Directories
¶
| Path | Synopsis |
|---|---|
|
Package archive writes reproducible tar.gz archives: for a given build of sealift, the same entries always give the same bytes.
|
Package archive writes reproducible tar.gz archives: for a given build of sealift, the same entries always give the same bytes. |
|
cmd
|
|
|
sealift
command
Command sealift serves the sealift backend.
|
Command sealift serves the sealift backend. |
|
internal
|
|
|
api
Package api provides primitives to interact with the openapi HTTP API.
|
Package api provides primitives to interact with the openapi HTTP API. |
|
jobs
Package jobs runs analysis and export jobs one at a time and streams their events to the interface.
|
Package jobs runs analysis and export jobs one at a time and streams their events to the interface. |
|
report
Package report builds the files an export writes beside its archive: manifest.json, findings.csv and summary.md.
|
Package report builds the files an export writes beside its archive: manifest.json, findings.csv and summary.md. |
|
runner
Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output.
|
Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output. |
|
store
Package store keeps sealift's data volume: settings, projects, analyses and exports.
|
Package store keeps sealift's data volume: settings, projects, analyses and exports. |
|
tools
Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses.
|
Package tools installs and manages the pnpm and Trivy binaries that sealift's jobs run as subprocesses. |
|
Package npm reads npm and pnpm data: package.json manifests, pnpm lockfiles, registry metadata and package tarballs.
|
Package npm reads npm and pnpm data: package.json manifests, pnpm lockfiles, registry metadata and package tarballs. |
|
Package rank scores vulnerability findings, flags risky candidate versions, and picks the best candidate version of a dependency.
|
Package rank scores vulnerability findings, flags risky candidate versions, and picks the best candidate version of a dependency. |
|
Package sbom writes CycloneDX software bills of materials for npm packages.
|
Package sbom writes CycloneDX software bills of materials for npm packages. |
|
Package web embeds the built frontend so cmd/sealift can serve it alongside the API, with no separate static asset directory to deploy.
|
Package web embeds the built frontend so cmd/sealift can serve it alongside the API, with no separate static asset directory to deploy. |
Click to show internal directories.
Click to hide internal directories.



