inspectra 2.0.0
inspectra: ^2.0.0 copied to clipboard
Enterprise software assurance and supply-chain security for Dart and Flutter: OSV.dev audit, package source inspection, trust and typosquat analysis, safe dependency installation, Git hooks, Trivy sca [...]
Changelog #
All notable changes to this project are documented in this file. The format follows Keep a Changelog and the project adheres to Semantic Versioning.
2.0.0 #
Baseline #
inspectra baseline createrecords the current findings of a package in a committedinspectra-baseline.json, andinspectra baseline pruneremoves the fixed ones without ever adding any.--only scan,lint,style,trivyselects scopes,--recursivecovers nested packages; a scope that cannot run completely exits with69and writes nothing.scan,audit,typosquat,trivy,lint,style,checkand thebuild_runnerbuilders leave out recorded findings. Entries are matched by scope, source, rule, package and file, without line numbers or package versions, and count their occurrences.inspect,addandtrustdo not use the baseline.- The
baseline:configuration section:enabled,file,max_severity,fail_on_stale; the publicBaselineConfigandBaselineSummary, and thebaselinefield ofInspectraConfig,StyleResult,LintResultandScanResult. - JSON:
baselinedin the reports ofscanandaudit, andbaselinewithcoveredandstalein the results oflint,styleand the Trivy scans, present only when a baseline was applied.
Dependency policy #
- The
dependency_policy:section turns organisation rules for dependencies into checks, each opt-in:DENIED_PACKAGE(also transitive),PACKAGE_NOT_ALLOWED,DISALLOWED_HOST(registries and Git hosts, also transitive),MISSING_UPPER_BOUND,SDK_BELOW_POLICY,DEV_ONLY_DEPENDENCY,MISSING_PUBLISH_TO,MISSING_METADATA,LOCKFILE_OUT_OF_SYNC,MISSING_CHECKSUM,UNUSED_DEPENDENCYandDEV_DEPENDENCY_IN_LIB, all of the sourcepubspec. inspectra deps [directory] [-r] [--fix]runs the pubspec rules and the policy without network access, for every package of a workspace with-r;--fixbounds constraints with a caret, moves development packages todev_dependenciesand addspublish_to: none, keeping comments and formatting.constraint_style: caret|range|pinnedreportsCONSTRAINT_STYLE(low) for hosted constraints written otherwise;--fixrewrites caret and range constraints into each other and exact versions into either.overrides.require_reasonwithoverrides.allowed(name,reason,expires, collected across layers) reportsUNJUSTIFIED_OVERRIDE(medium) for overrides without a valid justification; a justified override no longer reportsDEPENDENCY_OVERRIDE.lockfile_policy: committed|ignored|autoreportsLOCKFILE_POLICY(medium) when Git trackspubspec.lockagainst the policy;autoasks applications to commit it and publishable packages not to.depsandcheckapply it.max_major_behindandmax_libyearwithlibyear_scope: direct|allreportOUTDATED_MAJORandLIBYEAR_EXCEEDED(medium) from the version listings of the registry, cached for a day:deps --online,checkandreportcheck them unless offline. JSON ofdeps:outdatedCheckedandlibyears. A policy'sminimummay only lower both limits.- Library:
ConstraintStyle,LockfilePolicy,LibyearScope,AllowedOverrideand the matching fields ofDependencyPolicyConfig,ConfigStrictness.lowerNumber. scanapplies the policy to its pubspecs, andcheckruns it as the step "Dependency policy" whiledependency_policy.enabledis set.- New runtime dependency:
yaml_edit, for the fixes. - Library:
DependencyPolicyConfig,DeniedPackageandInspectraConfig.dependencyPolicy.
Configuration tools #
inspectra config showprints the effective configuration as YAML;--explaincomments every value with its origin (file and line, environment variable, command line or default) and--only-changedleaves out the defaults.-f jsonlistskey,value,default,origin,variableandlineper option.inspectra config validatechecks the configuration and that every file it refers to exists, and lists all problems at once (exit code65).inspectra config lintreports risky settings as findings of the new sourceconfig:CONFIG_INSECURE_URL,CONFIG_UNKNOWN_VARIABLE,CONFIG_TRIVY_DISABLED,CONFIG_UNPINNED_TRIVY,CONFIG_IGNORE_EXPIRED,CONFIG_IGNORE_WITHOUT_EXPIRY,CONFIG_GATE_NOT_FAILING,CONFIG_MIN_SEVERITY,CONFIG_NO_COVERAGE_THRESHOLDandCONFIG_BASELINE_UNBOUNDED.inspectra config schemaprints the JSON Schema ofinspectra.yaml, generated from the code and published asinspectra.schema.json;inspectra.example.yamlstarts with itsyaml-language-servermodeline.- Unknown keys in the configuration file, in
ignoreentries and on the command line name the closest valid option:Did you mean "secret"?. - Renamed options keep working under their old names until the next major version: every command
warns,
config lintreportsCONFIG_DEPRECATED_OPTION, and the old and the new name side by side are an error. Library:ConfigDeprecation,configDeprecations,DeprecatedOptionandInspectraConfig.deprecatedOptions. - Library:
ConfigRecorder,ConfigEntry,ConfigKind,ConfigOrigin,ConfigOverride,ConfigOverrides.resolveandknownPaths, arecorderparameter ofloadConfig,InspectraConfig.parseandInspectraConfig.fromSources, andFindingSource.config. inspectra config init [--preset app|library|plugin|enterprise] [--stdout] [--force]writes a startinginspectra.yamlfor the kind of package, detected frompubspec.yaml.inspectra config migrate [--dry-run]replaces the old names of renamed options in the configuration file and its profiles, keeping values, comments and order.inspectra config diff <a> [<b>] [--fail-on-weaker]compares two configurations, files orgit:<revision>, with the effective configuration by default, and marks values that got weaker.trivy.filesystem.scannersaccepts scanner names in any case, like the severities.
