Documentation
¶
Overview ¶
Package report builds the scan report model and renders it as a terminal table, JSON or Markdown.
Index ¶
- Constants
- func EscapeMarkdown(s string) string
- func Redact(r *Report, values []string, mask string)
- func Render(w io.Writer, r *Report, opts RenderOptions) error
- func RenderJSON(w io.Writer, r *Report) error
- func RenderMarkdown(w io.Writer, r *Report) error
- func RenderTable(w io.Writer, r *Report, opts TableOptions) error
- func WriteFile(path string, r *Report, opts RenderOptions) (err error)
- type ComposeTarget
- type Format
- type HostTarget
- type Input
- type Options
- type RenderOptions
- type Report
- type Scan
- type ScanType
- type Scanner
- type Summary
- type TableOptions
- type Target
Constants ¶
const ( ResultPass = "pass" ResultFail = "fail" ResultNoThreshold = "no_threshold" )
Result values of a scan with respect to --fail-on.
const DefaultWidth = 100
DefaultWidth is the line width the table renderer wraps text to.
const SchemaVersion = "1.0.0"
SchemaVersion is the version of the JSON report schema. It follows semantic versioning: additive changes bump the minor version, breaking changes the major version.
Variables ¶
This section is empty.
Functions ¶
func EscapeMarkdown ¶
EscapeMarkdown escapes characters that Markdown would interpret, so that free text renders literally.
func Redact ¶
Redact replaces every occurrence of the given sensitive values in all report text derived from the scanned configuration with mask. It is a defense in depth: rules are written never to include secret values in the first place. Constant rule texts (title, why it matters) are left intact.
func Render ¶
func Render(w io.Writer, r *Report, opts RenderOptions) error
Render writes the report in the requested format.
func RenderJSON ¶
RenderJSON writes the report as indented JSON followed by a newline. The structure is documented in docs/json-report.md and docs/report.schema.json.
func RenderMarkdown ¶
RenderMarkdown writes a self-contained Markdown report suitable for issues, change requests and audit documentation.
func RenderTable ¶
func RenderTable(w io.Writer, r *Report, opts TableOptions) error
RenderTable writes the human-readable terminal report.
func WriteFile ¶
func WriteFile(path string, r *Report, opts RenderOptions) (err error)
WriteFile renders the report and writes it to path atomically: the content is written to a temporary file in the same directory and renamed into place, so readers never observe a partially written report. The file is created with mode 0600 because reports describe infrastructure details.
Types ¶
type ComposeTarget ¶
type ComposeTarget struct {
Files []string `json:"files"`
ProjectName string `json:"project_name"`
ServiceCount int `json:"service_count"`
Services []string `json:"services"`
}
ComposeTarget holds metadata about a scanned Compose project.
type Format ¶
type Format string
Format is an output format.
const ( FormatTable Format = "table" FormatJSON Format = "json" FormatMarkdown Format = "markdown" )
Supported formats.
func ParseFormat ¶
ParseFormat validates a user supplied format name.
type HostTarget ¶
type HostTarget struct {
Endpoint string `json:"endpoint"`
ServerVersion string `json:"server_version"`
APIVersion string `json:"api_version"`
OperatingSystem string `json:"operating_system"`
OSType string `json:"os_type"`
Architecture string `json:"architecture"`
ContainersTotal int `json:"containers_total"`
ContainersRunning int `json:"containers_running"`
Images int `json:"images"`
}
HostTarget holds metadata about a scanned Docker host.
type Input ¶
type Input struct {
Scanner Scanner
ScanType ScanType
StartedAt time.Time
FinishedAt time.Time
RulesTotal int
Result engine.Result
SkippedRules []engine.SkippedRule
Target Target
Limitations []string
Warnings []string
MinSeverity findings.Severity
FailOn *findings.Severity
Only []string
Exclude []string
}
Input collects everything needed to build a report.
type Options ¶
type Options struct {
MinSeverity findings.Severity `json:"min_severity"`
FailOn *findings.Severity `json:"fail_on"`
Only []string `json:"only"`
Exclude []string `json:"exclude"`
}
Options records the user options that influenced the report.
type RenderOptions ¶
type RenderOptions struct {
Format Format
Table TableOptions
}
RenderOptions controls rendering for all formats.
type Report ¶
type Report struct {
SchemaVersion string `json:"schema_version"`
Scanner Scanner `json:"scanner"`
Scan Scan `json:"scan"`
Target Target `json:"target"`
Summary Summary `json:"summary"`
Findings []findings.Finding `json:"findings"`
Suppressed []engine.SuppressedFinding `json:"suppressed_findings"`
SkippedRules []engine.SkippedRule `json:"skipped_rules"`
Limitations []string `json:"limitations"`
Warnings []string `json:"warnings"`
}
Report is the complete, renderer-independent result of a scan.
type Scan ¶
type Scan struct {
Type ScanType `json:"type"`
StartedAt time.Time `json:"started_at"`
FinishedAt time.Time `json:"finished_at"`
RulesTotal int `json:"rules_total"`
RulesEvaluated int `json:"rules_evaluated"`
Options Options `json:"options"`
}
Scan holds scan metadata.
type Scanner ¶
type Scanner struct {
Name string `json:"name"`
Version string `json:"version"`
Commit string `json:"commit,omitempty"`
}
Scanner identifies the tool that produced the report.
type Summary ¶
type Summary struct {
// Total counts all findings produced by the evaluated rules, including
// findings hidden from the report by --severity.
Total int `json:"total"`
BySeverity findings.Counts `json:"by_severity"`
Displayed int `json:"displayed"`
// HiddenBelowMinSeverity counts findings omitted by --severity.
HiddenBelowMinSeverity int `json:"hidden_below_min_severity"`
// Suppressed counts findings matched by x-stacksentry exceptions; they
// are not part of Total and never trigger --fail-on.
Suppressed int `json:"suppressed"`
// FailOn is the --fail-on threshold, if any.
FailOn *findings.Severity `json:"fail_on"`
// AtOrAboveFailOn counts findings that meet the threshold, including
// findings hidden by --severity.
AtOrAboveFailOn int `json:"at_or_above_fail_on"`
Result string `json:"result"`
}
Summary aggregates the findings of a scan.
type TableOptions ¶
type TableOptions struct {
// Color enables ANSI colors. Callers enable it only for terminals.
Color bool
// Quiet prints only the findings, without header, notes or result.
Quiet bool
// Width is the wrapping width; DefaultWidth is used when zero.
Width int
}
TableOptions controls terminal rendering.
type Target ¶
type Target struct {
Type ScanType `json:"type"`
Name string `json:"name"`
Compose *ComposeTarget `json:"compose,omitempty"`
Host *HostTarget `json:"host,omitempty"`
}
Target describes what was scanned.