Baseline Presets

Every policy is built on a baseline preset: a curated bundle of rules that sits underneath your custom rules and decides any alert they do not match. Custom rules always win over the baseline for the same alert, so the baseline is a default, not a constraint — see Policies for how evaluation works.

PresetWhat it covers
EssentialBlocks malware; warns on critical vulnerabilities and monitors lower-severity ones.
BalancedAdds supply chain risks — typosquatting, packages pulled from git or URLs, and similar — on top of Essential.
ComprehensiveBlocks critical vulnerabilities and risky dependency sources as well; the broadest coverage across all risk types.
NoneNo baseline rules. Only your custom rules apply.

The Default policy starts on Balanced, which is the right starting point for most teams.

What Each Preset Does

The table below lists the action each preset applies to every alert type. An alert type marked Ignore has no rule in that preset — it is ignored unless one of your custom rules matches it.

Legend: 🔴 Block · 🟠 Warn · 🟡 Monitor · ⚪ Ignore

Alert TypeEssentialBalancedComprehensive
Known malware🔴🔴🔴
AI-detected potential malware🟠🟠🔴
Critical CVE🟠🟠🔴
High CVE🟡🟡🟠
Medium CVE🟡🟡🟡
Low CVE🟡🟡🟡
License Policy Violation🟠🟠🟠
Git dependency🟠🔴
GitHub dependency🟠🔴
HTTP dependency🟠🔴
Possible typosquat attack🟠🟠
Protestware or potentially unwanted behavior🟠🟠
Obfuscated code🟡🟠
Deprecated🟡🟠
Missing lockfile🟡🟠
Oversized manifest🟡🟡
Shrinkwrap🟡🟠
Telemetry🟡🟠
Unpopular package🟡🟠
Unpublished package🟡🟠
Unstable ownership🟡🟠
AI-detected potential security risk🟡
Bad dependency semver🟡
Install scripts🟡
Manifest confusion🟡
Potential vulnerability🟡
Unmaintained🟡
Wildcard dependency🟡

You can change a policy's baseline at any time without touching your custom rules.

Related Pages

  • Policies — how baselines interact with your custom rules.
  • Rule Conditions — writing rules that override the baseline.

Did this page help you?