Code
Hub
Workspaces
Following
Trending
Connect
MCP
copy
Create free account
hub
/
github.com/alpha-omega-security/scrutineer
/ functions
Functions
2,165 in github.com/alpha-omega-security/scrutineer
⨍
Functions
2,165
◇
Types & classes
203
↓ 1 callers
Method
stale
stale reports whether the source's cached payload is missing or older than its TTL as of now.
internal/worker/ecosystems.go:137
↓ 1 callers
Function
stringsEqual
(a, b []string)
internal/web/server_test.go:1157
↓ 1 callers
Function
summariseInput
(tool string, raw json.RawMessage)
internal/worker/stream.go:215
↓ 1 callers
Function
syncCVSSScore
syncCVSSScore keeps cvss_score in lock-step with cvss_vector. The vector is the canonical input (analyst form, disclose skill), the score is a pure fu
internal/db/finding_helpers.go:149
↓ 1 callers
Function
syncCVSSv4Score
syncCVSSv4Score is the v4 twin of syncCVSSScore. CVSS v4 changes the metric set and the base-score formula, so it lives in its own vector/score column
internal/db/finding_helpers.go:171
↓ 1 callers
Method
teardownHardenedScan
teardownHardenedScan runs at the end of a hardened scan: it forwards the egress proxy sidecar's noteworthy logs (allowlist denials, failures) into the
internal/worker/container.go:938
↓ 1 callers
Function
testGitEnv
()
internal/skills/git_testenv_test.go:5
↓ 1 callers
Function
toReferences
(refs []scanReference)
internal/worker/findings.go:140
↓ 1 callers
Function
toString
(v any)
internal/web/api_test.go:524
↓ 1 callers
Method
toolMetadataCached
(ctx context.Context)
internal/web/theme.go:183
↓ 1 callers
Function
truncateSchemaRepairReport
(report string)
internal/worker/skill.go:287
↓ 1 callers
Method
unsatisfiedPrereqs
unsatisfiedPrereqs classifies declared prereqs against the repository's scan history. A name lands in pending when it has at least one in-flight scan
internal/worker/preflight.go:119
↓ 1 callers
Method
upsertFindingReferences
upsertFindingReferences inserts any reference URLs not already on the finding. Used in the dedup branch so a re-observed finding picks up new or migra
internal/worker/skill.go:572
↓ 1 callers
Function
validEmail
validEmail is a pragmatic filter. Anything without an @ or containing "noreply" gets dropped.
internal/worker/findings.go:158
↓ 1 callers
Method
validate
()
internal/skills/parse.go:209
↓ 1 callers
Function
validateFindingField
validateFindingField rejects values that must follow a fixed format before they reach the column. Most fields are free text and pass through untouched
internal/db/finding_helpers.go:26
↓ 1 callers
Function
validateFlags
validateFlags runs the value-validators shared with the YAML config so an invalid --clone / --runtime / --selinux fails the same way whether it came f
cmd/scrutineer/main.go:313
↓ 1 callers
Method
validateMetadata
validateMetadata checks the scrutineer.* keys strictly. agentskills.io spec violations stay as warnings (see validate); scrutineer-specific keys are a
internal/skills/parse.go:235
↓ 1 callers
Function
validationAnchorCount
(s *Server)
internal/web/validate_fix_enqueue_test.go:62
↓ 1 callers
Function
verifyAllToast
(queued, skipped, errored int)
internal/web/server.go:1398
↓ 1 callers
Method
verifyHostProxyReachable
verifyHostProxyReachable runs probe (b) for the host-proxy path: a throwaway container on the --internal network, wiring the gateway alias exactly as
internal/worker/container.go:1038
↓ 1 callers
Method
verifyProxySidecarReachable
verifyProxySidecarReachable runs probe (b) for the sidecar path: a throwaway container on the --internal network must reach the egress proxy sidecar a
internal/worker/container.go:1067
↓ 1 callers
Function
walkMarkerPresent
walkMarkerPresent searches for a file named filepath.Base(m.Path) anywhere under filepath.Dir(m.Path) (relative to srcDir), bounded by markerWalkMaxDe
internal/worker/profile.go:386
↓ 1 callers
Function
workbenchSeed
workbenchSeed returns the report to seed the editor with when the operator has not saved an override yet. Only a root-scoped threat-model scan qualifi
internal/web/threat_workbench.go:70
↓ 1 callers
Function
writeArraySection
(b *strings.Builder, key string, items []any)
internal/web/scan_report.go:289
↓ 1 callers
Function
writeEscapingMavenResolverFixture
(t *testing.T, workRoot string)
internal/worker/skill_parsers_test.go:1222
↓ 1 callers
Function
writeFindingCommunications
(b *strings.Builder, gdb *gorm.DB, findingID uint)
internal/web/repo_report.go:527
↓ 1 callers
Function
writeFindingLabels
(b *strings.Builder, gdb *gorm.DB, findingID uint)
internal/web/repo_report.go:566
↓ 1 callers
Function
writeFindingNotes
(b *strings.Builder, gdb *gorm.DB, findingID uint)
internal/web/repo_report.go:510
↓ 1 callers
Function
writeFindingReferences
(b *strings.Builder, gdb *gorm.DB, findingID uint)
internal/web/repo_report.go:545
↓ 1 callers
Function
writeFindingReportHeader
writeFindingReportHeader mirrors the scan report's header (writeScanReportHeader) so a finding-scoped report opens the same way: a title line, the sou
internal/web/finding_report.go:64
↓ 1 callers
Function
writeMavenResolverFixture
(t *testing.T, src string)
internal/worker/skill_parsers_test.go:1174
↓ 1 callers
Function
writeOrgRepoSection
(b *strings.Builder, gdb *gorm.DB, repo db.Repository, findings []db.Finding)
internal/web/org_report.go:129
↓ 1 callers
Function
writeOrgSummary
(b *strings.Builder, repos []db.Repository, findings []db.Finding, bySeverity, byStatus map[string]int, byRep
internal/web/org_report.go:96
↓ 1 callers
Function
writeOrgSummaryFinding
(b *strings.Builder, f db.Finding)
internal/web/org_summary.go:176
↓ 1 callers
Function
writeOrgSummaryRepo
(b *strings.Builder, repo db.Repository, findings []db.Finding)
internal/web/org_summary.go:161
↓ 1 callers
Function
writeReportAdvisories
(b *strings.Builder, gdb *gorm.DB, repoID uint)
internal/web/repo_report.go:592
↓ 1 callers
Function
writeReportDependencies
(b *strings.Builder, gdb *gorm.DB, repoID uint)
internal/web/repo_report.go:619
↓ 1 callers
Function
writeReportDependents
(b *strings.Builder, gdb *gorm.DB, repoID uint)
internal/web/repo_report.go:606
↓ 1 callers
Function
writeReportFindings
(b *strings.Builder, gdb *gorm.DB, findings []db.Finding, latest *db.Scan, audience reportAudience)
internal/web/repo_report.go:377
↓ 1 callers
Function
writeReportHeader
(b *strings.Builder, repo *db.Repository)
internal/web/repo_report.go:90
↓ 1 callers
Function
writeReportMaintainers
(b *strings.Builder, gdb *gorm.DB, repoID uint)
internal/web/repo_report.go:637
↓ 1 callers
Function
writeReportMetadata
(b *strings.Builder, repo *db.Repository)
internal/web/repo_report.go:101
↓ 1 callers
Function
writeReportPackages
(b *strings.Builder, gdb *gorm.DB, repoID uint)
internal/web/repo_report.go:578
↓ 1 callers
Function
writeReportSummary
writeReportSummary emits a five-line block a maintainer can read in thirty seconds: severity counts, top findings, sink coverage, where to start, and
internal/web/repo_report.go:262
↓ 1 callers
Function
writeReportThreatModel
(b *strings.Builder, scan *db.Scan, tm map[string]any, disp map[string]sinkDisposition)
internal/web/repo_report.go:303
↓ 1 callers
Function
writeSSEEvent
writeSSEEvent emits one SSE event per the spec. Embedded newlines in data are expressed as multiple `data:` lines so the browser's EventSource parser
internal/web/sse.go:155
↓ 1 callers
Function
writeScalarTable
(b *strings.Builder, top map[string]any, keys []string)
internal/web/scan_report.go:269
↓ 1 callers
Function
writeScanReportFindings
(b *strings.Builder, gdb *gorm.DB, scan *db.Scan)
internal/web/scan_report.go:144
↓ 1 callers
Function
writeScanReportFreeform
writeScanReportFreeform renders a scan's report.json as the best markdown the shape allows: top-level scalar keys become a metadata table, top-level a
internal/web/scan_report.go:188
↓ 1 callers
Function
writeScanReportHeader
(b *strings.Builder, scan *db.Scan)
internal/web/scan_report.go:79
↓ 1 callers
Function
writeScanReportMetadata
(b *strings.Builder, scan *db.Scan, skill *db.Skill)
internal/web/scan_report.go:93
Method
AccountErrorText
(t string)
internal/worker/harness_test.go:125
Method
AccountErrorText
(s string)
internal/worker/harness.go:137
Method
Args
(SkillJob, string, int)
internal/worker/harness_test.go:118
Method
Args
(sj SkillJob, effort string, globalMaxTurns int)
internal/worker/harness.go:88
Function
BenchmarkListPagesLargeDataset
(b *testing.B)
internal/web/list_performance_test.go:75
Method
Binary
()
internal/worker/harness_test.go:117
Function
CWECategoryID
CWECategoryID returns the View-1400 category CWE-ID for a given weakness CWE-ID (e.g. "CWE-352" -> "CWE-1411"). Returns "" when the weakness is unknow
internal/web/cwe.go:114
Function
CategoryLabel
CategoryLabel formats a View-1400 category label with its CWE-ID prefix, e.g. "Injection" becomes "CWE-1409 — Injection". The pseudo-category Uncatego
internal/web/cwe.go:104
Method
Duration
()
internal/db/db.go:949
Method
EgressHosts
()
internal/worker/harness_test.go:122
Method
Env
(string)
internal/worker/harness_test.go:123
Method
Env
(baseURL string)
internal/worker/harness.go:104
Method
Error
()
internal/worker/claude.go:27
Method
Error
()
internal/worker/claude_limit.go:25
Function
FirstIfaceIPv4
FirstIfaceIPv4 returns the IPv4 of the sidecar's first up, non-loopback interface. The sidecar always runs in a Linux container (rootless podman is th
internal/worker/egress.go:403
Method
GuideFilename
()
internal/worker/harness_test.go:121
Method
NextURL
()
internal/web/server.go:548
Method
ParseStream
(io.Reader, func(Event))
internal/worker/harness_test.go:119
Method
ParseStream
(r io.Reader, emit func(Event))
internal/worker/harness.go:92
Method
PrevURL
()
internal/web/server.go:547
Method
RunSkill
RunSkill runs claude against a staged skill in a local workspace. The workspace layout is: {DataDir}/scan-{id}/src/ clone (read-only
internal/worker/claude.go:130
Method
RunSkill
(_ context.Context, sj SkillJob, _ func(Event))
internal/worker/max_turns_test.go:19
Method
RunSkill
(_ context.Context, sj SkillJob, emit func(Event))
internal/worker/schema_validate_test.go:120
Method
RunSkill
(_ context.Context, sj SkillJob, emit func(Event))
internal/worker/worker_resume_test.go:25
Method
RunSkill
(_ context.Context, sj SkillJob, emit func(Event))
internal/worker/worker_test.go:36
Method
RunSkill
(ctx context.Context, _ SkillJob, _ func(Event))
internal/worker/worker_test.go:52
Method
SkillDir
SkillDir is fixed at claude's discovery path: the no-container fallback is claude-only by design.
internal/worker/claude.go:120
Method
SkillDir
(wr, n string)
internal/worker/harness_test.go:120
Method
SkillDir
(workRoot, name string)
internal/worker/max_turns_test.go:24
Method
SkillDir
(workRoot, name string)
internal/worker/harness.go:96
Method
SkillDir
(workRoot, name string)
internal/worker/schema_validate_test.go:116
Method
SkillDir
(workRoot, name string)
internal/worker/worker_resume_test.go:33
Method
SkillDir
(workRoot, name string)
internal/worker/worker_test.go:44
Method
SkillDir
(workRoot, name string)
internal/worker/worker_test.go:58
Method
StateEnv
(string)
internal/worker/harness_test.go:124
Method
StateEnv
(containerPath string)
internal/worker/harness.go:133
Method
Summary
Summary gives a one-paragraph digest of the finding: first paragraph of Trace when present, else the Title. Kept as a method so templates can treat it
internal/db/db.go:666
Function
TestAPIAuth_capsRequestBody
(t *testing.T)
internal/web/api_test.go:536
Function
TestAPIEcosystemsRaw_400UnknownSource
(t *testing.T)
internal/web/api_ecosystems_test.go:56
Function
TestAPIEcosystemsRaw_403CrossRepo
(t *testing.T)
internal/web/api_ecosystems_test.go:67
Function
TestAPIEcosystemsRaw_404WhenEmpty
(t *testing.T)
internal/web/api_ecosystems_test.go:45
Function
TestAPIEcosystemsRaw_returnsCachedPayload
(t *testing.T)
internal/web/api_ecosystems_test.go:25
Function
TestAPIFindingChildCollections
TestAPIFindingChildCollections covers the POST-then-GET round trip for the three sibling child collections (notes, communications, references). They s
internal/web/api_finding_writes_test.go:106
Function
TestAPIFindingChildCollections_validation
The 422 paths differ per collection (notes reject empty body, references reject empty url, communications accept anything), so they get their own targ
internal/web/api_finding_writes_test.go:168
Function
TestAPIFindingReadsAndFilters
(t *testing.T)
internal/web/api_test.go:242
Function
TestAPIGetRepository_includesPostureFields
(t *testing.T)
internal/web/api_test.go:102
Function
TestAPIListCNAs
(t *testing.T)
internal/web/api_test.go:34
Function
TestAPIListDependencyFindings
(t *testing.T)
internal/web/api_test.go:297
← previous
next →
901–1,000 of 2,165, ranked by callers