ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Osv.Advisory

Description

Decode advisory evidence for the compiled artifact. Package keys use the same ecosystem identity as policy queries.

Synopsis

Documentation

data OsvAdvisory Source #

The OSV fields used to select and score active advisory evidence.

Constructors

OsvAdvisory 

Fields

data OsvAffected Source #

Constructors

OsvAffected 

Fields

data OsvRange Source #

Constructors

OsvRange 

Instances

Instances details
FromJSON OsvRange Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

Show OsvRange Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

Eq OsvRange Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

data OsvEvent Source #

One event in a range's ordered event list, carrying exactly one bound. introduced opens the affected interval inclusively, fixed closes it exclusively, and last_affected inclusively.

Instances

Instances details
FromJSON OsvEvent Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

Show OsvEvent Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

Eq OsvEvent Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

newtype OsvDatabaseSpecific Source #

The subset of an advisory's database_specific block the pipeline consumes.

Constructors

OsvDatabaseSpecific 

Fields

  • dbsSeverity :: Maybe Text

    The source database's qualitative severity label (for GHSA-sourced npm advisories: LOW, MODERATE, HIGH, or CRITICAL).

data OsvSeverityEntry Source #

One entry of an advisory's severity array: a scoring-system tag (CVSS_V3) and its value. For a CVSS system that value is the vector string, not a number.

Constructors

OsvSeverityEntry 

Fields

data ExtractedOsv Source #

An artifact segment keyed by the ecosystem's canonical package name. A missing introduced bound means affected from the beginning.

Constructors

ExtractedOsv 

Fields

Instances

Instances details
Show ExtractedOsv Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

Eq ExtractedOsv Source # 
Instance details

Defined in Ecluse.Core.Osv.Advisory

advisorySeverity :: OsvAdvisory -> Maybe Double Source #

Prefer the highest parsing CVSS vector, then the qualitative label's ceiling, or no score.

extractFromAdvisory :: EpssScores -> OsvAdvisory -> [ExtractedOsv] Source #

Emit only active advisory segments, with canonical package keys and raw version bounds. Withdrawn records emit nothing. Unknown ecosystems keep their package spelling.

orderableBounds :: Ecosystem -> ExtractedOsv -> Bool Source #

Does every bound this segment carries parse under the ecosystem's version grammar? A bound that does not leaves affecting matching every version, fail-closed.

unorderableBounds :: Ecosystem -> ExtractedOsv -> [Text] Source #

The bounds this segment carries that the ecosystem's version grammar cannot parse.

osvExportUrl :: Text -> Text -> String Source #

Build the ecosystem archive URL under a configured OSV export base.