Repository navigation
feat: monitor baseline trust and complete M5 verification tools - #10
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pinned dependencies can acquire advisories or change owners without a lockfile edit. Add
watchto re-evaluate a reviewed baseline, report changes and coverage loss, and keep the baseline unchanged. Complete the other implementable M5 features: optional local npm Sigstore verification through Cosign 3.1.3, policy-aware lazy download counts, optional sandboxed GuardDog 3.2.0 analysis, and narrowpolicy allowexceptions with review reason, expiry, preview and backups.Local verification binds the exact npm PURL/version/SHA512 subject, preserves verifier attribution through baselines, and never uses deps.dev to hide failed local verification. GuardDog results remain a separate supplement; exact public source identity, subprocess limits and explicit partial/unavailable states prevent scanning a substitute private or repointed package. The usual metadata command retains its six Go dependencies and size budget.
The original M5.5 assumption is false: the public crates.io dump does not expose complete historical owners. Document that boundary and test that current-owner rows never become historical maintainers or demote TD002. Update usage docs, schemas and the Turkish README source marker.
Validation: full Go suite, focused regressions after review fixes, live registry integration suite, go vet, golangci-lint (0 issues), gosec and govulncheck (no vulnerabilities); real Cosign valid-bundle/tampered-signature tests including network-denied local-root execution; real CLI npm check; GuardDog POSIX subprocess tests; six-platform GoReleaser snapshot and demo. The live Linux CI job passed actual Cosign verification and a real sandboxed GuardDog scan of a known benign npm release. A macOS /var-to-/private/var path alias exposed a subprocess isolation mismatch; canonicalize the private root and cover symlinked temporary parents with a regression that failed before the fix. The latest CI reruns the OS/Go matrix and race detector.