Auditor
Every dependency manifest (npm, pnpm, yarn, pip, go, cargo, composer) has a committed lockfile next to it.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative.)
| const MANIFESTS = [ |
| { manifest: 'package.json', locks: ['package-lock.json', 'pnpm-lock.yaml', 'yarn.lock', 'bun.lock'] }, |
| { manifest: 'go.mod', locks: ['go.sum'] }, |
| // ... one rule per ecosystem |
| ]; |
| // FAIL when a manifest folder has none of its lockfiles |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.