Reports and dashboards #
inspectra reportruns every evaluation - supply chain, dependencies, configuration, format, lint, style, public API, changelog, each configured Trivy scan and coverage - and reports each as a section with status, summary, key figures and findings. Package checks that are not enabled are reported as skipped with the option that enables them; an evaluation that cannot run is reported with its cause while the others still run, and the command exits with69after writing the report, also with--exit-zero.--skipleaves out sections,--also <format>=<path>writes further formats from the same run and--mergecombines JSON reports of earlier runs.-f htmlwrites a self-contained, offline HTML dashboard in the style of shadcn/ui: a sidebar with every evaluation, key figure cards, charts of findings by severity, line coverage and code composition, a table of the evaluations, a filterable finding explorer and an accordion with the details of each evaluation - coverage per file, the API diff, the code base per directory; light and dark mode, responsive and printable, with a content security policy that allows only its own inline stylesheet and script.- The codebase section of
reportcounts the lines of every Dart file: code with and without comments, comment and documentation lines, blank lines, the comment ratio and TODO markers, per directory and for the largest files, apart from generated files; and the dependencies ofpubspec.yamlandpubspec.lock. - New output formats for every command with
--format:junit,gitlab(Code Quality, with fingerprints that survive moved lines),sonarqube(generic issue import) andcheckstyle. - The package check results become findings of the new source
quality:UNFORMATTED, lint codes,API_CHANGED,API_DUMP_MISSING,CHANGELOG_PROBLEMandCOVERAGE_BELOW_THRESHOLD. - Library:
FindingSource.qualityandFindingSource.tryParse,Finding.fromJson. - New runtime dependency:
xml, for the JUnit and Checkstyle reports.
Configuration inheritance and central policies #
extends:builds a configuration on bases: paths relative to the declaring file,package:files resolved through.dart_tool/package_config.json, andhttpsURLs pinned by their SHA-256, which are verified and cached. Bases nest; mappings merge key by key, scalars and lists of the higher layer win,key: ~resets a value, andignoreanddependency_policy.deniedcollect the entries of every layer. License headers, secret rules and CA bundles named in a base resolve relative to it.- A list option written as
key+:adds to the list of the lower layers, or to the default, instead of replacing it:dependency_policy.dev_only+: [golden_toolkit]. The JSON Schema describes the+variant of every list option. policy:withlockedoptions andminimumvalues binds every layer above its file, includingINSPECTRA_*variables and the command line (--set,--fail-on,coverage --min); a violation is a configuration error naming the option, its origin and the policy.profiles:holds named partial configurations that--profile <name>orINSPECTRA_PROFILEapplies above the project's own configuration and below environment variables and the command line; profiles of the bases and the project merge, policies bind them, and they cannot setextends,policyorprofiles.config validatechecks every profile and lists them asprofilesin its JSON,config showrecords the selected one asprofile.check,format,lint,coverage,api check|dumpandchangelog checktake--profileas well.- Text values and list elements can refer to environment variables:
${env:NAME},${env:NAME:-default}, and$${for a literal${. An unset variable without a default is a configuration error.config showprints the reference instead of the resolved value and marks it with"interpolated": true; policies check the resolved value. Library:ConfigEntry.templateandConfigEntry.shown. policy.forbid_ignore_of: [critical]keeps findings of these severities reported whatever ignores them:ignorerules of any layer,--ignoreand the baseline. A finding an ignore matched carries the attributeignoreForbidden.inspectra config fetchdownloads and verifies remote bases for offline runs andbuild_runner; every command fetches missing bases first.config show --explainnames the base and line of each value,config show -f jsonaddslayersandfile, andconfig lintreportsCONFIG_PUBSPEC_SECTION_IGNORED. The JSON Schema describesextendsandpolicy.- Library:
ConfigLayer,ConfigLayerKind,ConfigLayerStack,ConfigBaseReference,ConfigPolicy,ConfigStrictness,InspectraConfig.fromLayers,ConfigEntry.file,ConfigRecorder.layers,InspectraConfigException.file,NetworkConfig.withResolvedPaths, andcacheRoot/packageRootparameters ofloadConfigandInspectraConfig.fromSources,ConfigPolicy.forbidIgnoreOf,InspectraConfig.forbiddenIgnoreSeverities,Finding.withAttributesandConfigLayerKind.profile.
Semantic versioning from the API dump #
inspectra api semver [--from <revision>]compares the API dump committed at the last release tag (changelog.tag_prefix, read withgit show) with the API of the current code, classifies every change as breaking or additive with a reason, and checks that theversionofpubspec.yamlmakes the required step: major for breaking changes, minor for additions, with Dart's rule before 1.0.0; a pre-release counts as its release. Removed declarations and members, changed signatures, types, default and constant values, added enum values and new abstract members are breaking; new declarations, deprecations and optional parameters of members nobody can override are additive.- Findings
SEMVER_VIOLATION(high,pubspec.yaml) and, withchangelog.enabled,SEMVER_UNDECLARED_BREAKING(medium) when no commit since the release announces a breaking change. Without a release tag, a dump at the release or a version the check is skipped and exits with0. api.semver: trueadds the step "API semver" tocheckand the section "Semantic versioning" (--skip semver) toreport.- Library:
checkSemver,evaluateSemver,SemverResult,classifyApiChanges,ApiChange,ApiChangeKind,ApiSurface,ApiDeclaration,ApiConfig.semver, and the Git typesGitHistory(withshowandhasCommits),GitCommit,ReleaseTag,ConventionalCommitandVersionBump.
Workspace policy #
- The
workspace_policy:section states the rules of a pub workspace at its root:align_versions(off,compatible,exact),require_membership,same_sdk,forbid_cycles,include_dev_dependenciesand architecturelayerswithpackagesglobs,may_depend_on,isolatedandforbidden_dependencies, collected across configuration layers. - Findings of the new source
workspace:WORKSPACE_MEMBER_MISSING,WORKSPACE_RESOLUTION_MISSING,WORKSPACE_VERSION_MISMATCH,WORKSPACE_SDK_MISMATCH,DEPENDENCY_CYCLE,LAYER_VIOLATION,FORBIDDEN_DEPENDENCYandLAYER_UNASSIGNED.deps -rapplies them at a workspace root,checkas the step "Workspace policy",reportin its dependencies section. inspectra graph [directory] [-f text|dot|mermaid|json] [--include-dev] [--external]draws the dependencies between the packages of a workspace, grouped by layer.inspectra workspace affected --since <revision> [-f text|json]lists the packages the changes since a Git revision affect, with every package depending on them;deps -r --changed-since <revision>checks only those.- Library:
WorkspacePolicyConfig,WorkspaceLayer,VersionAlignment,InspectraConfig.workspacePolicy,FindingSource.workspaceandGitHistory.changedFiles.
Developer experience #
inspectra explain [RULE_ID] [-f text|markdown|json]explains a rule offline - source, default severity, what it reports, why it matters and how to resolve it - from a catalog of every fixed rule id, or lists them all; advisory ids point to OSV.dev, a misspelled id gets the closest rule. The new Rule reference in the documentation lists every rule.inspectra doctor [--offline] [-f json]checks the configuration, the Dart and Flutter SDKs against the pubspec and.fvmrc, Git, Trivy, proxy, CA bundle, the reachability of OSV.dev, the registry and the Trivy releases, the token of a private registry and the cache, and exits with1when a check failed.inspectra hook runruns the checks of the newhook.checks(audit,typosquat,deps,format,style; default[audit, typosquat]) on the files staged for the commit, the dependency and style checks on the staged content. The pre-commit hook now calls it;inspectra hook installupdates an installed hook.- Library:
HookConfig,HookCheck,InspectraConfig.hook, andGitHistory.stagedFilesandstagedContent.
Changed #
deps -rat the root of a pub workspace checks the packages itsworkspace:list names instead of everypubspec.yamlbelow it, so a standaloneexample/package is no longer included.scan -rnow also checks the pubspecs of workspace members, which share the root lockfile.ANY_VERSIONandWILDCARD_VERSIONno longer report dependencies on packages of the same pub workspace, which pub resolves to the workspace's own copy.
Fixed #
- A list or mapping where the configuration expects another kind of value, such as
style.rules: [no_else], is reported as a configuration error instead of crashing with exit code70. trivy.executableis a known option again whileINSPECTRA_TRIVYis set: the key in the configuration file no longer fails as an unknown option, and--trivy-executableor--set trivy.executable=…now wins overINSPECTRA_TRIVYas the command line should.- Git runs in the C locale, so a translated Git no longer breaks
api semver,changelogand the semver step ofcheck: an empty repository or an unknown revision failed with exit code69instead of being recognised.ProcessRunner.runtakes anenvironmentfor this.
1.0.0 #
Package quality gates #
- Trivy scans for secrets, dependency licenses, dependency vulnerabilities and a plain filesystem
scan, configurable per scan and runnable from
build_runneror theinspectracommand line. - Public API dump of every public library, written by the
inspectra:apibuilder and checked withbuild_runner build --only-checkorinspectra api check; constants andconstprimary constructors are recorded and changes are shown as a unified diff. - Coverage gate on top of
package:coveragewith an optional line coverage threshold; files marked// coverage:ignore-fileare not listed as untested. - Format check (
dart format) and lint check (dart analyze,fail_on: error|warning|info|none) with--fix, as the first steps ofcheck, and asbuild_runnerbuilders. - A strict lint preset,
package:inspectra/lints/strict.yaml. - Style check (
inspectra style, a step ofcheck, theinspectra:stylebuilder) with rules no lint covers:license_headerfrom a template with{year},public_docs,private_docs,one_type_per_file,one_public_type_per_file,file_named_after_type,no_comments,no_else,no_default_caseandno_wildcard_case; the presetsnone,recommended(fits Flutter's widget-plus-private-Statefiles) andstrict, per-rule switches,// inspectra: ignore-styleandignore-style-filecomments, and text, JSON, Markdown and SARIF output. - Custom style rules:
package:inspectra/style.dartwithStyleRule,StyleFile,StyleReporterandStyleChecker; the files ofstyle.custom_rulesare run by a generated program throughdart run, so they work with the compiled executable as well. - Writerside documentation in
docs/, published to GitHub Pages.
Changelog #
inspectra changelog generatewrites the section of the next release from the Conventional Commits since the latest release tag, in the Keep a Changelog layout: breaking changes first, then Added, Changed, Deprecated, Removed, Fixed and Security, with commit and comparison links. It suggests the next semantic version, drops commits reverted within the release, and with--writeadds the section toCHANGELOG.mdwithout touching existing sections.--from,--to,--release,--date.inspectra changelog check, also part ofcheckwithchangelog.enabled, validates the changelog and fails when the version ofpubspec.yamlis not documented.inspectra changelog notes [version]prints the section of a release; the release workflow uses it as the description of the GitHub release.- The
changelog:configuration section:enabled,file,tag_prefix,types,unconventional,repository,commit_url,compare_url;checkChangelogin the library API.
Supply-chain security #
The supply-chain commands, with stable names, flags, rule ids, JSON fields and the exit codes 0,
1 and 64:
scan, the default command: OSV.dev audit, pubspec rules, typosquatting, dependency confusion and a Trivy filesystem scan in one report, with--recursivefor monorepos and pub workspaces.audit,inspect,trust [version],typosquat,add [--dev] [--force] [--dry-run],hook.- Output formats
json(versioned),sarif(GitHub code scanning) andmarkdown;--output,--fail-on,--min-severity,--ignore,--exit-zero,--offline,--quiet,--verbose,--color. - Ignore rules with mandatory reason, optional package scope and expiry date.
- Proxy, custom CA bundle,
PUB_HOSTED_URL, OSV mirror, retries with back-off andRetry-After, response size limits and an OSV advisory cache.
Full OSV records with pagination, CVSS v3/v2 scoring and per-range fix versions; checksum verified,
in-memory package inspection without zip-slip or decompression bombs; the archive and pubspec
scanners; the pub.dev trust endpoints of the requested version; code point based Unicode scanning;
exact URL host matching; typosquat detection with few false positives; add installs exactly the
inspected version and works with Flutter on Windows.
Trivy provisioning #
- Trivy is taken from
trivy.executable/INSPECTRA_TRIVY, thePATH, package manager directories or Inspectra's cache, or downloaded for Linux, macOS and Windows when the download host is reachable, with mandatory SHA-256 verification against the release checksums and atomic installation.mode,version(latestincluded),download,use_installed, mirrors and the database repository are configurable.inspectra trivy --installand--where;--wherenever downloads. --offlineandnetwork.offlinekeep Trivy offline as well: every scan, including the builders, starts it with--skip-db-update --offline-scan.
Configuration and command line #
- One configuration, in the
inspectra:section ofpubspec.yamlor ininspectra.yaml, with strict validation of every key; configuration errors name the key and, for YAML syntax errors, the line and column. - Every option can be overridden with
INSPECTRA_*environment variables and--set key=value. - Exit codes follow
sysexits.h:65for invalid input or configuration,69for unavailable services and tools,70for internal errors.