Releases: Stephan-Thomas/DripGuard
Release list
DripGuard v1.0.0
DripGuard v1.0.0
DripGuard v1.0.0 is the first production release of a funding-supply-chain linter for open-source projects using Drips.
DripGuard continuously checks whether a project's software dependencies remain aligned with its Drips funding policy, helping maintainers detect funding drift as their dependency graph changes.
Highlights
-
GitHub Action for continuous funding-policy checks in CI
-
CLI for local dependency and funding analysis
-
Live Drips network provider with strict failure handling
-
Deterministic offline/mock provider for testing
-
Multi-ecosystem dependency discovery:
- npm
- Cargo
- Go
- Python
-
Canonical dependency resolution from package identity to repository and Drips identity
-
Funding coverage and policy enforcement
-
Funding drift detection
-
Baseline comparison support
-
Concentration and HHI policy checks
-
GitHub Pull Request comments and Step Summaries
-
SARIF and JSON reporting
-
Self-contained Node 20 GitHub Action bundle
-
Least-privilege GitHub Action permissions
-
Strict protection against silently substituting mock data for unavailable live data
GitHub Action
Use DripGuard directly in your workflow:
- name: DripGuard
uses: Stephan-Thomas/DripGuard@v1
with:
provider: liveFor PR comments, grant the workflow the additional pull-requests: write permission.
CLI
Run DripGuard locally with:
npx dripguard checkOffline deterministic testing is available with:
npx dripguard check --mockRelease
This release establishes the v1 major-version channel for GitHub Action consumers while v1.0.0 provides an immutable version-specific reference.
See the README and documentation for configuration, policies, supported ecosystems, and usage examples.