Skip to content

feat: monitor baseline trust and complete M5 verification tools - #10

Merged
vahapogut merged 6 commits into
mainfrom
feat/m5-trust-monitoring
Sep 29, 2026
Merged

vahapogut merged 6 commits into
mainfrom
feat/m5-trust-monitoring

Conversation

@vahapogut

@vahapogut vahapogut commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Pinned dependencies can acquire advisories or change owners without a lockfile edit. Add watch to re-evaluate a reviewed baseline, report changes and coverage loss, and keep the baseline unchanged. Complete the other implementable M5 features: optional local npm Sigstore verification through Cosign 3.1.3, policy-aware lazy download counts, optional sandboxed GuardDog 3.2.0 analysis, and narrow policy allow exceptions with review reason, expiry, preview and backups.

Local verification binds the exact npm PURL/version/SHA512 subject, preserves verifier attribution through baselines, and never uses deps.dev to hide failed local verification. GuardDog results remain a separate supplement; exact public source identity, subprocess limits and explicit partial/unavailable states prevent scanning a substitute private or repointed package. The usual metadata command retains its six Go dependencies and size budget.

The original M5.5 assumption is false: the public crates.io dump does not expose complete historical owners. Document that boundary and test that current-owner rows never become historical maintainers or demote TD002. Update usage docs, schemas and the Turkish README source marker.

Validation: full Go suite, focused regressions after review fixes, live registry integration suite, go vet, golangci-lint (0 issues), gosec and govulncheck (no vulnerabilities); real Cosign valid-bundle/tampered-signature tests including network-denied local-root execution; real CLI npm check; GuardDog POSIX subprocess tests; six-platform GoReleaser snapshot and demo. The live Linux CI job passed actual Cosign verification and a real sandboxed GuardDog scan of a known benign npm release. A macOS /var-to-/private/var path alias exposed a subprocess isolation mismatch; canonicalize the private root and cover symlinked temporary parents with a regression that failed before the fix. The latest CI reruns the OS/Go matrix and race detector.

@vahapogut
vahapogut merged commit 1fab910 into main Sep 29, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant