synapse-ce

module
v0.2.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0

README

Synapse Synapse

Verify Everything. Trust Nothing.

A governed control plane for the whole security-assessment lifecycle, supply chain, code, cloud, offensive, and runtime defense.

Turn a fragmented, manual security process into one controlled, auditable workflow: SCA, SAST, secret and IaC scanning, reachability, recon and governed exploitation, cloud posture, and a distributed blue-team agent fleet, all behind server-side scope enforcement, hardened tool execution, tamper-evident evidence, and deterministic reports.

License Go Docs CI Go Report Card

Landing page · Documentation · Quickstart · Features · Configuration


[!IMPORTANT] Authorized use only. Synapse is built for authorized security testing, pentest engagements, and defensive security work. Every engagement enforces an explicit scope and a legal authorization window, server-side, before any tool runs. You are responsible for holding written permission to test any target.

Synapse engagements overview

Why Synapse

  • ✅ Deterministic first. Scanning, matching, and reporting are pure, reproducible Go. No model sits in the report path.
  • ✅ Evidence you can trust. Every artifact is hash-chained into a tamper-evident custody record. A broken chain blocks the report.
  • ✅ One platform, every angle. Supply chain, code, cloud, offensive, and runtime defense behind a single gate.
  • ✅ Reachability aware. A deterministic call graph decides whether a vulnerable symbol is actually reachable from your code.
  • ✅ Detection independent. Owns its SBOM parsers and advisory matching, and ingests OSV, GHSA, CSAF and OVAL.
  • ✅ A detection is evidence, not an alert. Runtime detections are attributable, hash-chained, and joined to the same asset, finding, and attack path the static pillars reason about.
  • ✅ CI ready. synapse-cli is a single static binary that gates a build and emits SARIF for code scanning.
  • ✅ Safe by construction. argv-only execution in a Linux sandbox, server-side scope and authorization before any tool runs, secrets never leave the server.

What is Synapse

Synapse runs the whole security-assessment lifecycle behind one governed control plane, across both point-in-time analysis (SCA, SAST, code quality, IaC) and runtime analysis (a distributed agent fleet, eBPF detections, response actions), over container and VM estates, with a single asset model, one authorization model, one hash-chained evidence chain, and one prioritized queue.

It is deterministic-first. Scanning, matching, license classification, scoring, and reporting are pure, reproducible Go with nothing else in the path. Where automated analysis is offered it stays strictly bounded: a proposal is only ever proposed, a typed Go state machine validates and executes, scope and authorization are checked in the execution layer, secrets never leave the server, every artifact is hash-chained into a tamper-evident custody record, and a human approves anything intrusive.

Features

Software supply chain

  • SBOM generation across many ecosystems (npm, PyPI, Maven, Gradle, Go, Cargo, RubyGems, Composer, NuGet, Hex, Dart, pnpm, Poetry, yarn and more) with owned per-ecosystem lockfile parsers.
  • Vulnerability detection from Synapse's own advisory store as the primary source, matched alongside a live advisory API, cross-correlated and de-duplicated; the store ingests OSV, GHSA, CSAF and OVAL for detection independence.
  • Risk-based prioritization ordered by exploitability (CISA KEV, then EPSS, then CVSS), never by raw CVSS alone.
  • License compliance: declared-license resolution, SPDX expression parsing, a curated category and risk model, and coordinate recovery for shaded or metadata-less JARs.
  • Reachability: a deterministic call-graph engine (Go, plus JVM and JS/TS tiers) decides whether a vulnerable symbol is actually reachable from application code.

Code & configuration

  • First-party SAST: a line-level pattern scanner for dangerous idioms (weak crypto, hardcoded secrets, a shell built by concatenation, an unsafe deserializer) across many languages, pinned to a labelled precision/recall corpus. Interprocedural and cross-file dataflow analysis is the separate reachability engine: a taint and call-graph analysis over the sandboxed go/ssa and tree-sitter graphs.
  • Secret scanning and IaC misconfiguration (Terraform, CloudFormation, ARM, Kubernetes, Helm, Dockerfile, Compose).
  • Code quality rules, quality gates and profiles, and third-party SARIF ingest into the same governance path.

Offensive

  • Recon in a hardened sandbox, an attack-path graph over the asset inventory, chained exploitation with per-step proof, and adversary emulation with expected-detection output, all gated by a written offensive policy and a kill switch.
  • DAST: authenticated crawling and a first-party check corpus with sessions from the credential vault.

Runtime defense (blue team)

  • A distributed agent fleet (host and Kubernetes cluster inventory, coverage/freshness, signed packaging and updates) with certificate enrolment and fenced leadership.
  • An eBPF detection engine, detections sealed as hash-chained evidence, a columnar telemetry tier with retention, governed response actions (same admission + evidence as exploitation), and purple-team coverage measured from emulation-expected vs actually-fired.

Cloud posture (CSPM)

  • Read-only AWS, Azure and GCP posture connectors behind a sandboxed helper, with vault-ref credentials over an inherited FD, per-operation server-side authorization, and IaC-vs-live drift findings.

Governance & evidence

  • Tamper-evident evidence: every artifact is hash-chained (RFC-3161 anchored); a broken chain blocks the report. Audit and evidence logs are append-only.
  • Hardened execution: tools run via argv arrays inside a Linux sandbox with egress scoping; scope and the authorization window are enforced before any tool runs.
  • RBAC, tenant isolation (Postgres RLS), and separation of duties through a single authorization chokepoint.
  • The Judgment primitive: every AI/analysis claim is propose → verify → confirm; gated capabilities promote only on a distinct verifier's sealed verdict.

AI analysis (optional, bounded)

  • AI false-positive triage grounded in deterministic evidence citations, with provider-independent proposer/verifier separation of duties, budgets, circuit breakers, observability, and a fail-closed adversarial counterfactual gate for model/prompt promotion.
  • The agent proposes; a distinct verifier or a human confirms. No model ever sits in the report path.

Standards & reports

  • Standards native: CycloneDX and SPDX with PURL, SARIF and OpenVEX exports; CSAF advisory ingestion; KEV and EPSS prioritization.
  • Deterministic reports templated from stored data, with a curated CWE → OWASP, PCI and ISO compliance mapping.

See the full walkthrough with screenshots on the documentation site.

How it compares

Detection is at parity with the popular scanners, and sometimes ahead. On one representative real-world repository, Synapse reported 261 unique CVEs to Trivy's 239 (235 in common) and attached a license to 1443 packages to Trivy's 1394. Numbers move with the project, so treat these as illustrative rather than a benchmark claim.

The lasting difference is what sits around the finding:

Capability Synapse Most scanners
SCA, license, IaC misconfig, secret scanning Yes Yes
First-party SAST (source-code rules) Yes Usually no
Reachability via a call graph Yes Rarely
Offensive: attack paths, chained exploitation, emulation, DAST Yes No
Runtime blue team: agent fleet, eBPF detections, response actions Yes No
Detections sealed as hash-chained evidence, joined to the same asset Yes No
Cloud posture (AWS/Azure/GCP), IaC-vs-live drift Yes Varies
Hash-chained, tamper-evident evidence Yes No
Server-side scope and authorization before a tool runs Yes No
RBAC, tenant isolation (RLS), separation of duties Yes No
Deterministic, model-free report path Yes Varies

Quickstart

Prerequisites

  • Go 1.26 (pinned in go.mod), Node and pnpm (use pnpm, not npm or yarn).
  • No external scanner is required: the owned SBOM producer + owned advisory store are the default and run with no third-party tool. Syft (optional, broadest SBOM coverage / cross-check) and Grype (optional, adds the offline database) are supported extras, make tools installs both, pinned and checksum-verified, into ./bin.
  • Docker is optional and is the easiest way to run the full stack.
  • The hardened sandbox and live recon need a Linux host. Without them the API still runs (SCA, findings, reports); sandboxed execution fails closed rather than running unsandboxed.

Install a released build

Grab a prebuilt binary from the Releases page (Linux and macOS on amd64/arm64, and Windows on amd64) and verify it against checksums.txt. Each archive bundles the packaged commands.

# Example: linux/amd64
curl -fsSL -o synapse.tar.gz \
  https://github.com/KKloudTarus/synapse-ce/releases/latest/download/synapse-ce_<version>_linux_amd64.tar.gz
tar -xzf synapse.tar.gz synapse-cli
./synapse-cli scan ./path/to/project --fail-on high

Or scan with zero install using the container image (bundles synapse-cli, plus grype for the opt-in OS-package cross-check):

Container images are not published by the current release workflow. Use a release archive or build deploy/Dockerfile locally when a containerized CLI is required.

Gate a repository in CI with the reusable action (see docs/guide/cli.md):

- uses: KKloudTarus/synapse-ce@v1
  with:
    fail-on: high

Run the full stack with Docker

The stack has no default database password and no default API token. That is deliberate: a credential committed to a public repository ends up in a deployment that somebody can reach, so the Compose file fails fast rather than booting with a password an attacker already knows. Generate the values once into deploy/.env.local, which .gitignore already covers:

umask 077
DB_ADMIN_PASSWORD="$(openssl rand -hex 16)"
DB_APP_PASSWORD="$(openssl rand -hex 16)"
BLOB_PASSWORD="$(openssl rand -hex 16)"
cat > deploy/.env.local <<EOF
DB_ADMIN_PASSWORD=$DB_ADMIN_PASSWORD
DB_APP_PASSWORD=$DB_APP_PASSWORD
BLOB_PASSWORD=$BLOB_PASSWORD
SYNAPSE_API_TOKEN=$(openssl rand -hex 32)
SYNAPSE_DB_DSN=postgres://synapse_app:$DB_APP_PASSWORD@postgres:5432/synapse?sslmode=disable
SYNAPSE_DB_MIGRATION_DSN=postgres://synapse_admin:$DB_ADMIN_PASSWORD@postgres:5432/synapse?sslmode=disable
EOF

docker compose --env-file deploy/.env.local \
  -f deploy/docker-compose.full.yml up -d --build --wait

--env-file is required. Compose does not read deploy/.env.local just because the Compose file lives in deploy/. Hex passwords keep the DSNs URL-safe; percent-encode anything else.

curl localhost:8080/readyz                       # {"status":"ready",...}
open http://localhost:5173                       # dashboard

Paste the SYNAPSE_API_TOKEN from deploy/.env.local into the dashboard and accept the Acceptable Use Policy. Two roles exist on purpose: synapse_admin owns the schema and runs migrations, synapse_app serves traffic and cannot bypass row level security. PostgreSQL writes its initial credentials into the volume, so rotating the env file afterwards does not change the stored password; for throwaway local data, reset with docker compose --env-file deploy/.env.local -f deploy/docker-compose.full.yml down -v.

Full details, including the port table and what this profile deliberately does not harden, are in Deployment.

Run natively (development)

make install                       # Go modules + web deps
make tools                         # optional: syft + grype for the opt-in cross-check
export PATH="$PWD/bin:$PATH"

export SYNAPSE_API_TOKEN="$(openssl rand -hex 32)"   # required for operational API routes; /healthz and /readyz are public
make dev                           # API on :8080, dashboard on :5173

Open http://localhost:5173, paste the token, accept the Acceptable Use Policy. A blank SYNAPSE_DB_DSN runs an in-memory dev store, so nothing is persisted. Migrations are embedded and applied automatically at startup.

For a durable local database, start the dependency stack and point the API at it. Its one-shot postgres-init container creates the application role the API connects as.

docker compose -f deploy/docker-compose.yml up -d   # Postgres + MinIO; same as `make docker-up`
# The stack's own defaults; set these in deploy/.env to use anything else.
export DB_PASSWORD="${DB_PASSWORD:-synapse}" DB_APP_PASSWORD="${DB_APP_PASSWORD:-synapse-app}"
export SYNAPSE_DB_DSN="postgres://synapse_app:${DB_APP_PASSWORD}@localhost:5432/synapse?sslmode=disable"
export SYNAPSE_DB_MIGRATION_DSN="postgres://synapse:${DB_PASSWORD}@localhost:5432/synapse?sslmode=disable"
make dev

Both DSNs are needed. synapse owns the schema, migrates it, and grants the runtime role its table privileges; synapse_app is NOSUPERUSER NOBYPASSRLS and is the only role the API will serve under. Connecting as the superuser stops the API at startup with rls: runtime DB role cannot enforce isolation: role is SUPERUSER, because row level security is silently a no-op for such a role. These credentials are throwaway local defaults.

Skip --wait on this stack: Compose counts the exited postgres-init container as not running and reports a failure even when it finished successfully. To block until the role exists, run docker compose -f deploy/docker-compose.yml run --rm postgres-init, which is idempotent.

Command line

synapse-cli runs the same pipeline as the server, ideal for CI gating.

make build
./bin/synapse-cli scan ./path/to/project --fail-on high

The exit code is 0 when no finding meets the threshold, non-zero otherwise.

Binaries

Binary Role
synapse-api HTTP API server, the primary service
synapse-cli Run an SCA/SAST scan from the command line, CI-friendly (SARIF, --fail-on)
synapse-worker Durable job runner for recon and background jobs, lease-based, leader-gated
synapse-callgraph Sandboxed go/ssa call-graph builder for reachability and taint
synapse-ast Sandboxed tree-sitter AST helper for source-code analysis
synapse-cspm Sandboxed cloud-posture helper (AWS/Azure/GCP), read-only, FD-passed credentials
synapse-dast-helper Sandboxed DAST crawler/check helper
synapse-agent Fleet agent: host inventory and eBPF runtime detections
synapse-cluster-agent Fleet agent: Kubernetes workload/exposure/identity inventory
synapse-fptriage-eval Offline evaluation harness for AI false-positive triage
synapse-fptriage-compare Deterministic candidate-vs-baseline gate for AI model/prompt promotion review
synapse-fptriage-release Versioned PM/Security-approved promotion and rollback ledger for AI triage
synapse-fptriage-curate Offline privacy- and label-reviewed feedback curation for AI false-positive evaluation
synapse-fptriage-drift Offline language/CWE/project distribution drift evidence for AI triage
synapse-mcp Read-only, propose-only integration server, never executes

Architecture

Clean architecture with a strict, inward-only dependency rule:

domain  <-  usecase  <-  adapter / infrastructure

All external I/O (database, tools, storage, sandbox) goes through ports, which are interfaces in internal/usecase/ports. cmd/* is the composition root, with dependency injection in main and no business logic.

Configuration

Synapse reads its configuration from the process environment. Copy .env.example and adjust. The only required variable in development is SYNAPSE_API_TOKEN. In production, SYNAPSE_MEASURE_CURSOR_SECRET is also required (generated via openssl rand -hex 32). See the configuration reference for the full list.

Full documentation lives in docs/guide/: introduction, installation, quickstart, features, configuration, CLI, architecture, deployment, and the security model. See CHANGELOG.md for what has changed.

Roadmap

Synapse is under active development. The current roadmap extends the shipped platform rather than introducing new pillars:

  • Broader deterministic rule and ecosystem coverage beyond the current Go, JavaScript/TypeScript, Python, Java/JVM, .NET, Rust, Ruby, PHP, Swift, Dart, Elixir, Conda, R, Julia, and Conan coverage.
  • Deeper language-aware reachability and taint analysis, with conservative handling for dynamic code.
  • More model-free compliance profiles and ready-to-run CI, fleet, and deployment recipes.
  • Continued hardening of sandbox, supply-chain, evidence, and agent-update boundaries.

Have a request? Open an issue or start a discussion. Issues tagged good first issue and help wanted are a good place to start.

Team & contributors

Synapse is built by its founding team and contributors.

Member Role
nghiadaulau nghiadaulau Founder
nnatuan03 nnatuan03 Co-founder
pho-veteran pho-veteran Lead maintainer
VietSory VietSory Engineer
lethanhsang188 lethanhsang188 Engineer
tuu-ngo tuu-ngo Brand identity designer
H1eu232 H1eu232 AI engineer (contributor)
XUanhoa04 XUanhoa04 AI engineer (contributor)
thx2an thx2an AI engineer (contributor)

Contributions are welcome. See CONTRIBUTING.md, the Code of Conduct, and report vulnerabilities per the Security Policy.

License

Licensed under the Apache License 2.0.

