Documentation
¶
Overview ¶
Package projectuc implements project application logic.
Index ¶
- func ValidateCursorSecret(key []byte) error
- type AnalysisMetadata
- type BehavioralHotspotItem
- type BehavioralHotspotsResponse
- type BehavioralMeasures
- type ChildCollection
- type CodeDiffView
- type CodeFile
- type CodeFileFilter
- type CodeFileView
- type CodeFinding
- type CodeLine
- type CodeLineOverlay
- type CodeRevision
- type ComplexityBaseline
- type ComplexityCoverageMetric
- type ComplexityMeasures
- type CountMetric
- type CouplingMeasures
- type CoverageMeasures
- type CreateInput
- type DebtMeasures
- type DependencyGraph
- type DependencyGraphEdge
- type DependencyGraphLicense
- type DependencyGraphNode
- type DependencyGraphSummary
- type DependencyGraphVulnerability
- type DuplicationMeasures
- type ImportAnalysisInput
- type IssueMeasures
- type LatestAnalysis
- type MeasureAvailabilityState
- type MeasureCountMetric
- type MeasureCursor
- type MeasureDecimalMetric
- type MeasureGradeMetric
- type MeasureNode
- type MeasureSignedMetric
- type MetricAvailability
- type Overview
- type OverviewAnalysis
- type OverviewGate
- type OverviewGateCondition
- type OverviewGateOperator
- type OverviewGateSource
- type OverviewGateStatus
- type OverviewGrade
- type OverviewIssueSummary
- type OverviewLens
- type OverviewNewCodePeriod
- type OverviewProject
- type OverviewState
- type PercentageMetric
- type ProjectMeasureResponse
- type ProjectNodeInfo
- type ProjectSummary
- type PublishSourceInput
- type RatingMetric
- type RatingsMeasures
- type Service
- func (s *Service) AnalysisStatus(ctx context.Context, tenantID shared.ID, key string) (ports.ScanJob, error)
- func (s *Service) AssignGate(ctx context.Context, actor string, tenantID shared.ID, key, gateID string) (*project.Project, error)
- func (s *Service) Branches(ctx context.Context, tenantID shared.ID, key string) ([]projectanalysis.BranchInfo, error)
- func (s *Service) Create(ctx context.Context, in CreateInput) (*project.Project, error)
- func (s *Service) CreateFromArchive(ctx context.Context, in CreateInput, filename string, src io.Reader) (*project.Project, error)
- func (s *Service) Delete(ctx context.Context, actor string, tenantID shared.ID, key string) error
- func (s *Service) ExportProjectDependencySubtree(ctx context.Context, tenantID shared.ID, key, root string) ([]byte, string, error)
- func (s *Service) Get(ctx context.Context, tenantID shared.ID, key string) (*project.Project, error)
- func (s *Service) GetAnalysis(ctx context.Context, tenantID shared.ID, key, id string) (projectanalysis.Analysis, error)
- func (s *Service) GetBehavioralHotspots(ctx context.Context, tenantID shared.ID, projectKey, analysisID, path string, ...) (BehavioralHotspotsResponse, error)
- func (s *Service) GetHotspot(ctx context.Context, tenantID shared.ID, key string, hotspotID shared.ID) (hotspot.Hotspot, error)
- func (s *Service) GetIssue(ctx context.Context, tenantID shared.ID, key string, issueID shared.ID) (issue.Issue, error)
- func (s *Service) GetMeasures(ctx context.Context, tenantID, projectKey, path string, domains []string, ...) (ProjectMeasureResponse, error)
- func (s *Service) HotspotHistory(ctx context.Context, tenantID shared.ID, key string, hotspotID shared.ID) ([]hotspot.ReviewEvent, error)
- func (s *Service) ImportAnalysis(ctx context.Context, tenantID shared.ID, key string, in ImportAnalysisInput) (projectanalysis.Analysis, error)
- func (s *Service) IssueHistory(ctx context.Context, tenantID shared.ID, key string, issueID shared.ID) ([]issue.ReviewEvent, error)
- func (s *Service) LatestAnalysis(ctx context.Context, tenantID shared.ID, key, branch string) (LatestAnalysis, error)
- func (s *Service) List(ctx context.Context, tenantID shared.ID) ([]*project.Project, error)
- func (s *Service) ListAnalyses(ctx context.Context, tenantID shared.ID, key, branch string, limit int, ...) ([]projectanalysis.Analysis, bool, error)
- func (s *Service) ListCodeFiles(ctx context.Context, tenantID shared.ID, key, analysisID string) ([]CodeFile, projectanalysis.SourceCapabilities, error)
- func (s *Service) ListCodeFilesWithFilter(ctx context.Context, tenantID shared.ID, key, analysisID string, ...) ([]CodeFile, projectanalysis.SourceCapabilities, error)
- func (s *Service) ListHotspots(ctx context.Context, tenantID shared.ID, key string, filter hotspot.ListFilter) (hotspot.Page, error)
- func (s *Service) ListIssues(ctx context.Context, tenantID shared.ID, key string, filter issue.ListFilter) (issue.Page, error)
- func (s *Service) ListSummaries(ctx context.Context, tenantID shared.ID) ([]ProjectSummary, error)
- func (s *Service) Overview(ctx context.Context, tenantID shared.ID, key, branch string) (Overview, error)
- func (s *Service) ProjectDependencyGraph(ctx context.Context, tenantID shared.ID, key string) (DependencyGraph, error)
- func (s *Service) PublishSource(ctx context.Context, in PublishSourceInput) (projectanalysis.SourceManifest, error)
- func (s *Service) ReadCodeDiff(ctx context.Context, tenantID shared.ID, key, analysisID, path, view string, ...) (CodeDiffView, projectanalysis.SourceCapabilities, error)
- func (s *Service) ReadCodeFile(ctx context.Context, tenantID shared.ID, key, analysisID, path string, ...) (CodeFileView, projectanalysis.SourceCapabilities, error)
- func (s *Service) RecordProjectAnalysis(ctx context.Context, engagementID shared.ID, jobID string, ...) error
- func (s *Service) SetAnalysisStore(store ports.ProjectAnalysisStore)
- func (s *Service) SetArchiveStore(store ports.ProjectArchiveStore)
- func (s *Service) SetCursorSecret(secret []byte) error
- func (s *Service) SetFindingRepository(repo ports.FindingRepository)
- func (s *Service) SetHotspotStore(store ports.ProjectHotspotStore)
- func (s *Service) SetIssueStore(store ports.ProjectIssueStore)
- func (s *Service) SetPRDecorator(decorator ports.PRDecorator)
- func (s *Service) SetProjectAnalysisCompletionTimeout(timeout time.Duration)
- func (s *Service) SetPullRequestDecoration(ctx context.Context, actor string, tenantID shared.ID, key string, ...) (*project.Project, error)
- func (s *Service) SetQualityGateMutator(mutator ports.QualityGateMutator)
- func (s *Service) SetQualityGates(gates *qualitygatesuc.Service)
- func (s *Service) SetQualityProfiles(profiles *qualityprofilesuc.Service)
- func (s *Service) SetRuleCatalog(catalog ports.RuleCatalog)
- func (s *Service) SetScanJobs(jobs ports.ScanJobStore)
- func (s *Service) SetScanner(scanner *scauc.Service)
- func (s *Service) SetShortLivedBranchKeep(keep int)
- func (s *Service) SetSourceArtifactStore(store ports.ProjectSourceArtifactStore)
- func (s *Service) StartAnalysis(ctx context.Context, actor string, tenantID shared.ID, key string, ...) (ports.ScanJob, error)
- func (s *Service) TransitionHotspot(ctx context.Context, actor string, tenantID shared.ID, key string, ...) (hotspot.Hotspot, hotspot.ReviewEvent, error)
- func (s *Service) TransitionIssue(ctx context.Context, actor string, tenantID shared.ID, key string, ...) (issue.Issue, issue.ReviewEvent, error)
- type SizeMeasures
- type UnavailableReason
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ValidateCursorSecret ¶
ValidateCursorSecret returns an error when key is nil or shorter than 32 bytes.
Types ¶
type AnalysisMetadata ¶
type AnalysisMetadata struct {
ID string `json:"id"`
CreatedAt time.Time `json:"created_at"`
SourceRef string `json:"source_ref,omitempty"`
SourceCommit string `json:"source_commit,omitempty"`
}
AnalysisMetadata provides contextual information about the analysis snapshot.
type BehavioralHotspotItem ¶ added in v0.2.0
type BehavioralHotspotItem struct {
Path string `json:"path"`
Language string `json:"language,omitempty"`
Cyclomatic int `json:"cyclomatic"`
ChangeCount int `json:"change_count"`
Score int `json:"score"`
}
BehavioralHotspotItem is one immutable, globally ranked file row.
type BehavioralHotspotsResponse ¶ added in v0.2.0
type BehavioralHotspotsResponse struct {
Project ProjectNodeInfo `json:"project"`
Analysis AnalysisMetadata `json:"analysis"`
Path string `json:"path"`
Availability measure.BehavioralAvailability `json:"availability"`
Reason *string `json:"unavailable_reason"`
FormulaVersion int `json:"formula_version"`
RequestedCommits int `json:"requested_commits"`
EvaluatedCommits int `json:"evaluated_commits"`
ReachedRoot bool `json:"reached_root"`
TotalEligible int `json:"total_eligible"`
TotalMeasured int `json:"total_measured"`
TotalExcluded int `json:"total_excluded"`
Shown int `json:"shown"`
Omitted int `json:"omitted"`
Items []BehavioralHotspotItem `json:"items"`
}
BehavioralHotspotsResponse is a bounded top-list pinned to one analysis.
type BehavioralMeasures ¶ added in v0.2.0
type BehavioralMeasures struct {
CyclomaticSum MeasureCountMetric `json:"cyclomatic_sum"`
ChangeCount MeasureCountMetric `json:"change_count"`
Score MeasureCountMetric `json:"score"`
}
BehavioralMeasures exposes per-file complexity/churn scores. For directory and project nodes, ChangeCount is the number of measured descendant files and Score is the maximum descendant score.
type ChildCollection ¶
type ChildCollection struct {
Items []MeasureNode `json:"items"`
NextCursor *string `json:"next_cursor"`
}
ChildCollection wraps a paginated list of immediate child nodes.
type CodeDiffView ¶ added in v0.1.8
type CodeDiffView struct {
AnalysisID string `json:"analysis_id"`
Base *CodeRevision `json:"base,omitempty"`
Head CodeRevision `json:"head"`
Path string `json:"path"`
View string `json:"view"`
ContextTruncated bool `json:"context_truncated"`
Change projectanalysis.FileChange `json:"change"`
BaseFile projectanalysis.SourceFile `json:"base_file,omitempty"`
SourceFile projectanalysis.SourceFile `json:"source_file,omitempty"`
}
type CodeFile ¶ added in v0.1.8
type CodeFile struct {
Path string `json:"path"`
OldPath string `json:"old_path,omitempty"`
Status string `json:"status"`
Language string `json:"language,omitempty"`
Lines int `json:"lines"`
FindingCount int `json:"finding_count"`
ChangedLineCount int `json:"changed_line_count"`
Binary bool `json:"binary"`
Generated bool `json:"generated"`
SourceAvailable bool `json:"source_available"`
SourceReason projectanalysis.UnavailableReason `json:"source_reason,omitempty"`
}
type CodeFileFilter ¶ added in v0.1.8
type CodeFileView ¶ added in v0.1.8
type CodeFileView struct {
AnalysisID string `json:"analysis_id"`
Base *CodeRevision `json:"base,omitempty"`
Head CodeRevision `json:"head"`
File CodeFile `json:"file"`
FromLine int `json:"from_line"`
ToLine int `json:"to_line"`
TotalLines int `json:"total_lines"`
Lines []CodeLine `json:"lines"`
Findings []CodeFinding `json:"findings"`
LineCoverageAvailable bool `json:"-"`
}
type CodeFinding ¶ added in v0.1.8
type CodeFinding struct {
ID string `json:"id"`
Kind string `json:"kind"`
RuleKey string `json:"rule_key,omitempty"`
RuleName string `json:"rule_name,omitempty"`
Type string `json:"type,omitempty"`
Severity shared.Severity `json:"severity"`
DetectionStatus finding.Status `json:"detection_status"`
CurrentStatus string `json:"current_status,omitempty"`
Message string `json:"message,omitempty"`
Location finding.SourceLocation `json:"location"`
New bool `json:"new"`
}
CodeFinding is the display-safe immutable finding marker for a source response. DetectionStatus is immutable; CurrentStatus is optional mutable triage state.
type CodeLineOverlay ¶ added in v0.1.8
type CodeLineOverlay struct {
Line int `json:"line"`
Covered *bool `json:"covered,omitempty"`
Changed bool `json:"changed,omitempty"`
Duplicated bool `json:"duplicated,omitempty"`
}
CodeLineOverlay is sparse: a nil coverage value means unknown/not executable.
type CodeRevision ¶ added in v0.1.8
type ComplexityBaseline ¶ added in v0.2.0
type ComplexityBaseline struct {
AnalysisID string `json:"analysis_id"`
CreatedAt time.Time `json:"created_at"`
SourceRef string `json:"source_ref,omitempty"`
}
ComplexityBaseline identifies the baseline analysis used for computing complexity deltas.
type ComplexityCoverageMetric ¶ added in v0.2.0
type ComplexityCoverageMetric struct {
Version int `json:"version"`
EligibleFiles MeasureCountMetric `json:"eligible_files"`
MeasuredFiles MeasureCountMetric `json:"measured_files"`
Availability MeasureAvailabilityState `json:"availability"`
Reason *string `json:"unavailable_reason"`
}
ComplexityCoverageMetric records how much of a node's source scope has usable complexity evidence.
type ComplexityMeasures ¶
type ComplexityMeasures struct {
Cyclomatic MeasureCountMetric `json:"cyclomatic"`
Cognitive MeasureCountMetric `json:"cognitive"`
CyclomaticDelta MeasureSignedMetric `json:"cyclomatic_delta"`
CognitiveDelta MeasureSignedMetric `json:"cognitive_delta"`
Coverage ComplexityCoverageMetric `json:"coverage"`
Baseline *ComplexityBaseline `json:"baseline,omitempty"`
}
ComplexityMeasures encapsulates structural complexity metrics.
type CountMetric ¶
type CountMetric struct {
Availability MetricAvailability
Value *int
}
type CouplingMeasures ¶ added in v0.2.0
type CouplingMeasures struct {
Afferent MeasureCountMetric `json:"afferent"`
Efferent MeasureCountMetric `json:"efferent"`
Instability MeasureDecimalMetric `json:"instability"`
}
CouplingMeasures describes incoming and outgoing first-party module dependencies. Instability is Ce/(Ca+Ce) and is unavailable for an isolated module.
type CoverageMeasures ¶
type CoverageMeasures struct {
CoveredLines MeasureCountMetric `json:"covered_lines"`
CoverableLines MeasureCountMetric `json:"coverable_lines"`
Coverage MeasureDecimalMetric `json:"coverage"`
NewCodeCoverage MeasureDecimalMetric `json:"new_code_coverage"`
}
CoverageMeasures encapsulates code coverage metrics.
type CreateInput ¶
type DebtMeasures ¶
type DebtMeasures struct {
RemediationEffortMinutes MeasureCountMetric `json:"remediation_effort_minutes"`
}
DebtMeasures encapsulates technical debt metrics.
type DependencyGraph ¶ added in v0.2.0
type DependencyGraph struct {
AnalysisID string `json:"analysis_id"`
Roots []string `json:"roots"`
Nodes []DependencyGraphNode `json:"nodes"`
Edges []DependencyGraphEdge `json:"edges"`
Summary DependencyGraphSummary `json:"summary"`
}
DependencyGraph is the latest immutable Project SBOM projected for interactive reads. It deliberately omits raw SBOM/source material and carries only bounded, stored facts.
type DependencyGraphEdge ¶ added in v0.2.0
type DependencyGraphLicense ¶ added in v0.2.0
type DependencyGraphNode ¶ added in v0.2.0
type DependencyGraphNode struct {
ID string `json:"id"`
Name string `json:"name"`
Version string `json:"version"`
PURL string `json:"purl,omitempty"`
Scope string `json:"scope"`
Reachability string `json:"reachability,omitempty"`
Direct bool `json:"direct"`
Depth int `json:"depth"`
Synthetic bool `json:"synthetic,omitempty"` // the synthetic project-root node that unifies a disconnected (monorepo) graph; not a real component
Licenses []DependencyGraphLicense `json:"licenses"`
LicenseRisk bool `json:"license_risk"`
LicenseVerdict string `json:"license_verdict"`
Vulnerabilities []DependencyGraphVulnerability `json:"vulnerabilities"`
VulnerabilityCount int `json:"vulnerability_count"`
WorstSeverity string `json:"worst_severity,omitempty"`
}
type DependencyGraphSummary ¶ added in v0.2.0
type DependencyGraphVulnerability ¶ added in v0.2.0
type DuplicationMeasures ¶
type DuplicationMeasures struct {
DuplicatedLines MeasureCountMetric `json:"duplicated_lines"`
DuplicationBlocks MeasureCountMetric `json:"duplication_blocks"`
DuplicationDensity MeasureDecimalMetric `json:"duplication_density"`
}
DuplicationMeasures encapsulates source code duplication metrics.
type ImportAnalysisInput ¶ added in v0.2.0
type ImportAnalysisInput struct {
Actor string
CI projectanalysis.CIContext
Result *scauc.ScanResult
}
ImportAnalysisInput is a scan result a pipeline produced with synapse-cli and is handing to the server to record as this project's next analysis.
type IssueMeasures ¶
type IssueMeasures struct {
ByType map[string]MeasureCountMetric `json:"by_type"`
BySeverity map[string]MeasureCountMetric `json:"by_severity"`
}
IssueMeasures encapsulates finding counts broken down by type and severity.
type LatestAnalysis ¶
type LatestAnalysis struct {
Analysis projectanalysis.Analysis
Result []byte
}
type MeasureAvailabilityState ¶
type MeasureAvailabilityState string
MeasureAvailabilityState describes whether a measure has a meaningful value.
const ( // AvailabilityAvailable indicates the measure value is present and valid. AvailabilityAvailable MeasureAvailabilityState = "available" AvailabilityUnavailable MeasureAvailabilityState = "unavailable" // AvailabilityNotApplicable indicates the measure does not apply to this node type. AvailabilityNotApplicable MeasureAvailabilityState = "not_applicable" )
type MeasureCountMetric ¶
type MeasureCountMetric struct {
Availability MeasureAvailabilityState `json:"availability"`
Value *int `json:"value"`
Reason *string `json:"unavailable_reason"`
}
MeasureCountMetric represents an integer measure and its availability state.
type MeasureCursor ¶
type MeasureCursor struct {
Version int `json:"v"`
AnalysisID string `json:"a"`
Path string `json:"r"`
LastKindRank int `json:"k"`
LastChildPath string `json:"l"`
}
MeasureCursor is the opaque pagination token used to iterate through children.
func DecodeMeasureCursor ¶
func DecodeMeasureCursor(s string, secret []byte) (*MeasureCursor, error)
DecodeMeasureCursor decodes, verifies the signature, and validates the integrity of a pagination cursor.
func (*MeasureCursor) Encode ¶
func (c *MeasureCursor) Encode(secret []byte) string
Encode serializes the cursor and cryptographically signs it to prevent tampering.
type MeasureDecimalMetric ¶
type MeasureDecimalMetric struct {
Availability MeasureAvailabilityState `json:"availability"`
Value *float64 `json:"value"`
Reason *string `json:"unavailable_reason"`
}
MeasureDecimalMetric represents a floating-point measure and its availability state.
type MeasureGradeMetric ¶
type MeasureGradeMetric struct {
Availability MeasureAvailabilityState `json:"availability"`
Grade *string `json:"grade"`
Reason *string `json:"unavailable_reason"`
}
MeasureGradeMetric represents a letter grade (e.g., A, B, C) and its availability state.
type MeasureNode ¶
type MeasureNode struct {
Path string `json:"path"`
Name string `json:"name"`
Kind measure.NodeKind `json:"kind"`
Language string `json:"language,omitempty"`
Size *SizeMeasures `json:"size,omitempty"`
Complexity *ComplexityMeasures `json:"complexity,omitempty"`
Coupling *CouplingMeasures `json:"coupling,omitempty"`
BehavioralHotspots *BehavioralMeasures `json:"behavioral_hotspots,omitempty"`
Coverage *CoverageMeasures `json:"coverage,omitempty"`
Duplication *DuplicationMeasures `json:"duplication,omitempty"`
Issues *IssueMeasures `json:"issues,omitempty"`
Debt *DebtMeasures `json:"debt,omitempty"`
Ratings *RatingsMeasures `json:"ratings,omitempty"`
}
MeasureNode represents a single directory, file, or project root with its computed measures.
type MeasureSignedMetric ¶ added in v0.2.0
type MeasureSignedMetric struct {
Availability MeasureAvailabilityState `json:"availability"`
Value *int `json:"value"`
Reason *string `json:"unavailable_reason"`
}
MeasureSignedMetric is a signed delta. Negative values are meaningful and never clamped.
type MetricAvailability ¶
type MetricAvailability string
const ( MetricAvailable MetricAvailability = "available" MetricNotSupplied MetricAvailability = "not_supplied" MetricNotApplicable MetricAvailability = "not_applicable" )
type Overview ¶
type Overview struct {
State OverviewState
Project OverviewProject
LatestAnalysis *OverviewAnalysis
Gate *OverviewGate
IssueSummary OverviewIssueSummary
Overall OverviewLens
NewCode OverviewLens
}
type OverviewAnalysis ¶
type OverviewGate ¶
type OverviewGate struct {
Status OverviewGateStatus
Key *string
Name *string
Source *OverviewGateSource
FailedConditions []OverviewGateCondition
}
type OverviewGateCondition ¶
type OverviewGateCondition struct {
Metric string
Operator OverviewGateOperator
Threshold float64
Actual float64
// Unmeasured: the condition failed because its metric had no measurement, not on a value; Actual
// is 0 only because there is nothing to report.
Unmeasured bool
}
type OverviewGateOperator ¶
type OverviewGateOperator string
const ( OverviewGateOperatorLE OverviewGateOperator = "<=" OverviewGateOperatorGE OverviewGateOperator = ">=" OverviewGateOperatorEQ OverviewGateOperator = "==" OverviewGateOperatorLT OverviewGateOperator = "<" OverviewGateOperatorGT OverviewGateOperator = ">" )
type OverviewGateSource ¶
type OverviewGateSource string
const ( OverviewGateSourceDefault OverviewGateSource = "default" OverviewGateSourceRepository OverviewGateSource = "repository" OverviewGateSourceManaged OverviewGateSource = "managed" )
type OverviewGateStatus ¶
type OverviewGateStatus string
const ( OverviewGatePassed OverviewGateStatus = "passed" OverviewGateFailed OverviewGateStatus = "failed" OverviewGateIncomplete OverviewGateStatus = "incomplete" )
type OverviewGrade ¶
type OverviewGrade string
const ( OverviewGradeA OverviewGrade = "A" OverviewGradeB OverviewGrade = "B" OverviewGradeC OverviewGrade = "C" OverviewGradeD OverviewGrade = "D" OverviewGradeE OverviewGrade = "E" )
type OverviewIssueSummary ¶
type OverviewIssueSummary struct {
NewCodeTotal CountMetric
AcceptedOverallTotal CountMetric
}
type OverviewLens ¶
type OverviewLens struct {
Security RatingMetric
Reliability RatingMetric
Maintainability RatingMetric
SecurityHotspotsReviewed PercentageMetric
Coverage PercentageMetric
Duplications PercentageMetric
}
type OverviewNewCodePeriod ¶
type OverviewProject ¶
type OverviewState ¶
type OverviewState string
const ( OverviewStateNotAnalyzed OverviewState = "not_analyzed" OverviewStateAnalyzed OverviewState = "analyzed" )
type PercentageMetric ¶
type PercentageMetric struct {
Availability MetricAvailability
Value *float64
Grade *OverviewGrade
}
type ProjectMeasureResponse ¶
type ProjectMeasureResponse struct {
State string `json:"state"` // "analyzed", "not_analyzed"
Project ProjectNodeInfo `json:"project"`
Analysis *AnalysisMetadata `json:"analysis"`
Path string `json:"path"`
IncludedDomains []string `json:"included_domains"`
Node *MeasureNode `json:"node"`
Children ChildCollection `json:"children"`
}
ProjectMeasureResponse is the root response payload for the measures API endpoint.
