Expand description
§deprot-core
The pure, zero-I/O heart of deprot. Everything here is deterministic: given the same
Facts and the same reference time, score always returns the same Score. That is
what makes the scoring engine fully unit-testable and replayable from cached fixtures — no
network, no clock, no filesystem reach into this crate.
The data pipeline is: an ecosystem manifest yields Dependency values, the collector turns
each one into Facts, and this crate turns Facts into a Score (a 0–100 value, a
letter Grade, a Tier verdict, and the list of Signals that explain it).
Structs§
- DepGraph
- A resolved dependency graph.
edges[i]holds the indices of the nodes that nodeidepends on (forward adjacency). - DepNode
- One resolved node in the dependency tree — a concrete package at a concrete version.
- Dependency
- A single dependency to analyze, as extracted from a manifest.
- Facts
- Everything deprot learned about one dependency. Populated by the collector from public data sources; all fields are optional so the engine degrades gracefully when a source is unavailable (e.g. no auth, offline, or the package has no linked repository).
- Maintainer
Reach - A maintainer and the packages they control within the analyzed set.
- Score
- The full result of scoring one dependency.
- Signal
- One scored dimension of dependency health.
- Suspect
- A dependency name that looks like a typo of a popular package.
- Vuln
- A known vulnerability affecting the analyzed version.
Enums§
- Ecosystem
- A package ecosystem. New ecosystems are added here and wired up with a manifest + collector adapter; the scoring engine does not change.
- Grade
- Letter grade derived from the 0–100 score.
- Severity
- Coarse severity bucket for a
Vuln. - Tier
- The headline verdict tier. This is what
--fail-ongates against and what the summary banner reports.
Functions§
- capture_
risk - Aggregate maintainer reach across
(package, maintainers)pairs, most-reaching first. - score
- Score one dependency from its
Factsat reference timenow. - top_
share - The share (0.0–1.0) of
total_packagescontrolled by the single most-reaching maintainer. - typosquat_
scan - Scan dependency names for likely typosquats of popular packages in the same ecosystem.