Phase 3c: re-point health.zig + trust.zig exclusion/path gates onto safety_core (isExcludedFromScan, hasSourceExtension, isExpectedBinaryPath) โ both hosts' repo-wide/trust scans now share the one canonical gate; safety.zig's copies drop to 0 external callers. Kept kepr-local: binaryBlobInSource (returns BlobKind core doesn't expose) + isAlwaysSafeUrl (URL context isn't a core concern) + analyzeBuildScriptEco/analyzeSupplyChain/provenance. Suite green 487+2 (v1.56.189)
$ koh steal kepr.uk/kepr@7a64b1b2642e
·
parent: 7676ff698398
discussion
log in to leave a comment.