inspectra 1.0.0
inspectra: ^1.0.0 copied to clipboard
Enterprise software assurance and supply-chain security for Dart and Flutter: OSV.dev audit, package source inspection, trust and typosquat analysis, safe dependency installation, Git hooks, Trivy sca [...]
Changelog #
All notable changes to this project are documented in this file. The format follows Keep a Changelog and the project adheres to Semantic Versioning.
1.0.0 #
Package quality gates #
- Trivy scans for secrets, dependency licenses, dependency vulnerabilities and a plain filesystem
scan, configurable per scan and runnable from
build_runneror theinspectracommand line. - Public API dump of every public library, written by the
inspectra:apibuilder and checked withbuild_runner build --only-checkorinspectra api check; constants andconstprimary constructors are recorded and changes are shown as a unified diff. - Coverage gate on top of
package:coveragewith an optional line coverage threshold; files marked// coverage:ignore-fileare not listed as untested. - Format check (
dart format) and lint check (dart analyze,fail_on: error|warning|info|none) with--fix, as the first steps ofcheck, and asbuild_runnerbuilders. - A strict lint preset,
package:inspectra/lints/strict.yaml. - Style check (
inspectra style, a step ofcheck, theinspectra:stylebuilder) with rules no lint covers:license_headerfrom a template with{year},public_docs,private_docs,one_type_per_file,one_public_type_per_file,file_named_after_type,no_comments,no_else,no_default_caseandno_wildcard_case; the presetsnone,recommended(fits Flutter's widget-plus-private-Statefiles) andstrict, per-rule switches,// inspectra: ignore-styleandignore-style-filecomments, and text, JSON, Markdown and SARIF output. - Custom style rules:
package:inspectra/style.dartwithStyleRule,StyleFile,StyleReporterandStyleChecker; the files ofstyle.custom_rulesare run by a generated program throughdart run, so they work with the compiled executable as well. - Writerside documentation in
docs/, published to GitHub Pages.
Changelog #
inspectra changelog generatewrites the section of the next release from the Conventional Commits since the latest release tag, in the Keep a Changelog layout: breaking changes first, then Added, Changed, Deprecated, Removed, Fixed and Security, with commit and comparison links. It suggests the next semantic version, drops commits reverted within the release, and with--writeadds the section toCHANGELOG.mdwithout touching existing sections.--from,--to,--release,--date.inspectra changelog check, also part ofcheckwithchangelog.enabled, validates the changelog and fails when the version ofpubspec.yamlis not documented.inspectra changelog notes [version]prints the section of a release; the release workflow uses it as the description of the GitHub release.- The
changelog:configuration section:enabled,file,tag_prefix,types,unconventional,repository,commit_url,compare_url;checkChangelogin the library API.
Supply-chain security #
Every command of dart_audit 0.3.1 with the same names, flags, rule ids, JSON fields and the exit
codes 0, 1 and 64:
scan, the default command: OSV.dev audit, pubspec rules, typosquatting, dependency confusion and a Trivy filesystem scan in one report, with--recursivefor monorepos and pub workspaces.audit,inspect,trust [version],typosquat,add [--dev] [--force] [--dry-run],hook.- Output formats
json(versioned),sarif(GitHub code scanning) andmarkdown;--output,--fail-on,--min-severity,--ignore,--exit-zero,--offline,--quiet,--verbose,--color. - Ignore rules with mandatory reason, optional package scope and expiry date.
- Proxy, custom CA bundle,
PUB_HOSTED_URL, OSV mirror, retries with back-off andRetry-After, response size limits and an OSV advisory cache.
Fixed compared to dart_audit: full OSV records with pagination, CVSS v3/v2 scoring and per-range
fix versions; checksum verified, in-memory package inspection without zip-slip or decompression
bombs; the archive and pubspec scanners actually run; correct pub.dev trust endpoints for the
requested version; code point based Unicode scanning; exact URL host matching; far fewer typosquat
false positives; add installs exactly the inspected version and works with Flutter on Windows.
Trivy provisioning #
- Trivy is taken from
trivy.executable/INSPECTRA_TRIVY, thePATH, package manager directories or Inspectra's cache, or downloaded for Linux, macOS and Windows when the download host is reachable, with mandatory SHA-256 verification against the release checksums and atomic installation.mode,version(latestincluded),download,use_installed, mirrors and the database repository are configurable.inspectra trivy --installand--where;--wherenever downloads. --offlineandnetwork.offlinekeep Trivy offline as well: every scan, including the builders, starts it with--skip-db-update --offline-scan.
Configuration and command line #
- One configuration, in the
inspectra:section ofpubspec.yamlor ininspectra.yaml, with strict validation of every key; configuration errors name the key and, for YAML syntax errors, the line and column. - Every option can be overridden with
INSPECTRA_*environment variables and--set key=value. - Exit codes follow
sysexits.h:65for invalid input or configuration,69for unavailable services and tools,70for internal errors.