service

package
v0.26.14 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 12, 2026 License: Apache-2.0 Imports: 19 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type BehaviorStore

type BehaviorStore interface {
	GetBehavioralSignals(ctx context.Context, username, provider string) (*model.Behavior, error)
	GetLifetimeActivity(ctx context.Context, username, provider string) (*model.LifetimeActivity, error)
	GetTopContributedRepos(ctx context.Context, username, provider string, limit int) ([]model.RepoContribution, error)
	GetRepoSummary(ctx context.Context, username, provider string) (*model.OwnedRepos, time.Time, error)
	SaveRepoSummary(ctx context.Context, username, provider string, summary *model.OwnedRepos) error
	GetSecurityCredits(ctx context.Context, username, provider string) (*model.SecurityCredits, time.Time, error)
	SaveSecurityCredits(ctx context.Context, username, provider string, credits []model.SecurityCredit) error
	GetOSSFScorecard(ctx context.Context, provider, owner, repo string) (*model.OSSFScorecard, time.Time, error)
	SaveOSSFScorecard(ctx context.Context, provider, owner, repo string, card *model.OSSFScorecard) error
	GetPublisherProfile(ctx context.Context, provider, username, registry string) (*model.RegistryProfile, time.Time, error)
	SavePublisherProfile(ctx context.Context, provider, username, registry string, profile *model.RegistryProfile) error
	GetStackOverflowProfile(ctx context.Context, provider, username string) (*model.StackOverflow, time.Time, error)
	SaveStackOverflowProfile(ctx context.Context, provider, username string, profile *model.StackOverflow) error
	GetCrossVCS(ctx context.Context, provider, username string) (*model.CrossVCS, time.Time, error)
	SaveCrossVCS(ctx context.Context, provider, username string, summary *model.CrossVCS) error
}

BehaviorStore provides behavioral signal data from contributor activity. GetLifetimeActivity returns aggregate lifetime counts; nil when no data exists. GetTopContributedRepos returns the top-N repos ranked by active-hour count. GetRepoSummary / SaveRepoSummary cache the contributor's owned-repos aggregate for 24h to amortize the cost of GitHub /users/{u}/repos calls. GetSecurityCredits / SaveSecurityCredits cache the contributor's GHSA advisory credits with a TTL governed by config.SecurityCreditTTL.

type ForgesFetcher

type ForgesFetcher interface {
	FetchSSHFingerprints(ctx context.Context, forge forges.Forge, username string) ([]string, error)
}

ForgesFetcher is the subset of the forges client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server. Returns the SHA-256 SSH-key fingerprints published by the user on the given forge.

type NPMFetcher

type NPMFetcher interface {
	FetchUserPackages(ctx context.Context, username string, topLimit int) (int, []registry.Package, error)
}

NPMFetcher is the subset of the npm registry client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server. Returns (total, top, err) where total is the unbounded count and top is the display-capped list.

type OSSFFetcher

type OSSFFetcher interface {
	Fetch(ctx context.Context, owner, repo string) (*ossf.Scorecard, error)
}

OSSFFetcher is the subset of the OSSF Scorecard client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server.

type ScoreService

type ScoreService struct {
	// contains filtered or unexported fields
}

ScoreService orchestrates signal fetching, scoring, and response enrichment.

func NewScoreService

func NewScoreService(gh ghclient.Client, version string) *ScoreService

NewScoreService returns a ScoreService wired to the given GitHub client. The OSSF Scorecard, npm publisher, Stack Overflow, and forges fetchers are initialized to defaults; pass the matching SetXxxFetcher methods to override (e.g., test mocks or to disable a fetcher entirely).

func (*ScoreService) Close

func (s *ScoreService) Close()

Close stops background goroutines (e.g., cache eviction).

func (*ScoreService) Score

func (s *ScoreService) Score(ctx context.Context, username, repo, planName string, trustedOrgs []string) (*model.ScoreResponse, error)

Score fetches signals, computes a reputation score, and builds a plan-aware response. Results are cached to avoid redundant GitHub API calls.

func (*ScoreService) SetBehaviorStore

func (s *ScoreService) SetBehaviorStore(bs BehaviorStore)

SetBehaviorStore sets an optional store for behavioral signal enrichment.

func (*ScoreService) SetClaudeClient

func (s *ScoreService) SetClaudeClient(c *claude.Client)

SetClaudeClient sets an optional Claude client for AI-powered risk narratives.

func (*ScoreService) SetForgesFetcher

func (s *ScoreService) SetForgesFetcher(f ForgesFetcher)

SetForgesFetcher overrides the default forges client. Pass nil to disable cross-VCS enrichment entirely.

func (*ScoreService) SetNPMFetcher

func (s *ScoreService) SetNPMFetcher(f NPMFetcher)

SetNPMFetcher overrides the default npm registry client. Pass nil to disable npm-publisher enrichment entirely; useful for tests and for environments where the npm registry is unreachable.

func (*ScoreService) SetOSSFFetcher

func (s *ScoreService) SetOSSFFetcher(f OSSFFetcher)

SetOSSFFetcher overrides the default OSSF Scorecard client. Pass nil to disable OSSF enrichment entirely; useful for tests and for environments where the OSSF API is unreachable.

func (*ScoreService) SetStackOverflowFetcher

func (s *ScoreService) SetStackOverflowFetcher(f StackOverflowFetcher)

SetStackOverflowFetcher overrides the default Stack Exchange API client. Pass nil to disable SO enrichment entirely.

type StackOverflowFetcher

type StackOverflowFetcher interface {
	FetchUser(ctx context.Context, userID int64) (*stackoverflow.Profile, error)
}

StackOverflowFetcher is the subset of the SE Data API client used by the score service. Defined here so tests can inject a mock without spinning up an httptest server.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL