meta

package
v1.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 11, 2026 License: MIT Imports: 1 Imported by: 0

Documentation

Overview

Package meta holds canonical project counts and verification-capability metadata published in the README banner, social-preview image, and docs.

These constants are the single source of truth for release metadata and registry/output counts. VerificationCapabilities is the separate source of truth for direct-live, context-required, format-only, and no-verifier capability counts:

  • Detectors and Verifiers are guarded at test time against the live registries (detector.All() / verifier.All()), so adding or removing one without updating the constant fails CI. See internal/detector/registry_count_test.go and cmd/stats_test.go.
  • Sources and OutputFormats change rarely and are golden values. They are not derived at runtime on purpose: the scan command also exposes a "repos" subcommand that is not a distinct source, and selectFormatter accepts fallback aliases, so neither maps cleanly to a count.

When any of these change, run `go generate ./...` to refresh the generated stat blocks in docs/assets/banner.html and site/assets/og.svg, then re-render their PNGs (the re-render command is in each asset's header).

Index

Constants

View Source
const (
	// Detectors is the number of compile-time registered secret detectors;
	// it must equal len(detector.All()).
	Detectors = 65

	// Verifiers is the number of registered verifiers; it must equal
	// len(verifier.All()).
	Verifiers = 54

	// Sources is the number of scan sources: filesystem, git, container image,
	// S3, GCS, and Slack.
	Sources = 6

	// OutputFormats is the number of output formats: json, sarif, csv, table,
	// and github.
	OutputFormats = 5

	// OutputFormatList is the canonical user-facing order and spelling used by
	// CLI help and documentation contracts.
	OutputFormatList = "json, sarif, csv, table, github"
)
View Source
const (
	// ReleaseVersion is the latest stable release published to users. Release
	// tooling still injects the running binary's exact build version; this value
	// owns static product surfaces such as the website footer and roadmap guards.
	ReleaseVersion = "v1.8.0"

	// ReleaseDate is the publication date of ReleaseVersion (ISO 8601).
	ReleaseDate = "2026-08-11"
)

Variables

This section is empty.

Functions

func IsOutputFormat added in v1.8.0

func IsOutputFormat(name string) bool

IsOutputFormat reports whether name is a canonical output format.

func OutputFormatNames added in v1.8.0

func OutputFormatNames() []string

OutputFormatNames returns the canonical output formats as a fresh slice.

Types

type CapabilityCounts added in v1.8.0

type CapabilityCounts struct {
	Live            int
	FormatOnly      int
	RequiresContext int
	None            int
}

CapabilityCounts summarizes the canonical manifest by verifier kind.

func VerificationCapabilityCounts added in v1.8.0

func VerificationCapabilityCounts() CapabilityCounts

VerificationCapabilityCounts returns the current category totals.

type EndpointClass added in v1.8.0

type EndpointClass string

EndpointClass describes how a verifier selects the endpoint that receives a credential. Values are closed and validated in tests so a typo cannot silently create a new routing contract.

const (
	EndpointNone                        EndpointClass = "none"
	EndpointOfflineFormat               EndpointClass = "offline_format"
	EndpointFixedProviderAPI            EndpointClass = "fixed_provider_api"
	EndpointFixedProviderSDK            EndpointClass = "fixed_provider_sdk"
	EndpointRegionalProviderAPI         EndpointClass = "regional_provider_api"
	EndpointBoundedRegionalProviderAPI  EndpointClass = "bounded_regional_provider_api"
	EndpointIssuerDerivedProviderAPI    EndpointClass = "issuer_derived_provider_api"
	EndpointDetectorContextProviderAPI  EndpointClass = "detector_context_provider_api"
	EndpointOperatorContextProviderAPI  EndpointClass = "operator_context_provider_api"
	EndpointCompanionContextProviderAPI EndpointClass = "companion_context_provider_api"
	EndpointCompanionContextFixedAPI    EndpointClass = "companion_context_fixed_provider_api"
	EndpointEmbeddedProviderURL         EndpointClass = "credential_embedded_provider_url"
)

type InactiveStatusContract added in v1.8.0

type InactiveStatusContract string

InactiveStatusContract identifies the exact class of evidence that may produce verified_inactive. It is deliberately distinct from EndpointClass.

