Documentation
¶
Index ¶
- Variables
- func BaseRiskScore(ut UpdateType) int
- func DetectBreakingChanges(body string) bool
- func FactorsToJSON(factors map[string]RiskFactor) string
- func ParseTag(tag string) (*semver.Version, error)
- func ParseTagOSVariant(tag string) (string, bool)
- func SortTags(tags []string) []*semver.Version
- type CVECacheEntry
- type CVEClient
- type CVEEvaluation
- type CVEEvaluationStatus
- type CVESeverity
- type CVSSMetrics
- type ChangelogResolver
- func (cr *ChangelogResolver) FetchLatestReleases(ctx context.Context, owner, repo string, count int) ([]ReleaseInfo, error)
- func (cr *ChangelogResolver) ResolveChangelog(ctx context.Context, imageRef, latestTag string) (changelogURL, summary string, hasBreaking bool, sourceURL string)
- func (cr *ChangelogResolver) ResolveSourceURL(ctx context.Context, imageRef string) (string, error)
- type ContainerCVE
- type ContainerInfo
- type ContainerLister
- type ContainerServiceAdapter
- func (a *ContainerServiceAdapter) GetContainerInfo(ctx context.Context, externalID string) (ContainerInfo, error)
- func (a *ContainerServiceAdapter) ListContainerInfos(ctx context.Context) ([]ContainerInfo, error)
- func (a *ContainerServiceAdapter) WithLabelFetcher(lf LabelFetcher) *ContainerServiceAdapter
- type Deps
- type DigestBaseline
- type DigestReport
- type EcosystemResolver
- type EcosystemResult
- type Enricher
- type EventCallback
- type ExclusionType
- type ImageCVEQuery
- type ImageUpdate
- type LabelFetcher
- type ListCVEsOpts
- type ListImageUpdatesOpts
- type ProEnricher
- type RegistryClient
- func (rc *RegistryClient) GetConfigLabels(ctx context.Context, imageRef string) (map[string]string, error)
- func (rc *RegistryClient) GetDigest(ctx context.Context, imageRef string) (string, error)
- func (rc *RegistryClient) GetManifest(ctx context.Context, imageRef string) (*remote.Descriptor, error)
- func (rc *RegistryClient) ListTags(ctx context.Context, imageRef string) ([]string, error)
- type ReleaseInfo
- type RiskContext
- type RiskEngine
- type RiskFactor
- type RiskLevel
- type RiskScore
- type RiskScoreRecord
- type ScanError
- type ScanRecord
- type ScanStatus
- type Scanner
- type Service
- func (s *Service) GenerateFixCommand(c ContainerInfo, currentTag, fixedInVersion string) string
- func (s *Service) GenerateRollbackCommand(c ContainerInfo, previousDigest string) string
- func (s *Service) GenerateUpdateCommand(c ContainerInfo, latestTag string) string
- func (s *Service) GetImageUpdateByContainer(ctx context.Context, containerID string) (*ImageUpdate, error)
- func (s *Service) GetLastScanTime() time.Time
- func (s *Service) GetLatestScanRecord(ctx context.Context) (*ScanRecord, error)
- func (s *Service) GetNextScanTime() time.Time
- func (s *Service) GetScanRecord(ctx context.Context, id string) (*ScanRecord, error)
- func (s *Service) GetUpdateSummary(ctx context.Context) (*UpdateSummary, error)
- func (s *Service) IsFixedByUpdate(latestTag, fixedInVersion string) bool
- func (s *Service) IsScanning() bool
- func (s *Service) ListImageUpdates(ctx context.Context, opts ListImageUpdatesOpts) ([]*ImageUpdate, error)
- func (s *Service) SetAlertChannel(ch chan<- interface{})
- func (s *Service) SetEnricher(e Enricher)
- func (s *Service) SetEventCallback(fn EventCallback)
- func (s *Service) Start(ctx context.Context)
- func (s *Service) TriggerScan(_ context.Context) (string, error)
- type StaleImageUpdate
- type Status
- type TagFilter
- type UpdateConfig
- type UpdateExclusion
- type UpdateResult
- type UpdateStore
- type UpdateSummary
- type UpdateType
- type VersionPin
Constants ¶
This section is empty.
