internal/

directory
v0.138.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0

Directories

Path Synopsis
Package builtins assembles the default registry of controllers and scanners that ship with Draugr.
Package builtins assembles the default registry of controllers and scanners that ship with Draugr.
Package ciguard holds assertions about this repository's own CI configuration.
Package ciguard holds assertions about this repository's own CI configuration.
Package cli assembles the Draugr command-line interface on top of Cobra.
Package cli assembles the Draugr command-line interface on top of Cobra.
Package controllers holds Draugr's built-in controllers (e.g.
Package controllers holds Draugr's built-in controllers (e.g.
Package depsdev asks deps.dev what is known about the packages a scan found.
Package depsdev asks deps.dev what is known about the packages a scan found.
Package english forms the words a count is attached to.
Package english forms the words a count is attached to.
Package enrich builds the signals a scan ranks its findings with: exploitability, the age a cached feed may reach, and dependency health.
Package enrich builds the signals a scan ranks its findings with: exploitability, the age a cached feed may reach, and dependency health.
Package exploitdata turns a scan's exploitability settings into the KEV and EPSS data its prioritizer ranks with, and describes where that data came from.
Package exploitdata turns a scan's exploitability settings into the KEV and EPSS data its prioritizer ranks with, and describes where that data came from.
Package feeds fetches and caches the exploitability datasets Draugr can enrich findings with: CISA's Known Exploited Vulnerabilities catalog and FIRST's EPSS scores.
Package feeds fetches and caches the exploitability datasets Draugr can enrich findings with: CISA's Known Exploited Vulnerabilities catalog and FIRST's EPSS scores.
Package git provides repository checkouts for scanners that operate on source trees.
Package git provides repository checkouts for scanners that operate on source trees.
Package inventory lists what a source tree holds that a control has something to say about: dependency files, vendored JavaScript, infrastructure code, Dockerfiles and API documents.
Package inventory lists what a source tree holds that a control has something to say about: dependency files, vendored JavaScript, infrastructure code, Dockerfiles and API documents.
Package manifests recognizes the files in a tree that declare or pin dependencies, and accounts for the ones a dependency scan did not read.
Package manifests recognizes the files in a tree that declare or pin dependencies, and accounts for the ones a dependency scan did not read.
Package mcp exposes Draugr to AI coding agents over the Model Context Protocol.
Package mcp exposes Draugr to AI coding agents over the Model Context Protocol.
Package mendapi is the client for Mend's v1.3 API: the half of a Mend scan that returns findings.
Package mendapi is the client for Mend's v1.3 API: the half of a Mend scan that returns findings.
Package netpolicy holds one answer to one question: may this process reach the network?
Package netpolicy holds one answer to one question: may this process reach the network?
Package observability provides Draugr's logging and telemetry foundations: structured logging via log/slog and distributed tracing via OpenTelemetry.
Package observability provides Draugr's logging and telemetry foundations: structured logging via log/slog and distributed tracing via OpenTelemetry.
Package preflight checks that this machine can reach what a scan would read: each repository at its revision, the paths a component is scoped to, each image, each endpoint.
Package preflight checks that this machine can reach what a scan would read: each repository at its revision, the paths a component is scoped to, each image, each endpoint.
Package registry asks a container registry whether it will serve an image's manifest to this machine, with the credentials a scanner running here would use.
Package registry asks a container registry whether it will serve an image's manifest to this machine, with the credentials a scanner running here would use.
Package sagafetch fetches Saga fragments held in other repositories.
Package sagafetch fetches Saga fragments held in other repositories.
Package sagatest holds a descriptor to both of the readers that judge it: the JSON Schema an editor validates against, and the loader `draugr validate` runs.
Package sagatest holds a descriptor to both of the readers that judge it: the JSON Schema an editor validates against, and the loader `draugr validate` runs.
Package sbom generates Software Bills of Materials by shelling out to Syft.
Package sbom generates Software Bills of Materials by shelling out to Syft.
Package scaffold renders the starter Saga `draugr init` writes for a source tree.
Package scaffold renders the starter Saga `draugr init` writes for a source tree.
Package scanners holds Draugr's built-in scanners, which wrap individual security tools and normalize their output to SARIF.
Package scanners holds Draugr's built-in scanners, which wrap individual security tools and normalize their output to SARIF.
Package scanpolicy holds the scoring choices a scan makes, so every entry point into Draugr makes the same ones.
Package scanpolicy holds the scoring choices a scan makes, so every entry point into Draugr makes the same ones.
Package schemagen keeps the Saga JSON Schema's knowledge of controls in step with the registry that actually answers for them.
Package schemagen keeps the Saga JSON Schema's knowledge of controls in step with the registry that actually answers for them.
gen command
Command gen rewrites the Saga JSON Schema's generated sections from the plugin registry.
Command gen rewrites the Saga JSON Schema's generated sections from the plugin registry.
Package selfupdate updates the running draugr binary to a released version.
Package selfupdate updates the running draugr binary to a released version.
Package surfaces maps what a descriptor declares to the controls that look at it.
Package surfaces maps what a descriptor declares to the controls that look at it.
Package surveyors holds Draugr's built-in surveyors.
Package surveyors holds Draugr's built-in surveyors.
Package toolexec runs the external tools Draugr orchestrates, and reports what it ran.
Package toolexec runs the external tools Draugr orchestrates, and reports what it ran.
Package tools describes the external command-line scanners Draugr orchestrates and detects whether they are installed.
Package tools describes the external command-line scanners Draugr orchestrates and detects whether they are installed.
cmd/pinbump command
Command pinbump moves one pinned scanner to a new version and records what that version hashes to.
Command pinbump moves one pinned scanner to a new version and records what that version hashes to.
Package version carries build metadata, injected at link time via -ldflags.
Package version carries build metadata, injected at link time via -ldflags.
Package vexload resolves the VEX sources a descriptor names into documents a run can apply.
Package vexload resolves the VEX sources a descriptor names into documents a run can apply.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL