core/

directory
v0.2.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 3, 2026 License: Apache-2.0

Directories

Path Synopsis
Package baseline tracks codefit's view of a project's audited surface across scans.
Package baseline tracks codefit's view of a project's audited surface across scans.
Package cache defines the content-hash finding cache (PRD section 15, optimization 2).
Package cache defines the content-hash finding cache (PRD section 15, optimization 2).
Package context defines AuditContext, the immutable struct that carries everything a sensor needs about the project under audit: where it lives, its language and framework, the parsed config, and the run modifiers (incremental ref, no-LLM mode).
Package context defines AuditContext, the immutable struct that carries everything a sensor needs about the project under audit: where it lives, its language and framework, the parsed config, and the run modifiers (incremental ref, no-LLM mode).
Package coverage models codefit's coverage manifest (PRD section 10, RF-07): the explicit, per-language declaration of what codefit detects and what it does not.
Package coverage models codefit's coverage manifest (PRD section 10, RF-07): the explicit, per-language declaration of what codefit detects and what it does not.
Package crossrules is codefit's family of deterministic checks that reason over BOTH neutral inputs at once — the schema (db.Schema) AND the code's query filters (query.QueryFilter) — the code↔schema cross that index-vs-query needs (ADR 0029).
Package crossrules is codefit's family of deterministic checks that reason over BOTH neutral inputs at once — the schema (db.Schema) AND the code's query filters (query.QueryFilter) — the code↔schema cross that index-vs-query needs (ADR 0029).
Package cve checks project dependencies against known vulnerabilities via OSV.dev (PRD section 18, RF-09).
Package cve checks project dependencies against known vulnerabilities via OSV.dev (PRD section 18, RF-09).
Package db is codefit's neutral, format-agnostic model of a database's structure — the schema a DB-dimension rule reasons over, blind to where it came from (Prisma or SQL-DDL — both parsers ship today).
Package db is codefit's neutral, format-agnostic model of a database's structure — the schema a DB-dimension rule reasons over, blind to where it came from (Prisma or SQL-DDL — both parsers ship today).
Package dbcoverage holds the DB dimension's coverage prose — what the rules in core/dbrules actually detect, in the same plain-prose form the coverage manifest uses (PRD §10, RF-07).
Package dbcoverage holds the DB dimension's coverage prose — what the rules in core/dbrules actually detect, in the same plain-prose form the coverage manifest uses (PRD §10, RF-07).
Package dbrules holds codefit's deterministic database-structure rules.
Package dbrules holds codefit's deterministic database-structure rules.
Package dwrules is the paradigm-aware DW (data-warehouse) rule family: a SEPARATE two-argument Rule family from dbrules.Rule (schema-only), mirroring how internal/core/crossrules solved "a rule needs a fact beyond the bare schema" (ADR 0029) without mutating dbrules.Rule.
Package dwrules is the paradigm-aware DW (data-warehouse) rule family: a SEPARATE two-argument Rule family from dbrules.Rule (schema-only), mirroring how internal/core/crossrules solved "a rule needs a fact beyond the bare schema" (ADR 0029) without mutating dbrules.Rule.
Package findings defines the universal, language-agnostic vocabulary of an audit: the Finding hallazgo, its Severity and Dimension, the ConsentRecord that authorizes suppressing a critical security finding, and the SensorResult every sensor returns.
Package findings defines the universal, language-agnostic vocabulary of an audit: the Finding hallazgo, its Severity and Dimension, the ConsentRecord that authorizes suppressing a critical security finding, and the SensorResult every sensor returns.
Package paradigm computes a database schema's analytic-vs-transactional paradigm and each table's warehouse role, as a pure function over the neutral internal/core/db model.
Package paradigm computes a database schema's analytic-vs-transactional paradigm and each table's warehouse role, as a pure function over the neutral internal/core/db model.
Package pipeline defines the filtering pyramid (PRD section 15): cheap layers run first and only what they cannot conclude is escalated to the next, more expensive layer.
Package pipeline defines the filtering pyramid (PRD section 15): cheap layers run first and only what they cannot conclude is escalated to the next, more expensive layer.
Package query is codefit's neutral, format-agnostic model of a database query filter issued from application code — the CODE side of the code↔schema cross (index-vs-query), mirroring how internal/core/db models the SCHEMA side.
Package query is codefit's neutral, format-agnostic model of a database query filter issued from application code — the CODE side of the code↔schema cross (index-vs-query), mirroring how internal/core/db models the SCHEMA side.
Package report defines the canonical audit report and the renderers that present it.
Package report defines the canonical audit report and the renderers that present it.
Package ruleengine is codefit's own matcher for a subset of the Semgrep rule format (PRD section 17).
Package ruleengine is codefit's own matcher for a subset of the Semgrep rule format (PRD section 17).
Package scoring computes the per-dimension scores (0-100) and the weighted global score from a set of findings, using the configurable weights from .codefit.yaml (PRD RF-07).
Package scoring computes the per-dimension scores (0-100) and the weighted global score from a set of findings, using the configurable weights from .codefit.yaml (PRD RF-07).
Package sourcetext decodes the RAW BYTES of a file codefit was asked to read into the UTF-8 text every layer above it assumes it already has.
Package sourcetext decodes the RAW BYTES of a file codefit was asked to read into the UTF-8 text every layer above it assumes it already has.
Package surface is the core framework for surface mapping (PRD section 10): the language-agnostic home for surface categories and, in Fase 1, the SurfaceQuery format (codefit's own declarative format for enumerating auditable structural surface, distinct from the Semgrep-format rules used for deterministic findings — PRD section 17).
Package surface is the core framework for surface mapping (PRD section 10): the language-agnostic home for surface categories and, in Fase 1, the SurfaceQuery format (codefit's own declarative format for enumerating auditable structural surface, distinct from the Semgrep-format rules used for deterministic findings — PRD section 17).
Package syntax is codefit's parser-agnostic AST boundary.
Package syntax is codefit's parser-agnostic AST boundary.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL