Documentation
¶
Overview ¶
Package issue models Project-scoped code-quality issue projections and their triage lifecycle (open / accepted / false-positive / won't-fix). It mirrors the Security Hotspot review model: a tenant- and Project-scoped read projection whose lifecycle state is retained across rescans and never deleted, so a resolved issue stays gate-exempt but auditable.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrInvalidTransition = errors.New("invalid issue transition")
ErrInvalidTransition marks an attempted lifecycle move the graph forbids.
Functions ¶
Types ¶
type Candidate ¶
type Candidate struct {
Key string
FindingIdentity string
RuleKey string
Type rule.Type
Title string
Description string
Severity shared.Severity
Kind finding.Kind
CWE string
Language string
File string
Location string
SourceLocation *finding.SourceLocation
}
Candidate is the immutable scan-time projection input for one non-hotspot finding. Tenant, Project, analysis timestamps, lifecycle state and version are assigned by the persistence boundary so a rescan cannot reset a triage decision.
type Facets ¶
type Facets struct {
Types map[string]int
Statuses map[string]int
Severities map[string]int
RuleKeys map[string]int
Languages map[string]int
}
Facets are the per-facet counts computed over the filtered (but unpaginated) set.
type Issue ¶
type Issue struct {
ID shared.ID
TenantID shared.ID
ProjectID shared.ID
Key string
FindingIdentity string
RuleKey string
Type rule.Type
Title string
Description string
Severity shared.Severity
Kind finding.Kind
CWE string
Language string
File string
Location string
SourceLocation *finding.SourceLocation
Status Status
Version int
// IsNew marks an issue that has only been observed in its latest analysis (i.e.
// introduced since the previous analysis); it drives the New Code lens/facet.
IsNew bool
FirstSeenAnalysisID string
LastSeenAnalysisID string
FirstSeenAt time.Time
LastSeenAt time.Time
LastReviewedBy string
LastReviewedAt *time.Time
Audit shared.Audit
}
Issue is a tenant- and Project-scoped read model. It deliberately carries no Engagement identity or raw scan payload.
func Project ¶
func Project(tenantID, projectID shared.ID, analysisID string, createdAt time.Time, candidate Candidate) (Issue, error)
Project creates and validates the initial Project-scoped projection for one issue candidate detected in an analysis.
func (Issue) Transition ¶
func (i Issue) Transition(to Status, actor, rationale string, expectedVersion int, eventID shared.ID, now time.Time) (Issue, ReviewEvent, error)
Transition evaluates and applies a triage decision, returning the new immutable Issue state and its ReviewEvent, or an error. Optimistic concurrency is enforced via expectedVersion (stale → ErrConflict); the transition graph and rationale are validated in the domain, never in the handler.
type ListFilter ¶
type ListFilter struct {
Lens Lens
Status *Status
Type *rule.Type
Severity *shared.Severity
RuleKey string
Language string
PathPrefix string
NewCodeOnly bool
Search string
Limit int
BeforeLastSeenAt time.Time
BeforeID shared.ID
}
ListFilter describes the read API's tenant/Project-local facet filters.
type ReviewEvent ¶
type ReviewEvent struct {
ID shared.ID
TenantID shared.ID
ProjectID shared.ID
IssueID shared.ID
From Status
To Status
Actor string
Rationale string
PreviousVersion int
Version int
CreatedAt time.Time
}
ReviewEvent is one immutable, append-only record of a lifecycle transition.
type Status ¶
type Status string
Status is the triage lifecycle vocabulary for a Project code-quality issue.
func (Status) CanTransitionTo ¶
CanTransitionTo enforces the allowed lifecycle graph: Open triages into any resolved bucket, a resolved issue can be re-triaged into another bucket or reopened, and no self-transition is permitted.
func (Status) GateExempt ¶
GateExempt reports whether an issue in this status is excluded from gate metrics.