internal/

directory
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 2, 2026 License: MIT

Directories

Path Synopsis
Package cli wires the cavet command surface (cli-spec §5).
Package cli wires the cavet command surface (cli-spec §5).
Package config loads and validates .cavet/config.yaml (artefacts-spec.md §4).
Package config loads and validates .cavet/config.yaml (artefacts-spec.md §4).
Package describe emits the machine contract for third-party installers: skill paths, subagent allowlists, trigger commands, engine digest, version metadata (cli-spec §12).
Package describe emits the machine contract for third-party installers: skill paths, subagent allowlists, trigger commands, engine digest, version metadata (cli-spec §12).
Package engineclient owns the long-lived cavet-engine container for one repository: lifecycle, exec plumbing, report copy-out, and path translation (cli-spec §10).
Package engineclient owns the long-lived cavet-engine container for one repository: lifecycle, exec plumbing, report copy-out, and path translation (cli-spec §10).
Package events owns every shape in the cavet log: constants, payload structs, validating constructors, and the canonical encoding.
Package events owns every shape in the cavet log: constants, payload structs, validating constructors, and the canonical encoding.
Package fingerprint owns finding identity: rule keys, context normalisation, and hashing (SPECIFICATION.md §3.3, artefacts-spec.md §5).
Package fingerprint owns finding identity: rule keys, context normalisation, and hashing (SPECIFICATION.md §3.3, artefacts-spec.md §5).
Package lookup answers identifier-only queries against allowlisted advisory sources (spec §5.3).
Package lookup answers identifier-only queries against allowlisted advisory sources (spec §5.3).
Package output renders cavet's normative result blocks: markdown tables with an aggregate line and next-step hints, golden-tested against spec §4.1 (cli-spec §9).
Package output renders cavet's normative result blocks: markdown tables with an aggregate line and next-step hints, golden-tested against spec §4.1 (cli-spec §9).
Package projection parses scanner SARIF into a finding model, normalises severities, and merges across scanners with pre-fingerprint secret collapse (cli-spec §§7–9; SPECIFICATION.md §3.3, §4).
Package projection parses scanner SARIF into a finding model, normalises severities, and merges across scanners with pre-fingerprint secret collapse (cli-spec §§7–9; SPECIFICATION.md §3.3, §4).
Package scan orchestrates one scan: scope resolution and staging inside the engine container, scanner invocation contracts, SARIF projection, and the delta fold against state (cli-spec §§6–8).
Package scan orchestrates one scan: scope resolution and staging inside the engine container, scanner invocation contracts, SARIF projection, and the delta fold against state (cli-spec §§6–8).
Package store owns the .cavet artefact directory: scaffolding, the repo lock, log append/read, replay, and atomic state writes (artefacts-spec.md §§1, 6, 7).
Package store owns the .cavet artefact directory: scaffolding, the repo lock, log append/read, replay, and atomic state writes (artefacts-spec.md §§1, 6, 7).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL