Skip to content

Add bundled or derived role predicate - #9

Merged
andrew merged 1 commit into
mainfrom
add-bundled-or-derived-predicate
Oct 1, 2026
Merged

andrew merged 1 commit into
mainfrom
add-bundled-or-derived-predicate

Conversation

@andrew

@andrew andrew commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Add Set.BundledOrDerived() to group Vendor, Fixture, Cache and BuildOutput for callers filtering project evidence. Generated, Test and Tooling alone return false, so generated lockfiles remain eligible as dependency evidence.

Clarify that role sets cannot establish first-party ownership and that requiring Source would exclude paths such as main.go and scripts/deploy.py.

Fixes #8.

@andrew
andrew merged commit 1f846e0 into main Oct 1, 2026
5 checks passed
@andrew
andrew deleted the add-bundled-or-derived-predicate branch October 1, 2026 08:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a Set predicate for bundled or derived paths

1 participant