Documentation
¶
Overview ¶
Package scacompose shares SCA execution composition between API and worker roots.
Index ¶
- func Configure(svc *scauc.Service, cfg config.Config, sb *sandbox.Runner, log *slog.Logger) func()
- func ConfigureJudgmentScanners(svc *scauc.Service, cfg config.Config, sb *sandbox.Runner, ...) error
- func ResolveDetectionSources(cfg config.Config, c DetectionCandidates, log *slog.Logger) ([]ports.DetectionSource, error)
- type DetectionCandidates
- type Execution
- type SBOMProducerKind
- type TaintProposer
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Configure ¶
Configure applies every scan-pipeline setting that must match between an in-process API scan and a worker-executed scan: license/coord/hash resolvers, severity enrichment, transitive resolvers, analyzers, AI false-positive triage, caches, and feature gates. The returned cleanup closes the optional offline JAR hash database.
func ConfigureJudgmentScanners ¶
func ConfigureJudgmentScanners(svc *scauc.Service, cfg config.Config, sb *sandbox.Runner, proposer TaintProposer, audit ports.AuditLogger, clock ports.Clock, log *slog.Logger) error
ConfigureJudgmentScanners attaches the source-only, judgment-minting analyzers that run in the DEFAULT scan path onto svc, so synapse-api and synapse-worker run the same default-scan analysis rather than a regex-only scan. Python semantic value-flow taint is wired today (JS/Java as they land). The synapse-ast sidecar it uses only PARSES target source (tree-sitter); it never compiles or executes the target, and it degrades to a clean no-op when the sidecar is not installed, so it is safe to attach by default. A nil proposer (judgments disabled) attaches nothing. A coordinator init error is returned so a misconfigured analyzer is a loud startup failure at the composition root, never a silently degraded scan.
func ResolveDetectionSources ¶
func ResolveDetectionSources(cfg config.Config, c DetectionCandidates, log *slog.Logger) ([]ports.DetectionSource, error)
Types ¶
type DetectionCandidates ¶
type DetectionCandidates struct {
Grype ports.DetectionSource
OSV ports.DetectionSource
AdvisoryStore ports.DetectionSource
}
DetectionCandidates are the detection-source instances a caller offers. A nil entry means the caller does not provide that source in the current posture (e.g. OSV under --offline, or advisory-store with no store wired), so a request for it is skipped rather than treated as an error.
type Execution ¶
type Execution struct {
Sandbox *sandbox.Runner
SyftGen *syft.Generator
Acquirer ports.Acquirer
SBOMGen ports.SBOMGenerator
Sources []ports.DetectionSource
}
Execution holds the concrete SCA execution adapters. Sandbox and SyftGen are exposed because the composition root still needs them (taint call-graph, SBOM cross-check).
func BuildExecution ¶
func BuildExecution(cfg config.Config, log *slog.Logger, advisoryStore ports.AdvisoryStore, gitCreds ports.GitCredentialResolver) (Execution, error)
type SBOMProducerKind ¶
type SBOMProducerKind int
ResolveDetectionSources turns SYNAPSE_DETECTION_SOURCES (or the legacy default) into the ordered list of detection sources, drawing from the caller's candidates. It is shared by the server (BuildExecution) and the CLI so the source posture is identical across binaries. Unknown names fail closed at startup; a requested name whose candidate is nil is skipped with a log line. SBOMProducerKind is the resolved SBOM-producer decision, so every composition root keys off one enum rather than re-interpreting the config string (and the meaning of an empty value) independently.
const ( // SBOMProducerOwned is the owned per-ecosystem parsers, the shipped default (EPIC #1034, #1037). SBOMProducerOwned SBOMProducerKind = iota // SBOMProducerSyft is the pinned Syft binary, an opt-in cross-check. SBOMProducerSyft )
func ResolveSBOMProducerKind ¶
func ResolveSBOMProducerKind(cfg config.Config) (SBOMProducerKind, error)
ResolveSBOMProducerKind is the SINGLE decision for which SBOM producer a config selects: an empty value resolves to the owned default (matching config.Load's default), "ownsbom" and "syft" are explicit, and any other value is an error. Every producer-selection site (the server and CLI primary producers, and the server SBOM cross-check's secondary producer) calls this so they can never disagree on what "" means.
func (SBOMProducerKind) String ¶
func (k SBOMProducerKind) String() string
type TaintProposer ¶
type TaintProposer interface {
Propose(ctx context.Context, proposer string, engagementID shared.ID, capability judgment.Capability, subjectKind judgment.SubjectKind, subjectID shared.ID, claim judgment.Claim) (judgment.Judgment, error)
}
TaintProposer is the judgment proposer a source-only taint scanner needs to mint gated CapSAST proposals. It is satisfied by analysis.Service and matches the proposer the taintscan coordinator consumes, so this composition package can wire the coordinator without importing the analysis service concretely.