| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Cve
Description
Read one synced advisory artifact through a pinned lookup capability. Package keys are canonical per ecosystem.
Synopsis
- data CveDb = CveDb {
- cveDbLookup :: CveLookup
- cveDbClose :: IO ()
- cveDbMeta :: [(Text, Text)]
- cveDbProvenance :: AdvisoryProvenance
- openCveDb :: Ecosystem -> EpssRequirement -> FilePath -> IO (Either CveDbRejected CveDb)
- data CveDbRejected
- data CveLookup = CveLookup {
- cveAdvisoriesFor :: Text -> IO [AdvisoryRange]
- cveCoveredNames :: IO [Text]
- data AdvisoryRange = AdvisoryRange {
- arCveId :: Text
- arSeverity :: Maybe Double
- arIntroduced :: Maybe Text
- arUpperBound :: UpperBound
- arEpss :: Maybe Double
- data CveQueryFault = CveQueryFault {}
- data PackageAdvisories
- packageAdvisories :: Ecosystem -> [AdvisoryRange] -> PackageAdvisories
- keepAdvisories :: (AdvisoryRange -> Bool) -> PackageAdvisories -> PackageAdvisories
- affecting :: PackageAdvisories -> Version -> [AdvisoryRange]
- fixedAt :: PackageAdvisories -> Version -> [AdvisoryRange]
- data MissingScorePolicy
- scoreAtLeast :: MissingScorePolicy -> Double -> Maybe Double -> Bool
The opened artifact
One opened artifact: the consumer view plus the owner's close. Whoever holds
this owns the connection's lifetime. Hand a consumer cveDbLookup only.
Constructors
| CveDb | |
Fields
| |
openCveDb :: Ecosystem -> EpssRequirement -> FilePath -> IO (Either CveDbRejected CveDb) Source #
Reject incompatible artifacts as values. Opening faults leave no connection behind.
data CveDbRejected Source #
Why the hardened open refused an artifact before building a handle over it. A rejection is a value, not a fault, so the caller can keep the last known-good database.
Constructors
| CveDbWrongEpoch Int | The artifact's |
| CveDbIntegrityFailed [Text] | SQLite refused the file or reported integrity faults, carrying its error or report. |
| CveDbSchemaNonConformant Text | A required relation is absent, non-strict, or lacks a column with its required type. |
| CveDbEcosystemMismatch (Maybe Text) | The ecosystem marker differs from the requested ecosystem or is absent. |
| CveDbEpssNotEstablished | Required feed enrichment lacks the exact success marker. |
Instances
| Show CveDbRejected Source # | |
Defined in Ecluse.Core.Cve.Internal Methods showsPrec :: Int -> CveDbRejected -> ShowS # show :: CveDbRejected -> String # showList :: [CveDbRejected] -> ShowS # | |
| Eq CveDbRejected Source # | |
Defined in Ecluse.Core.Cve.Internal Methods (==) :: CveDbRejected -> CveDbRejected -> Bool # (/=) :: CveDbRejected -> CveDbRejected -> Bool # | |
The consumer view
Query canonical package keys, with npm scopes inline, and raw version strings. Display names must not be used as query keys.
Constructors
| CveLookup | |
Fields
| |
data AdvisoryRange Source #
An advisory segment with nullable CVSS and EPSS scores and verbatim version bounds. The introduced bound is inclusive. Absence means the segment starts at the beginning.
Constructors
| AdvisoryRange | |
Fields
| |
Instances
| Show AdvisoryRange Source # | |
Defined in Ecluse.Core.Cve.Internal Methods showsPrec :: Int -> AdvisoryRange -> ShowS # show :: AdvisoryRange -> String # showList :: [AdvisoryRange] -> ShowS # | |
| Eq AdvisoryRange Source # | |
Defined in Ecluse.Core.Cve.Internal Methods (==) :: AdvisoryRange -> AdvisoryRange -> Bool # (/=) :: AdvisoryRange -> AdvisoryRange -> Bool # | |
data CveQueryFault Source #
A database query fault for the rule's resilience policy to classify.
Constructors
| CveQueryFault | |
Instances
| Exception CveQueryFault Source # | |
Defined in Ecluse.Core.Cve Methods toException :: CveQueryFault -> SomeException # fromException :: SomeException -> Maybe CveQueryFault # displayException :: CveQueryFault -> String # backtraceDesired :: CveQueryFault -> Bool # | |
| Show CveQueryFault Source # | |
Defined in Ecluse.Core.Cve Methods showsPrec :: Int -> CveQueryFault -> ShowS # show :: CveQueryFault -> String # showList :: [CveQueryFault] -> ShowS # | |
| Eq CveQueryFault Source # | |
Defined in Ecluse.Core.Cve Methods (==) :: CveQueryFault -> CveQueryFault -> Bool # (/=) :: CveQueryFault -> CveQueryFault -> Bool # | |
Pure range matching
data PackageAdvisories Source #
One package's advisory segments, each with its bounds parsed once under the package's ecosystem, so every version of the package tests against ordering keys.
packageAdvisories :: Ecosystem -> [AdvisoryRange] -> PackageAdvisories Source #
Parse every segment's bounds at most once, under the package's ecosystem.
keepAdvisories :: (AdvisoryRange -> Bool) -> PackageAdvisories -> PackageAdvisories Source #
Keep only the segments whose row passes the test.
affecting :: PackageAdvisories -> Version -> [AdvisoryRange] Source #
The rows whose affected interval holds a version of the package, in row order. Fail-closed: an unprovable comparison counts as inside, bar a point the grammar cannot order.
fixedAt :: PackageAdvisories -> Version -> [AdvisoryRange] Source #
The rows whose fixed bound is this version's exact text, in row order. A row with a fixed bound
always decodes to FixedBefore, so this is an exact match on the artifact's fixed_version.
data MissingScorePolicy Source #
Whether an individual absent score supplies threshold evidence.
Constructors
| DenyMissingScore | CVSS keeps its denial for unscored advisories, including malware. |
| AbstainMissingScore | EPSS requires a known score to supply a denial. |
scoreAtLeast :: MissingScorePolicy -> Double -> Maybe Double -> Bool Source #
Compare a score with the deny threshold using the metric's missing-score policy.