type ProjectNodeInfo ¶
ProjectNodeInfo provides basic identifying information about the project.
type ProjectSummary ¶
type ProjectSummary struct {
Project *project.Project
LatestAnalysis *projectanalysis.Analysis
LatestJob *ports.ScanJob
}
ProjectSummary combines a Project with its latest decision record and active job.
type PublishSourceInput ¶ added in v0.1.8
type PublishSourceInput struct {
TenantID shared.ID
ProjectKey string
AnalysisID string
Actor string
ToolVersion string
Archive io.Reader
}
PublishSourceInput contains only contributor-controlled facts that are safe to accept. Tenant and project identity are resolved by the authenticated server path, never from the archive.
type RatingMetric ¶
type RatingMetric struct {
Availability MetricAvailability
Grade *OverviewGrade
}
type RatingsMeasures ¶
type RatingsMeasures struct {
Security MeasureGradeMetric `json:"security"`
Reliability MeasureGradeMetric `json:"reliability"`
Maintainability MeasureGradeMetric `json:"maintainability"`
}
RatingsMeasures encapsulates high-level grades for security, reliability, and maintainability.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
func NewService ¶
func NewService(repo ports.ProjectRepository, engagements ports.EngagementRepository, clock ports.Clock, ids ports.IDGenerator, audit ports.AuditLogger, allowLocalSource bool) *Service
func (*Service) AnalysisStatus ¶
func (*Service) AssignGate ¶
func (*Service) Branches ¶ added in v0.2.0
func (s *Service) Branches(ctx context.Context, tenantID shared.ID, key string) ([]projectanalysis.BranchInfo, error)
Branches returns the distinct branch values recorded for the Project, sorted.
func (*Service) CreateFromArchive ¶
func (*Service) ExportProjectDependencySubtree ¶ added in v0.2.0
func (s *Service) ExportProjectDependencySubtree(ctx context.Context, tenantID shared.ID, key, root string) ([]byte, string, error)
ExportProjectDependencySubtree renders the selected component and every dependency below it as CycloneDX. An empty root exports the complete latest Project SBOM.
func (*Service) GetAnalysis ¶
func (s *Service) GetAnalysis(ctx context.Context, tenantID shared.ID, key, id string) (projectanalysis.Analysis, error)
GetAnalysis returns one snapshot without disclosing another Project's history.
func (*Service) GetBehavioralHotspots ¶ added in v0.2.0
func (s *Service) GetBehavioralHotspots(ctx context.Context, tenantID shared.ID, projectKey, analysisID, path string, limit int) (BehavioralHotspotsResponse, error)
GetBehavioralHotspots returns a bounded ranking from one immutable analysis. It never reads the working tree or invokes Git, so historical analyses cannot change underneath callers.
func (*Service) GetHotspot ¶
func (s *Service) GetHotspot(ctx context.Context, tenantID shared.ID, key string, hotspotID shared.ID) (hotspot.Hotspot, error)
GetHotspot returns one projection only after the Project has been resolved in the caller's tenant.
func (*Service) GetIssue ¶
func (s *Service) GetIssue(ctx context.Context, tenantID shared.ID, key string, issueID shared.ID) (issue.Issue, error)
GetIssue returns one issue only after the Project is resolved in the caller's tenant.
func (*Service) GetMeasures ¶
func (s *Service) GetMeasures(ctx context.Context, tenantID, projectKey, path string, domains []string, limit int, cursorStr string) (ProjectMeasureResponse, error)
GetMeasures retrieves the measure node and its direct children for a specific path.
func (*Service) HotspotHistory ¶
func (s *Service) HotspotHistory(ctx context.Context, tenantID shared.ID, key string, hotspotID shared.ID) ([]hotspot.ReviewEvent, error)
HotspotHistory returns the immutable review event history of a hotspot.
func (*Service) ImportAnalysis ¶ added in v0.2.0
func (s *Service) ImportAnalysis(ctx context.Context, tenantID shared.ID, key string, in ImportAnalysisInput) (projectanalysis.Analysis, error)
ImportAnalysis records a pipeline-produced scan result as an immutable project analysis.
