFetcher)
SetNPMFetcher overrides the default npm registry client. Pass nil to disable npm-publisher enrichment entirely; useful for tests and for environments where the npm registry is unreachable.
func (*ScoreService) SetOSSFFetcher ¶
func (s *ScoreService) SetOSSFFetcher(f OSSFFetcher)
SetOSSFFetcher overrides the default OSSF Scorecard client. Pass nil to disable OSSF enrichment entirely; useful for tests and for environments where the OSSF API is unreachable.
func (*ScoreService) SetStackOverflowFetcher ¶
func (s *ScoreService) SetStackOverflowFetcher(f StackOverflowFetcher)
SetStackOverflowFetcher overrides the default Stack Exchange API client. Pass nil to disable SO enrichment entirely.
type StackOverflowFetcher ¶
type StackOverflowFetcher interface {
FetchUser(ctx context.Context, userID int64) (*stackoverflow.Profile, error)
}
StackOverflowFetcher is the subset of the SE Data API client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server.