Documentation
¶
Overview ¶
Package engine contains the rule model, the rule registry and the scanning engine that turns rule issues into fully described findings.
Index ¶
- Constants
- func BuildFinding(meta Metadata, issue Issue, scannerVersion string, ts time.Time) findings.Finding
- func ParseRuleIDs(values []string) []string
- func Select[T any](reg *Registry[T], sel Selection) (enabled []Rule[T], skipped []SkippedRule)
- type FuncRule
- type Issue
- type Metadata
- type Registry
- type Result
- type Rule
- type RuleError
- type RunConfig
- type Scope
- type Selection
- type SkippedRule
- type SuppressedFinding
Constants ¶
const ( ReasonExcluded = "excluded with --exclude" ReasonNotInOnly = "not selected with --only" )
Skip reasons.
const DocsBaseURL = "https://github.com/6-SlX-6/stacksentry/blob/main/docs/rules.md"
DocsBaseURL is the location of the rule reference documentation.
Variables ¶
This section is empty.
Functions ¶
func BuildFinding ¶
BuildFinding combines rule metadata with a reported issue.
func ParseRuleIDs ¶
ParseRuleIDs normalizes user supplied rule IDs. Each value may itself be a comma-separated list. IDs are trimmed, upper-cased and de-duplicated while preserving their first occurrence order.
func Select ¶
func Select[T any](reg *Registry[T], sel Selection) (enabled []Rule[T], skipped []SkippedRule)
Select returns the rules to evaluate and the rules skipped by the selection. IDs that are not registered are ignored here; callers validate user input beforehand so that typos are reported as errors.
Types ¶
type Issue ¶
type Issue struct {
TargetType findings.TargetType
TargetName string
Location *findings.Location
Evidence []string
// Severity overrides the rule's default severity when set.
Severity findings.Severity
// Confidence defaults to high when empty.
Confidence findings.Confidence
// Description overrides the rule's generic description when set.
Description string
// Remediation overrides the rule's generic remediation when set.
Remediation string
}
Issue is what a rule reports. Optional fields left at their zero value are filled from the rule's metadata when the engine builds the final finding.
type Metadata ¶
type Metadata struct {
ID string
Version string
Title string
Category findings.Category
Severity findings.Severity
Scope Scope
Description string
Rationale string
Remediation string
Detection string
Limitations string
References []string
}
Metadata describes a rule independently of its implementation. It is used to build findings and to render "stacksentry rules" output and docs.
func (Metadata) DocumentationURL ¶
DocumentationURL returns the link to the rule's reference entry.
type Registry ¶
type Registry[T any] struct { // contains filtered or unexported fields }
Registry holds the rules available for one scan scope.
func MustRegistry ¶
MustRegistry is like NewRegistry but panics on invalid built-in rules. It is intended for package-level initialization of compiled-in rule sets, whose validity is enforced by unit tests.
func NewRegistry ¶
NewRegistry validates the rules' metadata and indexes them by ID.
type Result ¶
type Result struct {
Findings []findings.Finding
Suppressed []SuppressedFinding
Evaluated []string
Errors []RuleError
}
Result is the outcome of evaluating a set of rules against one target.
type RunConfig ¶
type RunConfig struct {
ScannerVersion string
Now time.Time
// Suppress optionally reports whether a finding was suppressed by the
// scanned configuration itself, returning the documented reason.
Suppress func(findings.Finding) (reason string, suppressed bool)
}
RunConfig carries scan-wide values stamped onto every finding.
type Selection ¶
Selection restricts which rules run. Only, when non-empty, is an allow list; Exclude is applied afterwards and always wins.
type SkippedRule ¶
type SkippedRule struct {
RuleID string `json:"rule_id"`
Title string `json:"title"`
Reason string `json:"reason"`
}
SkippedRule records a rule that was not evaluated and why.
type SuppressedFinding ¶
type SuppressedFinding struct {
findings.Finding
SuppressionReason string `json:"suppression_reason"`
}
SuppressedFinding is a finding that matched an explicit, documented exception in the scanned configuration.