Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
risk-guard
command
|
|
|
src
|
|
|
ctxutil
Package ctxutil provides context helpers for logger and source token only.
|
Package ctxutil provides context helpers for logger and source token only. |
|
dag-impl/provenance_verify
Package provenance_verify is a DAG node that verifies a package version's npm build-provenance (Sigstore) attestation and compares the attested source repository against the analyzed repository.
|
Package provenance_verify is a DAG node that verifies a package version's npm build-provenance (Sigstore) attestation and compares the attested source repository against the analyzed repository. |
|
lib/common/sbom
Package sbom provides format-agnostic helpers for reading SBOM files produced by the cdx16 and spdx30 sub-packages.
|
Package sbom provides format-agnostic helpers for reading SBOM files produced by the cdx16 and spdx30 sub-packages. |
|
lib/local/auditcache
Package auditcache stores per-package raw violations from the local audit pipeline on disk so repeat audits over the same SBOM are fast.
|
Package auditcache stores per-package raw violations from the local audit pipeline on disk so repeat audits over the same SBOM are fast. |
|
observe
Package observe is the seam between code that does work and code that shows work happening.
|
Package observe is the seam between code that does work and code that shows work happening. |
|
provenance
Package provenance verifies npm/Sigstore build-provenance attestations, establishing an unforgeable binding between a published artifact and the source repository + commit it was built from.
|
Package provenance verifies npm/Sigstore build-provenance attestations, establishing an unforgeable binding between a published artifact and the source repository + commit it was built from. |
|
provenance/fetchtrustedroot
command
Command fetchtrustedroot fetches the Sigstore public-good trusted_root.json via TUF and writes it to the path given as the first argument.
|
Command fetchtrustedroot fetches the Sigstore public-good trusted_root.json via TUF and writes it to the path given as the first argument. |
|
runpath
Package runpath carries per-run filesystem paths on the context: the single cache root and any explicit input dir for --no-fetch replays.
|
Package runpath carries per-run filesystem paths on the context: the single cache root and any explicit input dir for --no-fetch replays. |
|
ui
Package ui owns the terminal.
|
Package ui owns the terminal. |
Click to show internal directories.
Click to hide internal directories.