Documentation
¶
Index ¶
- Constants
- type AdapterType
- type Source
- func (s Source) AllowPrivateNetwork() bool
- func (s Source) BoolOption(name string) bool
- func (s Source) Clone() Source
- func (s Source) IntOption(name string, fallback int) int
- func (s *Source) Normalize() error
- func (s Source) SUSEHTTPSOrigin() (bool, error)
- func (s Source) StringListOption(name string) []string
- func (s Source) StringOption(name string) string
- func (s Source) Validate() error
- type SyncMode
Constants ¶
const SUSEOVALHTTPSOriginURL = "https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-sp6-affected.xml.gz"
SUSEOVALHTTPSOriginURL is the only HTTPS-origin exception for an otherwise OpenPGP-authenticated OVAL source. It names SUSE Linux Enterprise Server 15 SP6's affected OVAL artifact exactly; hosts, aliases, releases, query strings, fragments, and equivalent-looking URL spellings are intentionally not accepted.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AdapterType ¶
type AdapterType string
AdapterType identifies code-owned provider adapters. Operators can configure instances of these types, but cannot upload parser code.
const ( AdapterOSV AdapterType = "osv" AdapterCSAF AdapterType = "csaf" AdapterOVAL AdapterType = "oval" AdapterNVD AdapterType = "nvd" AdapterGHSA AdapterType = "ghsa" AdapterGitLab AdapterType = "gitlab" AdapterCISAKEV AdapterType = "cisa_kev" AdapterFIRSTEPSS AdapterType = "first_epss" AdapterPublicExploit AdapterType = "public_exploit" AdapterVulnCheckKEV AdapterType = "vulncheck_kev" )
func (AdapterType) Valid ¶
func (t AdapterType) Valid() bool
type Source ¶
type Source struct {
ID shared.ID `json:"id"`
Key string `json:"key"`
Name string `json:"name"`
AdapterType AdapterType `json:"adapter_type"`
Endpoint string `json:"endpoint"`
Enabled bool `json:"enabled"`
Archived bool `json:"archived"`
Cadence time.Duration `json:"cadence"`
StaleAfter time.Duration `json:"stale_after"`
SyncMode SyncMode `json:"sync_mode"`
AdapterConfig json.RawMessage `json:"adapter_config"`
CredentialRef string `json:"credential_ref,omitempty"`
Version int `json:"version"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}
Source is a global, operator-managed provider instance. CredentialRef is a secret-manager reference, never credential material.
func (Source) AllowPrivateNetwork ¶
func (Source) BoolOption ¶ added in v0.2.0
BoolOption returns a true JSON boolean adapter option. Invalid or absent options are false; source validation remains responsible for rejecting an invalid configured value.
func (Source) SUSEHTTPSOrigin ¶ added in v0.2.0
SUSEHTTPSOrigin reports whether this source selects the one code-owned SUSE HTTPS-origin mode. It validates the complete exception rather than treating a boolean alone as trust, so callers that bypass Normalize still cannot accept a near-match, a different adapter, a partial mode, or a mixed signature/discovery configuration.