pub struct Violation {
pub severity: ViolationSeverity,
pub category: ViolationCategory,
pub message: String,
pub element: Option<String>,
pub component_id: Option<String>,
pub counts: Option<ViolationCounts>,
pub requirement: String,
pub rule_id: &'static str,
pub standard_refs: Vec<StandardRef>,
}Expand description
A compliance violation
Fields§
§severity: ViolationSeveritySeverity: error, warning, info
category: ViolationCategoryCategory of the violation
message: StringHuman-readable message
element: Option<String>Component or element that violated (if applicable).
This is a human-readable label (usually the component name, sometimes
a format id) and is not unique across versions or duplicate names — use
Violation::component_id as the machine-readable join key.
component_id: Option<String>Canonical id of the offending component, when component-scoped.
Unlike Violation::element, this is a stable join key back to the
SBOM component (the component’s CanonicalId), so machine consumers
can reliably correlate findings with components. None for
document-level and aggregate findings.
Serialized as component_id, omitted when None; old payloads
without the field deserialize to None.
counts: Option<ViolationCounts>Affected/total component counts for aggregate findings.
Mirrors the numbers embedded in the human-readable message
(e.g. “7/10 components (70%)…”) in structured form. None for
non-aggregate findings.
Serialized as counts, omitted when None; old payloads without the
field deserialize to None.
requirement: StringStandard/requirement being violated
rule_id: &'static strStable internal rule key, set at the check site, indexing into
rule_meta. This — not the human-readable message — drives the
externally-visible SARIF rule ID, the harmonised-standard references,
and the remediation text. Defaults to "SBOM-CRA-GENERAL" for
violations built outside the checker (e.g., from external config).
Serialized as rule_id (alongside a derived sarif_rule_id; see the
manual Serialize impl) so machine consumers get a stable rule key
instead of regexing the message. Deserialization maps a known id back
to its registry &'static str key and falls back to the generic
default for unknown ids or old payloads without the field.
standard_refs: Vec<StandardRef>Structured references to harmonised-standard / regulation clauses.
Populated by ComplianceChecker::check() from Violation::rule_id
via rule_meta. Empty when a violation’s rule maps to no references.
Implementations§
Source§impl Violation
impl Violation
Sourcepub fn registry_standard_refs(&self) -> Vec<StandardRef>
pub fn registry_standard_refs(&self) -> Vec<StandardRef>
Structured standard references for this violation, looked up from the
rule registry by Violation::rule_id.
References are returned in registry order — typically the most specific
harmonised-standard ID first, then the regulation reference. The
registry, not the human-readable requirement string, is the single
source of truth, so rewording a message can never silently drop a
prEN/BSI cross-reference.
ComplianceChecker::check() calls this once and stores the result in
Violation::standard_refs, so most consumers should read the field
directly rather than re-deriving.
Sourcepub fn remediation_guidance(&self) -> &'static str
pub fn remediation_guidance(&self) -> &'static str
Remediation guidance for this violation, looked up from the rule
registry by Violation::rule_id.
Sourcepub fn sarif_rule_id(&self) -> &'static str
pub fn sarif_rule_id(&self) -> &'static str
Externally-visible SARIF rule id for this violation, looked up from
the rule registry by Violation::rule_id. Check sites stamp a
family-correct generic id (via generic_rule_id_for_level) when no
specific rule applies, so registered keys — i.e. every violation the
checkers produce — serialize identically in JSON and SARIF. Truly
unregistered keys (violations built outside the checkers, e.g. from
external config) fall back to the generic CRA rule here; the SARIF
renderer additionally re-buckets those by standard family, which is
the one residual place the two outputs can differ.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Violation
impl<'de> Deserialize<'de> for Violation
Source§fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>where
D: Deserializer<'de>,
fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>where
D: Deserializer<'de>,
Source§impl Serialize for Violation
impl Serialize for Violation
Source§fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>where
S: Serializer,
fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>where
S: Serializer,
Manual impl so the JSON carries both the stable internal rule_id and
the externally-visible sarif_rule_id derived from the rule registry
(never stored, so it cannot drift). Field order mirrors declaration
order; standard_refs is skipped when empty, and component_id /
counts are skipped when None, as their serde-derive
skip_serializing_if = "Option::is_none" equivalents would be.
Auto Trait Implementations§
impl Freeze for Violation
impl RefUnwindSafe for Violation
impl Send for Violation
impl Sync for Violation
impl Unpin for Violation
impl UnsafeUnpin for Violation
impl UnwindSafe for Violation
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more