Skip to content

refactor: rename darnit-reproducibility to darnit-amber - #532

Open
Marc-cn wants to merge 1 commit into
mainfrom
feat/rename-reproducibility-to-amber
Open

Marc-cn wants to merge 1 commit into
mainfrom
feat/rename-reproducibility-to-amber

refactor: rename darnit-reproducibility to darnit-amber

037b53c
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Oct 1, 2026 in 51s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both analyses recommend PROCEED. The code analysis found no code issues, exposed secrets, or workflow issues. The dependency findings (numpy 1.26.4, click 8.0, requests 2.31.0) appear only in test fixture requirements.txt files under tests/darnit_amber/fixtures, so they are intentionally pinned sample inputs and not runtime dependencies. Advisories exist for click (CVE-2026-7246) and requests (CVE-2026-25645, CVE-2024-47081, CVE-2024-35195). None are CISA KEV and EPSS is low. numpy is flagged end-of-life and has license text that is not OSS-classified. The only new package in the real lockfile is darnit-amber 0.1.0, the project's own package, so missing scorecard data is expected. The requests chain through sigstore comes from the existing lockfile, not from this PR. Upgrading the fixture pins (click==8.5.0, numpy==2.5.3, requests>=2.34.2) would only matter if the fixtures became real dependencies, and would likely defeat their test purpose. Combined, the risk profile is low.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 037b53c, performed at: 2026-10-01T18:54:46Z