ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Cve

Description

Read one synced advisory artifact through a pinned lookup capability. Package keys are canonical per ecosystem.

Synopsis

The opened artifact

data CveDb Source #

One opened artifact: the consumer view plus the owner's close. Whoever holds this owns the connection's lifetime. Hand a consumer cveDbLookup only.

Constructors

CveDb 

Fields

  • cveDbLookup :: CveLookup

    The view consumers query through.

  • cveDbClose :: IO ()

    Release the connection. Owner-only, and never throws, since the connection is going away either way.

  • cveDbMeta :: [(Text, Text)]

    The artifact's meta provenance rows, snapshotted at open and key-sorted for the audit trail.

  • cveDbProvenance :: AdvisoryProvenance

    What the artifact records about the sources it was compiled from. An artifact written before those keys decodes as absence.

openCveDb :: Ecosystem -> EpssRequirement -> FilePath -> IO (Either CveDbRejected CveDb) Source #

Reject incompatible artifacts as values. Opening faults leave no connection behind.

data CveDbRejected Source #

Why the hardened open refused an artifact before building a handle over it. A rejection is a value, not a fault, so the caller can keep the last known-good database.

Constructors

CveDbWrongEpoch Int

The artifact's user_version differs from osvSchemaEpoch.

CveDbIntegrityFailed [Text]

SQLite refused the file or reported integrity faults, carrying its error or report.

CveDbSchemaNonConformant Text

A required relation is absent, non-strict, or lacks a column with its required type.

CveDbEcosystemMismatch (Maybe Text)

The ecosystem marker differs from the requested ecosystem or is absent.

CveDbEpssNotEstablished

Required feed enrichment lacks the exact success marker.

Instances

Instances details
Show CveDbRejected Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

Eq CveDbRejected Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

The consumer view

data CveLookup Source #

Query canonical package keys, with npm scopes inline, and raw version strings. Display names must not be used as query keys.

Constructors

CveLookup 

Fields

data AdvisoryRange Source #

An advisory segment with nullable CVSS and EPSS scores and verbatim version bounds. The introduced bound is inclusive. Absence means the segment starts at the beginning.

Instances

Instances details
Show AdvisoryRange Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

Eq AdvisoryRange Source # 
Instance details

Defined in Ecluse.Core.Cve.Internal

data CveQueryFault Source #

A database query fault for the rule's resilience policy to classify.

Constructors

CveQueryFault 

Fields

  • cqfQuery :: Text

    Which handle field was asked (advisories-for or covered-names).

  • cqfDetail :: Text

    The rendered SQLError, for the operator's outage report. Never parsed.

Pure range matching

data PackageAdvisories Source #

One package's advisory segments, each with its bounds parsed once under the package's ecosystem, so every version of the package tests against ordering keys.

packageAdvisories :: Ecosystem -> [AdvisoryRange] -> PackageAdvisories Source #

Parse every segment's bounds at most once, under the package's ecosystem.

keepAdvisories :: (AdvisoryRange -> Bool) -> PackageAdvisories -> PackageAdvisories Source #

Keep only the segments whose row passes the test.

affecting :: PackageAdvisories -> Version -> [AdvisoryRange] Source #

The rows whose affected interval holds a version of the package, in row order. Fail-closed: an unprovable comparison counts as inside, bar a point the grammar cannot order.

fixedAt :: PackageAdvisories -> Version -> [AdvisoryRange] Source #

The rows whose fixed bound is this version's exact text, in row order. A row with a fixed bound always decodes to FixedBefore, so this is an exact match on the artifact's fixed_version.

data MissingScorePolicy Source #

Whether an individual absent score supplies threshold evidence.

Constructors

DenyMissingScore

CVSS keeps its denial for unscored advisories, including malware.

AbstainMissingScore

EPSS requires a known score to supply a denial.

scoreAtLeast :: MissingScorePolicy -> Double -> Maybe Double -> Bool Source #

Compare a score with the deny threshold using the metric's missing-score policy.