Documentation
¶
Overview ¶
Package inventory lists what a source tree holds that a control has something to say about: dependency files, vendored JavaScript, infrastructure code, Dockerfiles and API documents.
It is what `draugr init` reads to decide what a descriptor enables. Dependency files come from internal/manifests, so the files init proposes a scanner for are the files a scan later accounts for, and the two cannot disagree about what counts as one.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Tree ¶
type Tree struct {
// Dependencies are the files that declare or pin packages.
Dependencies []manifests.File
// Unresolved are the dependency files a manifest scanner takes no packages from: a declared
// manifest with no lockfile, a requirements file with no exact version.
Unresolved []manifests.Unread
// TrivyUnread are dependency files Trivy does not read and Grype does.
TrivyUnread []manifests.File
// Go are the directories holding a go.mod that requires something.
Go []string
// VendoredJS are JavaScript files committed as copies of a library rather than written here.
VendoredJS []string
// Terraform are the directories holding a .tf file.
Terraform []string
// Kubernetes are manifests outside a Helm chart.
Kubernetes []string
// Helm are the directories holding a Chart.yaml.
Helm []string
// Dockerfiles are the files an image is built from.
Dockerfiles []string
// OpenAPI are OpenAPI and Swagger documents.
OpenAPI []string
// Parts are the directories below the root that hold their own dependency file, the units a
// monorepo is made of.
Parts []string
}
Tree is what a directory holds. Every path is slash-separated and relative to the root.
Click to show internal directories.
Click to hide internal directories.