Directories
¶
| Path | Synopsis |
|---|---|
|
Package baseline tracks codefit's view of a project's audited surface across scans.
|
Package baseline tracks codefit's view of a project's audited surface across scans. |
|
Package cache defines the content-hash finding cache (PRD section 15, optimization 2).
|
Package cache defines the content-hash finding cache (PRD section 15, optimization 2). |
|
Package context defines AuditContext, the immutable struct that carries everything a sensor needs about the project under audit: where it lives, its language and framework, the parsed config, and the run modifiers (incremental ref, no-LLM mode).
|
Package context defines AuditContext, the immutable struct that carries everything a sensor needs about the project under audit: where it lives, its language and framework, the parsed config, and the run modifiers (incremental ref, no-LLM mode). |
|
Package coverage models codefit's coverage manifest (PRD section 10, RF-07): the explicit, per-language declaration of what codefit detects and what it does not.
|
Package coverage models codefit's coverage manifest (PRD section 10, RF-07): the explicit, per-language declaration of what codefit detects and what it does not. |
|
Package cve checks project dependencies against known vulnerabilities via OSV.dev (PRD section 18, RF-09).
|
Package cve checks project dependencies against known vulnerabilities via OSV.dev (PRD section 18, RF-09). |
|
Package findings defines the universal, language-agnostic vocabulary of an audit: the Finding hallazgo, its Severity and Dimension, the ConsentRecord that authorizes suppressing a critical security finding, and the SensorResult every sensor returns.
|
Package findings defines the universal, language-agnostic vocabulary of an audit: the Finding hallazgo, its Severity and Dimension, the ConsentRecord that authorizes suppressing a critical security finding, and the SensorResult every sensor returns. |
|
Package pipeline defines the filtering pyramid (PRD section 15): cheap layers run first and only what they cannot conclude is escalated to the next, more expensive layer.
|
Package pipeline defines the filtering pyramid (PRD section 15): cheap layers run first and only what they cannot conclude is escalated to the next, more expensive layer. |
|
Package report defines the canonical audit report and the renderers that present it.
|
Package report defines the canonical audit report and the renderers that present it. |
|
Package ruleengine is codefit's own matcher for a subset of the Semgrep rule format (PRD section 17).
|
Package ruleengine is codefit's own matcher for a subset of the Semgrep rule format (PRD section 17). |
|
Package scoring computes the per-dimension scores (0-100) and the weighted global score from a set of findings, using the configurable weights from .codefit.yaml (PRD RF-07).
|
Package scoring computes the per-dimension scores (0-100) and the weighted global score from a set of findings, using the configurable weights from .codefit.yaml (PRD RF-07). |
|
Package surface is the core framework for surface mapping (PRD section 10): the language-agnostic home for surface categories and, in Fase 1, the SurfaceQuery format (codefit's own declarative format for enumerating auditable structural surface, distinct from the Semgrep-format rules used for deterministic findings — PRD section 17).
|
Package surface is the core framework for surface mapping (PRD section 10): the language-agnostic home for surface categories and, in Fase 1, the SurfaceQuery format (codefit's own declarative format for enumerating auditable structural surface, distinct from the Semgrep-format rules used for deterministic findings — PRD section 17). |
|
Package syntax is codefit's parser-agnostic AST boundary.
|
Package syntax is codefit's parser-agnostic AST boundary. |
Click to show internal directories.
Click to hide internal directories.