Skip to main content

Crate deprot_core

Crate deprot_core 

Source
Expand description

§deprot-core

The pure, zero-I/O heart of deprot. Everything here is deterministic: given the same Facts and the same reference time, score always returns the same Score. That is what makes the scoring engine fully unit-testable and replayable from cached fixtures — no network, no clock, no filesystem reach into this crate.

The data pipeline is: an ecosystem manifest yields Dependency values, the collector turns each one into Facts, and this crate turns Facts into a Score (a 0–100 value, a letter Grade, a Tier verdict, and the list of Signals that explain it).

Structs§

DepGraph
A resolved dependency graph. edges[i] holds the indices of the nodes that node i depends on (forward adjacency).
DepNode
One resolved node in the dependency tree — a concrete package at a concrete version.
Dependency
A single dependency to analyze, as extracted from a manifest.
Facts
Everything deprot learned about one dependency. Populated by the collector from public data sources; all fields are optional so the engine degrades gracefully when a source is unavailable (e.g. no auth, offline, or the package has no linked repository).
MaintainerReach
A maintainer and the packages they control within the analyzed set.
Score
The full result of scoring one dependency.
Signal
One scored dimension of dependency health.
Suspect
A dependency name that looks like a typo of a popular package.
Vuln
A known vulnerability affecting the analyzed version.

Enums§

Ecosystem
A package ecosystem. New ecosystems are added here and wired up with a manifest + collector adapter; the scoring engine does not change.
Grade
Letter grade derived from the 0–100 score.
Severity
Coarse severity bucket for a Vuln.
Tier
The headline verdict tier. This is what --fail-on gates against and what the summary banner reports.

Functions§

capture_risk
Aggregate maintainer reach across (package, maintainers) pairs, most-reaching first.
score
Score one dependency from its Facts at reference time now.
top_share
The share (0.0–1.0) of total_packages controlled by the single most-reaching maintainer.
typosquat_scan
Scan dependency names for likely typosquats of popular packages in the same ecosystem.