Skip to content

Latest commit

 

History

History
64 lines (39 loc) · 1.35 KB

nixauditor.md

File metadata and controls

64 lines (39 loc) · 1.35 KB

Configuration for nixauditor

Supported environments/languages

  • image

Configuration

var purpose type default
SCA_BLACKLIST_nixauditor Blacklist filter for this tool space-separated-list ""
SCA_NIXAUDITOR_EXTRA_FATAL Extra error-IDs leading to build termination when found space-separated-list ""
SCA_NIXAUDITOR_EXTRA_SUPPRESS Extra error-IDs to be suppressed space-separated-list ""

Note

As this tool was intentionally written to check RHEL-releases all rules regarding rpm, yum and centos-specific things have been turned off by default.

Supports

  • suppression of IDs
  • terminate build on fatal
  • run on recipe
  • run on image
  • run with SCA-layer default settings (see SCA_AVAILABLE_MODULES)

Requires

  • requires online access

Known error-IDs

tbd

Checking scope

  • security
  • functional defects
  • compliance
  • style issues

Statistics

  • ⬛⬛⬛⬛⬛⬛⬛⬛⬛⬛ 10/10 Build Speed
  • ⬛⬛⬛⬜⬜⬜⬜⬜⬜⬜ 03/10 Execution Speed
  • ⬛⬛⬛⬛⬛⬛⬜⬜⬜⬜ 06/10 Quality

Score mapping

Error considered as security relevant

  • nixauditor.nixauditor.*

Error considered as functional defect

  • n.a

Error consired as compliance issue

  • n.a.

Error considered as style issue

  • n.a