diff --git a/.gitignore b/.gitignore index 28a9de11..e3744b62 100644 --- a/.gitignore +++ b/.gitignore @@ -25,3 +25,4 @@ test-build/.work/ # A lockfile committed from that directory would put the vulnerable package into the repository's # dependency graph, where its advisories cannot be told apart from advisories about the shipped package. examples/protect/package-lock.json +.public-types-check/ diff --git a/AGENT-INSTALL.md b/AGENT-INSTALL.md index 163df54d..02a70b5e 100644 --- a/AGENT-INSTALL.md +++ b/AGENT-INSTALL.md @@ -8,8 +8,8 @@ Every command at a glance — what it does, whether it reads your source, what i | Command | What it does | Reads your source? | Writes to your project | Sends over the network | |---|---|---|---|---| -| `scan` | Provision (or reuse) the site and POST the dependency list for vulnerability matching. Also runs automatically via `setup` and the install/build hooks. | No — lockfile only; `node_modules/` is enumerated when no lockfile can be read (e.g. `bun.lockb`) or when the lockfiles present disagree | `.patchstackrc.json` (public: site UUID + settings); `.patchstackrc.local.json` (the API key, created owner-only) and a `.gitignore` entry for it — the CLI says so if it could not add one; the widget `