Skip to content

Releases: Stephan-Thomas/DripGuard

Release list

DripGuard v1.0.0

Choose a tag to compare

@Stephan-Thomas Stephan-Thomas released this 14 Sep 11:55

DripGuard v1.0.0

DripGuard v1.0.0 is the first production release of a funding-supply-chain linter for open-source projects using Drips.

DripGuard continuously checks whether a project's software dependencies remain aligned with its Drips funding policy, helping maintainers detect funding drift as their dependency graph changes.

Highlights

  • GitHub Action for continuous funding-policy checks in CI

  • CLI for local dependency and funding analysis

  • Live Drips network provider with strict failure handling

  • Deterministic offline/mock provider for testing

  • Multi-ecosystem dependency discovery:

    • npm
    • Cargo
    • Go
    • Python
  • Canonical dependency resolution from package identity to repository and Drips identity

  • Funding coverage and policy enforcement

  • Funding drift detection

  • Baseline comparison support

  • Concentration and HHI policy checks

  • GitHub Pull Request comments and Step Summaries

  • SARIF and JSON reporting

  • Self-contained Node 20 GitHub Action bundle

  • Least-privilege GitHub Action permissions

  • Strict protection against silently substituting mock data for unavailable live data

GitHub Action

Use DripGuard directly in your workflow:

- name: DripGuard
  uses: Stephan-Thomas/DripGuard@v1
  with:
    provider: live

For PR comments, grant the workflow the additional pull-requests: write permission.

CLI

Run DripGuard locally with:

npx dripguard check

Offline deterministic testing is available with:

npx dripguard check --mock

Release

This release establishes the v1 major-version channel for GitHub Action consumers while v1.0.0 provides an immutable version-specific reference.

See the README and documentation for configuration, policies, supported ecosystems, and usage examples.