deprot-core 0.4.0

Pure, zero-I/O dependency health scoring engine for deprot
Documentation
//! # deprot-core
//!
//! The **pure, zero-I/O** heart of deprot. Everything here is deterministic: given the same
//! [`Facts`] and the same reference time, [`score`] always returns the same [`Score`]. That is
//! what makes the scoring engine fully unit-testable and replayable from cached fixtures — no
//! network, no clock, no filesystem reach into this crate.
//!
//! The data pipeline is: an ecosystem manifest yields [`Dependency`] values, the collector turns
//! each one into [`Facts`], and this crate turns [`Facts`] into a [`Score`] (a 0–100 value, a
//! letter [`Grade`], a [`Tier`] verdict, and the list of [`Signal`]s that explain it).

mod facts;
mod graph;
mod maintainers;
mod score;
mod signals;
mod typosquat;

pub use facts::{Dependency, Ecosystem, Facts, Severity, Vuln};
pub use graph::{DepGraph, DepNode};
pub use maintainers::{capture_risk, top_share, MaintainerReach};
pub use score::{score, Grade, Score, Tier};
pub use signals::Signal;
pub use typosquat::{scan as typosquat_scan, Suspect};