ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Osv.Compile

Description

Compile OSV advisories and EPSS scores into the artifact consumed by CVE sync. Every pass attempts the EPSS feed, and the ecosystem's EpssRequirement decides whether a failed feed stops publication or leaves the artifact recording unavailable enrichment.

Synopsis

Documentation

data CompileSources Source #

The two upstreams one compile pass reads: the ecosystem's advisories, and the exploitability scores it joins onto them.

Constructors

CompileSources 

Fields

compileOsvToSqlite :: (MonadResource m, MonadMask m, MonadUnliftIO m, KatipContext m) => AdvisoryCompileMetricsPort -> Maybe TracerProvider -> FilePath -> OsvEcosystem -> EpssRequirement -> CompileSources -> QuietTime -> m FilePath Source #

Compile one ecosystem into outDir, refusing systemic drops, zero relevant rows, or a failed EPSS feed the requirement makes fatal. A refusal leaves any previous artifact unchanged.

data PilotEpssRequired Source #

A compile whose ecosystem requires EPSS enrichment met a failed feed, so it published nothing. It names the feed by host and port alone, because the configured URL can carry a credential.

Constructors

PilotEpssRequired 

Fields

osvToRow :: ExtractedOsv -> (Text, Text, Maybe Text, Maybe Text, Maybe Text, Maybe Double, Maybe Double) Source #

One extracted segment as its artifact row. The upper bound spreads over the fixed_version and last_affected_version columns, and fills at most one of them.