Documentation
¶
Overview ¶
Package meta holds canonical project counts and verification-capability metadata published in the README banner, social-preview image, and docs.
These constants are the single source of truth for release metadata and registry/output counts. VerificationCapabilities is the separate source of truth for direct-live, context-required, format-only, and no-verifier capability counts:
- Detectors and Verifiers are guarded at test time against the live registries (detector.All() / verifier.All()), so adding or removing one without updating the constant fails CI. See internal/detector/registry_count_test.go and cmd/stats_test.go.
- Sources and OutputFormats change rarely and are golden values. They are not derived at runtime on purpose: the scan command also exposes a "repos" subcommand that is not a distinct source, and selectFormatter accepts fallback aliases, so neither maps cleanly to a count.
When any of these change, run `go generate ./...` to refresh the generated stat blocks in docs/assets/banner.html and site/assets/og.svg, then re-render their PNGs (the re-render command is in each asset's header).
Index ¶
Constants ¶
const ( // Detectors is the number of compile-time registered secret detectors; // it must equal len(detector.All()). Detectors = 65 // Verifiers is the number of registered verifiers; it must equal // len(verifier.All()). Verifiers = 54 // Sources is the number of scan sources: filesystem, git, container image, // S3, GCS, and Slack. Sources = 6 // OutputFormats is the number of output formats: json, sarif, csv, table, // and github. OutputFormats = 5 // OutputFormatList is the canonical user-facing order and spelling used by // CLI help and documentation contracts. OutputFormatList = "json, sarif, csv, table, github" )
const ( // ReleaseVersion is the latest stable release published to users. Release // tooling still injects the running binary's exact build version; this value // owns static product surfaces such as the website footer and roadmap guards. ReleaseVersion = "v1.8.0" // ReleaseDate is the publication date of ReleaseVersion (ISO 8601). ReleaseDate = "2026-08-11" )
Variables ¶
This section is empty.
Functions ¶
func IsOutputFormat ¶ added in v1.8.0
IsOutputFormat reports whether name is a canonical output format.
func OutputFormatNames ¶ added in v1.8.0
func OutputFormatNames() []string
OutputFormatNames returns the canonical output formats as a fresh slice.
Types ¶
type CapabilityCounts ¶ added in v1.8.0
CapabilityCounts summarizes the canonical manifest by verifier kind.
func VerificationCapabilityCounts ¶ added in v1.8.0
func VerificationCapabilityCounts() CapabilityCounts
VerificationCapabilityCounts returns the current category totals.
type EndpointClass ¶ added in v1.8.0
type EndpointClass string
EndpointClass describes how a verifier selects the endpoint that receives a credential. Values are closed and validated in tests so a typo cannot silently create a new routing contract.
const ( EndpointNone EndpointClass = "none" EndpointOfflineFormat EndpointClass = "offline_format" EndpointFixedProviderAPI EndpointClass = "fixed_provider_api" EndpointFixedProviderSDK EndpointClass = "fixed_provider_sdk" EndpointRegionalProviderAPI EndpointClass = "regional_provider_api" EndpointBoundedRegionalProviderAPI EndpointClass = "bounded_regional_provider_api" EndpointIssuerDerivedProviderAPI EndpointClass = "issuer_derived_provider_api" EndpointDetectorContextProviderAPI EndpointClass = "detector_context_provider_api" EndpointOperatorContextProviderAPI EndpointClass = "operator_context_provider_api" EndpointCompanionContextProviderAPI EndpointClass = "companion_context_provider_api" EndpointCompanionContextFixedAPI EndpointClass = "companion_context_fixed_provider_api" EndpointEmbeddedProviderURL EndpointClass = "credential_embedded_provider_url" )
type InactiveStatusContract ¶ added in v1.8.0
type InactiveStatusContract string
InactiveStatusContract identifies the exact class of evidence that may produce verified_inactive. It is deliberately distinct from EndpointClass.
const ( InactiveNone InactiveStatusContract = "none" InactiveDefinitiveAuthRejection InactiveStatusContract = "definitive_provider_auth_rejection" InactiveHTTP401Only InactiveStatusContract = "http_401_only" InactiveAllRegionsHTTP401 InactiveStatusContract = "all_regions_http_401" InactiveRegionAppropriateRejection InactiveStatusContract = "region_appropriate_auth_rejection" InactiveProviderBodyRejection InactiveStatusContract = "provider_body_auth_rejection" InactiveProviderSpecificRejection InactiveStatusContract = "provider_specific_definitive_rejection" InactivePairedAuthRejection InactiveStatusContract = "paired_credential_auth_rejection" InactiveTrustedInstanceHTTP401 InactiveStatusContract = "trusted_instance_http_401" InactiveTrustedIssuerHTTP401 InactiveStatusContract = "trusted_issuer_http_401" InactiveTrustedOriginHTTP401 InactiveStatusContract = "trusted_origin_http_401" InactiveTrustedOriginInvalid401 InactiveStatusContract = "trusted_origin_standard_invalid_token_401" InactiveTrustedOriginRejection InactiveStatusContract = "trusted_origin_auth_rejection" InactiveTrustedSiteRejection InactiveStatusContract = "trusted_site_auth_rejection" InactiveTrustedStoreHTTP401 InactiveStatusContract = "trusted_store_http_401" InactiveTrustedStoreRejection InactiveStatusContract = "trusted_store_auth_rejection" InactiveTypedAuthenticationError InactiveStatusContract = "typed_authentication_error" )
type VerificationCapability ¶ added in v1.8.0
type VerificationCapability struct {
DetectorID string
VerifierKind VerifierKind
RequiredContextFields []string
ProviderRegions []string
VerifiableSubtypes []string
UnverifiableSubtypes []string
EndpointClass EndpointClass
InactiveStatusContract InactiveStatusContract
LastContractReviewedAt string
ContractReferenceURLs []string
}
VerificationCapability is the canonical machine-readable contract for one built-in detector. Empty ProviderRegions means the provider exposes one global endpoint class or the region is encoded by trusted credential context. LastContractReviewedAt and ContractReferenceURLs are intentionally empty until the provider contract has been checked against current primary documentation; an empty value must never be presented as a completed audit.
func VerificationCapabilities ¶ added in v1.8.0
func VerificationCapabilities() []VerificationCapability
VerificationCapabilities returns a deep copy so callers cannot mutate the canonical manifest or any of its context/region slices.
type VerifierKind ¶ added in v1.8.0
type VerifierKind string
VerifierKind describes what a detector can truthfully prove in the normal production pipeline. It is deliberately independent of registry presence: a registered verifier may still need context the detector cannot supply, or may perform only offline format validation.
const ( VerifierLive VerifierKind = "live" VerifierFormatOnly VerifierKind = "format_only" VerifierRequiresContext VerifierKind = "requires_context" VerifierNone VerifierKind = "none" )
Directories
¶
| Path | Synopsis |
|---|---|
|
Command releasecheck rejects malformed release tags and prevents a stable tag from publishing artifacts whose metadata still names another release.
|
Command releasecheck rejects malformed release tags and prevents a stable tag from publishing artifacts whose metadata still names another release. |
|
Command statsgen rewrites the project's marketing-asset stat blocks from the canonical counts in internal/meta.
|
Command statsgen rewrites the project's marketing-asset stat blocks from the canonical counts in internal/meta. |