Variables ¶
var ErrInvalidCVSS = errors.New("invalid CVSS v3 vector")
ErrInvalidCVSS reports a malformed or incomplete CVSS v3.x base vector.
Functions ¶
func BaseRiskScore ¶
func BaseRiskScore(ut UpdateType) int
BaseRiskScore returns a risk score based on semver update type. CE uses this as the final score. Pro can enrich further with CVE data.
func DetectBreakingChanges ¶
DetectBreakingChanges scans release body text for breaking change indicators.
func FactorsToJSON ¶
func FactorsToJSON(factors map[string]RiskFactor) string
FactorsToJSON serializes risk factors to JSON for storage.
func ParseTag ¶
ParseTag attempts to parse a Docker tag as a semver version. Returns nil, error for non-semver tags like "latest", "alpine".
func ParseTagOSVariant ¶ added in v1.1.0
ParseTagOSVariant detects an OS variant from an image tag suffix. Returns the OSV ecosystem identifier and true if a variant was detected.
Types ¶
type CVECacheEntry ¶
type CVECacheEntry struct {
ID string `json:"id"`
Ecosystem string `json:"ecosystem"`
PackageName string `json:"package_name"`
PackageVersion string `json:"package_version"`
CVEID string `json:"cve_id"`
CVSSScore float64 `json:"cvss_score"`
CVSSVector string `json:"cvss_vector"`
Severity CVESeverity `json:"severity"`
Summary string `json:"summary"`
FixedIn string `json:"fixed_in"`
ReferencesJSON string `json:"references_json"`
FetchedAt time.Time `json:"fetched_at"`
ExpiresAt time.Time `json:"expires_at"`
}
CVECacheEntry caches CVE lookup results from OSV.dev.
type CVEClient ¶
type CVEClient struct {
// contains filtered or unexported fields
}
CVEClient queries OSV.dev for known vulnerabilities.
func NewCVEClient ¶
func NewCVEClient(store UpdateStore, logger *slog.Logger) *CVEClient
NewCVEClient creates a CVE lookup client.
func (*CVEClient) QueryCVEs ¶
func (c *CVEClient) QueryCVEs(ctx context.Context, queries []ImageCVEQuery) (map[string][]*CVECacheEntry, error)
QueryCVEs queries OSV.dev for a batch of images and returns CVEs, hydrating each vulnerability id returned by the batch endpoint with its full record.
type CVEEvaluation ¶ added in v1.5.0
type CVEEvaluation struct {
ContainerID string `json:"container_id"`
Status CVEEvaluationStatus `json:"status"`
EvaluatedAt time.Time `json:"evaluated_at"`
Ecosystem string `json:"ecosystem,omitempty"`
PackageName string `json:"package_name,omitempty"`
PackageVersion string `json:"package_version,omitempty"`
Error string `json:"error,omitempty"`
}
CVEEvaluation records that a container went through CVE analysis, and how it went, so an unevaluated container is never mistaken for a clean one.
type CVEEvaluationStatus ¶ added in v1.5.0
type CVEEvaluationStatus string
CVEEvaluationStatus records the outcome of a container's CVE analysis.
const ( CVEEvaluated CVEEvaluationStatus = "evaluated" CVEUnsupported CVEEvaluationStatus = "unsupported" CVEEvaluationError CVEEvaluationStatus = "error" )
type CVESeverity ¶
type CVESeverity string
CVESeverity classifies the severity of a CVE.
const ( CVESeverityCritical CVESeverity = "critical" CVESeverityHigh CVESeverity = "high" CVESeverityMedium CVESeverity = "medium" CVESeverityLow CVESeverity = "low" CVESeverityUnknown CVESeverity = "unknown" )
func SeverityForScore ¶ added in v1.5.0
func SeverityForScore(score float64) CVESeverity
SeverityForScore maps a CVSS base score to its qualitative severity rating.
type CVSSMetrics ¶ added in v1.5.0
type CVSSMetrics struct {
Version string
AV string
AC string
PR string
UI string
S string
C string
I string
A string
}
CVSSMetrics is a parsed CVSS v3.0/v3.1 base vector.
func ParseCVSSv3 ¶ added in v1.5.0
func ParseCVSSv3(vector string) (CVSSMetrics, error)
ParseCVSSv3 parses a "CVSS:3.x/AV:../AC:../PR:../UI:../S:../C:../I:../A:.." base vector.
func (CVSSMetrics) BaseScore ¶ added in v1.5.0
func (m CVSSMetrics) BaseScore() float64
BaseScore computes the CVSS base score of the metrics using the v3.1 formulas (the v3.0 spec differs only in Roundup precision, not the score itself).
type ChangelogResolver ¶
type ChangelogResolver struct {
// contains filtered or unexported fields
}
ChangelogResolver fetches release notes from GitHub.
func NewChangelogResolver ¶
func NewChangelogResolver(registry *RegistryClient, logger *slog.Logger) *ChangelogResolver
NewChangelogResolver creates a changelog resolver.
func (*ChangelogResolver) FetchLatestReleases ¶
func (cr *ChangelogResolver) FetchLatestReleases(ctx context.Context, owner, repo string, count int) ([]ReleaseInfo, error)
FetchLatestReleases fetches the latest releases from a GitHub repository.
func (*ChangelogResolver) ResolveChangelog ¶
func (cr *ChangelogResolver) ResolveChangelog(ctx context.Context, imageRef, latestTag string) (changelogURL, summary string, hasBreaking bool, sourceURL string)
ResolveChangelog resolves changelog data for an image update.
func (*ChangelogResolver) ResolveSourceURL ¶
ResolveSourceURL extracts the source repository URL from OCI image labels.
type ContainerCVE ¶
type ContainerCVE struct {
ID string `json:"id"`
ContainerID string `json:"container_id"`
CVEID string `json:"cve_id"`
Severity CVESeverity `json:"severity"`
CVSSScore float64 `json:"cvss_score"`
Summary string `json:"summary"`
FixedIn string `json:"fixed_in"`
FirstDetectedAt time.Time `json:"first_detected_at"`
ResolvedAt *time.Time `json:"resolved_at,omitempty"`
}
ContainerCVE links a container to an active CVE.
type ContainerInfo ¶
type ContainerInfo struct {
UID string // canonical store PK (uid.Container) — used as alert EntityID
ExternalID string
Name string
Image string
Labels map[string]string
OrchestrationGroup string
OrchestrationUnit string
RuntimeType string
ControllerKind string
ComposeWorkingDir string
}
ContainerInfo holds the minimal container data needed for scanning.
type ContainerLister ¶
type ContainerLister interface {
ListContainerInfos(ctx context.Context) ([]ContainerInfo, error)
}
ContainerLister provides the list of containers to scan.
type ContainerServiceAdapter ¶
type ContainerServiceAdapter struct {
// contains filtered or unexported fields
}
ContainerServiceAdapter adapts container.Service to the ContainerLister interface.
func NewContainerServiceAdapter ¶
func NewContainerServiceAdapter(svc *container.Service) *ContainerServiceAdapter
NewContainerServiceAdapter creates a new adapter.
func (*ContainerServiceAdapter) GetContainerInfo ¶ added in v1.1.0
func (a *ContainerServiceAdapter) GetContainerInfo(ctx context.Context, externalID string) (ContainerInfo, error)
GetContainerInfo returns container metadata for a single container by external ID.
func (*ContainerServiceAdapter) ListContainerInfos ¶
func (a *ContainerServiceAdapter) ListContainerInfos(ctx context.Context) ([]ContainerInfo, error)
ListContainerInfos returns container info for all running containers.
func (*ContainerServiceAdapter) WithLabelFetcher ¶ added in v1.2.0
func (a *ContainerServiceAdapter) WithLabelFetcher(lf LabelFetcher) *ContainerServiceAdapter
WithLabelFetcher attaches a runtime label fetcher to the adapter. When set, ContainerInfo.Labels is populated with live runtime labels at scan time.
type Deps ¶ added in v1.1.0
type Deps struct {
Store UpdateStore // required
Scanner *Scanner // required
Containers ContainerLister // required
Logger *slog.Logger // required
Enricher Enricher // optional — defaults to no-op
EventCallback EventCallback // optional — nil-safe
AlertChan chan<- interface{} // optional — nil-safe
}
Deps holds all dependencies for the update Service.
type DigestBaseline ¶ added in v1.1.2
type DigestBaseline struct {
ContainerID string `json:"container_id"`
Image string `json:"image"`
Tag string `json:"tag"`
RemoteDigest string `json:"remote_digest"`
CheckedAt time.Time `json:"checked_at"`
}
DigestBaseline stores the last-known remote digest for a non-semver tag. Used to detect when a channel tag (e.g. "lts", "alpine") has been republished.
type DigestReport ¶
type DigestReport struct {
Critical []ImageUpdate `json:"critical"`
Recommended []ImageUpdate `json:"recommended"`
Available []ImageUpdate `json:"available"`
UpToDate int `json:"up_to_date"`
Untracked int `json:"untracked"`
TotalCVEs int `json:"total_cves"`
}
DigestReport is a structured summary of all updates for digest generation.
type EcosystemResolver ¶ added in v1.1.0
type EcosystemResolver struct {
// contains filtered or unexported fields
}
EcosystemResolver resolves container images to CVE ecosystems using a fallback chain: cache → static → local OCI labels → remote registry labels → tag heuristics → image name fallback.
func NewEcosystemResolver ¶ added in v1.1.0
func NewEcosystemResolver(registry *RegistryClient, logger *slog.Logger) *EcosystemResolver
NewEcosystemResolver creates an ecosystem resolver.
func (*EcosystemResolver) Resolve ¶ added in v1.1.0
func (r *EcosystemResolver) Resolve(ctx context.Context, image, tag, digest string, localLabels map[string]string) *EcosystemResult
Resolve determines the CVE ecosystem for a container image using a fallback chain. Returns nil if no ecosystem can be determined.
type EcosystemResult ¶ added in v1.1.0
type EcosystemResult struct {
PackageName string `json:"package_name"`
Ecosystem string `json:"ecosystem"`
DetectionMethod string `json:"detection_method"`
}
EcosystemResult holds the resolved CVE ecosystem for a container image.
type Enricher ¶ added in v1.1.0
type Enricher interface {
Enrich(ctx context.Context, results []UpdateResult) error
}
Enricher enriches raw scan results with additional data. CE: no-op (returns nil). Pro: runs an enrichment pipeline (CVE, changelog, risk).
type EventCallback ¶
type EventCallback func(eventType string, data interface{})
EventCallback is the function signature for SSE event broadcasting.
type ExclusionType ¶
type ExclusionType string
ExclusionType represents the type of exclusion pattern.
const ( ExclusionTypeImage ExclusionType = "image" ExclusionTypeTag ExclusionType = "tag" )
type ImageCVEQuery ¶
ImageCVEQuery holds parameters for querying CVEs for an image.
type ImageUpdate ¶
type ImageUpdate struct {
ID string `json:"id"`
ScanID string `json:"scan_id"`
ContainerID string `json:"container_id"`
ContainerName string `json:"container_name"`
Image string `json:"image"`
CurrentTag string `json:"current_tag"`
CurrentDigest string `json:"current_digest"`
Registry string `json:"registry"`
LatestTag string `json:"latest_tag,omitempty"`
LatestDigest string `json:"latest_digest,omitempty"`
UpdateType UpdateType `json:"update_type,omitempty"`
PublishedAt *time.Time `json:"published_at,omitempty"`
ChangelogURL string `json:"changelog_url,omitempty"`
ChangelogSummary string `json:"changelog_summary,omitempty"`
HasBreakingChanges bool `json:"has_breaking_changes"`
RiskScore int `json:"risk_score"`
PreviousDigest string `json:"previous_digest,omitempty"`
SourceURL string `json:"source_url,omitempty"`
Status Status `json:"status"`
DetectedAt time.Time `json:"detected_at"`
}
ImageUpdate stores a detected update per container image.
type LabelFetcher ¶ added in v1.2.0
type LabelFetcher interface {
FetchLabels(ctx context.Context) (map[string]map[string]string, error)
}
LabelFetcher retrieves raw container labels from the runtime. Returns a map of externalID -> labels. Implemented by docker.Runtime via a thin adapter. Returns nil (not an error) when the runtime doesn't support label fetching (e.g. Kubernetes).
type ListCVEsOpts ¶
ListCVEsOpts contains filter parameters for listing CVEs.
type ListImageUpdatesOpts ¶
ListImageUpdatesOpts contains filter parameters for listing image updates.
type ProEnricher ¶
type ProEnricher struct {
// contains filtered or unexported fields
}
ProEnricher enriches scan results with CVE data, changelog info, and risk scores.
func NewProEnricher ¶
func NewProEnricher(store UpdateStore, cve *CVEClient, changelog *ChangelogResolver, risk *RiskEngine, ecosystem *EcosystemResolver, logger *slog.Logger) *ProEnricher
NewProEnricher creates the full enrichment pipeline.
func (*ProEnricher) Enrich ¶
func (e *ProEnricher) Enrich(ctx context.Context, results []UpdateResult) error
Enrich runs a CVE pass for every scanned container, then resolves the changelog and risk score of those that actually have an update pending.
type RegistryClient ¶
type RegistryClient struct{}
RegistryClient wraps go-containerregistry for read-only registry operations.
func NewRegistryClient ¶
func NewRegistryClient() *RegistryClient
NewRegistryClient creates a new registry client.
func (*RegistryClient) GetConfigLabels ¶
func (rc *RegistryClient) GetConfigLabels(ctx context.Context, imageRef string) (map[string]string, error)
GetConfigLabels returns the OCI/Docker config labels for the given image reference.
func (*RegistryClient) GetDigest ¶
GetDigest returns the platform-specific digest for the given image reference. For multi-arch manifests, it resolves the platform matching the host OS/arch.
func (*RegistryClient) GetManifest ¶
func (rc *RegistryClient) GetManifest(ctx context.Context, imageRef string) (*remote.Descriptor, error)
GetManifest returns the raw manifest descriptor for the given image reference.
type ReleaseInfo ¶
type ReleaseInfo struct {
TagName string `json:"tag_name"`
Name string `json:"name"`
Body string `json:"body"`
PublishedAt time.Time `json:"published_at"`
HTMLURL string `json:"html_url"`
HasBreakingChanges bool `json:"has_breaking_changes"`
}
ReleaseInfo holds information about a GitHub release.
type RiskContext ¶
type RiskContext struct {
HasEndpointCheck bool
RestartCount int
DependentCount int
Criticality string // from maintenant.severity label
}
RiskContext provides monitoring context for risk calculation.
type RiskEngine ¶
type RiskEngine struct{}
RiskEngine computes contextual risk scores for containers with updates.
func (*RiskEngine) CalculateScore ¶
func (re *RiskEngine) CalculateScore(u *ImageUpdate, cves []*ContainerCVE, rctx RiskContext) RiskScore
CalculateScore computes a risk score (0-100) from update data and monitoring context.
type RiskFactor ¶
RiskFactor represents one factor contributing to the risk score.
type RiskLevel ¶
type RiskLevel string
RiskLevel classifies the risk level based on score.
func RiskLevelFromScore ¶
RiskLevelFromScore converts a numeric score to a risk level.
type RiskScore ¶
type RiskScore struct {
ContainerID string `json:"container_id"`
Score int `json:"score"`
Level RiskLevel `json:"level"`
Factors map[string]RiskFactor `json:"factors"`
}
RiskScore is the computed risk assessment for a container.
type RiskScoreRecord ¶
type RiskScoreRecord struct {
ID string `json:"id"`
ContainerID string `json:"container_id"`
Score int `json:"score"`
FactorsJSON string `json:"factors_json"`
RecordedAt time.Time `json:"recorded_at"`
}
RiskScoreRecord stores historical risk scores for trend tracking.
type ScanRecord ¶
type ScanRecord struct {
ID string `json:"id"`
StartedAt time.Time `json:"started_at"`
CompletedAt *time.Time `json:"completed_at,omitempty"`
ContainersScanned int `json:"containers_scanned"`
UpdatesFound int `json:"updates_found"`
Errors int `json:"errors"`
Status ScanStatus `json:"status"`
}
ScanRecord stores the result of each periodic scan cycle.
type ScanStatus ¶
type ScanStatus string
ScanStatus represents the lifecycle status of a scan cycle.
const ( ScanStatusRunning ScanStatus = "running" ScanStatusCompleted ScanStatus = "completed" ScanStatusFailed ScanStatus = "failed" )
type Scanner ¶
type Scanner struct {
// contains filtered or unexported fields
}
func NewScanner ¶
func NewScanner(registry *RegistryClient, store UpdateStore, logger *slog.Logger) *Scanner
NewScanner creates a new registry scanner.
func (*Scanner) Scan ¶
func (sc *Scanner) Scan(ctx context.Context, containers []ContainerInfo) ([]UpdateResult, []ScanError)
Scan checks all provided containers for available updates.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service orchestrates update detection and notification.
func NewService ¶
NewService creates the update intelligence service.
func (*Service) GenerateFixCommand ¶ added in v1.1.0
func (s *Service) GenerateFixCommand(c ContainerInfo, currentTag, fixedInVersion string) string
GenerateFixCommand produces a shell command to update a container to a specific CVE fix version. Returns empty string if fixedInVersion is not a valid semver or is <= currentTag (prevents downgrades).
func (*Service) GenerateRollbackCommand ¶ added in v1.1.0
func (s *Service) GenerateRollbackCommand(c ContainerInfo, previousDigest string) string
GenerateRollbackCommand produces a shell command to revert a container to its previous image digest.
func (*Service) GenerateUpdateCommand ¶
func (s *Service) GenerateUpdateCommand(c ContainerInfo, latestTag string) string
GenerateUpdateCommand produces a shell command to update a container.
func (*Service) GetImageUpdateByContainer ¶
func (s *Service) GetImageUpdateByContainer(ctx context.Context, containerID string) (*ImageUpdate, error)
GetImageUpdateByContainer returns the latest update for a container.
func (*Service) GetLastScanTime ¶
GetLastScanTime returns when the last scan completed.
func (*Service) GetLatestScanRecord ¶
func (s *Service) GetLatestScanRecord(ctx context.Context) (*ScanRecord, error)
GetLatestScanRecord returns the most recent scan record.
func (*Service) GetNextScanTime ¶
GetNextScanTime returns when the next scan is scheduled.
func (*Service) GetScanRecord ¶
GetScanRecord returns a scan record by ID.
func (*Service) GetUpdateSummary ¶
func (s *Service) GetUpdateSummary(ctx context.Context) (*UpdateSummary, error)
GetUpdateSummary returns the aggregated update counts.
func (*Service) IsFixedByUpdate ¶ added in v1.1.0
IsFixedByUpdate returns true when the latest available tag already covers the CVE fix version.
func (*Service) IsScanning ¶
IsScanning returns whether a scan is currently in progress.
func (*Service) ListImageUpdates ¶
func (s *Service) ListImageUpdates(ctx context.Context, opts ListImageUpdatesOpts) ([]*ImageUpdate, error)
ListImageUpdates returns filtered updates.
func (*Service) SetAlertChannel ¶
func (s *Service) SetAlertChannel(ch chan<- interface{})
SetAlertChannel sets the alert engine's event channel for critical notifications.
func (*Service) SetEnricher ¶
SetEnricher sets the update enricher (no-op in CE, CVE/changelog/risk in Pro).
func (*Service) SetEventCallback ¶
func (s *Service) SetEventCallback(fn EventCallback)
SetEventCallback sets the SSE broadcasting callback.
type StaleImageUpdate ¶ added in v1.3.0
type StaleImageUpdate struct {
ContainerID string
ContainerName string
// ContainerUID is the maintenant id, filled for findings whose container is
// gone from the scan set and can no longer be looked up by the caller. Empty
// when the container row itself has been deleted.
ContainerUID string
}
StaleImageUpdate identifies a pending update that a fresh scan no longer found (the container was upgraded). Both id and name are carried so the recovery event can resolve the alert by its real entity id.
type TagFilter ¶ added in v1.2.0
type TagFilter struct {
// contains filtered or unexported fields
}
TagFilter filters registry tag lists based on include/exclude regex patterns and the automatic variant suffix (e.g. "-alpine").
Priority rules:
- If include is set, only matching tags are kept (variant filter is skipped).
- If include is nil and variant is non-empty, the automatic variant filter applies.
- If exclude is set, matching tags are removed from the remaining set.
- Exclude always wins — applied last.
func NewTagFilter ¶ added in v1.2.0
NewTagFilter creates a TagFilter from optional include/exclude patterns and a variant suffix. Pass nil for include or exclude to disable those filters. Pass an empty string for variant to disable the automatic variant filter.
func (*TagFilter) Filter ¶ added in v1.2.0
Filter returns the subset of tags that pass the configured filters.
When include is set:
- keeps only tags matching the include regex
- the automatic variant filter is NOT applied (include takes full control)
When include is nil:
- applies the automatic variant filter if variant is non-empty
- all tags pass when variant is empty
After include/variant, exclude removes any remaining matching tags.
type UpdateConfig ¶
type UpdateConfig struct {
Enabled bool
Track string // "major", "minor", "patch", "digest"
Pin string // pinned tag
IgnoreMajor bool
Registry string // override registry
AlertOn string // "all", "critical", "none"
DigestOnly bool
TagInclude *regexp.Regexp // compiled tag-include regex, nil if absent/invalid
TagExclude *regexp.Regexp // compiled tag-exclude regex, nil if absent/invalid
}
UpdateConfig holds parsed maintenant.update.* label values.
func ParseUpdateLabels ¶
func ParseUpdateLabels(labels map[string]string, logger *slog.Logger) UpdateConfig
ParseUpdateLabels extracts update configuration from Docker container labels.
type UpdateExclusion ¶
type UpdateExclusion struct {
ID string `json:"id"`
Pattern string `json:"pattern"`
PatternType ExclusionType `json:"pattern_type"`
CreatedAt time.Time `json:"created_at"`
}
UpdateExclusion is a global exclusion rule for images or tags.
type UpdateResult ¶
type UpdateResult struct {
ContainerID string
ContainerName string
Image string
CurrentTag string
CurrentDigest string
Registry string
LatestTag string
LatestDigest string
UpdateType UpdateType
HasUpdate bool
ChangelogURL string
ChangelogSummary string
HasBreakingChanges bool
SourceURL string
PreviousDigest string
}
UpdateResult is the output of scanning a single container.
type UpdateStore ¶
type UpdateStore interface {
// Scan records
InsertScanRecord(ctx context.Context, r *ScanRecord) (string, error)
UpdateScanRecord(ctx context.Context, r *ScanRecord) error
GetScanRecord(ctx context.Context, id string) (*ScanRecord, error)
GetLatestScanRecord(ctx context.Context) (*ScanRecord, error)
// Image updates
InsertImageUpdate(ctx context.Context, u *ImageUpdate) (string, error)
UpdateImageUpdate(ctx context.Context, u *ImageUpdate) error
GetImageUpdate(ctx context.Context, id string) (*ImageUpdate, error)
GetImageUpdateByContainer(ctx context.Context, containerID string) (*ImageUpdate, error)
ListImageUpdates(ctx context.Context, opts ListImageUpdatesOpts) ([]*ImageUpdate, error)
GetUpdateSummary(ctx context.Context) (*UpdateSummary, error)
DeleteImageUpdatesByContainer(ctx context.Context, containerID string) error
DeleteStaleImageUpdates(ctx context.Context, scanID string, scannedContainerNames []string) (int64, error)
ListStaleImageUpdates(ctx context.Context, scanID string, scannedContainerNames []string) ([]StaleImageUpdate, error)
ListOrphanImageUpdates(ctx context.Context) ([]StaleImageUpdate, error)
DeleteOrphanImageUpdates(ctx context.Context) (int64, error)
// Version pins
InsertVersionPin(ctx context.Context, p *VersionPin) (string, error)
GetVersionPin(ctx context.Context, containerID string) (*VersionPin, error)
DeleteVersionPin(ctx context.Context, containerID string) error
// Update exclusions
InsertExclusion(ctx context.Context, e *UpdateExclusion) (string, error)
ListExclusions(ctx context.Context) ([]*UpdateExclusion, error)
DeleteExclusion(ctx context.Context, id string) error
// CVE cache
InsertCVECacheEntry(ctx context.Context, e *CVECacheEntry) (string, error)
GetCVECacheEntries(ctx context.Context, ecosystem, packageName, packageVersion string) ([]*CVECacheEntry, error)
IsCVECacheFresh(ctx context.Context, ecosystem, packageName, packageVersion string) (bool, error)
// Container CVEs
UpsertContainerCVE(ctx context.Context, c *ContainerCVE) error
ListContainerCVEs(ctx context.Context, containerID string) ([]*ContainerCVE, error)
ListAllActiveCVEs(ctx context.Context, opts ListCVEsOpts) ([]*ContainerCVE, error)
ResolveContainerCVE(ctx context.Context, containerID, cveID string) error
DeleteContainerCVEs(ctx context.Context, containerID string) error
GetCVESummaryCounts(ctx context.Context) (map[string]int, error)
// CVE evaluations
UpsertCVEEvaluation(ctx context.Context, e *CVEEvaluation) error
GetCVEEvaluation(ctx context.Context, containerID string) (*CVEEvaluation, error)
DeleteCVEEvaluation(ctx context.Context, containerID string) error
// Digest baselines (non-semver tags)
UpsertDigestBaseline(ctx context.Context, b *DigestBaseline) error
GetDigestBaseline(ctx context.Context, containerID string) (*DigestBaseline, error)
// Risk score history
InsertRiskScoreRecord(ctx context.Context, r *RiskScoreRecord) (string, error)
ListRiskScoreHistory(ctx context.Context, containerID string, from, to time.Time) ([]*RiskScoreRecord, error)
// Retention cleanup
CleanupExpired(ctx context.Context, olderThan time.Time) (int64, error)
}
UpdateStore defines the persistence interface for update intelligence data.
type UpdateSummary ¶
type UpdateSummary struct {
Critical int `json:"critical"`
Recommended int `json:"recommended"`
Available int `json:"available"`
UpToDate int `json:"up_to_date"`
Untracked int `json:"untracked"`
Pinned int `json:"pinned"`
}
UpdateSummary holds aggregated update counts.
type UpdateType ¶
type UpdateType string
UpdateType classifies the type of version update.
const ( UpdateTypeMajor UpdateType = "major" UpdateTypeMinor UpdateType = "minor" UpdateTypePatch UpdateType = "patch" UpdateTypeDigestOnly UpdateType = "digest_only" UpdateTypeUnknown UpdateType = "unknown" )
func ClassifyUpdate ¶
func ClassifyUpdate(current, latest *semver.Version) UpdateType
ClassifyUpdate determines the type of version bump between two versions.
func FindBestUpdate ¶
func FindBestUpdate(currentTag string, allTags []string) (bestTag string, updateType UpdateType)
FindBestUpdate finds the best available update for the given current tag among all tags. For pinned semver tags (major.minor.patch): finds the highest version with the same variant suffix (e.g. -alpine). For floating tags (non-semver channels like "latest" or "lts", and partial versions like "v3" or "1.2"), the registry already moves the tag to the newest release of that line, so a more precise tag underneath it is what the container runs, not an update. Only a higher tag of the same shape counts; otherwise the same tag is returned so the scanner compares digests.
type VersionPin ¶
type VersionPin struct {
ID string `json:"id"`
ContainerID string `json:"container_id"`
Image string `json:"image"`
PinnedTag string `json:"pinned_tag"`
PinnedDigest string `json:"pinned_digest"`
Reason string `json:"reason,omitempty"`
PinnedAt time.Time `json:"pinned_at"`
}
VersionPin tracks a pinned (intentionally frozen) image.