This is the join the product lacked: synapse-cli was a self-contained gate whose result died with the process, and the console was fed only by scans the server ran itself. Everything after the scan is shared with the server path, on purpose. The same recorder builds the same aggregate, so the analysis takes its place in the history, moves the trend, evaluates the project's managed quality gate, and carries ratings, issues and hotspots exactly as a server analysis would. The only things that differ are what the pipeline is trusted to say: the source is the pipeline's checkout and the branch and commit are the pipeline's claim, which is why the analysis is marked OriginCI and carries the CI context for the reader to see.
The gate is deliberately NOT taken from the payload. The project's managed gate is the server's policy, and a pipeline that could ship its own gate definition could ship a passing one.
func (*Service) IssueHistory ¶
func (s *Service) IssueHistory(ctx context.Context, tenantID shared.ID, key string, issueID shared.ID) ([]issue.ReviewEvent, error)
IssueHistory returns the immutable, append-only lifecycle history of an issue.
func (*Service) LatestAnalysis ¶
func (s *Service) LatestAnalysis(ctx context.Context, tenantID shared.ID, key, branch string) (LatestAnalysis, error)
LatestAnalysis returns the newest completed analysis. An empty branch means the latest across all branches (the default); a non-empty branch restricts the result to that branch.
func (*Service) ListAnalyses ¶
func (s *Service) ListAnalyses(ctx context.Context, tenantID shared.ID, key, branch string, limit int, beforeCreatedAt time.Time, beforeID shared.ID) ([]projectanalysis.Analysis, bool, error)
ListAnalyses returns one immutable Project history page, newest first. An empty branch means all branches; a non-empty branch restricts the page to analyses produced on that branch.
func (*Service) ListCodeFiles ¶ added in v0.1.8
func (s *Service) ListCodeFiles(ctx context.Context, tenantID shared.ID, key, analysisID string) ([]CodeFile, projectanalysis.SourceCapabilities, error)
ListCodeFiles returns the immutable snapshot inventory enriched with retained-source state.
func (*Service) ListCodeFilesWithFilter ¶ added in v0.1.8
func (s *Service) ListCodeFilesWithFilter(ctx context.Context, tenantID shared.ID, key, analysisID string, filter CodeFileFilter) ([]CodeFile, projectanalysis.SourceCapabilities, error)
ListCodeFilesWithFilter derives the inventory only from persisted analysis metadata.
func (*Service) ListHotspots ¶
func (s *Service) ListHotspots(ctx context.Context, tenantID shared.ID, key string, filter hotspot.ListFilter) (hotspot.Page, error)
ListHotspots returns projections belonging to the requested tenant and Project for the current analysis lens.
func (*Service) ListIssues ¶
func (s *Service) ListIssues(ctx context.Context, tenantID shared.ID, key string, filter issue.ListFilter) (issue.Page, error)
ListIssues returns the tenant- and Project-scoped code-quality issues for the faceted explorer. Cross-tenant/unknown projects resolve to not-found via Get.
func (*Service) ListSummaries ¶
ListSummaries serves the unpaginated Project portfolio without browser-side N+1 requests. add cursor pagination plus server-side filters when returning a tenant's full searchable portfolio becomes materially expensive.
func (*Service) Overview ¶
func (s *Service) Overview(ctx context.Context, tenantID shared.ID, key, branch string) (Overview, error)
Overview summarizes the project's newest analysis. An empty branch reflects the latest overall analysis; a non-empty branch reflects that branch's newest completed analysis.
func (*Service) ProjectDependencyGraph ¶ added in v0.2.0
func (s *Service) ProjectDependencyGraph(ctx context.Context, tenantID shared.ID, key string) (DependencyGraph, error)
ProjectDependencyGraph returns the latest analysis's dependency graph without exposing the entire cached scan result. Tenant ownership is resolved before the immutable result is read.
func (*Service) PublishSource ¶ added in v0.1.8
func (s *Service) PublishSource(ctx context.Context, in PublishSourceInput) (projectanalysis.SourceManifest, error)
PublishSource contributes source bytes to an already-created server-owned analysis. It never creates an analysis and never lets the caller choose an artifact namespace.
func (*Service) ReadCodeDiff ¶ added in v0.1.8
func (s *Service) ReadCodeDiff(ctx context.Context, tenantID shared.ID, key, analysisID, path, view string, contextLines int) (CodeDiffView, projectanalysis.SourceCapabilities, error)
ReadCodeDiff serves scan-time persisted hunk data. Git is never called from this read path.
func (*Service) ReadCodeFile ¶ added in v0.1.8
func (s *Service) ReadCodeFile(ctx context.Context, tenantID shared.ID, key, analysisID, path string, fromLine, toLine int) (CodeFileView, projectanalysis.SourceCapabilities, error)
ReadCodeFile resolves exact analysis ownership before reading one bounded source window.
func (*Service) RecordProjectAnalysis ¶
func (s *Service) RecordProjectAnalysis(ctx context.Context, engagementID shared.ID, jobID string, completedAt time.Time, result *scauc.ScanResult) error
RecordProjectAnalysis is called by SCA only after a successful pipeline and before its ScanJob becomes succeeded. Non-Project scans intentionally no-op.
func (*Service) SetAnalysisStore ¶
func (s *Service) SetAnalysisStore(store ports.ProjectAnalysisStore)
func (*Service) SetArchiveStore ¶
func (s *Service) SetArchiveStore(store ports.ProjectArchiveStore)
func (*Service) SetCursorSecret ¶
SetCursorSecret injects the HMAC signing key for pagination cursors. Returns an error when the key is absent or shorter than 32 bytes. The byte slice is copied so later caller mutation cannot alter the service key.
func (*Service) SetFindingRepository ¶
func (s *Service) SetFindingRepository(repo ports.FindingRepository)
func (*Service) SetHotspotStore ¶
func (s *Service) SetHotspotStore(store ports.ProjectHotspotStore)
func (*Service) SetIssueStore ¶
func (s *Service) SetIssueStore(store ports.ProjectIssueStore)
func (*Service) SetPRDecorator ¶ added in v0.2.0
func (s *Service) SetPRDecorator(decorator ports.PRDecorator)
func (*Service) SetProjectAnalysisCompletionTimeout ¶ added in v0.1.8
func (*Service) SetPullRequestDecoration ¶ added in v0.2.0
func (s *Service) SetPullRequestDecoration(ctx context.Context, actor string, tenantID shared.ID, key string, enabled bool) (*project.Project, error)
SetPullRequestDecoration toggles the project's opt-in to forge PR decoration. Decoration stays off for every project until this is enabled, so no project performs an outward forge write by default.
func (*Service) SetQualityGateMutator ¶
func (s *Service) SetQualityGateMutator(mutator ports.QualityGateMutator)
func (*Service) SetQualityGates ¶
func (s *Service) SetQualityGates(gates *qualitygatesuc.Service)
func (*Service) SetQualityProfiles ¶
func (s *Service) SetQualityProfiles(profiles *qualityprofilesuc.Service)
func (*Service) SetRuleCatalog ¶
func (s *Service) SetRuleCatalog(catalog ports.RuleCatalog)
func (*Service) SetScanJobs ¶ added in v0.2.0
func (s *Service) SetScanJobs(jobs ports.ScanJobStore)
SetScanJobs lets an imported analysis leave a scan-job record behind, so the project's analysis status and its job history show the CI run the same way they show a server run.
func (*Service) SetScanner ¶
func (*Service) SetShortLivedBranchKeep ¶ added in v0.2.0
SetShortLivedBranchKeep sets how many of the newest analyses to keep on a short-lived (feature/PR) branch; older ones are pruned after each new analysis. A value < 1 disables pruning (keep all).
func (*Service) SetSourceArtifactStore ¶ added in v0.1.8
func (s *Service) SetSourceArtifactStore(store ports.ProjectSourceArtifactStore)
func (*Service) StartAnalysis ¶
func (*Service) TransitionHotspot ¶
func (s *Service) TransitionHotspot(ctx context.Context, actor string, tenantID shared.ID, key string, hotspotID shared.ID, to hotspot.Status, rationale string, expectedVersion int) (hotspot.Hotspot, hotspot.ReviewEvent, error)
TransitionHotspot applies a human review decision to a hotspot.
func (*Service) TransitionIssue ¶
func (s *Service) TransitionIssue(ctx context.Context, actor string, tenantID shared.ID, key string, issueID shared.ID, to issue.Status, rationale string, expectedVersion int) (issue.Issue, issue.ReviewEvent, error)
TransitionIssue applies an attributable, gate-affecting triage decision to an issue.
type SizeMeasures ¶
type SizeMeasures struct {
Files MeasureCountMetric `json:"files"`
NCLOC MeasureCountMetric `json:"ncloc"`
CommentLines MeasureCountMetric `json:"comment_lines"`
BlankLines MeasureCountMetric `json:"blank_lines"`
Functions MeasureCountMetric `json:"functions"`
CommentDensity MeasureDecimalMetric `json:"comment_density"`
}
SizeMeasures encapsulates size-related metrics such as line counts and functions.
type UnavailableReason ¶
type UnavailableReason string
const ( ReasonNoAnalysis UnavailableReason = "no_analysis" ReasonRatingNotAvailable UnavailableReason = "rating_not_available" ReasonIssueLifecycleNotAvailable UnavailableReason = "issue_lifecycle_not_available" ReasonSecurityHotspotsNotAvailable UnavailableReason = "security_hotspots_not_available" ReasonChangedLineMetricsNotAvailable UnavailableReason = "changed_line_metrics_not_available" ReasonCoverageNotSupplied UnavailableReason = "coverage_not_supplied" ReasonNoExecutableLines UnavailableReason = "no_executable_lines" ReasonDuplicationNotAvailable UnavailableReason = "duplication_not_available" )