Baseline Presets
Every policy is built on a baseline preset: a curated bundle of rules that sits underneath your custom rules and decides any alert they do not match. Custom rules always win over the baseline for the same alert, so the baseline is a default, not a constraint — see Policies for how evaluation works.
| Preset | What it covers |
|---|---|
| Essential | Blocks malware; warns on critical vulnerabilities and monitors lower-severity ones. |
| Balanced | Adds supply chain risks — typosquatting, packages pulled from git or URLs, and similar — on top of Essential. |
| Comprehensive | Blocks critical vulnerabilities and risky dependency sources as well; the broadest coverage across all risk types. |
| None | No baseline rules. Only your custom rules apply. |
The Default policy starts on Balanced, which is the right starting point for most teams.
What Each Preset Does
The table below lists the action each preset applies to every alert type. An alert type marked Ignore has no rule in that preset — it is ignored unless one of your custom rules matches it.
Legend: 🔴 Block · 🟠 Warn · 🟡 Monitor · ⚪ Ignore
| Alert Type | Essential | Balanced | Comprehensive |
|---|---|---|---|
| Known malware | 🔴 | 🔴 | 🔴 |
| AI-detected potential malware | 🟠 | 🟠 | 🔴 |
| Critical CVE | 🟠 | 🟠 | 🔴 |
| High CVE | 🟡 | 🟡 | 🟠 |
| Medium CVE | 🟡 | 🟡 | 🟡 |
| Low CVE | 🟡 | 🟡 | 🟡 |
| License Policy Violation | 🟠 | 🟠 | 🟠 |
| Git dependency | ⚪ | 🟠 | 🔴 |
| GitHub dependency | ⚪ | 🟠 | 🔴 |
| HTTP dependency | ⚪ | 🟠 | 🔴 |
| Possible typosquat attack | ⚪ | 🟠 | 🟠 |
| Protestware or potentially unwanted behavior | ⚪ | 🟠 | 🟠 |
| Obfuscated code | ⚪ | 🟡 | 🟠 |
| Deprecated | ⚪ | 🟡 | 🟠 |
| Missing lockfile | ⚪ | 🟡 | 🟠 |
| Oversized manifest | ⚪ | 🟡 | 🟡 |
| Shrinkwrap | ⚪ | 🟡 | 🟠 |
| Telemetry | ⚪ | 🟡 | 🟠 |
| Unpopular package | ⚪ | 🟡 | 🟠 |
| Unpublished package | ⚪ | 🟡 | 🟠 |
| Unstable ownership | ⚪ | 🟡 | 🟠 |
| AI-detected potential security risk | ⚪ | ⚪ | 🟡 |
| Bad dependency semver | ⚪ | ⚪ | 🟡 |
| Install scripts | ⚪ | ⚪ | 🟡 |
| Manifest confusion | ⚪ | ⚪ | 🟡 |
| Potential vulnerability | ⚪ | ⚪ | 🟡 |
| Unmaintained | ⚪ | ⚪ | 🟡 |
| Wildcard dependency | ⚪ | ⚪ | 🟡 |
You can change a policy's baseline at any time without touching your custom rules.
Related Pages
- Policies — how baselines interact with your custom rules.
- Rule Conditions — writing rules that override the baseline.
Updated 1 day ago
Did this page help you?
