List of all items
Structs
- custom_rules::CustomRule
- custom_rules::MatchSpec
- custom_rules::MetadataMatcher
- custom_rules::MetadataOp
- custom_rules::NodeMatcher
- custom_rules::PathMatcher
- finding::Finding
- graph::AuthorityGraph
- graph::Edge
- graph::Node
- graph::ParamSpec
- graph::PipelineSource
- ignore::IgnoreConfig
- ignore::IgnoreResult
- ignore::IgnoreRule
- map::AuthorityMap
- map::MapRow
- propagation::PropagationPath
Enums
- custom_rules::CustomRuleError
- custom_rules::MetadataPredicate
- custom_rules::OneOrMany
- error::TauditError
- finding::FindingCategory
- finding::Recommendation
- finding::Severity
- graph::AuthorityCompleteness
- graph::EdgeKind
- graph::IdentityScope
- graph::NodeKind
- graph::TrustZone
Traits
Functions
- custom_rules::evaluate_custom_rules
- custom_rules::load_rules_dir
- graph::is_docker_digest_pinned
- graph::is_sha_pinned
- ignore::glob_match
- map::authority_map
- map::job_names
- map::render_dot
- map::render_map
- propagation::propagation_analysis
- rules::addspn_with_inline_script
- rules::artifact_boundary_crossing
- rules::authority_cycle
- rules::authority_propagation
- rules::checkout_self_pr_exposure
- rules::cross_workflow_authority_chain
- rules::floating_image
- rules::keyvault_secret_to_plaintext
- rules::long_lived_credential
- rules::over_privileged_identity
- rules::parameter_interpolation_into_shell
- rules::persisted_credential
- rules::run_all_rules
- rules::secret_materialised_to_workspace_file
- rules::secret_to_inline_script_env_export
- rules::self_hosted_pool_pr_hijack
- rules::self_mutating_pipeline
- rules::service_connection_scope_mismatch
- rules::short_lived_sas_in_command_line
- rules::template_extends_unpinned_branch
- rules::terraform_auto_approve_in_prod
- rules::trigger_context_mismatch
- rules::unpinned_action
- rules::untrusted_with_authority
- rules::uplift_without_attestation
- rules::variable_group_in_pr_job
- rules::vm_remote_exec_via_pipeline_secret
Type Aliases
Constants
- graph::META_ADD_SPN_TO_ENV
- graph::META_ATTESTS
- graph::META_CHECKOUT_SELF
- graph::META_CLI_FLAG_EXPOSED
- graph::META_CONTAINER
- graph::META_DIGEST
- graph::META_ENV_APPROVAL
- graph::META_IDENTITY_SCOPE
- graph::META_IMPLICIT
- graph::META_INFERRED
- graph::META_JOB_NAME
- graph::META_OIDC
- graph::META_PERMISSIONS
- graph::META_REPOSITORIES
- graph::META_SCRIPT_BODY
- graph::META_SELF_HOSTED
- graph::META_SERVICE_CONNECTION
- graph::META_SERVICE_CONNECTION_NAME
- graph::META_TERRAFORM_AUTO_APPROVE
- graph::META_TRIGGER
- graph::META_VARIABLE_GROUP
- graph::META_WRITES_ENV_GATE
- propagation::DEFAULT_MAX_HOPS