Documentation
¶
Overview ¶
Package exploitdata turns a scan's exploitability settings into the KEV and EPSS data its prioritizer ranks with, and describes where that data came from.
Both `draugr scan` and the MCP scan tool load it here, so a descriptor's config.exploitability ranks the same findings the same way whichever of them started the run.
Index ¶
Constants ¶
const ( Auto = "auto" // read the cache, fetching when it is missing or stale Cache = "cache" // read the cache and never touch the network )
Keywords accepted in place of a path, by --kev and --epss and by config.exploitability.
const DefaultThreshold = 0.5
DefaultThreshold is the EPSS probability at or above which a finding is raised one band when nothing else sets one.
Variables ¶
var Fetch = feeds.Fetch
Fetch is feeds.Fetch, indirected so tests can exercise `auto` without a network.
Functions ¶
func Load ¶
Load builds an exploitability source and describes the data it was built from. Returns nil when neither signal is configured, which disables enrichment.
The provenance comes back alongside the source rather than being derivable from it, because only this function knows whether a value was a cache entry with a fetch date or a file someone handed us, and a report that raised a finding to critical has to be able to say which.
Types ¶
type Resolved ¶
Resolved is where a feed's data came from: the path to read, and what the cache knew about it. The record is zero for a file the operator named. There is no fetch to describe.
func Resolve ¶
func Resolve(ctx context.Context, n feeds.Name, value, from string, maxAge time.Duration, cacheOnly bool) (Resolved, error)
Resolve turns a setting into a path on disk.
Anything that is not one of the two keywords is a path, used as given, the air-gapped route, unchanged. Cache reads what `draugr feeds update` left and never reaches the network, which is what CI should use: the fetch is then a step that can fail visibly on its own. Auto fetches when the cache is missing or stale, for someone at a laptop who should not have to think about it, unless cacheOnly is set.
type Settings ¶
type Settings struct {
KEV string // a path, Cache, Auto, or "" for off
EPSS string
Threshold float64
MaxAge time.Duration
// KEVFrom and EPSSFrom name where each value came from, so an error can point at the thing
// the reader would have to edit. "--kev" or "config.exploitability.kev".
KEVFrom string
EPSSFrom string
// ThresholdFrom is the same for the EPSS threshold, and travels further: it goes into the
// report, because the line a score was measured against is a decision somebody made and the
// finding it raised cannot be argued with unless the report says who made it.
ThresholdFrom string
// CacheOnly reads Auto as Cache. A caller that has not been given leave to reach the network
// or write to the feed cache sets it, and a missing feed is then an error naming the command
// that fetches it.
CacheOnly bool
}
Settings is the settled configuration for enrichment.
func FromDescriptor ¶
func FromDescriptor(cfg *saga.ExploitabilityConfig, threshold float64) Settings
FromDescriptor is the descriptor's settings alone, with threshold as the value used when the descriptor sets none.