Directories

Path Synopsis
cmd
seed-detections command
Command seed-detections enrols a fleet agent, registers a detection signing key, and ships a few SIGNED detection batches (real v2 wire contract) so the incident/fleet flow can be demonstrated with data.
Command seed-detections enrols a fleet agent, registers a detection signing key, and ships a few SIGNED detection batches (real v2 wire contract) so the incident/fleet flow can be demonstrated with data.
seed-fleet-detections command
Command seed-fleet-detections emulates a real EDR agent end-to-end so the incident flow can be demonstrated with genuine (non-mock) data.
Command seed-fleet-detections emulates a real EDR agent end-to-end so the incident flow can be demonstrated with genuine (non-mock) data.
synapse-agent command
Command synapse-agent is the fleet VM agent (#410, epic #405).
Command synapse-agent is the fleet VM agent (#410, epic #405).
synapse-api command
Command synapse-api is the HTTP API server entrypoint.
Command synapse-api is the HTTP API server entrypoint.
synapse-assessment-backfill command
Command synapse-assessment-backfill runs the resumable historical singleton-Cycle backfill.
Command synapse-assessment-backfill runs the resumable historical singleton-Cycle backfill.
synapse-assessment-integrity command
Command synapse-assessment-integrity runs the read-only Assessment Cycle integrity verifier.
Command synapse-assessment-integrity runs the read-only Assessment Cycle integrity verifier.
synapse-assessment-snapshot-backfill command
Command synapse-assessment-snapshot-backfill projects historical scan evidence into immutable legacy Assessment Snapshots.
Command synapse-assessment-snapshot-backfill projects historical scan evidence into immutable legacy Assessment Snapshots.
synapse-ast command
Command synapse-ast parses a source tree with language-aware (tree-sitter) grammars and emits structural facts as JSON on stdout.
Command synapse-ast parses a source tree with language-aware (tree-sitter) grammars and emits structural facts as JSON on stdout.
synapse-bench command
Command synapse-bench produces deterministic reports from supplied observations or the embedded owned SCA corpus.
Command synapse-bench produces deterministic reports from supplied observations or the embedded owned SCA corpus.
synapse-callgraph command
Command synapse-callgraph builds a general first-party call graph from Go source (via go/ssa) and emits it as the taintcallgraph wire JSON on stdout.
Command synapse-callgraph builds a general first-party call graph from Go source (via go/ssa) and emits it as the taintcallgraph wire JSON on stdout.
synapse-cli command
Command synapse-cli runs Synapse's own SCA pipeline from the command line.
Command synapse-cli runs Synapse's own SCA pipeline from the command line.
synapse-cluster-agent command
Command synapse-cluster-agent is the Kubernetes cluster agent (#411/#446, epic #405).
Command synapse-cluster-agent is the Kubernetes cluster agent (#411/#446, epic #405).
synapse-cspm command
Command synapse-cspm is the sandboxed CSPM SDK helper.
Command synapse-cspm is the sandboxed CSPM SDK helper.
synapse-dast-helper command
synapse-dast-helper owns HTTP clients and authenticated session state outside the API process.
synapse-dast-helper owns HTTP clients and authenticated session state outside the API process.
synapse-finding-lineage-backfill command
Command synapse-finding-lineage-backfill projects legacy Findings into versioned Identities and immutable Observations.
Command synapse-finding-lineage-backfill projects legacy Findings into versioned Identities and immutable Observations.
synapse-fptriage-blind command
Command synapse-fptriage-blind manages offline blinded human review packets for an existing shadow evaluation report.
Command synapse-fptriage-blind manages offline blinded human review packets for an existing shadow evaluation report.
synapse-fptriage-compare command
Command synapse-fptriage-compare validates and compares two deterministic AI false-positive triage shadow reports.
Command synapse-fptriage-compare validates and compares two deterministic AI false-positive triage shadow reports.
synapse-fptriage-curate command
Command synapse-fptriage-curate converts explicitly reviewed AI-triage outcomes into an offline evaluation dataset after privacy and label-quality approval.
Command synapse-fptriage-curate converts explicitly reviewed AI-triage outcomes into an offline evaluation dataset after privacy and label-quality approval.
synapse-fptriage-drift command
Command synapse-fptriage-drift compares a saved AI-triage observability distribution with a versioned, human-approved baseline.
Command synapse-fptriage-drift compares a saved AI-triage observability distribution with a versioned, human-approved baseline.
synapse-fptriage-eval command
Command synapse-fptriage-eval runs the production false-positive triager in shadow mode over a versioned, human-reviewed golden dataset and emits a deterministic machine-readable report.
Command synapse-fptriage-eval runs the production false-positive triager in shadow mode over a versioned, human-reviewed golden dataset and emits a deterministic machine-readable report.
synapse-fptriage-release command
Command synapse-fptriage-release creates an immutable, versioned ledger of independently approved AI-triage promotions and rollbacks.
Command synapse-fptriage-release creates an immutable, versioned ledger of independently approved AI-triage promotions and rollbacks.
synapse-mcp command
Command synapse-mcp exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
Command synapse-mcp exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
synapse-migrate command
Command synapse-migrate applies the embedded PostgreSQL migration set once.
Command synapse-migrate applies the embedded PostgreSQL migration set once.
synapse-reachability-authority command
Command synapse-reachability-authority curates fixed reachability controller assets.
Command synapse-reachability-authority curates fixed reachability controller assets.
synapse-reachability-cycle command
Command synapse-reachability-cycle runs the fixed reachability benchmark lifecycle.
Command synapse-reachability-cycle runs the fixed reachability benchmark lifecycle.
synapse-release-evidence command
Command synapse-release-evidence creates and verifies deterministic release asset manifests.
Command synapse-release-evidence creates and verifies deterministic release asset manifests.
synapse-sandbox-check command
synapse-sandbox-check proves the production sandbox runner's confinement posture.
synapse-sandbox-check proves the production sandbox runner's confinement posture.
synapse-sca-archive command
Command synapse-sca-archive preserves benchmark evidence in content-addressed storage.
Command synapse-sca-archive preserves benchmark evidence in content-addressed storage.
synapse-sca-bench command
Command synapse-sca-bench captures one pinned SCA benchmark observation.
Command synapse-sca-bench captures one pinned SCA benchmark observation.
synapse-sca-cycle command
Command synapse-sca-cycle runs fixed SCA benchmark cycles.
Command synapse-sca-cycle runs fixed SCA benchmark cycles.
synapse-sca-prepare command
Command synapse-sca-prepare creates public diagnostic inputs for an SCA benchmark.
Command synapse-sca-prepare creates public diagnostic inputs for an SCA benchmark.
synapse-verify-restore command
Command synapse-verify-restore verifies a restored PostgreSQL database and evidence bucket without changing either system.
Command synapse-verify-restore verifies a restored PostgreSQL database and evidence bucket without changing either system.
synapse-worker command
Command synapse-worker is the privileged execution worker: it claims recon jobs the API enqueued to the durable queue and runs them under the SAME gate/audit/evidence invariants as the in-process path, but with the sandbox + kernel egress allowlist (through a narrow root-owned broker on hardened execution hosts).
Command synapse-worker is the privileged execution worker: it claims recon jobs the API enqueued to the durable queue and runs them under the SAME gate/audit/evidence invariants as the in-process path, but with the sandbox + kernel egress allowlist (through a narrow root-owned broker on hardened execution hosts).
internal
adapter/agentspool
Package agentspool adapts the existing detection sensor and sink contracts to the canonical telemetry normalizer and the durable agent spool.
Package agentspool adapts the existing detection sensor and sink contracts to the canonical telemetry normalizer and the durable agent spool.
adapter/httpapi
Package httpapi is the HTTP driving adapter: it maps routes to use case services.
Package httpapi is the HTTP driving adapter: it maps routes to use case services.
adapter/mcpserver
Package mcpserver exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
Package mcpserver exposes Synapse's agent tool catalog to external AI clients over the Model Context Protocol.
adapter/observability
Package observability adapts Synapse's bounded telemetry seams to Prometheus.
Package observability adapts Synapse's bounded telemetry seams to Prometheus.
composition/exportcompose
Package exportcompose wires the published rule catalog into the report exporters.
Package exportcompose wires the published rule catalog into the report exporters.
composition/responseobserver
Package responseobserver composes the agent-side response-observation workflow.
Package responseobserver composes the agent-side response-observation workflow.
composition/sandboxcheck
Package sandboxcheck runs conformance checks through the production sandbox runner.
Package sandboxcheck runs conformance checks through the production sandbox runner.
composition/scacompose
Package scacompose shares SCA execution composition between API and worker roots.
Package scacompose shares SCA execution composition between API and worker roots.
domain/accuracy
Package accuracy holds the domain model for a persisted detection-accuracy regression run: the owned engine's precision/recall over the golden corpus, captured over time so the console can show a trend.
Package accuracy holds the domain model for a persisted detection-accuracy regression run: the owned engine's precision/recall over the golden corpus, captured over time so the console can show a trend.
domain/advisory
Package advisory is the OWNED vulnerability-advisory matching brain: it decides whether a component version is affected by an advisory's version ranges WITHOUT querying a third-party service (OSV.dev / Grype), so detection does not depend on any one external matcher.
Package advisory is the OWNED vulnerability-advisory matching brain: it decides whether a component version is affected by an advisory's version ranges WITHOUT querying a third-party service (OSV.dev / Grype), so detection does not depend on any one external matcher.
domain/agent
Package agent holds the pure domain types for AI orchestration: the LLM conversation values (messages, tool-calls, usage) and the orchestration state (session, proposed action, risk class, approval decision).
Package agent holds the pure domain types for AI orchestration: the LLM conversation values (messages, tool-calls, usage) and the orchestration state (session, proposed action, risk class, approval decision).
domain/aitriagereview
Package aitriagereview models the human decision that follows an AI false-positive critique which the deterministic gate policy refused to authorize on its own.
Package aitriagereview models the human decision that follows an AI false-positive critique which the deterministic gate policy refused to authorize on its own.
domain/alerting
Package alerting is the domain of operator notifications: the alert a defender receives when the platform records something that needs a human, and the rule that decides which events qualify.
Package alerting is the domain of operator notifications: the alert a defender receives when the platform records something that needs a human, and the rule that decides which events qualify.
domain/assessmentsnapshot
Package assessmentsnapshot defines immutable, comparison-ready Assessment snapshots.
Package assessmentsnapshot defines immutable, comparison-ready Assessment snapshots.
domain/asset
Package asset contains the technical fleet Asset and business-level BusinessAsset models.
Package asset contains the technical fleet Asset and business-level BusinessAsset models.
domain/attackpath
Package attackpath derives bounded, evidence-carrying paths from estate assets to findings.
Package attackpath derives bounded, evidence-carrying paths from estate assets to findings.
domain/audit
Package audit makes the audit trail tamper-evident: each entry's Hash covers its content AND the previous entry's Hash, exactly like the evidence chain (golden rule 6).
Package audit makes the audit trail tamper-evident: each entry's Hash covers its content AND the previous entry's Hash, exactly like the evidence chain (golden rule 6).
domain/aup
Package aup models acceptance of the Acceptable-Use Policy.
Package aup models acceptance of the Acceptable-Use Policy.
domain/baseline
Package baseline is the pure-domain behavioral-baseline model for Phase D of the EDR data plane (#594, D1-D4).
Package baseline is the pure-domain behavioral-baseline model for Phase D of the EDR data plane (#594, D1-D4).
domain/callgraph
Package callgraph is the deterministic call-graph domain model (Tier-2 shared foundation): a directed graph of function-call edges plus the entrypoints reachability is measured from, and the pure query primitives over it.
Package callgraph is the deterministic call-graph domain model (Tier-2 shared foundation): a directed graph of function-call edges plus the entrypoints reachability is measured from, and the pure query primitives over it.
domain/cloudposture
Package cloudposture models vendor-neutral live cloud inventory and posture.
Package cloudposture models vendor-neutral live cloud inventory and posture.
domain/clusterinventory
Package clusterinventory is the pure-domain core of the Kubernetes cluster agent (#411, epic #405): it maps a vendor-neutral snapshot of a cluster to the fleet asset model (domain/asset).
Package clusterinventory is the pure-domain core of the Kubernetes cluster agent (#411, epic #405): it maps a vendor-neutral snapshot of a cluster to the fleet asset model (domain/asset).
domain/compliance
Package compliance maps a finding's CWE to the regulatory/standard controls it bears on (compliance mapping).
Package compliance maps a finding's CWE to the regulatory/standard controls it bears on (compliance mapping).
domain/correlation
Package correlation is the pure-domain, deterministic engine that folds runtime detection signals into incidents for Phase C of the EDR data plane (#594, C2 #676).
Package correlation is the pure-domain, deterministic engine that folds runtime detection signals into incidents for Phase C of the EDR data plane (#594, C2 #676).
domain/dastcheck
Package dastcheck defines the metadata contract for first-party DAST checks.
Package dastcheck defines the metadata contract for first-party DAST checks.
domain/dastrun
Package dastrun is the durable record of a governed DAST verification run.
Package dastrun is the durable record of a governed DAST verification run.
domain/dastsession
Package dastsession defines secret-free authenticated DAST session configuration.
Package dastsession defines secret-free authenticated DAST session configuration.
domain/dastsurface
Package dastsurface models the deterministic, bounded DAST application surface.
Package dastsurface models the deterministic, bounded DAST application surface.
domain/detection
Package detection is the pure domain for the agent-side blue-team detection engine (issue #422): the typed event classes an eBPF sensor observes, the clean-room rules that match over them, the detection a match emits, and the coverage honesty that says a class the agent could not observe is a GAP, never a clean host.
Package detection is the pure domain for the agent-side blue-team detection engine (issue #422): the typed event classes an eBPF sensor observes, the clean-room rules that match over them, the detection a match emits, and the coverage honesty that says a class the agent could not observe is a GAP, never a clean host.
domain/distro
Package distro captures the operating-system distribution of a scanned target (from its OS packages) and flags releases that are past End-of-Life – i.e.
Package distro captures the operating-system distribution of a scanned target (from its OS packages) and flags releases that are past End-of-Life – i.e.
domain/emulation
Package emulation is the pure domain for adversary emulation (issue #421): techniques mapped to a public taxonomy, each declaring the detection it should produce, and the coverage record that pairs what executed with what was detected.
Package emulation is the pure domain for adversary emulation (issue #421): techniques mapped to a public taxonomy, each declaring the detection it should produce, and the coverage record that pairs what executed with what was detected.
domain/endpoint
Package endpoint is Phase B of the security data plane (#594): it turns the raw, per-event telemetry the A-phase data plane delivers (telemetry.TelemetryEnvelope) into queryable ENDPOINT VISIBILITY — stable entities (processes, network connections, …) with lifecycle state, plus a per-asset State Timeline of their transitions.
Package endpoint is Phase B of the security data plane (#594): it turns the raw, per-event telemetry the A-phase data plane delivers (telemetry.TelemetryEnvelope) into queryable ENDPOINT VISIBILITY — stable entities (processes, network connections, …) with lifecycle state, plus a per-asset State Timeline of their transitions.
domain/engagement
Package engagement is the aggregate root for a security-testing project: its scope, legal authorization window, and lifecycle status.
Package engagement is the aggregate root for a security-testing project: its scope, legal authorization window, and lifecycle status.
domain/evidence
Package evidence models tamper-evident, hash-chained records of what an engagement produced (scans, findings, reports).
Package evidence models tamper-evident, hash-chained records of what an engagement produced (scans, findings, reports).
domain/exploitation
Package exploitation is the pure domain for a multi-step attack chain (issue #420).
Package exploitation is the pure domain for a multi-step attack chain (issue #420).
domain/exposure
Package exposure is the pure-domain continuous-exposure fusion for cross-cutting workstream X5 (#634): it fuses per-component vulnerability exposures for one asset into a single riskassessment.RiskContext Exposure factor (0..100).
Package exposure is the pure-domain continuous-exposure fusion for cross-cutting workstream X5 (#634): it fuses per-component vulnerability exposures for one asset into a single riskassessment.RiskContext Exposure factor (0..100).
domain/finding
Package finding models a confirmed or candidate security issue in an engagement.
Package finding models a confirmed or candidate security issue in an engagement.
domain/fleetagent
Package fleetagent is the epic-#405 fleet agent identity model: an enrolled, addressable agent and the single-use enrolment token that mints it.
Package fleetagent is the epic-#405 fleet agent identity model: an enrolled, addressable agent and the single-use enrolment token that mints it.
domain/fleetcoverage
Package fleetcoverage is the pure-domain truth model for fleet coverage (#413, epic #405): given the facts about one (asset, capability) pair, it resolves a single coverage verdict.
Package fleetcoverage is the pure-domain truth model for fleet coverage (#413, epic #405): given the facts about one (asset, capability) pair, it resolves a single coverage verdict.
domain/fleetdesired
Package fleetdesired defines control-plane-owned fleet intent for canonical technical assets.
Package fleetdesired defines control-plane-owned fleet intent for canonical technical assets.
domain/fleetrollout
Package fleetrollout decides whether ONE agent is offered an update, and to which version.
Package fleetrollout decides whether ONE agent is offered an update, and to which version.
domain/fleetversion
Package fleetversion is the pure-domain version model for fleet agent/control-plane version skew (#412, epic #405).
Package fleetversion is the pure-domain version model for fleet agent/control-plane version skew (#412, epic #405).
domain/hostinventory
Package hostinventory is the fleet VM-agent inventory model (#410, epic #405): the facts and installed packages an agent collects from a host that is not a container.
Package hostinventory is the fleet VM-agent inventory model (#410, epic #405): the facts and installed packages an agent collects from a host that is not a container.
domain/hotspot
Package hotspot models Project-scoped Security Hotspot projections.
Package hotspot models Project-scoped Security Hotspot projections.
domain/identity
Package identity defines persisted OIDC identities, authorization transactions, and sessions.
Package identity defines persisted OIDC identities, authorization transactions, and sessions.
domain/ignore
Package ignore models a repo-committed, declarative finding-suppression policy: the accepted-risk decisions a team version-controls alongside its code – Synapse's take on Trivy's .trivyignore, made governance-first.
Package ignore models a repo-committed, declarative finding-suppression policy: the accepted-risk decisions a team version-controls alongside its code – Synapse's take on Trivy's .trivyignore, made governance-first.
domain/importedfinding
Package importedfinding models a finding produced by a THIRD-PARTY scanner and ingested into this system's governance path.
Package importedfinding models a finding produced by a THIRD-PARTY scanner and ingested into this system's governance path.
domain/importedsbom
Package importedsbom models a client-supplied SBOM attached to an engagement.
Package importedsbom models a client-supplied SBOM attached to an engagement.
domain/importreceipt
Package importreceipt models durable receipts for logical external imports.
Package importreceipt models durable receipts for logical external imports.
domain/incident
Package incident is the pure-domain, event-sourced Incident primitive for Phase C of the EDR data plane (#594, C1 #675).
Package incident is the pure-domain, event-sourced Incident primitive for Phase C of the EDR data plane (#594, C1 #675).
domain/integration
Package integration models tenant-scoped external CI/CD connections and provider-neutral build provenance.
Package integration models tenant-scoped external CI/CD connections and provider-neutral build provenance.
domain/issue
Package issue models Project-scoped code-quality issue projections and their triage lifecycle (open / accepted / false-positive / won't-fix).
Package issue models Project-scoped code-quality issue projections and their triage lifecycle (open / accepted / false-positive / won't-fix).
domain/javaprogram
Package javaprogram defines the deterministic, source-only semantic facts used by Java value-flow taint.
Package javaprogram defines the deterministic, source-only semantic facts used by Java value-flow taint.
domain/jsprogram
Package jsprogram defines the deterministic, source-only semantic facts used by JavaScript/TypeScript value-flow taint.
Package jsprogram defines the deterministic, source-only semantic facts used by JavaScript/TypeScript value-flow taint.
domain/jsresolution
Package jsresolution models deterministic JavaScript and TypeScript package identity resolution without embedding filesystem or parser implementation details.
Package jsresolution models deterministic JavaScript and TypeScript package identity resolution without embedding filesystem or parser implementation details.
domain/jssymbols
Package jssymbols holds the decision rules for Tier-2 JavaScript and TypeScript reachability: given what first-party source statically does with an imported npm package, can a specific AFFECTED SYMBOL of that package be reached?
Package jssymbols holds the decision rules for Tier-2 JavaScript and TypeScript reachability: given what first-party source statically does with an imported npm package, can a specific AFFECTED SYMBOL of that package be reached?
domain/judgment
Package judgment is the AI "analysis brain" primitive: a propose→verify→confirm CLAIM about a subject (a finding, component, vulnerability, or the engagement), evidence-gated and hash-chainable, that generalizes the exploitation gate.
Package judgment is the AI "analysis brain" primitive: a propose→verify→confirm CLAIM about a subject (a finding, component, vulnerability, or the engagement), evidence-gated and hash-chainable, that generalizes the exploitation gate.
domain/legalhold
Package legalhold is the pure domain for a LEGAL HOLD on an engagement's data (#635 privacy & data governance).
Package legalhold is the pure domain for a LEGAL HOLD on an engagement's data (#635 privacy & data governance).
domain/measure
Package measure holds numeric, non-finding project measures (code size, complexity, duplication, coverage).
Package measure holds numeric, non-finding project measures (code size, complexity, duplication, coverage).
domain/modulegraph
Package modulegraph defines the deterministic, source-only JavaScript and TypeScript module graph used by the first phase of import reachability.
Package modulegraph defines the deterministic, source-only JavaScript and TypeScript module graph used by the first phase of import reachability.
domain/notification
Package notification defines tenant-owned notification channels, rules, events, and durable delivery history.
Package notification defines tenant-owned notification channels, rules, events, and durable delivery history.
domain/offensivepolicy
Package offensivepolicy is the machine-readable half of the offensive governance policy (docs/redteam/offensive-policy.md, issue #418).
Package offensivepolicy is the machine-readable half of the offensive governance policy (docs/redteam/offensive-policy.md, issue #418).
domain/ownership
Package ownership models explainable team routing without granting access to findings.
Package ownership models explainable team routing without granting access to findings.
domain/privacy
Package privacy is the SOURCE-SIDE telemetry redaction classifier (A6, #627 — the A0.6 privacy half of #611).
Package privacy is the SOURCE-SIDE telemetry redaction classifier (A6, #627 — the A0.6 privacy half of #611).
domain/project
Package project is the aggregate root for a long-lived code-quality project.
Package project is the aggregate root for a long-lived code-quality project.
domain/projectanalysis
Package projectanalysis models immutable, tenant-scoped Project analysis snapshots.
Package projectanalysis models immutable, tenant-scoped Project analysis snapshots.
domain/promotion
Package promotion defines deterministic cross-pillar finding-priority rules.
Package promotion defines deterministic cross-pillar finding-priority rules.
domain/purplecoverage
Package purplecoverage is the pure domain that closes the purple loop (issue #426): it joins the detection each emulated technique EXPECTED (#421) with the detections that ACTUALLY fired (#422/#423) and resolves a coverage verdict.
Package purplecoverage is the pure domain that closes the purple loop (issue #426): it joins the detection each emulated technique EXPECTED (#421) with the detections that ACTUALLY fired (#422/#423) and resolves a coverage verdict.
domain/pythonprogram
Package pythonprogram defines the deterministic, source-only semantic facts used by Python Tier-2 reachability and value-flow taint.
Package pythonprogram defines the deterministic, source-only semantic facts used by Python Tier-2 reachability and value-flow taint.
domain/qualitygate
Package qualitygate is the deterministic pass/fail gate over a codebase's measured metrics – the "Clean as You Code" quality gate.
Package qualitygate is the deterministic pass/fail gate over a codebase's measured metrics – the "Clean as You Code" quality gate.
domain/qualityprofile
Package qualityprofile models named, per-language rule sets — the industry-standard "Quality Profile".
Package qualityprofile models named, per-language rule sets — the industry-standard "Quality Profile".
domain/rating
Package rating turns findings + size measures into deterministic project health grades (A-E) and a technical-debt estimate, the counterpart on the code-quality side to risk priority on the security side.
Package rating turns findings + size measures into deterministic project health grades (A-E) and a technical-debt estimate, the counterpart on the code-quality side to risk priority on the security side.
domain/recon
Package recon holds the domain types for reconnaissance runs.
Package recon holds the domain types for reconnaissance runs.
domain/response
Package response is the pure domain for governed defensive response actions (issue #425): contain, isolate, quarantine.
Package response is the pure domain for governed defensive response actions (issue #425): contain, isolate, quarantine.
domain/responsesaga
Package responsesaga is the pure-domain state machine for a GOVERNED response action's full lifecycle (Phase C, C6 #680) — the distributed saga from proposal through approval, agent execution, and a TELEMETRY-VERIFIED post-condition to an optional rollback.
Package responsesaga is the pure-domain state machine for a GOVERNED response action's full lifecycle (Phase C, C6 #680) — the distributed saga from proposal through approval, agent execution, and a TELEMETRY-VERIFIED post-condition to an optional rollback.
domain/riskassessment
Package riskassessment is the pure-domain tri-score risk model for Phase C of the EDR data plane (#594, C3 #677).
Package riskassessment is the pure-domain tri-score risk model for Phase C of the EDR data plane (#594, C3 #677).
domain/riskstory
Package riskstory is the pure, deterministic domain for the unified per-asset risk story (issue #427): one narrative per asset assembled from records already produced by the other pillars — the asset inventory (#431), the findings of every engine + their reachability verdicts, the attack-path graph (#419), runtime detections (#423), and the continuous vulnerability occurrences/assessments (#514).
Package riskstory is the pure, deterministic domain for the unified per-asset risk story (issue #427): one narrative per asset assembled from records already produced by the other pillars — the asset inventory (#431), the findings of every engine + their reachability verdicts, the attack-path graph (#419), runtime detections (#423), and the continuous vulnerability occurrences/assessments (#514).
domain/rulepack
Package rulepack models signed, versioned detection content and its release metadata (#630).
Package rulepack models signed, versioned detection content and its release metadata (#630).
domain/runtimereach
Package runtimereach models the deterministic join from an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) to the OS package that owns the loaded file, and from that package to the finding it affects.
Package runtimereach models the deterministic join from an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) to the OS package that owns the loaded file, and from that package to the finding it affects.
domain/sbom
Package sbom models a Software Bill of Materials and its components/licenses.
Package sbom models a Software Bill of Materials and its components/licenses.
domain/scmconnector
Package scmconnector is the aggregate for a tenant-scoped source-control credential binding: a git host and the username a personal access token authenticates as, so the server can clone a PRIVATE repository on that host.
Package scmconnector is the aggregate for a tenant-scoped source-control credential binding: a git host and the username a personal access token authenticates as, so the server can clone a PRIVATE repository on that host.
domain/sensorstate
Package sensorstate defines immutable endpoint sensor-state observations.
Package sensorstate defines immutable endpoint sensor-state observations.
domain/shared
Package shared holds value objects and errors common to all domain packages.
Package shared holds value objects and errors common to all domain packages.
domain/sla
Package sla is the pure, deterministic domain for the risk-based remediation SLA (issue #80, Phase 0).
Package sla is the pure, deterministic domain for the risk-based remediation SLA (issue #80, Phase 0).
domain/sourcepolicy
Package sourcepolicy defines the server-authoritative policy for durable Code source snapshots.
Package sourcepolicy defines the server-authoritative policy for durable Code source snapshots.
domain/suppression
Package suppression models .synapseignore: operator-declared suppressions that hide known/accepted findings, each REQUIRING a reason and an expiry date.
Package suppression models .synapseignore: operator-declared suppressions that hide known/accepted findings, each REQUIRING a reason and an expiry date.
domain/symbolcanon
Package symbolcanon canonicalizes vulnerable-symbol names so the advisory side and the reachability/observed side compare identically.
Package symbolcanon canonicalizes vulnerable-symbol names so the advisory side and the reachability/observed side compare identically.
domain/taint
Package taint is the deterministic taint-analysis domain model: a data-flow graph from untrusted SOURCES to dangerous SINKS, with SANITIZER nodes that neutralize a flow, plus the pure query that reports an injection – a source→sink path that crosses no sanitizer.
Package taint is the deterministic taint-analysis domain model: a data-flow graph from untrusted SOURCES to dangerous SINKS, with SANITIZER nodes that neutralize a flow, plus the pure query that reports an injection – a source→sink path that crosses no sanitizer.
domain/telemetry
Package telemetry is the pure domain for the raw-telemetry tier's HONESTY semantics (#611, A0.4/A0.6): how a batch's fidelity is classified so coverage/confidence never lie.
Package telemetry is the pure domain for the raw-telemetry tier's HONESTY semantics (#611, A0.4/A0.6): how a batch's fidelity is classified so coverage/confidence never lie.
domain/telemetryschema
Package telemetryschema owns the wire-format version of telemetry events and batches (A0.3, epic #594).
Package telemetryschema owns the wire-format version of telemetry events and batches (A0.3, epic #594).
domain/threatmodel
Package threatmodel is the architecture-input model that threat modeling reasons over: a data-flow diagram – components (processes, data stores, external entities), directed data flows between them, trust boundaries that partition them by trust level, and the assets at stake.
Package threatmodel is the architecture-input model that threat modeling reasons over: a data-flow diagram – components (processes, data stores, external entities), directed data flows between them, trust boundaries that partition them by trust level, and the assets at stake.
domain/user
Package user models operator identities: each consultant is a distinct user with their own API key, so every action – comments, findings, assignments, audit, evidence – is attributable to a real person, not a shared "operator".
Package user models operator identities: each consultant is a distinct user with their own API key, so every action – comments, findings, assignments, audit, evidence – is attributable to a real person, not a shared "operator".
domain/verdict
Package verdict is the shared adversarial-verdict value type + evidence bar used by BOTH finding (exploitation) and judgment (AI analysis).
Package verdict is the shared adversarial-verdict value type + evidence bar used by BOTH finding (exploitation) and judgment (AI analysis).
domain/vex
Package vex holds the OpenVEX domain vocabulary (the closed justification enum, shared by the VEX export and the AI vex-justification judgment) AND the consume-side parser + product-to-finding matcher (document.go: Parse, Statement.Suppresses, Statement.MatchesFinding) shared by the post-scan VEX apply and the in-scan .vex consumer.
Package vex holds the OpenVEX domain vocabulary (the closed justification enum, shared by the VEX export and the AI vex-justification judgment) AND the consume-side parser + product-to-finding matcher (document.go: Parse, Statement.Suppresses, Statement.MatchesFinding) shared by the post-scan VEX apply and the in-scan .vex consumer.
domain/vulnerability
Package vulnerability models a known issue affecting an SBOM component.
Package vulnerability models a known issue affecting an SBOM component.
domain/workorder
Package workorder is the epic-#405 fleet work order model: a unit of work addressed to a specific agent identity, authorised by an engagement, signed by the control plane, and driven through an explicit state machine.
Package workorder is the epic-#405 fleet work order model: a unit of work addressed to a specific agent identity, authorised by an engagement, signed by the control plane, and driven through an explicit state machine.
domain/writeup
Package writeup holds the built-in finding-writeup library: reusable, curated finding text + remediation an operator inserts when authoring a manual finding, so report prose is consistent.
Package writeup holds the built-in finding-writeup library: reusable, curated finding text + remediation an operator inserts when authoring a manual finding, so report prose is consistent.
domain/writeupdraft
Package writeupdraft holds AI-proposed, human-gated finding write-up DRAFTS ("human-gated authoritative drafts").
Package writeupdraft holds AI-proposed, human-gated finding write-up DRAFTS ("human-gated authoritative drafts").
infrastructure/accuracyprobe
Package accuracyprobe adapts the owned advisory-matching engine (ownadvisory.Source) into the accuracyeval.CaseScanner the usecase-layer accuracy evaluation needs.
Package accuracyprobe adapts the owned advisory-matching engine (ownadvisory.Source) into the accuracyeval.CaseScanner the usecase-layer accuracy evaluation needs.
infrastructure/acquire
Package acquire prepares an isolated workspace for an SCA target.
Package acquire prepares an isolated workspace for an SCA target.
infrastructure/agentstate
Package agentstate persists small agent-control records which are separate from the append-only telemetry WAL.
Package agentstate persists small agent-control records which are separate from the append-only telemetry WAL.
infrastructure/alertsink/webhook
Package webhook delivers alerts as signed JSON POSTs to an operator-configured URL.
Package webhook delivers alerts as signed JSON POSTs to an operator-configured URL.
infrastructure/benchid
Package benchid records the identity of the benchmark-only competitor tools used in the owned-vs-competitor differentials, so a head-to-head is reproducible.
Package benchid records the identity of the benchmark-only competitor tools used in the owned-vs-competitor differentials, so a head-to-head is reproducible.
infrastructure/benchperf
Package benchperf measures pinned workloads and checks committed allocation ceilings.
Package benchperf measures pinned workloads and checks committed allocation ceilings.
infrastructure/blob
Package blob provides content-addressed artifact storage for the evidence vault a MinIO/S3 adapter for deployments and an in-memory store for dev/tests.
Package blob provides content-addressed artifact storage for the evidence vault a MinIO/S3 adapter for deployments and an in-memory store for dev/tests.
infrastructure/cache/fptriagecache
Package fptriagecache provides a bounded, filesystem-backed cache for typed AI false-positive triage claims.
Package fptriagecache provides a bounded, filesystem-backed cache for typed AI false-positive triage claims.
infrastructure/cache/sbomcache
Package sbomcache is a filesystem-backed, content-addressed cache of generated SBOMs.
Package sbomcache is a filesystem-backed, content-addressed cache of generated SBOMs.
infrastructure/cloud/aws
Package aws implements the read-only AWS cloud posture connector.
Package aws implements the read-only AWS cloud posture connector.
infrastructure/cloud/azure
Package azure implements the read-only Azure Resource Graph cloud-posture connector.
Package azure implements the read-only Azure Resource Graph cloud-posture connector.
infrastructure/cloud/gcp
Package gcp provides the read-only Google Cloud posture connector.
Package gcp provides the read-only Google Cloud posture connector.
infrastructure/cloudsandbox
Package cloudsandbox executes credentialed cloud SDK helpers inside the hardened sandbox.
Package cloudsandbox executes credentialed cloud SDK helpers inside the hardened sandbox.
infrastructure/cqbenchrun
Package cqbenchrun runs the shipped owned code-quality engine over the cqbench corpus and reduces its findings into the engine-agnostic scorecard observations the cqbench reducer consumes.
Package cqbenchrun runs the shipped owned code-quality engine over the cqbench corpus and reduces its findings into the engine-agnostic scorecard observations the cqbench reducer consumes.
infrastructure/dastchecks
Package dastchecks evaluates deterministic, passive DAST observations.
Package dastchecks evaluates deterministic, passive DAST observations.
infrastructure/dastengine
Package dastengine runs authenticated DAST plans through a dedicated helper.
Package dastengine runs authenticated DAST plans through a dedicated helper.
infrastructure/detectsink
Package detectsink provides the milestone-1 landing spot for the detections the agent-side engine (#422) emits: an append-only JSONL file on the host.
Package detectsink provides the milestone-1 landing spot for the detections the agent-side engine (#422) emits: an append-only JSONL file on the host.
infrastructure/ebpf
Package ebpf is the egress connection observer: a cgroup connect4/connect6 eBPF program (compiled to bytecode by clang, embedded, loaded by cilium/ebpf – no toolchain at runtime) attached to a per-run cgroup.
Package ebpf is the egress connection observer: a cgroup connect4/connect6 eBPF program (compiled to bytecode by clang, embedded, loaded by cilium/ebpf – no toolchain at runtime) attached to a per-run cgroup.
infrastructure/egress
Package egress applies a compiled egress.Policy as a real, kernel-enforced network namespace.
Package egress applies a compiled egress.Policy as a real, kernel-enforced network namespace.
infrastructure/fleetca
Package fleetca is the control-plane certificate authority for fleet agents (#408).
Package fleetca is the control-plane certificate authority for fleet agents (#408).
infrastructure/fleetclient
Package fleetclient is the agent-side HTTP client for the fleet transport (#410): it enrols, heartbeats, claims work and reports results against the control plane's /api/v1/fleet API.
Package fleetclient is the agent-side HTTP client for the fleet transport (#410): it enrols, heartbeats, claims work and reports results against the control plane's /api/v1/fleet API.
infrastructure/fleetupdate
Package fleetupdate is the agent self-update state machine (#412, epic #405): download a control-plane-offered version, VERIFY its checksum and signature BEFORE replacing anything, install atomically, then gate on a successful health check and AUTOMATICALLY ROLL BACK if the new version does not become healthy within a bounded window.
Package fleetupdate is the agent self-update state machine (#412, epic #405): download a control-plane-offered version, VERIFY its checksum and signature BEFORE replacing anything, install atomically, then gate on a successful health check and AUTOMATICALLY ROLL BACK if the new version does not become healthy within a bounded window.
infrastructure/hostinv
Package hostinv collects a fleet VM agent's host inventory (#410): host facts and installed OS packages, read from the host filesystem under a configurable root.
Package hostinv collects a fleet VM agent's host inventory (#410): host facts and installed OS packages, read from the host filesystem under a configurable root.
infrastructure/k8sinv
Package k8sinv is the Kubernetes infrastructure adapter for the cluster agent (#411, epic #405).
Package k8sinv is the Kubernetes infrastructure adapter for the cluster agent (#411, epic #405).
infrastructure/llm/openai
Package openai implements ports.LLM against an OpenAI-compatible Chat Completions API – the reference provider, tested against the LLM gateway.
Package openai implements ports.LLM against an OpenAI-compatible Chat Completions API – the reference provider, tested against the LLM gateway.
infrastructure/logstream
Package logstream is an in-memory pub/sub for recon-run logs, backing the SSE endpoint (ports.LogStream).
Package logstream is an in-memory pub/sub for recon-run logs, backing the SSE endpoint (ports.LogStream).
infrastructure/notificationsender
Package notificationsender delivers one durable notification attempt.
Package notificationsender delivers one durable notification attempt.
infrastructure/oidc
Package oidc provides the OpenID Connect protocol boundary for Synapse's browser BFF.
Package oidc provides the OpenID Connect protocol boundary for Synapse's browser BFF.
infrastructure/ownershipcapture
Package ownershipcapture retains CODEOWNERS and validates application paths while an acquired workspace still exists.
Package ownershipcapture retains CODEOWNERS and validates application paths while an acquired workspace still exists.
infrastructure/persistence/file
Package file provides simple file-backed stores for single-tenant self-host mode and tests.
Package file provides simple file-backed stores for single-tenant self-host mode and tests.
infrastructure/persistence/memory
Package memory provides in-memory repository implementations for the walking skeleton and tests.
Package memory provides in-memory repository implementations for the walking skeleton and tests.
infrastructure/persistence/postgres
Package postgres provides PostgreSQL-backed repositories (pgx/v5) and applies migrations via goose.
Package postgres provides PostgreSQL-backed repositories (pgx/v5) and applies migrations via goose.
infrastructure/reachbench
Package reachbench runs the trusted reachability measurement lifecycle.
Package reachbench runs the trusted reachability measurement lifecycle.
infrastructure/reachcache
Package reachcache holds the infrastructure adapters for the reachability cache (EPIC #1042, 0.7): a filesystem source-tree fingerprinter that feeds the coordinator's verdict-complete cache key.
Package reachcache holds the infrastructure adapters for the reachability cache (EPIC #1042, 0.7): a filesystem source-tree fingerprinter that feeds the coordinator's verdict-complete cache key.
infrastructure/recon
Package recon provides ports.ReconTool adapters: each knows one recon binary's argv and output format.
Package recon provides ports.ReconTool adapters: each knows one recon binary's argv and output format.
infrastructure/releaseevidence
Package releaseevidence creates and verifies deterministic manifests for promoted release assets.
Package releaseevidence creates and verifies deterministic manifests for promoted release assets.
infrastructure/report
DOCX report renderer.
DOCX report renderer.
infrastructure/responseactuator
Package responseactuator executes the deliberately narrow endpoint response protocol.
Package responseactuator executes the deliberately narrow endpoint response protocol.
infrastructure/responsefleet
Package responsefleet dispatches governed response commands through the durable fleet work lane.
Package responsefleet dispatches governed response commands through the durable fleet work lane.
infrastructure/responsekey
Package responsekey loads the endpoint's pinned control-plane response-command trust roots.
Package responsekey loads the endpoint's pinned control-plane response-command trust roots.
infrastructure/responseobserver
Package responseobserver provides endpoint-side observation infrastructure.
Package responseobserver provides endpoint-side observation infrastructure.
infrastructure/runtimeevidence
Package runtimeevidence is the fleet-agent collector that turns observed shared-library loads into a runtime-reachability report (EPIC #1042 #1060/#1061): the OS packages that own the loaded objects, scoped to the loaded set, with filesystem identity (device+inode) for the misattribution-safe server-side join.
Package runtimeevidence is the fleet-agent collector that turns observed shared-library loads into a runtime-reachability report (EPIC #1042 #1060/#1061): the OS packages that own the loaded objects, scoped to the loaded set, with filesystem identity (device+inode) for the misattribution-safe server-side join.
infrastructure/sandbox
Package sandbox implements ports.ToolRunner by confining each argv tool run in an unprivileged sandbox (see docs/08-security-model.md for the as-built control set).
Package sandbox implements ports.ToolRunner by confining each argv tool run in an unprivileged sandbox (see docs/08-security-model.md for the as-built control set).
infrastructure/scabench
Package scabench captures one fully pinned SCA benchmark observation.
Package scabench captures one fully pinned SCA benchmark observation.
infrastructure/scaprepare
Package scaprepare materializes public, diagnostic-only SCA benchmark inputs.
Package scaprepare materializes public, diagnostic-only SCA benchmark inputs.
infrastructure/secretverify
Package secretverify implements opt-in active secret verification (EPIC #860 D6.3): given a detected credential and the rule that found it, it makes ONE minimal read-only API call to the issuing provider to determine whether the credential is currently live.
Package secretverify implements opt-in active secret verification (EPIC #860 D6.3): given a detected credential and the rule that found it, it makes ONE minimal read-only API call to the issuing provider to determine whether the credential is currently live.
infrastructure/signing
Package signing implements ports.ChainSigner with ed25519: it attests to an evidence chain head so a custody chain proves origin (non-repudiation), not just integrity.
Package signing implements ports.ChainSigner with ed25519: it attests to an evidence chain head so a custody chain proves origin (non-repudiation), not just integrity.
infrastructure/sourceartifact
Package sourceartifact stores immutable Project analysis source on local disk.
Package sourceartifact stores immutable Project analysis source on local disk.
infrastructure/sourcesnippet
Package sourcesnippet reads a bounded source excerpt from a scanned workspace for the AI false-positive triage.
Package sourcesnippet reads a bounded source excerpt from a scanned workspace for the AI false-positive triage.
infrastructure/timestamp
Package timestamp implements ports.TimestampAuthority with an RFC-3161 client: it anchors a custody chain head to an EXTERNAL trusted timestamp, so a head can be proven to have existed before a given instant independent of the server's own ed25519 key – i.e.
Package timestamp implements ports.TimestampAuthority with an RFC-3161 client: it anchors a custody chain head to an EXTERNAL trusted timestamp, so a head can be proven to have existed before a given instant independent of the server's own ed25519 key – i.e.
infrastructure/toolrunner
Package toolrunner runs argv-based tools for the recon use case.
Package toolrunner runs argv-based tools for the recon use case.
infrastructure/tools/ast
Package ast adapts the synapse-ast sidecar to the ports.ASTProvider port: it shells out (argv only, no shell) to the binary, which parses the target with tree-sitter and returns per-language function counts as JSON.
Package ast adapts the synapse-ast sidecar to the ports.ASTProvider port: it shells out (argv only, no shell) to the binary, which parses the target with tree-sitter and returns per-language function counts as JSON.
infrastructure/tools/astwalk
Package astwalk is the source-tree walk + result model shared by the synapse-ast sidecar's CGO (tree-sitter) and CGO-free (stub) builds.
Package astwalk is the source-tree walk + result model shared by the synapse-ast sidecar's CGO (tree-sitter) and CGO-free (stub) builds.
infrastructure/tools/bincat
Package bincat catalogs installed language packages from a materialized image root filesystem that a lockfile would miss: Go module dependencies embedded in compiled Go binaries (via stdlib debug/buildinfo), Python distributions installed on disk (*.dist-info / *.egg-info metadata), Java archives (the embedded Maven META-INF/maven/.../pom.properties), installed Node.js packages (node_modules/<pkg>/package.json), and installed Ruby gems (the serialized specifications/*.gemspec).
Package bincat catalogs installed language packages from a materialized image root filesystem that a lockfile would miss: Go module dependencies embedded in compiled Go binaries (via stdlib debug/buildinfo), Python distributions installed on disk (*.dist-info / *.egg-info metadata), Java archives (the embedded Maven META-INF/maven/.../pom.properties), installed Node.js packages (node_modules/<pkg>/package.json), and installed Ruby gems (the serialized specifications/*.gemspec).
infrastructure/tools/codeanalysis
Package codeanalysis is a deterministic, pure-Go maintainability and reliability rule engine.
Package codeanalysis is a deterministic, pure-Go maintainability and reliability rule engine.
infrastructure/tools/codeinventory
Package codeinventory is a deterministic, pure-Go code-size inventory: it walks a source tree, classifies each file's language with go-enry, and counts code / comment / blank lines per language, plus functions where a first-party parser exists (Go today, via go/parser).
Package codeinventory is a deterministic, pure-Go code-size inventory: it walks a source tree, classifies each file's language with go-enry, and counts code / comment / blank lines per language, plus functions where a first-party parser exists (Go today, via go/parser).
infrastructure/tools/coupling
Package coupling builds deterministic first-party source dependency evidence.
Package coupling builds deterministic first-party source dependency evidence.
infrastructure/tools/coverage
Package coverage parses a test-coverage report (lcov, Cobertura XML, or JaCoCo XML) into per-file, per-line coverage.
Package coverage parses a test-coverage report (lcov, Cobertura XML, or JaCoCo XML) into per-file, per-line coverage.
infrastructure/tools/doctor
Package doctor provides an offline, read-only preflight report for synapse-cli.
Package doctor provides an offline, read-only preflight report for synapse-cli.
infrastructure/tools/dotnetreach
