runtime

package
v0.1.0-alpha.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 12, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultMaxLineBytes = 1 << 20
	DefaultMaxEvents    = 1_000_000
)

Variables

This section is empty.

Functions

func ApplyBaseline

func ApplyBaseline(report *AuditReport, baseline io.Reader) error

func ApplySuppressions

func ApplySuppressions(report *AuditReport, source io.Reader, now time.Time) error

Types

type AgentSummary

type AgentSummary struct {
	AgentID          string         `json:"agent_id,omitempty"`
	AgentName        string         `json:"agent_name,omitempty"`
	EventCount       int            `json:"event_count"`
	SuccessfulEvents int            `json:"successful_events"`
	FailedEvents     int            `json:"failed_events"`
	WriteEvents      int            `json:"write_events"`
	FirstSeen        time.Time      `json:"first_seen"`
	LastSeen         time.Time      `json:"last_seen"`
	Targets          []string       `json:"targets,omitempty"`
	Environments     []string       `json:"environments,omitempty"`
	Operations       map[string]int `json:"operations,omitempty"`
	Providers        []string       `json:"providers,omitempty"`
}

type AuditReport

type AuditReport struct {
	SchemaVersion string    `json:"schema_version"`
	Runtime       Report    `json:"runtime"`
	MatchedAgents int       `json:"matched_agents"`
	Unmatched     int       `json:"unmatched_agents"`
	Findings      []Finding `json:"findings"`
}

func Audit

func Audit(runtimeReport Report, inventory scan.Report) AuditReport

func ReadAuditReport

func ReadAuditReport(path string) (AuditReport, error)

func (AuditReport) SARIF

func (r AuditReport) SARIF() ([]byte, error)

SARIF returns a deterministic SARIF 2.1.0 report for runtime findings.

type Diff

type Diff struct {
	SchemaVersion string    `json:"schema_version"`
	Added         []Finding `json:"added_findings"`
	Removed       []Finding `json:"removed_findings"`
	Unchanged     int       `json:"unchanged_findings"`
}

func DiffReports

func DiffReports(before, after AuditReport) Diff

func (Diff) CSV

func (d Diff) CSV() ([]byte, error)

func (Diff) HTML

func (d Diff) HTML() ([]byte, error)

type Event

type Event struct {
	Timestamp   time.Time `json:"timestamp"`
	RequestID   string    `json:"request_id,omitempty"`
	AgentID     string    `json:"agent_id,omitempty"`
	AgentName   string    `json:"agent_name,omitempty"`
	Environment string    `json:"environment,omitempty"`
	Operation   string    `json:"operation"`
	Target      string    `json:"target"`
	Provider    string    `json:"provider,omitempty"`
	Action      string    `json:"action,omitempty"`
	Success     bool      `json:"success"`
}

func ReadEvents

func ReadEvents(r io.Reader, options Options) ([]Event, int, error)

func ReadSource

func ReadSource(r io.Reader, source Source, options Options) ([]Event, int, error)

type Finding

type Finding struct {
	ID                   string   `json:"id"`
	RuleID               string   `json:"rule_id"`
	Severity             string   `json:"severity"`
	Message              string   `json:"message"`
	AgentID              string   `json:"agent_id,omitempty"`
	Confidence           float64  `json:"confidence"`
	Evidence             []string `json:"evidence,omitempty"`
	RemediationHint      string   `json:"remediation_hint"`
	Suppressed           bool     `json:"suppressed,omitempty"`
	SuppressionReason    string   `json:"suppression_reason,omitempty"`
	SuppressionExpiresAt string   `json:"suppression_expires_at,omitempty"`
}

type Options

type Options struct {
	MaxLineBytes int
	MaxEvents    int
}

type Report

type Report struct {
	SchemaVersion string         `json:"schema_version"`
	EventsRead    int            `json:"events_read"`
	EventsSkipped int            `json:"events_skipped"`
	Agents        []AgentSummary `json:"agents"`
}

func Aggregate

func Aggregate(events []Event, skipped int) Report

func AggregateReader

func AggregateReader(r io.Reader, options Options) (Report, error)

AggregateReader consumes JSONL one event at a time and does not retain the input events.

func AggregateSource

func AggregateSource(r io.Reader, source Source, options Options) (Report, error)

AggregateSource streams JSONL directly into an aggregate report. Structured adapter formats are normalized first because their envelope must be decoded.

type Source

type Source string
const (
	SourceJSONL      Source = "jsonl"
	SourceOTelJSON   Source = "otel-json"
	SourceAPIGateway Source = "api-gateway"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL