Documentation
¶
Index ¶
Constants ¶
View Source
const ( DefaultMaxLineBytes = 1 << 20 DefaultMaxEvents = 1_000_000 )
Variables ¶
This section is empty.
Functions ¶
func ApplyBaseline ¶
func ApplyBaseline(report *AuditReport, baseline io.Reader) error
func ApplySuppressions ¶
Types ¶
type AgentSummary ¶
type AgentSummary struct {
AgentID string `json:"agent_id,omitempty"`
AgentName string `json:"agent_name,omitempty"`
EventCount int `json:"event_count"`
SuccessfulEvents int `json:"successful_events"`
FailedEvents int `json:"failed_events"`
WriteEvents int `json:"write_events"`
FirstSeen time.Time `json:"first_seen"`
LastSeen time.Time `json:"last_seen"`
Targets []string `json:"targets,omitempty"`
Environments []string `json:"environments,omitempty"`
Operations map[string]int `json:"operations,omitempty"`
Providers []string `json:"providers,omitempty"`
}
type AuditReport ¶
type AuditReport struct {
SchemaVersion string `json:"schema_version"`
Runtime Report `json:"runtime"`
MatchedAgents int `json:"matched_agents"`
Unmatched int `json:"unmatched_agents"`
Findings []Finding `json:"findings"`
}
func ReadAuditReport ¶
func ReadAuditReport(path string) (AuditReport, error)
func (AuditReport) SARIF ¶
func (r AuditReport) SARIF() ([]byte, error)
SARIF returns a deterministic SARIF 2.1.0 report for runtime findings.
type Diff ¶
type Diff struct {
SchemaVersion string `json:"schema_version"`
Added []Finding `json:"added_findings"`
Removed []Finding `json:"removed_findings"`
Unchanged int `json:"unchanged_findings"`
}
func DiffReports ¶
func DiffReports(before, after AuditReport) Diff
type Event ¶
type Event struct {
Timestamp time.Time `json:"timestamp"`
RequestID string `json:"request_id,omitempty"`
AgentID string `json:"agent_id,omitempty"`
AgentName string `json:"agent_name,omitempty"`
Environment string `json:"environment,omitempty"`
Operation string `json:"operation"`
Target string `json:"target"`
Provider string `json:"provider,omitempty"`
Action string `json:"action,omitempty"`
Success bool `json:"success"`
}
type Finding ¶
type Finding struct {
ID string `json:"id"`
RuleID string `json:"rule_id"`
Severity string `json:"severity"`
Message string `json:"message"`
AgentID string `json:"agent_id,omitempty"`
Confidence float64 `json:"confidence"`
Evidence []string `json:"evidence,omitempty"`
RemediationHint string `json:"remediation_hint"`
Suppressed bool `json:"suppressed,omitempty"`
SuppressionReason string `json:"suppression_reason,omitempty"`
SuppressionExpiresAt string `json:"suppression_expires_at,omitempty"`
}
type Report ¶
type Report struct {
SchemaVersion string `json:"schema_version"`
EventsRead int `json:"events_read"`
EventsSkipped int `json:"events_skipped"`
Agents []AgentSummary `json:"agents"`
}
func AggregateReader ¶
AggregateReader consumes JSONL one event at a time and does not retain the input events.
Click to show internal directories.
Click to hide internal directories.