Package dotnetreach implements build-aware .NET (NuGet) reachability: it maps a resolved NuGet package to the assemblies it actually ships (via project.assets.json and the package cache) and to the namespaces those assemblies export (via a PE/ECMA-335 metadata reader), so reachability is decided against a package's REAL namespaces rather than a guess from its ID.
Package dotnetreach implements build-aware .NET (NuGet) reachability: it maps a resolved NuGet package to the assemblies it actually ships (via project.assets.json and the package cache) and to the namespaces those assemblies export (via a PE/ECMA-335 metadata reader), so reachability is decided against a package's REAL namespaces rather than a guess from its ID.
infrastructure/tools/duplication
Package duplication is a deterministic, pure-Go copy-paste (clone) detector: it walks a source tree, tokenizes each file (comment- and whitespace-insensitive, language-aware comment stripping), and finds runs of duplicated tokens across and within files via a Rabin-Karp rolling hash, then reports the standard duplication metrics (blocks, duplicated lines, files, density).
Package duplication is a deterministic, pure-Go copy-paste (clone) detector: it walks a source tree, tokenizes each file (comment- and whitespace-insensitive, language-aware comment stripping), and finds runs of duplicated tokens across and within files via a Rabin-Karp rolling hash, then reports the standard duplication metrics (blocks, duplicated lines, files, density).
infrastructure/tools/enry
Package enry adapts source-language detection to the LanguageDetector port, backed by go-enry (the GitHub Linguist port).
Package enry adapts source-language detection to the LanguageDetector port, backed by go-enry (the GitHub Linguist port).
infrastructure/tools/gitdiff
Package gitdiff computes the set of added/changed lines per file between a base ref and the working tree, for "new code" (Clean-as-You-Code) gating: a finding is "new" when it sits on a changed line.
Package gitdiff computes the set of added/changed lines per file between a base ref and the working tree, for "new code" (Clean-as-You-Code) gating: a finding is "new" when it sits on a changed line.
infrastructure/tools/gobinreach
Package gobinreach provides raise-only reachability evidence from compiled Go binaries.
Package gobinreach provides raise-only reachability evidence from compiled Go binaries.
infrastructure/tools/gomodgraph
Package gomodgraph resolves the transitive dependency EDGES of a Go module by shelling out to `go mod graph` via argv and mapping its module-graph output onto the SBOM's existing golang components.
Package gomodgraph resolves the transitive dependency EDGES of a Go module by shelling out to `go mod graph` via argv and mapping its module-graph output onto the SBOM's existing golang components.
infrastructure/tools/govulncheck
Package govulncheck adapts the Go call-graph builder to the CallGraphBuilder port by shelling out to a pinned govulncheck binary via argv.
Package govulncheck adapts the Go call-graph builder to the CallGraphBuilder port by shelling out to a pinned govulncheck binary via argv.
infrastructure/tools/gradleresolve
Package gradleresolve resolves a Gradle project's full dependency tree (direct + transitive, with the resolved versions) by shelling out (argv only) to a pinned `gradle` with a Synapse init script that walks the resolution-result GRAPH of the `runtimeClasspath` of EVERY project in the build (root + all subprojects) and prints each resolved Maven module.
Package gradleresolve resolves a Gradle project's full dependency tree (direct + transitive, with the resolved versions) by shelling out (argv only) to a pinned `gradle` with a Synapse init script that walks the resolution-result GRAPH of the `runtimeClasspath` of EVERY project in the build (root + all subprojects) and prints each resolved Maven module.
infrastructure/tools/grype
Package grype is a DetectionSource that augments OSV.
Package grype is a DetectionSource that augments OSV.
infrastructure/tools/ignorefile
Package ignorefile loads a repo-committed .synapseignore suppression policy from a prepared workspace.
Package ignorefile loads a repo-committed .synapseignore suppression policy from a prepared workspace.
infrastructure/tools/imageconfig
Package imageconfig runs owned hardening checks over a scanned container image's configuration and build history (EPIC #860 D7.10): a container that runs as root, a credential baked into an environment variable, and a sensitive build command (a remote script piped to a shell, or an ADD of a remote URL).
Package imageconfig runs owned hardening checks over a scanned container image's configuration and build history (EPIC #860 D7.10): a container that runs as root, a credential baked into an environment variable, and a sensitive build command (a remote script piped to a shell, or an ADD of a remote URL).
infrastructure/tools/jarchecksum
Package jarchecksum captures the artifact SHA-1 of JVM components by hashing the JAR files in the prepared workspace.
Package jarchecksum captures the artifact SHA-1 of JVM components by hashing the JAR files in the prepared workspace.
infrastructure/tools/jarhash
Package jarhash recovers the Maven coordinate of a shaded / relocated / metadata-less JVM component from its artifact SHA-1, by querying Maven Central's SHA-1 search API.
Package jarhash recovers the Maven coordinate of a shaded / relocated / metadata-less JVM component from its artifact SHA-1, by querying Maven Central's SHA-1 search API.
infrastructure/tools/jarlicense
Package jarlicense recovers component licenses from the license TEXT embedded in JARs in the prepared workspace, for components the registry lookup left unknown.
Package jarlicense recovers component licenses from the license TEXT embedded in JARs in the prepared workspace, for components the registry lookup left unknown.
infrastructure/tools/jsimports
Package jsimports implements the deterministic, source-only JavaScript and TypeScript module-import scanner behind ports.JSImportScanner (epic #378 phase R1).
Package jsimports implements the deterministic, source-only JavaScript and TypeScript module-import scanner behind ports.JSImportScanner (epic #378 phase R1).
infrastructure/tools/jsresolve
Package jsresolve provides offline, deterministic JavaScript and TypeScript package-identity metadata processing.
Package jsresolve provides offline, deterministic JavaScript and TypeScript package-identity metadata processing.
infrastructure/tools/jvmreach
Package jvmreach computes COARSE, deterministic class-level reachability for JVM projects: starting from the application's own compiled classes, does anything (transitively) reference a dependency's classes at all? A dependency whose classes are never referenced is "present but not wired in" – the signal behind the field complaint that a scan lists packages the project does not use.
Package jvmreach computes COARSE, deterministic class-level reachability for JVM projects: starting from the application's own compiled classes, does anything (transitively) reference a dependency's classes at all? A dependency whose classes are never referenced is "present but not wired in" – the signal behind the field complaint that a scan lists packages the project does not use.
infrastructure/tools/license
Package license adapts license classification + policy to the LicenseScanner port.
Package license adapts license classification + policy to the LicenseScanner port.
infrastructure/tools/licensefile
Package licensefile recovers component licenses by classifying the LICENSE / COPYING files present in the prepared workspace – the cross-ecosystem equivalent of Trivy's `--license-full`, but for ANY language (not just JARs, which jarlicense handles).
Package licensefile recovers component licenses by classifying the LICENSE / COPYING files present in the prepared workspace – the cross-ecosystem equivalent of Trivy's `--license-full`, but for ANY language (not just JARs, which jarlicense handles).
infrastructure/tools/licensemeta
Package licensemeta enriches SBOM components with license metadata from package registries (license recovery).
Package licensemeta enriches SBOM components with license metadata from package registries (license recovery).
infrastructure/tools/licensetext
Package licensetext classifies license FILE TEXT into an SPDX id with a confidence score, using github.com/google/licensecheck (the classifier deps.dev/pkgsite use).
Package licensetext classifies license FILE TEXT into an SPDX id with a confidence score, using github.com/google/licensecheck (the classifier deps.dev/pkgsite use).
infrastructure/tools/manifest
Package manifest enriches a generator's SBOM from dependency manifests the generator under-uses: it reconstructs missing dependency edges (Gemfile.lock), recovers dependencies the generator cannot resolve from source (Maven pom.xml, Gradle version catalogs), and refines component scope via pnpm workspace attribution.
Package manifest enriches a generator's SBOM from dependency manifests the generator under-uses: it reconstructs missing dependency edges (Gemfile.lock), recovers dependencies the generator cannot resolve from source (Maven pom.xml, Gradle version catalogs), and refines component scope via pnpm workspace attribution.
infrastructure/tools/manifestresolve
Package manifestresolve resolves the dependency tree of a lockfile-less package manifest by shelling out (argv only, no shell) to the ecosystem's own tool in a LOCK-ONLY, NO-SCRIPTS mode over a THROWAWAY COPY of the manifest, then reusing the owned lockfile parser to emit pinned components.
Package manifestresolve resolves the dependency tree of a lockfile-less package manifest by shelling out (argv only, no shell) to the ecosystem's own tool in a LOCK-ONLY, NO-SCRIPTS mode over a THROWAWAY COPY of the manifest, then reusing the owned lockfile parser to emit pinned components.
infrastructure/tools/mavencoord
Package mavencoord recovers authoritative Maven coordinates for SBOM components whose groupId was mis-derived during SBOM generation.
Package mavencoord recovers authoritative Maven coordinates for SBOM components whose groupId was mis-derived during SBOM generation.
infrastructure/tools/mavenresolve
Package mavenresolve resolves a Maven project's full dependency tree (direct + transitive, with the real versions) by shelling out to `mvn dependency:list` via argv, then parsing the resolved coordinates into SBOM components.
Package mavenresolve resolves a Maven project's full dependency tree (direct + transitive, with the real versions) by shelling out to `mvn dependency:list` via argv, then parsing the resolved coordinates into SBOM components.
infrastructure/tools/misconfig
Package misconfig is an owned, deterministic infrastructure-as-code / config scanner over a prepared workspace.
Package misconfig is an owned, deterministic infrastructure-as-code / config scanner over a prepared workspace.
infrastructure/tools/msi
Package msi parses a Windows Installer (.msi) file — a pure-Go, dependency-free reader for the OLE2 Compound File Binary Format (MS-CFB) container plus the MSI table layout on top of it — to recover the installed product's identity (name, version, manufacturer, product code) for cataloging.
Package msi parses a Windows Installer (.msi) file — a pure-Go, dependency-free reader for the OLE2 Compound File Binary Format (MS-CFB) container plus the MSI table layout on top of it — to recover the installed product's identity (name, version, manufacturer, product code) for cataloging.
infrastructure/tools/notebook
Package notebook decodes the small, stable subset of the Jupyter notebook format needed by source analyzers.
Package notebook decodes the small, stable subset of the Jupyter notebook format needed by source analyzers.
infrastructure/tools/npmresolve
Package npmresolve resolves an npm project's dependency tree (direct + transitive, with pinned versions) from a package.json that has NO committed lockfile — the common raw-source state where the manifest declares only semver RANGES (^1.2.3, ~1.0, >=2) and the SBOM otherwise sees no resolvable version to advisory-match.
Package npmresolve resolves an npm project's dependency tree (direct + transitive, with pinned versions) from a package.json that has NO committed lockfile — the common raw-source state where the manifest declares only semver RANGES (^1.2.3, ~1.0, >=2) and the SBOM otherwise sees no resolvable version to advisory-match.
infrastructure/tools/nvd
Package nvd backfills the severity of vulnerabilities the detection sources left UNKNOWN (an OSV-only distro CVE often carries no CVSS) by looking up the CVE's CVSS base score in the NVD CVE API.
Package nvd backfills the severity of vulnerabilities the detection sources left UNKNOWN (an OSV-only distro CVE often carries no CVSS) by looking up the CVE's CVSS base score in the NVD CVE API.
infrastructure/tools/ospkg
Package ospkg catalogs installed OS packages from a materialized image root filesystem: Debian/Ubuntu dpkg (/var/lib/dpkg/status), Alpine apk (/lib/apk/db/installed), and RHEL-family rpm (/var/lib/rpm/rpmdb.sqlite), with the distro release read from /etc/os-release.
Package ospkg catalogs installed OS packages from a materialized image root filesystem: Debian/Ubuntu dpkg (/var/lib/dpkg/status), Alpine apk (/lib/apk/db/installed), and RHEL-family rpm (/var/lib/rpm/rpmdb.sqlite), with the distro release read from /etc/os-release.
infrastructure/tools/osv
Package osv is a DetectionSource that queries OSV.dev – the primary vuln source (free, no auth, no rate limit).
Package osv is a DetectionSource that queries OSV.dev – the primary vuln source (free, no auth, no rate limit).
infrastructure/tools/ownadvisory
Package ownadvisory is the OWNED advisory DetectionSource: it matches an SBOM against Synapse's own normalized advisory store using the owned matcher (internal/domain/advisory), producing the same vulnerability.RawFinding the OSV/Grype adapters do – but WITHOUT querying any third-party service.
Package ownadvisory is the OWNED advisory DetectionSource: it matches an SBOM against Synapse's own normalized advisory store using the owned matcher (internal/domain/advisory), producing the same vulnerability.RawFinding the OSV/Grype adapters do – but WITHOUT querying any third-party service.
infrastructure/tools/ownsbom
Package ownsbom is Synapse's OWNED SBOM producer: a per-ecosystem parser registry that reads dependency manifests/lockfiles directly and emits a normalized sbom.SBOM, WITHOUT shelling out to a third-party scanner.
Package ownsbom is Synapse's OWNED SBOM producer: a per-ecosystem parser registry that reads dependency manifests/lockfiles directly and emits a normalized sbom.SBOM, WITHOUT shelling out to a third-party scanner.
infrastructure/tools/pyimports
Package pyimports is a SOURCE-ONLY Python import scanner: it reads a target's first-party .py files and extracts the top-level modules they import, plus whether the code uses dynamic imports.
Package pyimports is a SOURCE-ONLY Python import scanner: it reads a target's first-party .py files and extracts the top-level modules they import, plus whether the code uses dynamic imports.
infrastructure/tools/qualityprofile
Package qualityprofile loads the .synapse-gate.yaml (quality gate) and .synapse-rules.yaml (rule profile) config files into the pure-domain qualitygate types.
Package qualityprofile loads the .synapse-gate.yaml (quality gate) and .synapse-rules.yaml (rule profile) config files into the pure-domain qualitygate types.
infrastructure/tools/risk
Package risk enriches vulnerabilities with CISA KEV + FIRST EPSS so they can be ordered by real risk priority (KEV -> EPSS x CVSS).
Package risk enriches vulnerabilities with CISA KEV + FIRST EPSS so they can be ordered by real risk priority (KEV -> EPSS x CVSS).
infrastructure/tools/sast
Package sast is a deterministic, pure-Go pattern scanner: it walks a source tree and flags high-signal weaknesses (weak crypto, hardcoded secrets/keys, insecure TLS config) by regex, emitting one finding per (file, line, rule).
Package sast is a deterministic, pure-Go pattern scanner: it walks a source tree and flags high-signal weaknesses (weak crypto, hardcoded secrets/keys, insecure TLS config) by regex, emitting one finding per (file, line, rule).
infrastructure/tools/secretscan
Package secretscan is an owned, deterministic secret scanner over a prepared workspace.
Package secretscan is an owned, deterministic secret scanner over a prepared workspace.
infrastructure/tools/srcimports
Package srcimports implements source-only first-party import scanners for languages whose dependency usage is observable as an import/require/use statement (Rust, PHP, Ruby).
Package srcimports implements source-only first-party import scanners for languages whose dependency usage is observable as an import/require/use statement (Rust, PHP, Ruby).
infrastructure/tools/ssacallgraph
Package ssacallgraph builds a deterministic call graph from Go SOURCE using go/ssa – the general, first-party call graph taint analysis needs.
Package ssacallgraph builds a deterministic call graph from Go SOURCE using go/ssa – the general, first-party call graph taint analysis needs.
infrastructure/tools/syft
Package syft adapts SBOM generation to the SBOMGenerator port by shelling out to a pinned Syft binary.
Package syft adapts SBOM generation to the SBOMGenerator port by shelling out to a pinned Syft binary.
infrastructure/tools/taintcallgraph
Package taintcallgraph is the adapter that produces a general first-party call graph for E39 taint analysis by shelling out to the sandboxed `synapse-callgraph` argv binary (which runs the heavy go/ssa builder, internal/infrastructure/tools/ssacallgraph).
Package taintcallgraph is the adapter that produces a general first-party call graph for E39 taint analysis by shelling out to the sandboxed `synapse-callgraph` argv binary (which runs the heavy go/ssa builder, internal/infrastructure/tools/ssacallgraph).
infrastructure/tools/taintrules
Package taintrules loads an operator-provided custom taint-rule file (Semgrep-style user rules) into the pure-domain taint.CustomRules type.
Package taintrules loads an operator-provided custom taint-rule file (Semgrep-style user rules) into the pure-domain taint.CustomRules type.
infrastructure/tools/vexfile
Package vexfile loads an in-repo OpenVEX document (.synapse.vex.json) from a prepared workspace.
Package vexfile loads an in-repo OpenVEX document (.synapse.vex.json) from a prepared workspace.
infrastructure/vault
Package vault is the credential store: per-engagement secrets encrypted at rest with AES-256-GCM under a master key that never touches the database, logs, or the LLM transcript.
Package vault is the credential store: per-engagement secrets encrypted at rest with AES-256-GCM under a master key that never touches the database, logs, or the LLM transcript.
platform/agenttoken
Package agenttoken mints and parses fleet agent credentials.
Package agenttoken mints and parses fleet agent credentials.
platform/binregistry
Package binregistry verifies tool-binary integrity before execution (F5).
Package binregistry verifies tool-binary integrity before execution (F5).
platform/buildinfo
Package buildinfo reports dependency + application versions from the compiled binary's build metadata, used to record scan reproducibility.
Package buildinfo reports dependency + application versions from the compiled binary's build metadata, used to record scan reproducibility.
platform/config
Package config loads runtime configuration from the environment.
Package config loads runtime configuration from the environment.
platform/executionmode
Package executionmode provides fail-closed adapters for process roles that may compose execution-capable use cases but are not authorized to execute locally.
Package executionmode provides fail-closed adapters for process roles that may compose execution-capable use cases but are not authorized to execute locally.
platform/fssecurity
Package fssecurity exposes platform facts used when checking local secret-file protections.
Package fssecurity exposes platform facts used when checking local secret-file protections.
platform/httpserver
Package httpserver runs an HTTP server with graceful shutdown.
Package httpserver runs an HTTP server with graceful shutdown.
platform/idgen
Package idgen provides Clock and IDGenerator implementations for the platform.
Package idgen provides Clock and IDGenerator implementations for the platform.
platform/jobs
Package jobs is a small bounded worker pool: a fixed number of workers draining a fixed-size queue.
Package jobs is a small bounded worker pool: a fixed number of workers draining a fixed-size queue.
platform/logging
Package logging builds the application's structured logger.
Package logging builds the application's structured logger.
platform/redact
Package redact is the shared belt-and-suspenders scrubber for secret material on its way to any sink – logs, the audit writer, the evidence seal, tool output.
Package redact is the shared belt-and-suspenders scrubber for secret material on its way to any sink – logs, the audit writer, the evidence seal, tool output.
platform/untrusted
Package untrusted is the shared guard for any UNTRUSTED text a source-reading AI ingests – dependency source excerpts, files a SAST/threat brain reads, or a tool's stdout.
Package untrusted is the shared guard for any UNTRUSTED text a source-reading AI ingests – dependency source excerpts, files a SAST/threat brain reads, or a tool's stdout.
platform/worksign
Package worksign is the platform adapter that signs and verifies fleet work order payloads with an HMAC-SHA256 keyed MAC.
Package worksign is the platform adapter that signs and verifies fleet work order payloads with an HMAC-SHA256 keyed MAC.
testutil/gobinbenchmark
Package gobinbenchmark drives the current Go-binary binding regression from each production composition root.
Package gobinbenchmark drives the current Go-binary binding regression from each production composition root.
usecase/accuracyeval
Package accuracyeval loads an embedded golden corpus of labeled detection cases and reduces the owned engine's produced-vs-expected results to detection-accuracy metrics (precision, recall, false-discovery / false-negative rates), overall and per ecosystem group.
Package accuracyeval loads an embedded golden corpus of labeled detection cases and reduces the owned engine's produced-vs-expected results to detection-accuracy metrics (precision, recall, false-discovery / false-negative rates), overall and per ecosystem group.
usecase/advisoryingest
Package advisoryingest loads the owned normalized-advisory store from a bulk feed.
Package advisoryingest loads the owned normalized-advisory store from a bulk feed.
usecase/agenttools
Package agenttools is the agent's tool catalog: the bounded set of capabilities the LLM is allowed to invoke.
Package agenttools is the agent's tool catalog: the bounded set of capabilities the LLM is allowed to invoke.
usecase/aitriagereviewuc
Package aitriagereviewuc implements the durable human-review workflow for AI false-positive recommendations held back by the deterministic policy.
Package aitriagereviewuc implements the durable human-review workflow for AI false-positive recommendations held back by the deterministic policy.
usecase/alerting
Package alerting turns platform events a defender must act on into delivered notifications.
Package alerting turns platform events a defender must act on into delivered notifications.
usecase/analysis
Package analysis runs the evidence-gated lifecycle for AI "judgments" – the generalized twin of the exploitation gate.
Package analysis runs the evidence-gated lifecycle for AI "judgments" – the generalized twin of the exploitation gate.
usecase/approval
Package approval is the Human-In-The-Loop gate for AI-proposed actions.
Package approval is the Human-In-The-Loop gate for AI-proposed actions.
usecase/assetuc
Package assetuc is the use-case layer for the fleet asset model (#431, epic #405).
Package assetuc is the use-case layer for the fleet asset model (#431, epic #405).
usecase/attackpath
Package attackpath assembles tenant-scoped attack paths from existing records.
Package attackpath assembles tenant-scoped attack paths from existing records.
usecase/audit
Package audit is the read/verify use case over the append-only audit log.
Package audit is the read/verify use case over the append-only audit log.
usecase/aup
Package aup (use case) implements first-run Acceptable-Use-Policy logic.
Package aup (use case) implements first-run Acceptable-Use-Policy logic.
usecase/benchagg
Package benchagg aggregates the per-dimension accuracy results of the owned scanner benchmark dimensions (secrets, IaC/misconfiguration, DAST, CSPM, runtime host-CVE, SAST per-CWE) into one machine-readable report WITHOUT erasing per-dimension semantics.
Package benchagg aggregates the per-dimension accuracy results of the owned scanner benchmark dimensions (secrets, IaC/misconfiguration, DAST, CSPM, runtime host-CVE, SAST per-CWE) into one machine-readable report WITHOUT erasing per-dimension semantics.
usecase/benchmark
Package benchmark reduces fixture-supplied benchmark observations into a deterministic, versioned report.
Package benchmark reduces fixture-supplied benchmark observations into a deterministic, versioned report.
usecase/capabilities
Package capabilities answers one product question: which optional subsystems are switched on in this deployment, and which SYNAPSE_* variable switches each one.
Package capabilities answers one product question: which optional subsystems are switched on in this deployment, and which SYNAPSE_* variable switches each one.
usecase/chainrehearsal
Package chainrehearsal drives a governed exploitation chain as a no-host SIMULATION.
Package chainrehearsal drives a governed exploitation chain as a no-host SIMULATION.
usecase/codequality
Package codequality assembles the code-quality findings for a source tree: it runs the deterministic maintainability/reliability rule engine and layers on the metric-derived signals (duplication, and complexity when an AST backend is available), mapping everything to first-party finding.Finding values (Kind=quality/reliability, ungated, publishable like SAST).
Package codequality assembles the code-quality findings for a source tree: it runs the deterministic maintainability/reliability rule engine and layers on the metric-derived signals (duplication, and complexity when an AST backend is available), mapping everything to first-party finding.Finding values (Kind=quality/reliability, ungated, publishable like SAST).
usecase/cqbench
Package cqbench defines the deterministic code-quality accuracy corpus contract and its regression ratchet, and reduces an engine's detections into a per-language, per-issue-type precision/recall scorecard plus a metric-agreement section.
Package cqbench defines the deterministic code-quality accuracy corpus contract and its regression ratchet, and reduces an engine's detections into a per-language, per-issue-type precision/recall scorecard plus a metric-agreement section.
usecase/credentials
Package credentials is the management use case over the credential vault (secrets never enter logs): an operator stores per-engagement secrets (write-only) and lists or deletes them by NAME.
Package credentials is the management use case over the credential vault (secrets never enter logs): an operator stores per-engagement secrets (write-only) and lists or deletes them by NAME.
usecase/crosscheckjudge
Package crosscheckjudge turns cross-check DISAGREEMENTS into Judgments for human review.
Package crosscheckjudge turns cross-check DISAGREEMENTS into Judgments for human review.
usecase/cspm
Package cspm orchestrates read-only live cloud posture scans.
Package cspm orchestrates read-only live cloud posture scans.
usecase/curatedsinks
Package curatedsinks bridges the curated vulnerable-methods DB (advisory.CuratedSymbols) into the taint engine: each CONFIRMED curated vulnerable API becomes a taint sink, so the dataflow engine proves attacker input reaches that exact function (EPIC #1042 2.2, the curated moat).
Package curatedsinks bridges the curated vulnerable-methods DB (advisory.CuratedSymbols) into the taint engine: each CONFIRMED curated vulnerable API becomes a taint sink, so the dataflow engine proves attacker input reaches that exact function (EPIC #1042 2.2, the curated moat).
usecase/dastcrawl
Package dastcrawl derives a bounded, deterministic HTTP surface from authenticated observations.
Package dastcrawl derives a bounded, deterministic HTTP surface from authenticated observations.
usecase/dastrun
Package dastrun turns a governed DAST verification probe from a synchronous request-thread execution into a durable, lease-executed job.
Package dastrun turns a governed DAST verification probe from a synchronous request-thread execution into a durable, lease-executed job.
usecase/dastrunner
Package dastrunner executes narrowly-scoped, approved runtime verification probes.
Package dastrunner executes narrowly-scoped, approved runtime verification probes.
usecase/dastsession
Package dastsession executes approved, authenticated DAST request batches.
Package dastsession executes approved, authenticated DAST request batches.
usecase/dastverifier
Package dastverifier ingests runtime-verifier results for AppSec findings.
Package dastverifier ingests runtime-verifier results for AppSec findings.
usecase/dastworkflow
Package dastworkflow coordinates the governed DAST verification lifecycle.
Package dastworkflow coordinates the governed DAST verification lifecycle.
usecase/egress
Package egress compiles an engagement scope into a default-deny egress policy: the concrete set of {destination, ports} a sandboxed tool may reach.
Package egress compiles an engagement scope into a default-deny egress policy: the concrete set of {destination, ports} a sandboxed tool may reach.
usecase/egressgrant
Package egressgrant authorizes short-lived, process-bound egress grants from authoritative execution and engagement state.
Package egressgrant authorizes short-lived, process-bound egress grants from authoritative execution and engagement state.
usecase/emulation
Package emulation runs adversary emulation (issue #421) as a SUBSET of the exploitation machine's guarantees, never a looser path.
Package emulation runs adversary emulation (issue #421) as a SUBSET of the exploitation machine's guarantees, never a looser path.
usecase/engagement
Package engagement (use case) implements engagement application logic.
Package engagement (use case) implements engagement application logic.
usecase/enginecompare
Package enginecompare produces an honest differential between two vulnerability detection engines run over the SAME SBOM: which (component, CVE) pairs each engine found, and specifically what the candidate (the owned Synapse engine) found that a baseline competitor (e.g.
Package enginecompare produces an honest differential between two vulnerability detection engines run over the SAME SBOM: which (component, CVE) pairs each engine found, and specifically what the candidate (the owned Synapse engine) found that a baseline competitor (e.g.
usecase/evidence
Package evidence is the tamper-evident evidence vault: it appends sealed, hash-chained links, stores artifacts content-addressed in a blob store, and verifies the chain on read – emitting an append-only tamper ALERT on any mismatch.
Package evidence is the tamper-evident evidence vault: it appends sealed, hash-chained links, stores artifacts content-addressed in a blob store, and verifies the chain on read – emitting an append-only tamper ALERT on any mismatch.
usecase/execution
Package execution holds the shared server-side execution guard: engagement scope + legal authorization-window enforcement with append-only audit, applied BEFORE any tool runs.
Package execution holds the shared server-side execution guard: engagement scope + legal authorization-window enforcement with append-only audit, applied BEFORE any tool runs.
usecase/exploitation
Package exploitation is the evidence-gated lifecycle for AI/exploitation findings.
Package exploitation is the evidence-gated lifecycle for AI/exploitation findings.
usecase/export
Package export builds deterministic SARIF 2.1.0 + OpenVEX documents from stored findings.
Package export builds deterministic SARIF 2.1.0 + OpenVEX documents from stored findings.
usecase/findings
Package findings handles the human findings workflow: manual authoring, triage status transitions (with optimistic concurrency), assignment, and the persisted comment thread.
Package findings handles the human findings workflow: manual authoring, triage status transitions (with optimistic concurrency), assignment, and the persisted comment thread.
usecase/fleet/baselineuc
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
usecase/fleet/behaviorbaseline
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
usecase/fleet/clusterinventory
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
usecase/fleet/correlationuc
Package correlationuc orchestrates durable, two-phase event-time correlation.
Package correlationuc orchestrates durable, two-phase event-time correlation.
usecase/fleet/coverage
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
usecase/fleet/coveragewindow
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
usecase/fleet/desired
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
usecase/fleet/detect
Package detect is the agent-side detection engine (issue #422, phase 3).
Package detect is the agent-side detection engine (issue #422, phase 3).
usecase/fleet/detectionship
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
usecase/fleet/detectledger
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
usecase/fleet/endpointstate
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
usecase/fleet/exposurereader
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
usecase/fleet/exposureuc
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
usecase/fleet/hostinventory
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
usecase/fleet/hostvuln
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
usecase/fleet/incidenttriage
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
usecase/fleet/incidentuc
Package incidentuc is the usecase seam over the event-sourced incident store.
Package incidentuc is the usecase seam over the event-sourced incident store.
usecase/fleet/keyregistry
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
usecase/fleet/legalholduc
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
usecase/fleet/normalize
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
usecase/fleet/privacyexport
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
usecase/fleet/privacypolicy
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
usecase/fleet/processreport
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
usecase/fleet/responseexecute
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
usecase/fleet/responseobservation
Package responseobservation runs the endpoint-side, independent response-observation workflow.
Package responseobservation runs the endpoint-side, independent response-observation workflow.
usecase/fleet/responseobserver
Package responseobserver governs secondary agents that may observe response post-conditions.
Package responseobserver governs secondary agents that may observe response post-conditions.
usecase/fleet/responseverificationingest
Package responseverificationingest authenticates and persists purpose-signed response observations.
Package responseverificationingest authenticates and persists purpose-signed response observations.
usecase/fleet/retrohunt
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
usecase/fleet/riskscorebridge
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
usecase/fleet/riskscoreuc
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
usecase/fleet/runtimeevidence
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
usecase/fleet/telemetry
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
usecase/fleet/telemetryingest
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
usecase/fleetagentuc
Package fleetagentuc is the use-case layer for fleet agent identity (#409, epic #405): an operator mints a single-use enrolment token; an agent exchanges it for a long-lived bearer credential; the API authenticates every subsequent call by that credential.
Package fleetagentuc is the use-case layer for fleet agent identity (#409, epic #405): an operator mints a single-use enrolment token; an agent exchanges it for a long-lived bearer credential; the API authenticates every subsequent call by that credential.
usecase/fleetrolloutuc
Package fleetrolloutuc is the operator-facing lifecycle of an agent update rollout: set a target, promote it past the canary, pause it, resume it, and answer what one agent should be offered.
Package fleetrolloutuc is the operator-facing lifecycle of an agent update rollout: set a target, promote it past the canary, pause it, resume it, and answer what one agent should be offered.
usecase/fleetwork
Package fleetwork is the use-case layer for the fleet work order lifecycle (#407, epic #405): issue a signed, addressed, authorised order; let an agent claim orders addressed to it; and drive orders through the validated state machine.
Package fleetwork is the use-case layer for the fleet work order lifecycle (#407, epic #405): issue a signed, addressed, authorised order; let an agent claim orders addressed to it; and drive orders through the validated state machine.
usecase/fptriage
Package fptriage runs an LLM-assisted false-positive critique over safe-to-transmit first-party source-analysis findings (SAST and misconfig).
Package fptriage runs an LLM-assisted false-positive critique over safe-to-transmit first-party source-analysis findings (SAST and misconfig).
usecase/gobinsubject
Package gobinsubject encodes a version-bound Go affected-symbol query for binary reachability.
Package gobinsubject encodes a version-bound Go affected-symbol query for binary reachability.
usecase/hotspots
Package hotspots contains Project Security Hotspot projection use cases.
Package hotspots contains Project Security Hotspot projection use cases.
usecase/identitybff
Package identitybff orchestrates the OIDC browser flow without exposing provider credentials to HTTP handlers.
Package identitybff orchestrates the OIDC browser flow without exposing provider credentials to HTTP handlers.
usecase/identityuc
Package identityuc manages secure persistence primitives for OIDC login and opaque sessions.
Package identityuc manages secure persistence primitives for OIDC login and opaque sessions.
usecase/integrations
Package integrations orchestrates provider-neutral CI/CD integrations.
Package integrations orchestrates provider-neutral CI/CD integrations.
usecase/issues
Package issues contains Project code-quality issue projection use cases.
Package issues contains Project code-quality issue projection use cases.
usecase/jsreach
Package jsreach implements deterministic Tier-1 reachability for npm components: does first-party JavaScript or TypeScript source actually import a given package?
Package jsreach implements deterministic Tier-1 reachability for npm components: does first-party JavaScript or TypeScript source actually import a given package?
usecase/leaderuc
Package leaderuc runs leader election over a fenced lease (#406, epic #405) so more than one control-plane instance can run while exactly one is the scheduler leader at a time.
Package leaderuc runs leader election over a fenced lease (#406, epic #405) so more than one control-plane instance can run while exactly one is the scheduler leader at a time.
usecase/llmverifier
Package llmverifier is the automated LLM judgment-verifier: it makes SYNAPSE_VERIFIER_MODEL live on the server.
Package llmverifier is the automated LLM judgment-verifier: it makes SYNAPSE_VERIFIER_MODEL live on the server.
usecase/notification
Package notification provides tenant-scoped notification administration, durable publication, and worker delivery orchestration.
Package notification provides tenant-scoped notification administration, durable publication, and worker delivery orchestration.
usecase/nugetreach
Package nugetreach is the build-aware .NET reachability analyzer.
Package nugetreach is the build-aware .NET reachability analyzer.
usecase/offensivepolicy
Package offensivepolicy enforces the offensive governance policy (docs/redteam/offensive-policy.md, issue #418) before an offensive action is admitted.
Package offensivepolicy enforces the offensive governance policy (docs/redteam/offensive-policy.md, issue #418) before an offensive action is admitted.
usecase/orchestrator
Package orchestrator is the AI orchestrator – the typed Go state machine that owns control flow.
Package orchestrator is the AI orchestrator – the typed Go state machine that owns control flow.
usecase/ownership
Package ownership exposes tenant-bound ownership administration and human triage.
Package ownership exposes tenant-bound ownership administration and human triage.
usecase/ports
Package ports defines application boundaries.
Package ports defines application boundaries.
usecase/projectuc
Package projectuc implements project application logic.
Package projectuc implements project application logic.
usecase/promotion
Package promotion implements the use-case layer for deterministic finding-priority promotion.
Package promotion implements the use-case layer for deterministic finding-priority promotion.
usecase/purplecoverage
Package purplecoverage is the control plane that closes the purple loop (#426): it joins the offensive half of the ledger (an emulation.Run's per-technique coverage records — what each technique executed and EXPECTED to be detected, #421) with the defensive half (the detections that ACTUALLY fired on the same asset in the run window, #422/#423) and resolves a per-technique coverage verdict through the pure domain.
Package purplecoverage is the control plane that closes the purple loop (#426): it joins the offensive half of the ledger (an emulation.Run's per-technique coverage records — what each technique executed and EXPECTED to be detected, #421) with the defensive half (the detections that ACTUALLY fired on the same asset in the run window, #422/#423) and resolves a per-technique coverage verdict through the pure domain.
usecase/purpleteam
Package purpleteam orchestrates a governed adversary-emulation run and turns it into purple-team coverage.
Package purpleteam orchestrates a governed adversary-emulation run and turns it into purple-team coverage.
usecase/pyreach
Package pyreach answers Tier-1 Python reachability by IMPORT: a vulnerable PyPI package is "reachable" iff first-party code imports it.
Package pyreach answers Tier-1 Python reachability by IMPORT: a vulnerable PyPI package is "reachable" iff first-party code imports it.
usecase/qualitygates
Package qualitygates manages tenant-scoped quality-gate definitions.
Package qualitygates manages tenant-scoped quality-gate definitions.
usecase/qualityprofiles
Package qualityprofiles manages named, per-language quality profiles: built-in defaults generated from the rule catalog plus tenant-scoped custom copies, and their per-project assignment.
Package qualityprofiles manages named, per-language quality profiles: built-in defaults generated from the rule catalog plus tenant-scoped custom copies, and their per-project assignment.
usecase/reachability
Package reachability is the Tier-2 reachability query API: it wraps a ports.CallGraphBuilder + the deterministic callgraph domain queries into the service consumers use to turn "is this vulnerable symbol actually called?" into an evidence-backed reachability judgment.
Package reachability is the Tier-2 reachability query API: it wraps a ports.CallGraphBuilder + the deterministic callgraph domain queries into the service consumers use to turn "is this vulnerable symbol actually called?" into an evidence-backed reachability judgment.
usecase/reachbench
Package reachbench defines the deterministic reachability accuracy corpus contract and its recall ratchet.
Package reachbench defines the deterministic reachability accuracy corpus contract and its recall ratchet.
usecase/reachproof
Package reachproof is the coordinator that turns a deterministic reachability result into a CONFIRMED reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package reachproof is the coordinator that turns a deterministic reachability result into a CONFIRMED reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
usecase/recon
Package recon orchestrates reconnaissance runs.
Package recon orchestrates reconnaissance runs.
usecase/report
Package report generates an engagement's report from stored data and seals it with a SHA-256 (chain-of-custody).
Package report generates an engagement's report from stored data and seals it with a SHA-256 (chain-of-custody).
usecase/response
Package response applies governed defensive response actions (issue #425): isolate a host, quarantine a file, stop a process.
Package response applies governed defensive response actions (issue #425): isolate a host, quarantine a file, stop a process.
usecase/restoreverify
Package restoreverify verifies the read-only integrity surface of a restored deployment: evidence chains and their content-addressed objects, the global audit chain, and applied migration metadata.
Package restoreverify verifies the read-only integrity surface of a restored deployment: evidence chains and their content-addressed objects, the global audit chain, and applied migration metadata.
usecase/riskstoryuc
Package riskstoryuc is the read-model assembler for the unified per-asset risk story (issue #427).
Package riskstoryuc is the read-model assembler for the unified per-asset risk story (issue #427).
usecase/rulepack
Package rulepack evaluates deterministic release evidence for signed detection RulePacks.
Package rulepack evaluates deterministic release evidence for signed detection RulePacks.
usecase/runtimereach
Package runtimereach is the coordinator that turns an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) into a CONFIRMED, RAISE-ONLY reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
Package runtimereach is the coordinator that turns an OBSERVED runtime library load on a monitored host (EPIC #1042 #1061) into a CONFIRMED, RAISE-ONLY reachability Judgment, reusing the existing audited propose→verify gate rather than any new confirmed-state path.
usecase/rustsymreach
Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?
Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?
usecase/safety
Package safety is the single admission gate for AI-proposed actions and the structural embodiment of the rule that AI orchestration is a typed Go state machine, not prompt-driven control flow.
Package safety is the single admission gate for AI-proposed actions and the structural embodiment of the rule that AI orchestration is a typed Go state machine, not prompt-driven control flow.
usecase/sarifingest
Package sarifingest accepts SARIF 2.1.0 from third-party scanners so external findings enter the same asset model, prioritisation and governance path as first-party ones — without ever being presented as this system's own analysis.
Package sarifingest accepts SARIF 2.1.0 from third-party scanners so external findings enter the same asset model, prioritisation and governance path as first-party ones — without ever being presented as this system's own analysis.
usecase/sastbench
Package sastbench scores the owned SAST/taint engine against a standard external benchmark (OWASP BenchmarkJava) and reduces the result to a per-category precision/recall scorecard with a regression ratchet.
Package sastbench scores the owned SAST/taint engine against a standard external benchmark (OWASP BenchmarkJava) and reduces the result to a per-category precision/recall scorecard with a regression ratchet.
usecase/sbomcrosscheckjudge
Package sbomcrosscheckjudge (SBOM side) turns SBOM-PRODUCER cross-check DISAGREEMENTS into Judgments for human review.
Package sbomcrosscheckjudge (SBOM side) turns SBOM-PRODUCER cross-check DISAGREEMENTS into Judgments for human review.
usecase/sca
Package sca orchestrates the Software Composition Analysis pipeline.
Package sca orchestrates the Software Composition Analysis pipeline.
usecase/sca/remediation
Package remediation computes the smallest set of direct-dependency upgrades that removes a transitive vulnerability from a resolved dependency graph (EPIC #860 D3.8).
Package remediation computes the smallest set of direct-dependency upgrades that removes a transitive vulnerability from a resolved dependency graph (EPIC #860 D3.8).
usecase/scabench
Package scabench defines the pure, provenance-backed contract for SCA accuracy benchmarks.
Package scabench defines the pure, provenance-backed contract for SCA accuracy benchmarks.
usecase/scmconnectoruc
Package scmconnectoruc is the management use case for tenant-scoped source-control connectors: create, list, and delete the git-host + PAT bindings the acquirer uses to clone a PRIVATE repository.
Package scmconnectoruc is the management use case for tenant-scoped source-control connectors: create, list, and delete the git-host + PAT bindings the acquirer uses to clone a PRIVATE repository.
usecase/slauc
Package slauc coordinates tenant policy versions, immutable SLA assessments, and human-owned remediation transitions.
Package slauc coordinates tenant policy versions, immutable SLA assessments, and human-owned remediation transitions.
usecase/srcreach
Package srcreach implements deterministic Tier-1 reachability over a first-party source import scan, shared by every language whose dependency usage is observable as an import/require/use statement.
Package srcreach implements deterministic Tier-1 reachability over a first-party source import scan, shared by every language whose dependency usage is observable as an import/require/use statement.
usecase/symreach
Package symreach implements deterministic, RAISE-ONLY symbol-level reachability for the source ecosystems whose vulnerable symbols come from the curated DB: PHP (Composer), Ruby (RubyGems), and .NET (NuGet).
Package symreach implements deterministic, RAISE-ONLY symbol-level reachability for the source ecosystems whose vulnerable symbols come from the curated DB: PHP (Composer), Ruby (RubyGems), and .NET (NuGet).
usecase/taintscan
Package taintscan is the coordinator that turns a target's deterministic taint analysis into PROPOSED, gated CapSAST judgments – one per reported injection path × injection class – reusing the existing propose→verify gate.
Package taintscan is the coordinator that turns a target's deterministic taint analysis into PROPOSED, gated CapSAST judgments – one per reported injection path × injection class – reusing the existing propose→verify gate.
usecase/threatmodeluc
Package threatmodeluc is the architecture-input threat-model ingest use case: it accepts an UNTRUSTED architecture model (from the API), bounds its size, runs the domain's fail-closed Validate (referential integrity), persists it per engagement, and audits the action – the server-side enforcement the domain seam (internal/domain/threatmodel) is reasoned over by.
Package threatmodeluc is the architecture-input threat-model ingest use case: it accepts an UNTRUSTED architecture model (from the API), bounds its size, runs the domain's fail-closed Validate (referential integrity), persists it per engagement, and audits the action – the server-side enforcement the domain seam (internal/domain/threatmodel) is reasoned over by.
usecase/transfer
Package transfer implements engagement export/import: a portable bundle of an engagement's scope/findings/comments and its tamper-evident evidence chain.
Package transfer implements engagement export/import: a portable bundle of an engagement's scope/findings/comments and its tamper-evident evidence chain.
usecase/users
Package users manages operator identities + API keys.
Package users manages operator identities + API keys.
usecase/vex
Package vex consumes OpenVEX documents (CRA-aligned): a client hands Synapse a VEX doc asserting the exploitability status of vulnerabilities in their products, and Synapse applies each statement to the matching finding – e.g.
Package vex consumes OpenVEX documents (CRA-aligned): a client hands Synapse a VEX doc asserting the exploitability status of vulnerabilities in their products, and Synapse applies each statement to the matching finding – e.g.
usecase/worker
Package worker is the durable-queue claim-loop: it pulls jobs from a ports.JobQueue, dispatches each to a Handler registered by Kind, heartbeats long runs so their lease does not expire mid-flight, and Completes or Fails (with backoff) the job.
Package worker is the durable-queue claim-loop: it pulls jobs from a ports.JobQueue, dispatches each to a Handler registered by Kind, heartbeats long runs so their lease does not expire mid-flight, and Completes or Fails (with backoff) the job.
usecase/writeupdraftuc
Package writeupdraftuc is the use case for AI-proposed, human-gated finding write-up drafts ("human-gated authoritative drafts").
Package writeupdraftuc is the use case for AI-proposed, human-gated finding write-up drafts ("human-gated authoritative drafts").
Package migrations embeds the SQL migration files so the server can apply them at startup via goose (no external migration tool needed for self-host).
Package migrations embeds the SQL migration files so the server can apply them at startup via goose (no external migration tool needed for self-host).
scripts
centos7manifest command
centos7manifest generates a reproducible, small CentOS 7 package-header allowlist from the archived CentOS Vault.
centos7manifest generates a reproducible, small CentOS 7 package-header allowlist from the archived CentOS Vault.
test
e2e
Package e2e is the Phase-A (#628, A7) data-plane exit-gate harness: it composes the REAL A1–A6 components — canonical normalizer (A1), durable WAL/spool (A2), signed telemetry ingest + ACK/gap (A3), signed detection ingest + evidence seal (A4/A5), and source-side redaction (A6) — and drives the whole software loop end to end, under the failure matrix, and under a bounded soak, asserting the coverage-honesty invariant (no silent loss; loss becomes a durable queryable gap) across it.
Package e2e is the Phase-A (#628, A7) data-plane exit-gate harness: it composes the REAL A1–A6 components — canonical normalizer (A1), durable WAL/spool (A2), signed telemetry ingest + ACK/gap (A3), signed detection ingest + evidence seal (A4/A5), and source-side redaction (A6) — and drives the whole software loop end to end, under the failure matrix, and under a bounded soak, asserting the coverage-honesty invariant (no silent loss; loss becomes a durable queryable gap) across it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL