usecase/

directory
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0

Directories

Path Synopsis
Package accuracyeval loads an embedded golden corpus of labeled detection cases and reduces the owned engine's produced-vs-expected results to detection-accuracy metrics (precision, recall, false-discovery / false-negative rates), overall and per ecosystem group.
Package accuracyeval loads an embedded golden corpus of labeled detection cases and reduces the owned engine's produced-vs-expected results to detection-accuracy metrics (precision, recall, false-discovery / false-negative rates), overall and per ecosystem group.
Package advisoryingest loads the owned normalized-advisory store from a bulk feed.
Package advisoryingest loads the owned normalized-advisory store from a bulk feed.
Package agenttools is the agent's tool catalog: the bounded set of capabilities the LLM is allowed to invoke.
Package agenttools is the agent's tool catalog: the bounded set of capabilities the LLM is allowed to invoke.
Package aitriagereviewuc implements the durable human-review workflow for AI false-positive recommendations held back by the deterministic policy.
Package aitriagereviewuc implements the durable human-review workflow for AI false-positive recommendations held back by the deterministic policy.
Package alerting turns platform events a defender must act on into delivered notifications.
Package alerting turns platform events a defender must act on into delivered notifications.
Package analysis runs the evidence-gated lifecycle for AI "judgments" – the generalized twin of the exploitation gate.
Package analysis runs the evidence-gated lifecycle for AI "judgments" – the generalized twin of the exploitation gate.
Package approval is the Human-In-The-Loop gate for AI-proposed actions.
Package approval is the Human-In-The-Loop gate for AI-proposed actions.
Package assetuc is the use-case layer for the fleet asset model (#431, epic #405).
Package assetuc is the use-case layer for the fleet asset model (#431, epic #405).
Package attackpath assembles tenant-scoped attack paths from existing records.
Package attackpath assembles tenant-scoped attack paths from existing records.
Package audit is the read/verify use case over the append-only audit log.
Package audit is the read/verify use case over the append-only audit log.
Package aup (use case) implements first-run Acceptable-Use-Policy logic.
Package aup (use case) implements first-run Acceptable-Use-Policy logic.
Package benchagg aggregates the per-dimension accuracy results of the owned scanner benchmark dimensions (secrets, IaC/misconfiguration, DAST, CSPM, runtime host-CVE, SAST per-CWE) into one machine-readable report WITHOUT erasing per-dimension semantics.
Package benchagg aggregates the per-dimension accuracy results of the owned scanner benchmark dimensions (secrets, IaC/misconfiguration, DAST, CSPM, runtime host-CVE, SAST per-CWE) into one machine-readable report WITHOUT erasing per-dimension semantics.
Package benchmark reduces fixture-supplied benchmark observations into a deterministic, versioned report.
Package benchmark reduces fixture-supplied benchmark observations into a deterministic, versioned report.
Package capabilities answers one product question: which optional subsystems are switched on in this deployment, and which SYNAPSE_* variable switches each one.
Package capabilities answers one product question: which optional subsystems are switched on in this deployment, and which SYNAPSE_* variable switches each one.
Package chainrehearsal drives a governed exploitation chain as a no-host SIMULATION.
Package chainrehearsal drives a governed exploitation chain as a no-host SIMULATION.
Package codequality assembles the code-quality findings for a source tree: it runs the deterministic maintainability/reliability rule engine and layers on the metric-derived signals (duplication, and complexity when an AST backend is available), mapping everything to first-party finding.Finding values (Kind=quality/reliability, ungated, publishable like SAST).
Package codequality assembles the code-quality findings for a source tree: it runs the deterministic maintainability/reliability rule engine and layers on the metric-derived signals (duplication, and complexity when an AST backend is available), mapping everything to first-party finding.Finding values (Kind=quality/reliability, ungated, publishable like SAST).
Package cqbench defines the deterministic code-quality accuracy corpus contract and its regression ratchet, and reduces an engine's detections into a per-language, per-issue-type precision/recall scorecard plus a metric-agreement section.
Package cqbench defines the deterministic code-quality accuracy corpus contract and its regression ratchet, and reduces an engine's detections into a per-language, per-issue-type precision/recall scorecard plus a metric-agreement section.
Package credentials is the management use case over the credential vault (secrets never enter logs): an operator stores per-engagement secrets (write-only) and lists or deletes them by NAME.
Package credentials is the management use case over the credential vault (secrets never enter logs): an operator stores per-engagement secrets (write-only) and lists or deletes them by NAME.
Package crosscheckjudge turns cross-check DISAGREEMENTS into Judgments for human review.
Package crosscheckjudge turns cross-check DISAGREEMENTS into Judgments for human review.
Package cspm orchestrates read-only live cloud posture scans.
Package cspm orchestrates read-only live cloud posture scans.
Package curatedsinks bridges the curated vulnerable-methods DB (advisory.CuratedSymbols) into the taint engine: each CONFIRMED curated vulnerable API becomes a taint sink, so the dataflow engine proves attacker input reaches that exact function (EPIC #1042 2.2, the curated moat).
Package curatedsinks bridges the curated vulnerable-methods DB (advisory.CuratedSymbols) into the taint engine: each CONFIRMED curated vulnerable API becomes a taint sink, so the dataflow engine proves attacker input reaches that exact function (EPIC #1042 2.2, the curated moat).
Package dastcrawl derives a bounded, deterministic HTTP surface from authenticated observations.
Package dastcrawl derives a bounded, deterministic HTTP surface from authenticated observations.
Package dastrun turns a governed DAST verification probe from a synchronous request-thread execution into a durable, lease-executed job.
Package dastrun turns a governed DAST verification probe from a synchronous request-thread execution into a durable, lease-executed job.
Package dastrunner executes narrowly-scoped, approved runtime verification probes.
Package dastrunner executes narrowly-scoped, approved runtime verification probes.
Package dastsession executes approved, authenticated DAST request batches.
Package dastsession executes approved, authenticated DAST request batches.
Package dastverifier ingests runtime-verifier results for AppSec findings.
Package dastverifier ingests runtime-verifier results for AppSec findings.
Package dastworkflow coordinates the governed DAST verification lifecycle.
Package dastworkflow coordinates the governed DAST verification lifecycle.
Package egress compiles an engagement scope into a default-deny egress policy: the concrete set of {destination, ports} a sandboxed tool may reach.
Package egress compiles an engagement scope into a default-deny egress policy: the concrete set of {destination, ports} a sandboxed tool may reach.
Package egressgrant authorizes short-lived, process-bound egress grants from authoritative execution and engagement state.
Package egressgrant authorizes short-lived, process-bound egress grants from authoritative execution and engagement state.
Package emulation runs adversary emulation (issue #421) as a SUBSET of the exploitation machine's guarantees, never a looser path.
Package emulation runs adversary emulation (issue #421) as a SUBSET of the exploitation machine's guarantees, never a looser path.
Package engagement (use case) implements engagement application logic.
Package engagement (use case) implements engagement application logic.
Package enginecompare produces an honest differential between two vulnerability detection engines run over the SAME SBOM: which (component, CVE) pairs each engine found, and specifically what the candidate (the owned Synapse engine) found that a baseline competitor (e.g.
Package enginecompare produces an honest differential between two vulnerability detection engines run over the SAME SBOM: which (component, CVE) pairs each engine found, and specifically what the candidate (the owned Synapse engine) found that a baseline competitor (e.g.
Package evidence is the tamper-evident evidence vault: it appends sealed, hash-chained links, stores artifacts content-addressed in a blob store, and verifies the chain on read – emitting an append-only tamper ALERT on any mismatch.
Package evidence is the tamper-evident evidence vault: it appends sealed, hash-chained links, stores artifacts content-addressed in a blob store, and verifies the chain on read – emitting an append-only tamper ALERT on any mismatch.
Package execution holds the shared server-side execution guard: engagement scope + legal authorization-window enforcement with append-only audit, applied BEFORE any tool runs.
Package execution holds the shared server-side execution guard: engagement scope + legal authorization-window enforcement with append-only audit, applied BEFORE any tool runs.
Package exploitation is the evidence-gated lifecycle for AI/exploitation findings.
Package exploitation is the evidence-gated lifecycle for AI/exploitation findings.
Package export builds deterministic SARIF 2.1.0 + OpenVEX documents from stored findings.
Package export builds deterministic SARIF 2.1.0 + OpenVEX documents from stored findings.
Package findings handles the human findings workflow: manual authoring, triage status transitions (with optimistic concurrency), assignment, and the persisted comment thread.
Package findings handles the human findings workflow: manual authoring, triage status transitions (with optimistic concurrency), assignment, and the persisted comment thread.
fleet
baselineuc
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
behaviorbaseline
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
clusterinventory
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
correlationuc
Package correlationuc orchestrates durable, two-phase event-time correlation.
Package correlationuc orchestrates durable, two-phase event-time correlation.
coverage
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
coveragewindow
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
desired
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
detect
Package detect is the agent-side detection engine (issue #422, phase 3).
Package detect is the agent-side detection engine (issue #422, phase 3).
detectionship
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
detectledger
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
endpointstate
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
exposurereader
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
exposureuc
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
hostinventory
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
hostvuln
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
incidenttriage
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
incidentuc
Package incidentuc is the usecase seam over the event-sourced incident store.
Package incidentuc is the usecase seam over the event-sourced incident store.
keyregistry
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
legalholduc
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
normalize
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
privacyexport
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
privacypolicy
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
processreport
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
responseexecute
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
responseobservation
Package responseobservation runs the endpoint-side, independent response-observation workflow.
Package responseobservation runs the endpoint-side, independent response-observation workflow.
responseobserver
Package responseobserver governs secondary agents that may observe response post-conditions.
Package responseobserver governs secondary agents that may observe response post-conditions.
responseverificationingest
Package responseverificationingest authenticates and persists purpose-signed response observations.
Package responseverificationingest authenticates and persists purpose-signed response observations.
retrohunt
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
riskscorebridge
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
riskscoreuc
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
runtimeevidence
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
telemetry
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
telemetryingest
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
Package fleetagentuc is the use-case layer for fleet agent identity (#409, epic #405): an operator mints a single-use enrolment token; an agent exchanges it for a long-lived bearer credential; the API authenticates every subsequent call by that credential.
Package fleetagentuc is the use-case layer for fleet agent identity (#409, epic #405): an operator mints a single-use enrolment token; an agent exchanges it for a long-lived bearer credential; the API authenticates every subsequent call by that credential.
Package fleetrolloutuc is the operator-facing lifecycle of an agent update rollout: set a target, promote it past the canary, pause it, resume it, and answer what one agent should be offered.
Package fleetrolloutuc is the operator-facing lifecycle of an agent update rollout: set a target, promote it past the canary, pause it, resume it, and answer what one agent should be offered.
Package fleetwork is the use-case layer for the fleet work order lifecycle (#407, epic #405): issue a signed, addressed, authorised order; let an agent claim orders addressed to it; and drive orders through the validated state machine.
Package fleetwork is the use-case layer for the fleet work order lifecycle (#407, epic #405): issue a signed, addressed, authorised order; let an agent claim orders addressed to it; and drive orders through the validated state machine.
Package fptriage runs an LLM-assisted false-positive critique over safe-to-transmit first-party source-analysis findings (SAST and misconfig).
Package fptriage runs an LLM-assisted false-positive critique over safe-to-transmit first-party source-analysis findings (SAST and misconfig).
Package gobinsubject encodes a version-bound Go affected-symbol query for binary reachability.
Package gobinsubject encodes a version-bound Go affected-symbol query for binary reachability.
Package hotspots contains Project Security Hotspot projection use cases.
Package hotspots contains Project Security Hotspot projection use cases.
Package identitybff orchestrates the OIDC browser flow without exposing provider credentials to HTTP handlers.
Package identitybff orchestrates the OIDC browser flow without exposing provider credentials to HTTP handlers.
Package identityuc manages secure persistence primitives for OIDC login and opaque sessions.
Package identityuc manages secure persistence primitives for OIDC login and opaque sessions.
Package integrations orchestrates provider-neutral CI/CD integrations.
Package integrations orchestrates provider-neutral CI/CD integrations.
Package issues contains Project code-quality issue projection use cases.
Package issues contains Project code-quality issue projection use cases.
Package jsreach implements deterministic Tier-1 reachability for npm components: does first-party JavaScript or TypeScript source actually import a given package?
Package jsreach implements deterministic Tier-1 reachability for npm components: does first-party JavaScript or TypeScript source actually import a given package?
Package leaderuc runs leader election over a fenced lease (#406, epic #405) so more than one control-plane instance can run while exactly one is the scheduler leader at a time.
Package leaderuc runs leader election over a fenced lease (#406, epic #405) so more than one control-plane instance can run while exactly one is the scheduler leader at a time.
Package llmverifier is the automated LLM judgment-verifier: it makes SYNAPSE_VERIFIER_MODEL live on the server.
Package llmverifier is the automated LLM judgment-verifier: it makes SYNAPSE_VERIFIER_MODEL live on the server.
Package notification provides tenant-scoped notification administration, durable publication, and worker delivery orchestration.
Package notification provides tenant-scoped notification administration, durable publication, and worker delivery orchestration.
Package nugetreach is the build-aware .NET reachability analyzer.
Package nugetreach is the build-aware .NET reachability analyzer.
Package offensivepolicy enforces the offensive governance policy (docs/redteam/offensive-policy.md, issue #418) before an offensive action is admitted.
Package offensivepolicy enforces the offensive governance policy (docs/redteam/offensive-policy.md, issue #418) before an offensive action is admitted.
Package orchestrator is the AI orchestrator – the typed Go state machine that owns control flow.
Package orchestrator is the AI orchestrator – the typed Go state machine that owns control flow.
Package ownership exposes tenant-bound ownership administration and human triage.
Package ownership exposes tenant-bound ownership administration and human triage.
Package ports defines application boundaries.
Package ports defines application boundaries.
Package projectuc implements project application logic.
Package projectuc implements project application logic.
Package promotion implements the use-case layer for deterministic finding-priority promotion.
Package promotion implements the use-case layer for deterministic finding-priority promotion.
Package purplecoverage is the control plane that closes the purple loop (#426): it joins the offensive half of the ledger (an emulation.Run's per-technique coverage records — what each technique executed and EXPECTED to be detected, #421) with the defensive half (the detections that ACTUALLY fired on the same asset in the run window, #422/#423) and resolves a per-technique coverage verdict through the pure domain.
Package purplecoverage is the control plane that closes the purple loop (#426): it joins the offensive half of the ledger (an emulation.Run's per-technique coverage records — what each technique executed and EXPECTED to be detected, #421) with the defensive half (the detections that ACTUALLY fired on the same asset in the run window, #422/#423) and resolves a per-technique coverage verdict through the pure domain.
Package purpleteam orchestrates a governed adversary-emulation run and turns it into purple-team coverage.
Package purpleteam orchestrates a governed adversary-emulation run and turns it into purple-team coverage.
Package pyreach answers Tier-1 Python reachability by IMPORT: a vulnerable PyPI package is "reachable" iff first-party code imports it.
Package pyreach answers Tier-1 Python reachability by IMPORT: a vulnerable PyPI package is "reachable" iff first-party code imports it.
Package qualitygates manages tenant-scoped quality-gate definitions.
Package qualitygates manages tenant-scoped quality-gate definitions.
Package qualityprofiles manages named, per-language quality profiles: built-in defaults generated from the rule catalog plus tenant-scoped custom copies, and their per-project assignment.
Package qualityprofiles manages named, per-language quality profiles: built-in defaults generated from the rule catalog plus tenant-scoped custom copies, and their per-project assignment.
Package reachability is the Tier-2 reachability query API: it wraps a ports.CallGraphBuilder + the deterministic callgraph domain queries into the service consumers use to turn "is this vulnerable symbol actually called?" into an evidence-backed reachability judgment.
Package reachability is the Tier-2 reachability query API: it wraps a ports.CallGraphBuilder + the deterministic callgraph domain queries into the service consumers use to turn "is this vulnerable symbol actually called?" into an evidence-backed reachability judgment.
Package reachbench defines the deterministic reachability accuracy corpus contract and its recall ratchet.
Package reachbench defines the deterministic reachability accuracy corpus contract and its recall ratchet.
Package reachproof is the coordinator that turns a deterministic reachability result into a CONFIRMED reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package reachproof is the coordinator that turns a deterministic reachability result into a CONFIRMED reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package recon orchestrates reconnaissance runs.
Package recon orchestrates reconnaissance runs.
Package report generates an engagement's report from stored data and seals it with a SHA-256 (chain-of-custody).
Package report generates an engagement's report from stored data and seals it with a SHA-256 (chain-of-custody).
Package response applies governed defensive response actions (issue #425): isolate a host, quarantine a file, stop a process.
Package response applies governed defensive response actions (issue #425): isolate a host, quarantine a file, stop a process.
Package restoreverify verifies the read-only integrity surface of a restored deployment: evidence chains and their content-addressed objects, the global audit chain, and applied migration metadata.
Package restoreverify verifies the read-only integrity surface of a restored deployment: evidence chains and their content-addressed objects, the global audit chain, and applied migration metadata.
Package riskstoryuc is the read-model assembler for the unified per-asset risk story (issue #427).
Package riskstoryuc is the read-model assembler for the unified per-asset risk story (issue #427).
Package rulepack evaluates deterministic release evidence for signed detection RulePacks.
Package rulepack evaluates deterministic release evidence for signed detection RulePacks.
Package runtimereach is the coordinator that turns an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) into a CONFIRMED, RAISE-ONLY reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package runtimereach is the coordinator that turns an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) into a CONFIRMED, RAISE-ONLY reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?
Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?
Package safety is the single admission gate for AI-proposed actions and the structural embodiment of the rule that AI orchestration is a typed Go state machine, not prompt-driven control flow.
Package safety is the single admission gate for AI-proposed actions and the structural embodiment of the rule that AI orchestration is a typed Go state machine, not prompt-driven control flow.
Package sarifingest accepts SARIF 2.1.0 from third-party scanners so external findings enter the same asset model, prioritisation and governance path as first-party ones — without ever being presented as this system's own analysis.
Package sarifingest accepts SARIF 2.1.0 from third-party scanners so external findings enter the same asset model, prioritisation and governance path as first-party ones — without ever being presented as this system's own analysis.
Package sastbench scores the owned SAST/taint engine against a standard external benchmark (OWASP BenchmarkJava) and reduces the result to a per-category precision/recall scorecard with a regression ratchet.
Package sastbench scores the owned SAST/taint engine against a standard external benchmark (OWASP BenchmarkJava) and reduces the result to a per-category precision/recall scorecard with a regression ratchet.
Package sbomcrosscheckjudge (SBOM side) turns SBOM-PRODUCER cross-check DISAGREEMENTS into Judgments for human review.
Package sbomcrosscheckjudge (SBOM side) turns SBOM-PRODUCER cross-check DISAGREEMENTS into Judgments for human review.
sca
Package sca orchestrates the Software Composition Analysis pipeline.
Package sca orchestrates the Software Composition Analysis pipeline.
remediation
Package remediation computes the smallest set of direct-dependency upgrades that removes a transitive vulnerability from a resolved dependency graph (EPIC #860 D3.8).
