controllers

package
v0.20.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 17, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package controllers holds Draugr's built-in controllers (e.g. images, sast, opensource, dast), each orchestrating scanners for one security control.

See docs/ARCHITECTURE.md.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func NewHeaders added in v0.9.0

func NewHeaders() plugin.Controller

NewHeaders returns the headers controller.

func NewIAC added in v0.4.0

func NewIAC() plugin.Controller

NewIAC returns the iac controller.

func NewImages

func NewImages() plugin.Controller

NewImages returns the images controller.

func NewSAST added in v0.3.0

func NewSAST() plugin.Controller

NewSAST returns the sast controller.

func NewSCA

func NewSCA() plugin.Controller

NewSCA returns the sca controller.

func NewSecrets added in v0.2.0

func NewSecrets() plugin.Controller

NewSecrets returns the secrets controller.

func SASTScannerSet added in v0.14.0

func SASTScannerSet(model saga.Model) map[string]bool

SASTScannerSet returns the set of sast scanner names the model will actually run — the union of the selection across all components (each resolved against its override / the project default). Used to decide which sast tools are truly required (e.g. gosec only when selected), rather than every scanner that *could* serve the control.

func SeverityFloor added in v0.5.0

func SeverityFloor(control string) sarif.Severity

SeverityFloor returns the minimum normalized severity for a control's findings, or an empty severity (no floor) when the control declares none. Used by prioritization when resolving a finding's severity.

Types

type Headers added in v0.9.0

type Headers struct{}

Headers is the HTTP security-header control. It plans one native header scan per host declared on a component and aggregates the findings. No external tool is required.

func (Headers) Aggregate added in v0.9.0

func (Headers) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and summarizes findings by severity.

func (Headers) Info added in v0.9.0

func (Headers) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (Headers) Plan added in v0.9.0

func (Headers) Plan(_ saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces one scan job per host with a URL declared on the component.

type IAC added in v0.4.0

type IAC struct{}

IAC is the Infrastructure-as-Code / misconfiguration control: it scans a component's repositories for insecure IaC (Terraform, Kubernetes manifests, Dockerfiles, …). It plans one scan per repository.

func (IAC) Aggregate added in v0.4.0

func (IAC) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and summarizes findings by severity. Trivy reports per-check severity, so severity is taken as reported.

func (IAC) Info added in v0.4.0

func (IAC) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (IAC) Plan added in v0.4.0

func (IAC) Plan(_ saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces one scan job per repository declared on the component.

type Images

type Images struct{}

Images is the container-image security control. It plans one Trivy scan per image in a component and aggregates the results.

func (Images) Aggregate

func (Images) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and summarizes findings by severity.

func (Images) Info

func (Images) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (Images) Plan

func (Images) Plan(_ saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces one scan job per image declared on the component.

type SAST added in v0.3.0

type SAST struct{}

SAST is the Static Application Security Testing control: it analyzes a component's own source code (not its dependencies) for security bugs. It plans one scan per repository, per selected scanner.

func (SAST) Aggregate added in v0.3.0

func (SAST) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and summarizes findings by severity. Semgrep emits per-rule SARIF levels, so severity is taken as reported.

func (SAST) Info added in v0.3.0

func (SAST) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (SAST) Plan added in v0.3.0

func (SAST) Plan(model saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces a scan job for each repository × each selected sast scanner. The scanner set is controllers.sast.scanners (default [semgrep]); e.g. a Go component can opt into gosec alongside Semgrep with `scanners: [semgrep, gosec]`.

type SCA

type SCA struct{}

SCA is the Software Composition Analysis control: dependency vulnerabilities (and, later, licenses) for a component's source repositories. It plans one scan per repository.

func (SCA) Aggregate

func (SCA) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and summarizes findings by severity.

func (SCA) Info

func (SCA) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (SCA) Plan

func (SCA) Plan(_ saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces one scan job per repository declared on the component.

type Secrets added in v0.2.0

type Secrets struct{}

Secrets is the secret-detection control: it scans a component's repositories for leaked credentials. Any detected secret is treated as an error — a leaked secret should fail the gate regardless of how the scanner rated it.

func (Secrets) Aggregate added in v0.2.0

func (Secrets) Aggregate(reports []sarif.Report) (plugin.ControlResult, error)

Aggregate merges the scan reports and escalates every finding to error severity — a detected secret is always gate-failing.

func (Secrets) Info added in v0.2.0

func (Secrets) Info() plugin.ControllerInfo

Info identifies the controller (component-scoped).

func (Secrets) Plan added in v0.2.0

func (Secrets) Plan(_ saga.Model, comp *saga.Component) ([]plugin.ScanJob, error)

Plan produces one scan job per repository declared on the component.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL