scacompose

package
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 57 Imported by: 0

Documentation

Overview

Package scacompose shares SCA execution composition between API and worker roots.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Configure

func Configure(svc *scauc.Service, cfg config.Config, sb *sandbox.Runner, log *slog.Logger) func()

Configure applies every scan-pipeline setting that must match between an in-process API scan and a worker-executed scan: license/coord/hash resolvers, severity enrichment, transitive resolvers, analyzers, AI false-positive triage, caches, and feature gates. The returned cleanup closes the optional offline JAR hash database.

func ConfigureJudgmentScanners

func ConfigureJudgmentScanners(svc *scauc.Service, cfg config.Config, sb *sandbox.Runner, proposer TaintProposer, audit ports.AuditLogger, clock ports.Clock, log *slog.Logger) error

ConfigureJudgmentScanners attaches the source-only, judgment-minting analyzers that run in the DEFAULT scan path onto svc, so synapse-api and synapse-worker run the same default-scan analysis rather than a regex-only scan. Python semantic value-flow taint is wired today (JS/Java as they land). The synapse-ast sidecar it uses only PARSES target source (tree-sitter); it never compiles or executes the target, and it degrades to a clean no-op when the sidecar is not installed, so it is safe to attach by default. A nil proposer (judgments disabled) attaches nothing. A coordinator init error is returned so a misconfigured analyzer is a loud startup failure at the composition root, never a silently degraded scan.

func ResolveDetectionSources

func ResolveDetectionSources(cfg config.Config, c DetectionCandidates, log *slog.Logger) ([]ports.DetectionSource, error)

Types

type DetectionCandidates

type DetectionCandidates struct {
	Grype         ports.DetectionSource
	OSV           ports.DetectionSource
	AdvisoryStore ports.DetectionSource
}

DetectionCandidates are the detection-source instances a caller offers. A nil entry means the caller does not provide that source in the current posture (e.g. OSV under --offline, or advisory-store with no store wired), so a request for it is skipped rather than treated as an error.

type Execution

type Execution struct {
	Sandbox  *sandbox.Runner
	SyftGen  *syft.Generator
	Acquirer ports.Acquirer
	SBOMGen  ports.SBOMGenerator
	Sources  []ports.DetectionSource
}

Execution holds the concrete SCA execution adapters. Sandbox and SyftGen are exposed because the composition root still needs them (taint call-graph, SBOM cross-check).

func BuildExecution

func BuildExecution(cfg config.Config, log *slog.Logger, advisoryStore ports.AdvisoryStore, gitCreds ports.GitCredentialResolver) (Execution, error)

type SBOMProducerKind

type SBOMProducerKind int

ResolveDetectionSources turns SYNAPSE_DETECTION_SOURCES (or the legacy default) into the ordered list of detection sources, drawing from the caller's candidates. It is shared by the server (BuildExecution) and the CLI so the source posture is identical across binaries. Unknown names fail closed at startup; a requested name whose candidate is nil is skipped with a log line. SBOMProducerKind is the resolved SBOM-producer decision, so every composition root keys off one enum rather than re-interpreting the config string (and the meaning of an empty value) independently.

const (
	// SBOMProducerOwned is the owned per-ecosystem parsers, the shipped default (EPIC #1034, #1037).
	SBOMProducerOwned SBOMProducerKind = iota
	// SBOMProducerSyft is the pinned Syft binary, an opt-in cross-check.
	SBOMProducerSyft
)

func ResolveSBOMProducerKind

func ResolveSBOMProducerKind(cfg config.Config) (SBOMProducerKind, error)

ResolveSBOMProducerKind is the SINGLE decision for which SBOM producer a config selects: an empty value resolves to the owned default (matching config.Load's default), "ownsbom" and "syft" are explicit, and any other value is an error. Every producer-selection site (the server and CLI primary producers, and the server SBOM cross-check's secondary producer) calls this so they can never disagree on what "" means.

func (SBOMProducerKind) String

func (k SBOMProducerKind) String() string

type TaintProposer

type TaintProposer interface {
	Propose(ctx context.Context, proposer string, engagementID shared.ID, capability judgment.Capability, subjectKind judgment.SubjectKind, subjectID shared.ID, claim judgment.Claim) (judgment.Judgment, error)
}

TaintProposer is the judgment proposer a source-only taint scanner needs to mint gated CapSAST proposals. It is satisfied by analysis.Service and matches the proposer the taintscan coordinator consumes, so this composition package can wire the coordinator without importing the analysis service concretely.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL