app

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 17 Imported by: 0

Documentation

Overview

Package app wires the Compose loader, the Docker inspector, the rule engine and the report builder into the two scan workflows.

Index

Constants

View Source
const HostScanTimeout = 2 * time.Minute

HostScanTimeout bounds the total time spent talking to the Docker daemon.

Variables

This section is empty.

Functions

func Rule

func Rule(id string) (engine.Metadata, bool)

Rule returns the metadata of one rule. The lookup is case-insensitive.

func Rules

func Rules() []engine.Metadata

Rules returns the metadata of all built-in rules sorted by ID.

Types

type App

type App struct {
	Version version.Info
	Now     func() time.Time
	// ConnectDocker opens a verified connection to the Docker daemon.
	ConnectDocker func(context.Context) (*docker.Connection, error)
	// HostFS is the host root filesystem used by the host scan for
	// daemon.json and /proc. Nil disables those checks.
	HostFS fs.FS
	GOOS   string
}

App runs scans. The zero value is not usable; use New.

func New

func New() *App

New returns an App configured for the current machine.

func (*App) ScanCompose

func (a *App) ScanCompose(ctx context.Context, paths []string, opts ScanOptions) (*report.Report, error)

ScanCompose statically analyzes Compose files.

func (*App) ScanHost

func (a *App) ScanHost(ctx context.Context, opts ScanOptions) (*report.Report, error)

ScanHost inspects the local Docker daemon. It returns a *docker.UnavailableError when the daemon cannot be used.

type ScanOptions

type ScanOptions struct {
	// MinSeverity hides less severe findings from the report.
	MinSeverity findings.Severity
	// FailOn is the exit code threshold; nil disables it.
	FailOn *findings.Severity
	// Only and Exclude contain normalized rule IDs.
	Only    []string
	Exclude []string
}

ScanOptions are the user options shared by both scan modes.

type SelectionError

type SelectionError struct {
	Message string
}

SelectionError reports invalid --only/--exclude values. It is a user input error and maps to exit code 2.

func (*SelectionError) Error

func (e *SelectionError) Error() string

Error implements error.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL