Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
bomly
command
Command bomly scans source trees, SBOMs, Git refs, and container images for dependency intelligence.
|
Command bomly scans source trees, SBOMs, Git refs, and container images for dependency intelligence. |
|
internal
|
|
|
assurance
Package assurance implements Bomly's release assurance framework: the shared check-result contract every quality check emits, the declarative catalog that declares which checks must exist, and the report the public assurance page renders for each release.
|
Package assurance implements Bomly's release assurance framework: the shared check-result contract every quality check emits, the declarative catalog that declares which checks must exist, and the report the public assurance page renders for each release. |
|
assurance/cmd
command
Command assurance drives Bomly's release assurance framework.
|
Command assurance drives Bomly's release assurance framework. |
|
assurance/perfrun
command
Command perfrun repeatedly executes one deterministic assurance case and records cold/warm samples in a versioned machine-readable manifest.
|
Command perfrun repeatedly executes one deterministic assurance case and records cold/warm samples in a versioned machine-readable manifest. |
|
assurance/sbominterop
command
Command sbominterop generates canonical SBOMs and validates them with checksum-pinned upstream tools.
|
Command sbominterop generates canonical SBOMs and validates them with checksum-pinned upstream tools. |
|
baseline
Package baseline implements portable, package-specific finding suppression.
|
Package baseline implements portable, package-specific finding suppression. |
|
benchmark
Package benchmark owns Bomly's hidden local dependency-graph benchmark.
|
Package benchmark owns Bomly's hidden local dependency-graph benchmark. |
|
cli/opts
Package opts resolves +/- selector expressions used by the CLI to filter detectors, auditors, matchers, and ecosystems.
|
Package opts resolves +/- selector expressions used by the CLI to filter detectors, auditors, matchers, and ecosystems. |
|
cli/render
Package render owns CLI presentation primitives: ANSI styling, the startup logo, and SBOM output spec parsing.
|
Package render owns CLI presentation primitives: ANSI styling, the startup logo, and SBOM output spec parsing. |
|
composition
Package composition declares the build-time composition of Bomly's embedded (native) components as execution-neutral plugin.Module entries.
|
Package composition declares the build-time composition of Bomly's embedded (native) components as execution-neutral plugin.Module entries. |
|
config
Package config defines Bomly's resolved CLI configuration shape.
|
Package config defines Bomly's resolved CLI configuration shape. |
|
engine/diff
Package diff runs two engine pipelines and classifies their audit deltas.
|
Package diff runs two engine pipelines and classifies their audit deltas. |
|
engine/scan
Package scan exposes the command-facing scan pipeline API.
|
Package scan exposes the command-facing scan pipeline API. |
|
progress
Package progress renders a CLI progress display: a live region of per-step lines, each animating its own spinner and bubbles-rendered progress bar, plus a stream of completed steps that get promoted in place (rewritten as a past-tense title with their child tree) and scroll into history as new steps start.
|
Package progress renders a CLI progress display: a live region of per-step lines, each animating its own spinner and bubbles-rendered progress bar, plus a stream of completed steps that get promoted in place (rewritten as a past-tense title with their child tree) and scroll into history as new steps start. |
|
support/cmd/componentdocs
command
|
|
|
support/cmd/configref
command
|
|
|
support/cmd/schemadocs
command
|
|
|
support/cmd/schemajson
command
|
|
|
support/cmd/supportmatrix
command
|
|
|
testnodes
Package testnodes builds graph nodes for tests.
|
Package testnodes builds graph nodes for tests. |
|
tools/benchmarkreport
command
|
|
|
tools/gofmtcheck
command
|
|
|
tools/guardcheck
command
Command guardcheck runs Bomly's structural house rules as go/analysis analyzers.
|
Command guardcheck runs Bomly's structural house rules as go/analysis analyzers. |
|
tools/guardcheck/analyzers
Package analyzers holds the house rules that are about the shape of code rather than about a resolved name: a lookup followed by an insert, a package URL pasted together from a literal, a detection result built without its attribution, a name the export layer may not mention even inside a string.
|
Package analyzers holds the house rules that are about the shape of code rather than about a resolved name: a lookup followed by an insert, a package URL pasted together from a literal, a detection result built without its attribution, a name the export layer may not mention even inside a string. |
Click to show internal directories.
Click to hide internal directories.