Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AddJasScannersTasks ¶ added in v1.4.0
func AddJasScannersTasks(params JasRunnerParams) error
Types ¶
type CveProvider ¶ added in v1.20.0
Cves are only available after the SCA scan is performed, so we need a provider to dynamically pass the discovered cves.
type JasRunnerParams ¶ added in v1.12.0
type JasRunnerParams struct {
Runner *utils.SecurityParallelRunner
ServerDetails *config.ServerDetails
Scanner *jas.JasScanner
// Module / Target flags
ConfigProfile *services.ConfigProfile
TargetCount int
ScanResults *results.TargetResults
// Scan flags
AllowPartialResults bool
ScansToPerform []utils.SubScanType
// Diff mode flags
SourceResultsToCompare *results.TargetResults
ChangedFiles []string
DiffMode bool
// Secret scan flags
SecretsScanType secrets.SecretsScanType
SecretValidation bool
// Contextual Analysis scan flags
CvesProvider CveProvider
ApplicableScanType applicability.ApplicabilityScanType
ThirdPartyApplicabilityScan bool
ProjectKey string
// V3Flow is true for the V3 (SBOM-based) audit flow. Indirect CVE contextual (reachability) paths from
// Catalog are only ever fetched for this flow - the V2 graph-scan flow (e.g. binary scan) is out of scope.
V3Flow bool
// TransitiveContextualAnalysisEnabled is the caller's resolved gate for the transitive_contextual_analysis
// feature (entitlement check result, already false on error or when the underlying JAS entitlement is missing).
// Indirect CVE contextual paths are only fetched when true.
TransitiveContextualAnalysisEnabled bool
// SAST scan flags
SastChangedFilesMode bool
SignedDescriptions bool
SastRules string
// Outputs
TargetOutputDir string
}
Click to show internal directories.
Click to hide internal directories.