ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Osv.Provenance

Description

What one advisory artifact records about the sources it was compiled from, and how old those sources say their data is.

Pilot writes these values into the artifact's meta table (Ecluse.Core.Osv.Schema) and the consumer decodes them back at open. They are diagnostics and ordering evidence: nothing here refuses a version. A source that declares no value records no row, so absence stays distinguishable from a guess.

Synopsis

The recorded sources

data AdvisoryProvenance Source #

The sources one artifact was compiled from, as they described themselves. Every field is Nothing when the source supplied no such value, or when an older artifact predates the key.

Constructors

AdvisoryProvenance 

Fields

noProvenance :: AdvisoryProvenance Source #

Nothing recorded, which is what an artifact compiled before these keys decodes to.

provenanceRows :: AdvisoryProvenance -> [(Text, Text)] Source #

The meta rows one provenance writes. A value the source did not supply writes no row.

decodeProvenance :: [(Text, Text)] -> AdvisoryProvenance Source #

Read the provenance an artifact's meta rows carry. An absent key, an over-long value, and an unreadable timestamp all read as absence, never as a fault.

Source timestamps

parseSourceTime :: Text -> Maybe UTCTime Source #

An RFC 3339 timestamp, or a bare date read as its UTC start of day. Anything else is Nothing, which records no value rather than an invented one.

parseHttpDate :: Text -> Maybe UTCTime Source #

The instant an HTTP Last-Modified header names, or Nothing when it is unreadable.

lastModifiedOf :: [ByteString] -> Maybe UTCTime Source #

The instant a response's Last-Modified names. An absent or unreadable header records nothing.

The quiet-time reading

data QuietTime Source #

How old each source may be before Pilot raises its alarm. Loud ecosystems take a short threshold and slow ones a long threshold, so a quiet feed is not read as a stalled one.

Constructors

QuietTime 

Fields

Instances

Instances details
Show QuietTime Source # 
Instance details

Defined in Ecluse.Core.Osv.Provenance

Eq QuietTime Source # 
Instance details

Defined in Ecluse.Core.Osv.Provenance

defaultQuietTime :: NominalDiffTime Source #

Seven days, the threshold a source with no configured value of its own is judged by.

data ProvenanceSource Source #

Which upstream an age was read from.

Constructors

OsvExport

The ecosystem's advisory export, aged by its newest record modified.

EpssFeed

The EPSS feed, aged by its declared score_date.

data SourceAge Source #

One source's age at an instant, with the threshold that decides whether it is quiet.

Constructors

SourceAge 

Fields

Instances

Instances details
Show SourceAge Source # 
Instance details

Defined in Ecluse.Core.Osv.Provenance

Eq SourceAge Source # 
Instance details

Defined in Ecluse.Core.Osv.Provenance

sourceAges :: UTCTime -> QuietTime -> AdvisoryProvenance -> [SourceAge] Source #

The ages this provenance supports at now. A source that recorded no timestamp yields no age, because nothing about it can be read as quiet or fresh.

sourceQuiet :: SourceAge -> Bool Source #

Whether this source has gone longer than its threshold without changing.

renderSourceAge :: SourceAge -> Text Source #

The age as an operator reads it, in the seconds its threshold is configured in.