Documentation
¶
Overview ¶
Package app wires the Compose loader, the Docker inspector, the rule engine and the report builder into the two scan workflows.
Index ¶
Constants ¶
View Source
const HostScanTimeout = 2 * time.Minute
HostScanTimeout bounds the total time spent talking to the Docker daemon.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type App ¶
type App struct {
Version version.Info
Now func() time.Time
// ConnectDocker opens a verified connection to the Docker daemon.
ConnectDocker func(context.Context) (*docker.Connection, error)
// HostFS is the host root filesystem used by the host scan for
// daemon.json and /proc. Nil disables those checks.
HostFS fs.FS
GOOS string
}
App runs scans. The zero value is not usable; use New.
func (*App) ScanCompose ¶
func (a *App) ScanCompose(ctx context.Context, paths []string, opts ScanOptions) (*report.Report, error)
ScanCompose statically analyzes Compose files.
type ScanOptions ¶
type ScanOptions struct {
// MinSeverity hides less severe findings from the report.
MinSeverity findings.Severity
// FailOn is the exit code threshold; nil disables it.
FailOn *findings.Severity
// Only and Exclude contain normalized rule IDs.
Only []string
Exclude []string
}
ScanOptions are the user options shared by both scan modes.
type SelectionError ¶
type SelectionError struct {
Message string
}
SelectionError reports invalid --only/--exclude values. It is a user input error and maps to exit code 2.
Click to show internal directories.
Click to hide internal directories.