Closed raghavkaul closed 3 weeks ago
Attention: Patch coverage is 48.14815%
with 28 lines
in your changes missing coverage. Please review.
Project coverage is 59.97%. Comparing base (
02f72e0
) to head (7df77ec
). Report is 4 commits behind head on main.
What kind of change does this PR introduce?
Add a probe to check for verified provenance. Look up the package associated with the GitHub/GitLab project, and check if the package. In the current version, this check only supports NPM packages.
Which issue(s) this PR fixes
Closes #3038.
Addresses #1776 and #298.
Special notes for your reviewer
For now, treating "No package found" the same as "this ecosystem doesn't have packages / doesn't support publishing provenance" - with
finding.NotAvailable
. In the future, we might add ecosystem detection to make the latter scenariofinding.NotApplicable
.Does this PR introduce a user-facing change?