ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Cve.Internal

Description

The advisory lookup's internals: the hardened SQLite open and the raw queries Ecluse.Core.Cve curates into the public handle.

Importing this module opts out of the public surface's stability promises. It exists so a test can pin the hardening properties against the connection the handle actually uses.

Synopsis

Documentation

data AdvisoryRange Source #

An advisory segment with nullable CVSS and EPSS scores and verbatim version bounds. The introduced bound is inclusive. Absence means the segment starts at the beginning.

Instances

Instances details
Show AdvisoryRange Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

Eq AdvisoryRange Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

data CveDbRejected Source #

Why the hardened open refused an artifact before building a handle over it. A rejection is a value, not a fault, so the caller can keep the last known-good database.

Constructors

CveDbWrongEpoch Int

The artifact's user_version differs from osvSchemaEpoch.

CveDbIntegrityFailed [Text]

SQLite refused the file or reported integrity faults, carrying its error or report.

CveDbSchemaNonConformant Text

A required relation is absent, non-strict, or lacks a column with its required type.

CveDbEcosystemMismatch (Maybe Text)

The ecosystem marker differs from the requested ecosystem or is absent.

CveDbEpssNotEstablished

Required feed enrichment lacks the exact success marker.

Instances

Instances details
Show CveDbRejected Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

Eq CveDbRejected Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

openHardenedConnection :: Ecosystem -> EpssRequirement -> FilePath -> IO (Either CveDbRejected Connection) Source #

Harden the connection before acceptance. SQLite's query-only pragma refuses writes. Rejection and opening faults close the connection before returning.

advisoriesQuery :: Connection -> Text -> IO [AdvisoryRange] Source #

Every advisory segment recorded against a package name.

coveredNamesQuery :: Connection -> IO [Text] Source #

Every package name this artifact records an advisory against, each once. The name index covers the scan, and the result is what a store sweep intersects its listing with.

toRange :: (Text, Maybe Text, Maybe Text, Maybe Text, Maybe Double, Maybe Double) -> AdvisoryRange Source #

One artifact row as an advisory segment, decoding the two nullable bound columns into the segment's single upper bound.

provenanceQuery :: Connection -> IO [(Text, Text)] Source #

The artifact's meta provenance rows, key-sorted for a deterministic snapshot. It runs only on an accepted connection, so the (Text, Text) decode cannot throw.