Skip to content

test(openscore): prove non-yarn multi-ecosystem provider audit#33

Open
hammadtq wants to merge 1 commit into
mainfrom
test/multi-ecosystem-openscore-provider-proof
Open

test(openscore): prove non-yarn multi-ecosystem provider audit#33
hammadtq wants to merge 1 commit into
mainfrom
test/multi-ecosystem-openscore-provider-proof

Conversation

@hammadtq
Copy link
Copy Markdown
Collaborator

@hammadtq hammadtq commented May 18, 2026

Summary

  • Proves explicit Open Score provider request identity and verdict/audit provenance for npm, pnpm, pip, cargo, and Go install flows.
  • Covers ALLOW/ASK/DENY plus provider-unavailable behavior across supported non-Yarn package managers.
  • Adds a raw-upstream-shape guard so audit/explain output preserves source refs without dumping raw source objects.

Checks

  • go test ./...
  • go vet ./...
  • git diff --check origin/main...HEAD
  • Added-content scan for secrets, live hosted calls, Socket-default drift, proprietary score claims, and raw upstream dump exposure
  • Codex review: CLEAN, no critical/warning findings

Source/legal

  • Local mocked Open Score provider only.
  • No hosted Attach calls, no live registry/source fetching, no Socket behavior changes, no proprietary vendor data, no raw upstream dataset redistribution.
  • Yarn runtime support is intentionally excluded and split to Kanban card t_fe92144b.

Do not merge without Hammad approval.


View in Codesmith
Need help on this PR? Tag @codesmith with what you need.

  • Let Codesmith autofix CI failures and bot reviews

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant