packages/security-analysis
ARCLUX Security Analysis
This package provides defensive, source-based security findings and provenance contracts.analyzeRepositorySecurity(repository) is the integration point for
the ARCLUX engine. It does not execute repository code or perform network scans.
Exports (dari index.ts):
DiskSourceProvidertype SourceProviderdetectSecretExposureshannonEntropyDEFAULT_SECRET_RULEStype SecretRuletype SecretDetectionOptionsdetectUnsafePatternsDEFAULT_UNSAFE_PATTERN_RULEStype UnsafePatternRuletype UnsafePatternOptionsdetectSensitiveDataFlowDEFAULT_DATA_FLOW_RULEStype DataFlowRuletype SensitiveDataFlowOptionsdetectTrustBoundaryViolationsclassifyTrustZoneDEFAULT_TRUST_ZONEStype TrustZoneDefinitiontype TrustZoneIdtype TrustBoundaryOptionsdetectCrossBoundaryCallsanalyzeSecurityImpactattachImpactToFindingstype SecurityImpactReporttype ImpactedFindingremediateRuleattachRemediationsbuildSecurityReportsummarizetype SecurityReporttype SecurityReportSummarytype ReportAttackSurfacetype BuildSecurityReportInputparseLockfilesnormalizeVersionLOCKFILE_NAMEStype LockedDependencytype LockfileParseResultcompareSemverisVulnerabledetectVulnerableDependenciestoSecurityFindingsDEFAULT_KNOWN_VULNERABILITIEStype KnownVulnerabilitytype VulnerableDependencyFindinganalyzeTransitiveRiskvulnerableNamestype TransitiveRiskReportanalyzeDependencyRiskisUnpinnedRangetype DependencyRiskInputtype DependencyRiskResult