exploitdata

package
v0.135.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 26, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package exploitdata turns a scan's exploitability settings into the KEV and EPSS data its prioritizer ranks with, and describes where that data came from.

Both `draugr scan` and the MCP scan tool load it here, so a descriptor's config.exploitability ranks the same findings the same way whichever of them started the run.

Index

Constants

View Source
const (
	Auto  = "auto"  // read the cache, fetching when it is missing or stale
	Cache = "cache" // read the cache and never touch the network
)

Keywords accepted in place of a path, by --kev and --epss and by config.exploitability.

View Source
const DefaultThreshold = 0.5

DefaultThreshold is the EPSS probability at or above which a finding is raised one band when nothing else sets one.

Variables

View Source
var Fetch = feeds.Fetch

Fetch is feeds.Fetch, indirected so tests can exercise `auto` without a network.

Functions

func Load

Load builds an exploitability source and describes the data it was built from. Returns nil when neither signal is configured, which disables enrichment.

The provenance comes back alongside the source rather than being derivable from it, because only this function knows whether a value was a cache entry with a fetch date or a file someone handed us, and a report that raised a finding to critical has to be able to say which.

Types

type Resolved

type Resolved struct {
	Path   string
	Record feeds.Record
	Stale  bool
}

Resolved is where a feed's data came from: the path to read, and what the cache knew about it. The record is zero for a file the operator named. There is no fetch to describe.

func Resolve

func Resolve(ctx context.Context, n feeds.Name, value, from string, maxAge time.Duration, cacheOnly bool) (Resolved, error)

Resolve turns a setting into a path on disk.

Anything that is not one of the two keywords is a path, used as given, the air-gapped route, unchanged. Cache reads what `draugr feeds update` left and never reaches the network, which is what CI should use: the fetch is then a step that can fail visibly on its own. Auto fetches when the cache is missing or stale, for someone at a laptop who should not have to think about it, unless cacheOnly is set.

type Settings

type Settings struct {
	KEV       string // a path, Cache, Auto, or "" for off
	EPSS      string
	Threshold float64
	MaxAge    time.Duration
	// KEVFrom and EPSSFrom name where each value came from, so an error can point at the thing
	// the reader would have to edit. "--kev" or "config.exploitability.kev".
	KEVFrom  string
	EPSSFrom string
	// ThresholdFrom is the same for the EPSS threshold, and travels further: it goes into the
	// report, because the line a score was measured against is a decision somebody made and the
	// finding it raised cannot be argued with unless the report says who made it.
	ThresholdFrom string
	// CacheOnly reads Auto as Cache. A caller that has not been given leave to reach the network
	// or write to the feed cache sets it, and a missing feed is then an error naming the command
	// that fetches it.
	CacheOnly bool
}

Settings is the settled configuration for enrichment.

func FromDescriptor

func FromDescriptor(cfg *saga.ExploitabilityConfig, threshold float64) Settings

FromDescriptor is the descriptor's settings alone, with threshold as the value used when the descriptor sets none.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL