Skip to content

Configuration files ​

.dagsecignore ​

Suppresses secret findings you've reviewed and accepted. Put it at the repository root on the default branch:

# Test fixture, not a real key
aws-access-key-id:3f2a9c1d7e04:config/deploy.env:1

github-token:9b8c7d6e5f4a:scripts/seed.sh:12
  • One fingerprint per line.
  • # starts a comment; blank lines are ignored.
  • On pull requests the file is read from the base branch, so a pull request can't silence its own findings. Outside pull requests it's read from the working tree.

.dagsec.toml ​

Repository policy, at the root on the default branch. Read from the base branch on pull requests, like .dagsecignore.

toml
[licenses]
# Fail the check when a direct dependency is under one of these licenses.
block = ["GPL-3.0", "AGPL-3.0"]
KeyTypeDefaultMeaning
licenses.blocklist of SPDX IDs[]Licenses that fail the scan. See License policy.

A file that isn't valid TOML is ignored with a warning; the scan still runs.

.pkgriskrc.toml ​

Advanced tuning of the health score and cache, for the CLI. dagsec looks for .pkgriskrc.toml in the current directory, then ~/.config/pkgrisk/config.toml. The file must contain every section:

toml
[general]
cache_ttl_hours = 24          # how long registry and OSV answers are cached
default_format = "terminal"

[thresholds]
fail_under = 40               # used when --fail-under isn't given
warn_under = 65

[license]
project_license = "MIT"
blocklist = ["AGPL-3.0", "GPL-2.0"]   # scores these licenses 0 in the health score

[ecosystems]
disabled = []

If the file is missing or incomplete, the defaults above are used. The license.blocklist here only lowers the health score; to fail a scan on licenses, use .dagsec.toml.