inventory

package
v0.136.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Overview

Package inventory lists what a source tree holds that a control has something to say about: dependency files, vendored JavaScript, infrastructure code, Dockerfiles and API documents.

It is what `draugr init` reads to decide what a descriptor enables. Dependency files come from internal/manifests, so the files init proposes a scanner for are the files a scan later accounts for, and the two cannot disagree about what counts as one. A go.mod is found on its own as well, because the Go controls check a module that requires nothing and a scan has no packages to read from it.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Tree

type Tree struct {
	// Dependencies are the files that declare or pin packages.
	Dependencies []manifests.File
	// Unresolved are the dependency files a manifest scanner takes no packages from: a declared
	// manifest with no lockfile, a requirements file with no exact version.
	Unresolved []manifests.Unread
	// TrivyUnread are dependency files Trivy does not read and Grype does.
	TrivyUnread []manifests.File
	// TrivyByPattern are the requirements files Trivy reads only where trivyFs.filePatterns names
	// them: its pip analyzer opens requirements.txt and no other name.
	TrivyByPattern []manifests.File
	// Go are the directories holding a go.mod, whether or not it requires anything: standard-library
	// code still has SAST findings, and still builds with a toolchain that has advisories of its own.
	Go []string
	// VendoredJS are JavaScript files committed as copies of a library rather than written here.
	VendoredJS []string
	// Terraform are the directories holding a .tf file.
	Terraform []string
	// Kubernetes are manifests outside a Helm chart.
	Kubernetes []string
	// Helm are the directories holding a Chart.yaml.
	Helm []string
	// Dockerfiles are the files an image is built from.
	Dockerfiles []string
	// OpenAPI are OpenAPI and Swagger documents.
	OpenAPI []string
	// Parts are the directories below the root that hold their own dependency file or go.mod, the
	// units a monorepo is made of. A JavaScript workspace member, a directory the root package.json
	// or pnpm-workspace.yaml names, is not one by its package.json alone: the lockfile at the
	// workspace root resolves it, so it stays with that root.
	Parts []string
}

Tree is what a directory holds. Every path is slash-separated and relative to the root.

func Read

func Read(root string) Tree

Read walks root and returns what it holds.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL