exposurereader

package
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity. It reuses the already-evaluated risk (vulnerabilityrisk.Assessment); it recomputes nothing. Every read is tenant-scoped from ctx. When constructed with NewReaderWithRuntime it also resolves running-vs-installed — marking a vulnerable component Running if its package matches a process observed executing on one of the asset's hosts (the B5 process store); constructed with NewReader (no runtime signals) it reports installed-only and the producer notes the reduced precision.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type ComponentLister

type ComponentLister interface {
	ListCurrentComponentsByEngagement(ctx context.Context, tenantID, engagementID shared.ID) ([]sbom.ComponentRecord, error)
}

ComponentLister enumerates an engagement's current components so a vulnerable ComponentID can be resolved to a package name for process matching. The concrete ComponentInventoryStore satisfies it.

type ContextResolver

type ContextResolver interface {
	ProjectContexts(ctx context.Context, tenantID shared.ID, projectIDs []shared.ID) (map[shared.ID]*engagement.Engagement, error)
	GetByHostAssetID(ctx context.Context, tenantID, assetID shared.ID) (*engagement.Engagement, error)
}

ContextResolver resolves a linked project or host to its machine-owned engagement, where that project's or host's SBOM and occurrences live. ports.EngagementRepository satisfies it.

type MembershipReader

type MembershipReader interface {
	ListEngagementsByBusinessAsset(ctx context.Context, tenantID, assetID shared.ID) ([]*engagement.Engagement, error)
	ListBusinessAssetProjects(ctx context.Context, tenantID, assetID shared.ID) ([]asset.ComponentMembership, error)
	ListBusinessAssetTechnicalAssets(ctx context.Context, tenantID, assetID shared.ID) ([]asset.ComponentMembership, error)
}

MembershipReader is the asset-side view: which engagements an asset is assigned to and which projects and technical (fleet) assets make it up. ports.BusinessAssetRepository satisfies it. Occurrences carry no AssetID; they carry an EngagementID, so the bridge from an asset to its vulnerabilities is the set of engagements that belong to the asset: the ones assigned to it, plus the hidden analysis context of each linked project and the hidden vulnerability context of each linked host (see ContextResolver).

type OccurrenceReader

type OccurrenceReader interface {
	ListByEngagement(ctx context.Context, tenantID, engagementID shared.ID, states []vulnerabilityoccurrence.State) ([]vulnerabilityoccurrence.Occurrence, error)
}

OccurrenceReader lists an engagement's vulnerability occurrences by state. ports.VulnerabilityOccurrenceStore satisfies it.

type ProcessLister

type ProcessLister interface {
	ListRunningByAsset(ctx context.Context, assetID shared.ID) ([]ports.ProcessSnapshot, error)
}

ProcessLister returns the running processes for a HOST/fleet asset (the running side of running-vs-installed). ports.EndpointProcessStore satisfies it.

type Reader

type Reader struct {
	// contains filtered or unexported fields
}

Reader implements exposureuc.AssetVulnerabilityReader over the SCA stores. processes + components are OPTIONAL: when both are wired (NewReaderWithRuntime), the reader resolves the running-vs-installed Presence; when nil (NewReader), every component is reported installed-only.

func NewReader

func NewReader(memberships MembershipReader, contexts ContextResolver, occurrences OccurrenceReader, risk RiskReader) (*Reader, error)

NewReader constructs the adapter. All four stores are required.

func NewReaderWithRuntime

func NewReaderWithRuntime(memberships MembershipReader, contexts ContextResolver, occurrences OccurrenceReader, risk RiskReader, processes ProcessLister, components ComponentLister) (*Reader, error)

NewReaderWithRuntime is NewReader plus the runtime signals needed to resolve running-vs-installed: the B5 process store (running processes per host) and a component enumerator (ComponentID -> package name). With both wired, a vulnerable component whose package matches a running process is marked Running.

func (*Reader) ListAssetVulnerableComponents

func (r *Reader) ListAssetVulnerableComponents(ctx context.Context, assetID shared.ID) ([]exposureuc.AssetVulnerableComponent, error)

ListAssetVulnerableComponents resolves, for one asset, the engagements that belong to it and the currently-open vulnerability occurrences on those engagements (with their evaluated risk). The engagements are the ones assigned to the asset, the hidden analysis context of every linked project and the hidden vulnerability context of every linked host; an occurrence on one of them is the asset's by construction, so no further component filter is applied. (The previous join compared project and technical asset ids with SBOM component ids, two namespaces that never match, and read every asset as clean: #819.)

It ABSTAINS with shared.ErrNotFound when the asset has no exposure data to assess: no memberships and no assigned engagement, or, when a component lister is wired, no engagement with a component inventory (nothing was ever scanned). An asset that IS scanned but has no open occurrences returns (nil, nil), a trustworthy clean.

type RiskReader

type RiskReader interface {
	Current(ctx context.Context, tenantID, occurrenceID shared.ID) (vulnerabilityrisk.Assessment, error)
}

RiskReader returns the current risk evaluation for one occurrence. ports.VulnerabilityRiskAssessmentStore satisfies it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL