Configuration files
.dagsecignore
Suppresses secret findings you've reviewed and accepted. Put it at the repository root on the default branch:
# Test fixture, not a real key
aws-access-key-id:3f2a9c1d7e04:config/deploy.env:1
github-token:9b8c7d6e5f4a:scripts/seed.sh:12- One fingerprint per line.
#starts a comment; blank lines are ignored.- On pull requests the file is read from the base branch, so a pull request can't silence its own findings. Outside pull requests it's read from the working tree.
.dagsec.toml
Repository policy, at the root on the default branch. Read from the base branch on pull requests, like .dagsecignore.
toml
[licenses]
# Fail the check when a direct dependency is under one of these licenses.
block = ["GPL-3.0", "AGPL-3.0"]| Key | Type | Default | Meaning |
|---|---|---|---|
licenses.block | list of SPDX IDs | [] | Licenses that fail the scan. See License policy. |
A file that isn't valid TOML is ignored with a warning; the scan still runs.
.pkgriskrc.toml
Advanced tuning of the health score and cache, for the CLI. dagsec looks for .pkgriskrc.toml in the current directory, then ~/.config/pkgrisk/config.toml. The file must contain every section:
toml
[general]
cache_ttl_hours = 24 # how long registry and OSV answers are cached
default_format = "terminal"
[thresholds]
fail_under = 40 # used when --fail-under isn't given
warn_under = 65
[license]
project_license = "MIT"
blocklist = ["AGPL-3.0", "GPL-2.0"] # scores these licenses 0 in the health score
[ecosystems]
disabled = []If the file is missing or incomplete, the defaults above are used. The license.blocklist here only lowers the health score; to fail a scan on licenses, use .dagsec.toml.