Skip to content

v0.13.0 — dependency origin in alerts

Choose a tag to compare

@MicroMilo MicroMilo released this 15 Aug 18:08
· 25 commits to main since this release
cb048b1

Highlights

  • Preserve whether an affected dependency came from the plugin profile or DSH's shared host runtime.
  • Carry the origin into vulnerability events and durable DSH analysis tasks.
  • Render Origin: plugin profile, Origin: DSH host runtime, or both in human alerts.
  • Extend the dependency-graph showcase so the distinction is visible in the README.

Validation

  • 80 tests passing on Node 22/24 CI
  • Real DSH headless delivery showcase passed
  • Real DSH with live OSV + npm feeds passed
  • No implemented static scan findings