Package remediation computes the smallest set of direct-dependency upgrades that removes a transitive vulnerability from a resolved dependency graph (EPIC #860 D3.8).
Package scabench defines the pure, provenance-backed contract for SCA accuracy benchmarks.
Package scabench defines the pure, provenance-backed contract for SCA accuracy benchmarks.
Package scmconnectoruc is the management use case for tenant-scoped source-control connectors: create, list, and delete the git-host + PAT bindings the acquirer uses to clone a PRIVATE repository.
Package scmconnectoruc is the management use case for tenant-scoped source-control connectors: create, list, and delete the git-host + PAT bindings the acquirer uses to clone a PRIVATE repository.
Package slauc coordinates tenant policy versions, immutable SLA assessments, and human-owned remediation transitions.
Package slauc coordinates tenant policy versions, immutable SLA assessments, and human-owned remediation transitions.
Package srcreach implements deterministic Tier-1 reachability over a first-party source import scan, shared by every language whose dependency usage is observable as an import/require/use statement.
Package srcreach implements deterministic Tier-1 reachability over a first-party source import scan, shared by every language whose dependency usage is observable as an import/require/use statement.
Package symreach implements deterministic, RAISE-ONLY symbol-level reachability for the source ecosystems whose vulnerable symbols come from the curated DB: PHP (Composer), Ruby (RubyGems), and .NET (NuGet).
Package symreach implements deterministic, RAISE-ONLY symbol-level reachability for the source ecosystems whose vulnerable symbols come from the curated DB: PHP (Composer), Ruby (RubyGems), and .NET (NuGet).
Package taintscan is the coordinator that turns a target's deterministic taint analysis into PROPOSED, gated CapSAST judgments – one per reported injection path × injection class – reusing the existing propose→verify gate.
Package taintscan is the coordinator that turns a target's deterministic taint analysis into PROPOSED, gated CapSAST judgments – one per reported injection path × injection class – reusing the existing propose→verify gate.
Package threatmodeluc is the architecture-input threat-model ingest use case: it accepts an UNTRUSTED architecture model (from the API), bounds its size, runs the domain's fail-closed Validate (referential integrity), persists it per engagement, and audits the action – the server-side enforcement the domain seam (internal/domain/threatmodel) is reasoned over by.
Package threatmodeluc is the architecture-input threat-model ingest use case: it accepts an UNTRUSTED architecture model (from the API), bounds its size, runs the domain's fail-closed Validate (referential integrity), persists it per engagement, and audits the action – the server-side enforcement the domain seam (internal/domain/threatmodel) is reasoned over by.
Package transfer implements engagement export/import: a portable bundle of an engagement's scope/findings/comments and its tamper-evident evidence chain.
Package transfer implements engagement export/import: a portable bundle of an engagement's scope/findings/comments and its tamper-evident evidence chain.
Package users manages operator identities + API keys.
Package users manages operator identities + API keys.
Package vex consumes OpenVEX documents (CRA-aligned): a client hands Synapse a VEX doc asserting the exploitability status of vulnerabilities in their products, and Synapse applies each statement to the matching finding – e.g.
Package vex consumes OpenVEX documents (CRA-aligned): a client hands Synapse a VEX doc asserting the exploitability status of vulnerabilities in their products, and Synapse applies each statement to the matching finding – e.g.
Package worker is the durable-queue claim-loop: it pulls jobs from a ports.JobQueue, dispatches each to a Handler registered by Kind, heartbeats long runs so their lease does not expire mid-flight, and Completes or Fails (with backoff) the job.
Package worker is the durable-queue claim-loop: it pulls jobs from a ports.JobQueue, dispatches each to a Handler registered by Kind, heartbeats long runs so their lease does not expire mid-flight, and Completes or Fails (with backoff) the job.
Package writeupdraftuc is the use case for AI-proposed, human-gated finding write-up drafts ("human-gated authoritative drafts").
Package writeupdraftuc is the use case for AI-proposed, human-gated finding write-up drafts ("human-gated authoritative drafts").

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL