pub struct Facts {Show 17 fields
pub analyzed_version: Option<String>,
pub latest_published: Option<DateTime<Utc>>,
pub releases_last_year: Option<u32>,
pub total_versions: Option<u32>,
pub deprecated: bool,
pub deprecated_reason: Option<String>,
pub archived: bool,
pub licenses: Vec<String>,
pub vulns: Vec<Vuln>,
pub repo: Option<String>,
pub stars: Option<u64>,
pub open_issues: Option<u64>,
pub scorecard_maintained: Option<f64>,
pub scorecard_overall: Option<f64>,
pub top_contributor_share: Option<f64>,
pub maintainers: Vec<String>,
pub has_install_script: bool,
}Expand description
Everything deprot learned about one dependency. Populated by the collector from public data sources; all fields are optional so the engine degrades gracefully when a source is unavailable (e.g. no auth, offline, or the package has no linked repository).
Fields§
§analyzed_version: Option<String>The concrete version these facts describe (the version deprot chose to analyze).
latest_published: Option<DateTime<Utc>>When the most recent release was published (drives the staleness signal).
releases_last_year: Option<u32>Number of releases published in the trailing 12 months (drives the cadence signal).
total_versions: Option<u32>Total number of published versions ever.
deprecated: boolThe registry has marked this version (or package) deprecated.
deprecated_reason: Option<String>Reason string attached to the deprecation, if any.
archived: boolThe source repository is archived (read-only / abandoned upstream).
licenses: Vec<String>SPDX-ish license identifiers reported for the analyzed version.
vulns: Vec<Vuln>Known vulnerabilities affecting the analyzed version.
repo: Option<String>Canonical source repository (e.g. github.com/lodash/lodash), if known.
stars: Option<u64>Repository star count, if known.
open_issues: Option<u64>Open issue count, if known.
scorecard_maintained: Option<f64>OpenSSF Scorecard “Maintained” check (0–10), if available.
scorecard_overall: Option<f64>OpenSSF Scorecard aggregate score (0–10), if available.
Fraction (0.0–1.0) of recent commits authored by the single most active contributor. High concentration = high bus-factor / capture risk. Optional (needs a GitHub token).
maintainers: Vec<String>Registry maintainer/owner identities (email or login). Populated only in --deep mode.
has_install_script: boolThe package runs an install/pre/post-install script (npm) — a code-execution vector.
Implementations§
Source§impl Facts
impl Facts
Sourcepub fn is_unresolved(&self) -> bool
pub fn is_unresolved(&self) -> bool
Whether the collector obtained no registry data for this package — an unknown or
typosquatted name, a registry 404, or a failed/offline lookup. The collector always sets
total_versions (and usually latest_published) the moment it reaches the registry, so
both being absent means we never got a usable response.
Scoring uses this to avoid presenting an unassessed package as healthy: absence of data is not absence of risk.