LowEndInsight

build status Hex.pm Coverage Status

Current Version: 0.10.0

LowEndInsight is a simple "bus-factor" risk analysis library for Open Source Software managed within Git repositories. Provide a git URL, and the library responds with a structured report highlighting potential maintenance and supply-chain risks.


What's New

Version 0.10.0

Version 0.9.1

Version 0.9.0


Why LowEndInsight?

If you are concerned about risks associated with upstream dependency requirements, LowEndInsight provides valuable, actionable information about the likelihood of critical issues being resolved.

LowEndInsight provides a simple mechanism for investigating and applying basic governance (based on configurable tolerance levels) and responds with a useful report for integrating into your DevSecOps automation.


Key Metrics


Installation

LowEndInsight is available on Hex. Add it to your mix.exs:

def deps do
  [
    {:lowendinsight, "~> 0.9"}
  ]
end

For Scanning in a Mix-based Project

Add it as a development dependency:

defp deps do
  [
    {:lowendinsight, "~> 0.9", only: [:dev, :test], runtime: false}
  ]
end

Then run mix deps.get and mix lei.scan.


Usage

Scanning Local or Remote Repos

# Scan a remote repository
mix lei.analyze https://github.com/facebook/react

# Scan a local directory
mix lei.scan /path/to/local/repo

NPM-Based Projects

LowEndInsight can run against NPM projects. It requires an existing package.json for first-degree dependencies, and package-lock.json for a complete scan including transitive dependencies.

mix lei.scan /path/to/npm/project

Note: A local installation of Mix is still required.

SARIF Output for GitHub Security

Generate SARIF output for integration with GitHub's Security tab:

mix lei.sarif . --output lei-results.sarif

ZarfGate - Quality Gate for CI/CD

Fail CI pipelines when dependencies exceed risk thresholds:

# Fail if any dependency has high or critical risk
mix lei.gate . --threshold high

AI Rules Generation

Generate rules for AI coding assistants (Cursor, GitHub Copilot):

mix lei.generate_rules --target cursor

Example Report Output

Click to view a full JSON analysis report for React
{
  "state": "complete",
  "report": {
    "uuid": "caa7f920-aaa3-11ec-9c05-f47b09cc5c9a",
    "repos": [
      {
        "header": {
          "repo": "https://github.com/facebook/react",
          "start_time": "2022-03-23T12:21:13.234974Z",
          "end_time": "2022-03-23T12:21:39.762485Z",
          "duration": 26
        },
        "data": {
          "risk": "medium",
          "results": {
            "contributor_count": 1671,
            "functional_contributors": 97,
            "contributor_risk": "low",
            "commit_currency_weeks": 0,
            "commit_currency_risk": "low",
            "sbom_risk": "medium",
            "large_recent_commit_risk": "low"
          },
          "git": {
            "hash": "de516ca5a635220d0cbe82b8f04003820e3f4072",
            "default_branch": "refs/remotes/origin/main"
          }
        }
      }
    ]
  },
  "metadata": {
    "risk_counts": { "medium": 1 },
    "repo_count": 1
  }
}

Configuration

LowEndInsight allows customization of risk levels. You can set these in your config/config.exs or via environment variables.

Environment Variable Default Metric
LEI_CRITICAL_CURRENCY_LEVEL 104 Weeks since last commit
LEI_CRITICAL_CONTRIBUTOR_LEVEL 2 Minimum discrete contributors
LEI_CRITICAL_LARGE_COMMIT_LEVEL 0.40 Max percentage of codebase changed in a commit

Example override:

LEI_CRITICAL_CURRENCY_LEVEL=60 mix lei.scan

GitHub Action

Add LowEndInsight to your GitHub workflow:

name: LEI
on:
  push:
    branches: [ main ]

jobs:
  analyze:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - name: Generate Report
        uses: kitplummer/lowendinsight@gha
        with:
          github_token: ${{ secrets.GITHUB_TOKEN }}
          branch: main

Contributing

We welcome contributions!

License

BSD 3-Clause. See LICENSE for details.

Includes code from mix-deps-json, Copyright (c) 2016 Andrew Nesbitt, MIT License.


Advanced Usage & Integration

For more specialized use cases, refer to the following: