Loop 6 of the PkgSafe Loop Engineering roadmap.
Goal: strengthen dependency confusion and private registry protection while keeping PkgSafe npm-first and local-first.
Scope:
- npm private scopes
- PyPI private prefixes
- no public fallback
- registry token redaction
- registry test command
- dependency confusion evidence
Validation target:
- gofmt -w .
- go test ./...
- go test -race ./...
- go vet ./...
- make build
- evidence recorded in evidence/loops/loop-06-private-registry-governance.md
Do not add SaaS, billing, SSO, hosted services, or behavior analysis changes.
Loop 6 of the PkgSafe Loop Engineering roadmap.
Goal: strengthen dependency confusion and private registry protection while keeping PkgSafe npm-first and local-first.
Scope:
Validation target:
Do not add SaaS, billing, SSO, hosted services, or behavior analysis changes.