dependency-risk-suite
SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL
This repository is part of the Layerfault synthetic security corpus.
It is deliberately constructed to contain security-relevant characteristics for scanner testing.
Corpus ID: LF-CORPUS-DEP-0001
Purpose
Mixed Python/npm dependency manifests exercising alternate indexes, URLs, missing includes, insecure transport, local paths, path escapes, install hooks and VCS references.
Direct expected Layerfault rules
LF-DEP-ALT-INDEX
LF-DEP-DIRECT-URL
LF-DEP-INCLUDE-MISSING
LF-DEP-INSECURE-TRANSPORT
LF-DEP-BUILD-BACKEND
LF-DEP-INSTALL-HOOK
LF-DEP-LOCAL-PATH
LF-DEP-PATH-ESCAPE
LF-DEP-NPM-INSTALL-HOOK
LF-DEP-RUNTIME-INSTALL
LF-DEP-VCS
LF-DEP-VCS-MUTABLE-REF
Candidate rules
These are deliberately plausible targets that remain marked as candidates until the exact
Layerfault build used for certification confirms them.
Negative-control rules
These should remain silent for this corpus item.
Safety
The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output,
and synthetic model behavior only. It is intended for static scanning and isolated security testing.