{"id":"security.pack.turbineh","compat":{"runtime":"node@>=20","framework":"next@^16.0.0"},"schema":"turbineh.component/v0.1","source":{"purl":"pkg:generic/turbineh/security.pack.turbineh@0.1.0","repo":"https://github.com/alejandroruiz3c/code-api-turbineh"},"status":"approved","effects":{"db":false,"fs":false,"network":false,"external_services":[]},"license":{"declared":"Apache-2.0","detected":"Apache-2.0","obligations":["preserve-notice"]},"quality":{"tests":{"date":"2026-10-10","passed":true,"command":"recipe saas-crud: typecheck, lint, unit, build, e2e (sandbox, no network)"}},"version":"0.1.0","category":"security","contract":{"errors":["see source"],"inputs":["see source"],"limits":["see source"],"outputs":["see source"]},"evidence":[{"ref":"bench/results/2026-10-10-d1-recipe-saas-crud.json","claim":"Unit tests: headers deny framing/sniffing and CSP is restrictive; rate limiter blocks after the limit","origin":"tested"}],"security":{"scope":"First-party source reviewed; no third-party dependencies of its own.","tools":["gitleaks","review"],"findings":[],"scanned_at":"2026-10-10"},"relations":{"provides":["security.headers","ops.rate-limit"],"requires":[],"conflicts":[],"tested_with":["recipe.saas-crud"]},"capability":{"cons":["Single-instance assumptions documented in code"],"does":"Security Pack: HTTP security headers with CSP, fixed-window rate limiting and safe error messages","pros":["Maintained by TurbineH","No third-party runtime dependency beyond the stack"],"does_not":"Does not provide a WAF, bot detection or distributed rate limiting","use_cases":["saas-crud","landing-waitlist","internal-tool","bookings","client-portal"],"alternatives":[]},"integration":{"config":[],"install":"Included in recipe templates at src/security/","strategy":"vendored-with-provenance","migrations":false}}