Documentation
¶
Overview ¶
Package config loads layered security policies. Project policy is additive only.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func PolicyPath ¶
func SetDefault ¶
Types ¶
type Config ¶
type Config struct {
Name string
StateDir string
Killswitch *Killswitch
Patterns []string
AllowRead []string
JevScoring bool
Mode string
Yolo bool
Injection Injection
Tests []Test
Asker interface {
Ask(context.Context, jev.Request) (*jev.Response, error)
}
}
func Builtin ¶
func Builtin(opts LoadOptions) (*Config, error)
Builtin has a small, conservative destructive-command blocklist. Scoring starts disabled because a Jev request on each hook adds latency.
func Load ¶
func Load(opts LoadOptions) (*Config, error)
func LoadForHook ¶
func LoadForHook(opts LoadOptions) (*Config, error)
LoadForHook keeps the embedded killswitch active when a local policy fails to load. The error is returned so the caller can record telemetry.
type Injection ¶
type Injection struct {
Mode string `yaml:"mode" json:"mode"`
Scan string `yaml:"scan" json:"scan"`
MaxBytes int `yaml:"max_bytes" json:"max_bytes"`
Tools []string `yaml:"tools" json:"tools"`
HeuristicHalt bool `yaml:"heuristic_halt" json:"heuristic_halt"`
HaltOn string `yaml:"halt_on" json:"halt_on"`
}
type Killswitch ¶
type Killswitch struct {
// contains filtered or unexported fields
}
func NewKillswitch ¶
func NewKillswitch(patterns []string) (*Killswitch, error)
type LoadOptions ¶
Click to show internal directories.
Click to hide internal directories.