georesearch-dsh/georesearch-dsh--packages-installation-guard1

@georesearch/dsh-installation-guard

Fail-closed activation validation for the managed GeoResearch installation

AI 분석

核心用途是验证 GeoResearch 安装的完整性。适合需要防止安装漂移、监控会话遥测并自动卸载受影响消费者的安全管理任务。

패키지
@georesearch/dsh-installation-guard
버전
0.1.0
라이선스
MIT
최근 업데이트
2026. 8. 28.

설치

검증된 bundle이 없거나 호환성 검사에 실패했습니다. 먼저 저장소 설명을 읽어 주세요. 전체 README 읽기 ↗

@georesearch/dsh-installation-guard

Provides ctx.geoResearchInstallation only after the managed generation and all recorded digests validate. A polling monitor disposes the provider fiber when installation drift or Session Telemetry appears, which unloads injected GeoResearch consumers.

Validation covers the managed installation carrier, the shared runtime package tree, and the GeoResearch-owned dependency and bundle fields in every integrated Web Profile. Unrelated user fields and dependencies remain outside the managed digest surface.

The Profile cordis.yml root is a Harness-owned runtime anchor and is excluded from new managed tree digests. Legacy installation manifests that explicitly recorded the file continue to use the legacy digest policy.

The maintenance nonce is single-use and 256-bit. Disk stores only its SHA-256 digest; the child environment receives a Windows DPAPI CurrentUser-protected blob whose optional entropy binds transaction, generation, executable, and deadline. Tests may use AES-256-GCM only when NODE_ENV=test and an explicit 32-byte GEORESEARCH_TEST_NONCE_KEY is supplied.