const (
	InactiveNone                       InactiveStatusContract = "none"
	InactiveDefinitiveAuthRejection    InactiveStatusContract = "definitive_provider_auth_rejection"
	InactiveHTTP401Only                InactiveStatusContract = "http_401_only"
	InactiveAllRegionsHTTP401          InactiveStatusContract = "all_regions_http_401"
	InactiveRegionAppropriateRejection InactiveStatusContract = "region_appropriate_auth_rejection"
	InactiveProviderBodyRejection      InactiveStatusContract = "provider_body_auth_rejection"
	InactiveProviderSpecificRejection  InactiveStatusContract = "provider_specific_definitive_rejection"
	InactivePairedAuthRejection        InactiveStatusContract = "paired_credential_auth_rejection"
	InactiveTrustedInstanceHTTP401     InactiveStatusContract = "trusted_instance_http_401"
	InactiveTrustedIssuerHTTP401       InactiveStatusContract = "trusted_issuer_http_401"
	InactiveTrustedOriginHTTP401       InactiveStatusContract = "trusted_origin_http_401"
	InactiveTrustedOriginInvalid401    InactiveStatusContract = "trusted_origin_standard_invalid_token_401"
	InactiveTrustedOriginRejection     InactiveStatusContract = "trusted_origin_auth_rejection"
	InactiveTrustedSiteRejection       InactiveStatusContract = "trusted_site_auth_rejection"
	InactiveTrustedStoreHTTP401        InactiveStatusContract = "trusted_store_http_401"
	InactiveTrustedStoreRejection      InactiveStatusContract = "trusted_store_auth_rejection"
	InactiveTypedAuthenticationError   InactiveStatusContract = "typed_authentication_error"
)

type VerificationCapability added in v1.8.0

type VerificationCapability struct {
	DetectorID             string
	VerifierKind           VerifierKind
	RequiredContextFields  []string
	ProviderRegions        []string
	VerifiableSubtypes     []string
	UnverifiableSubtypes   []string
	EndpointClass          EndpointClass
	InactiveStatusContract InactiveStatusContract
	LastContractReviewedAt string
	ContractReferenceURLs  []string
}

VerificationCapability is the canonical machine-readable contract for one built-in detector. Empty ProviderRegions means the provider exposes one global endpoint class or the region is encoded by trusted credential context. LastContractReviewedAt and ContractReferenceURLs are intentionally empty until the provider contract has been checked against current primary documentation; an empty value must never be presented as a completed audit.

func VerificationCapabilities added in v1.8.0

func VerificationCapabilities() []VerificationCapability

VerificationCapabilities returns a deep copy so callers cannot mutate the canonical manifest or any of its context/region slices.

type VerifierKind added in v1.8.0

type VerifierKind string

VerifierKind describes what a detector can truthfully prove in the normal production pipeline. It is deliberately independent of registry presence: a registered verifier may still need context the detector cannot supply, or may perform only offline format validation.

const (
	VerifierLive            VerifierKind = "live"
	VerifierFormatOnly      VerifierKind = "format_only"
	VerifierRequiresContext VerifierKind = "requires_context"
	VerifierNone            VerifierKind = "none"
)

Directories

Path Synopsis
Command releasecheck rejects malformed release tags and prevents a stable tag from publishing artifacts whose metadata still names another release.
Command releasecheck rejects malformed release tags and prevents a stable tag from publishing artifacts whose metadata still names another release.
Command statsgen rewrites the project's marketing-asset stat blocks from the canonical counts in internal/meta.
Command statsgen rewrites the project's marketing-asset stat blocks from the canonical counts in internal/meta.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL