Documentation
¶
Index ¶
- func RenderCodeQLTemplate(request CodeQLRequest, customTemplatePath string) (string, error)
- func WriteUnifiedResultsToFile(results *UnifiedOutput, filename string) error
- func WriteUnifiedResultsToStdout(results *UnifiedOutput) error
- type Analyzer
- type CodeQLRequest
- type Config
- type ModelPricing
- type Pipeline
- func (p *Pipeline) LoadEnvironmentConfig(config *Config) error
- func (p *Pipeline) ProcessResults(ctx context.Context, input *UnifiedOutput) (*UnifiedOutput, error)
- func (p *Pipeline) ReadInputResults(inputFile string) (*UnifiedOutput, error)
- func (p *Pipeline) WriteOutputResults(results *UnifiedOutput, outputFile string) error
- type PipelineConfig
- type ProcessFunc
- type RankInfo
- type TemplateMetadata
- type TokenStats
- type TokenUsage
- type UnifiedOutput
- type UnifiedResult
- type WorkItem
- type WorkProcessor
- type WorkResult
- type WorkerPool
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func RenderCodeQLTemplate ¶
func RenderCodeQLTemplate(request CodeQLRequest, customTemplatePath string) (string, error)
RenderCodeQLTemplate renders the CodeQL template with the provided data
func WriteUnifiedResultsToFile ¶
func WriteUnifiedResultsToFile(results *UnifiedOutput, filename string) error
WriteUnifiedResultsToFile writes UnifiedOutput to a JSON file
func WriteUnifiedResultsToStdout ¶
func WriteUnifiedResultsToStdout(results *UnifiedOutput) error
WriteUnifiedResultsToStdout writes UnifiedOutput to stdout
Types ¶
type Analyzer ¶
type Analyzer struct {
// contains filtered or unexported fields
}
Analyzer handles LLM-based analysis with structured JSON output
func (*Analyzer) GetTokenStats ¶
func (a *Analyzer) GetTokenStats() TokenStats
GetTokenStats returns current token usage statistics
func (*Analyzer) ProcessCodeQLFinding ¶
func (a *Analyzer) ProcessCodeQLFinding(ctx context.Context, request CodeQLRequest, templatePath string) (interface{}, error)
ProcessCodeQLFinding processes a CodeQL finding using the specified template
type CodeQLRequest ¶
type CodeQLRequest struct {
CodeQLResult codeql.CodeQLResult `json:"codeql_result"`
SourceCode codeql.SourceCode `json:"source_code"`
CallValidation *codeql.CallValidation `json:"call_validation,omitempty"`
FreeFuncDef string `json:"free_function_definition"`
UseFuncDef string `json:"use_function_definition"`
IntermediateFuncDefs []string `json:"intermediate_function_definitions"`
CallChains [][]string `json:"chains"`
FreeSnippet string `json:"free_snippet"`
UseSnippet string `json:"use_snippet"`
}
CodeQLRequest contains the data needed for LLM processing of CodeQL findings
type Config ¶
type Config struct {
APIKey string `json:"api_key"`
BaseURL string `json:"base_url"` // For OpenAI-compatible APIs
Model string `json:"model"` // Model to use (e.g., "gpt-4", "gpt-3.5-turbo")
Temperature float32 `json:"temperature"` // Temperature for response generation
MaxTokens int `json:"max_tokens"` // Maximum tokens in response
ReasoningEffort string `json:"reasoning_effort"` // Reasoning effort for GPT-5: minimal, low, medium, high
PromptTemplate string `json:"prompt_template"` // Path to custom prompt template file
}
Config holds the configuration for LLM analysis
type ModelPricing ¶
type ModelPricing struct {
InputPerMillion float64 // USD per 1M input tokens
CachedInputPerMillion float64 // USD per 1M cached input tokens (if supported)
OutputPerMillion float64 // USD per 1M output tokens
}
ModelPricing represents the pricing structure for a model
func GetModelPricing ¶
func GetModelPricing(model string) *ModelPricing
GetModelPricing returns pricing information for known models
type Pipeline ¶
type Pipeline struct {
// contains filtered or unexported fields
}
Pipeline handles the complete LLM processing pipeline for vulnerability analysis
func NewPipeline ¶
func NewPipeline(analyzerConfig Config, pipelineConfig PipelineConfig) *Pipeline
NewPipeline creates a new LLM processing pipeline
func (*Pipeline) LoadEnvironmentConfig ¶
LoadEnvironmentConfig loads configuration from environment variables
func (*Pipeline) ProcessResults ¶
func (p *Pipeline) ProcessResults(ctx context.Context, input *UnifiedOutput) (*UnifiedOutput, error)
ProcessResults processes unified results using the template-driven approach
func (*Pipeline) ReadInputResults ¶
func (p *Pipeline) ReadInputResults(inputFile string) (*UnifiedOutput, error)
ReadInputResults reads unified results from file or stdin
func (*Pipeline) WriteOutputResults ¶
func (p *Pipeline) WriteOutputResults(results *UnifiedOutput, outputFile string) error
WriteOutputResults writes unified results to file or stdout
type PipelineConfig ¶
type PipelineConfig struct {
Timeout time.Duration
Concurrency int
PromptTemplate string
OutputAll bool
}
PipelineConfig contains configuration for the processing pipeline
type ProcessFunc ¶
ProcessFunc is a function type that implements WorkProcessor
type RankInfo ¶
type RankInfo struct {
Score float64 `json:"score"` // Ranking score from raink
Exposure int `json:"exposure"` // How many times seen during ranking
Pos int `json:"pos"` // 1-based rank position (1 = highest priority)
}
RankInfo contains ranking information from raink
type TemplateMetadata ¶
type TemplateMetadata struct {
Type string `json:"type"`
Schema map[string]interface{} `json:"schema"`
Timeout int `json:"timeout"`
MaxTokens int `json:"max_tokens"`
Temperature float32 `json:"temperature"`
}
TemplateMetadata holds parsed template metadata
func ParseTemplateMetadata ¶
func ParseTemplateMetadata(templatePath string) (*TemplateMetadata, error)
ParseTemplateMetadata parses template metadata into a structured format
type TokenStats ¶
type TokenStats struct {
TotalPromptTokens int64 `json:"total_prompt_tokens"`
TotalCompletionTokens int64 `json:"total_completion_tokens"`
TotalReasoningTokens int64 `json:"total_reasoning_tokens"`
TotalTokens int64 `json:"total_tokens"`
CallCount int64 `json:"call_count"`
// Cost tracking
TotalInputCostUSD float64 `json:"total_input_cost_usd"`
TotalOutputCostUSD float64 `json:"total_output_cost_usd"`
TotalCostUSD float64 `json:"total_cost_usd"`
}
TokenStats tracks cumulative token usage across all API calls
type TokenUsage ¶
type TokenUsage struct {
Timestamp string `json:"timestamp"`
Model string `json:"model"`
FunctionContext string `json:"function_context"` // template type
PromptTokens int64 `json:"prompt_tokens"`
CompletionTokens int64 `json:"completion_tokens"`
ReasoningTokens int64 `json:"reasoning_tokens,omitempty"`
AudioTokens int64 `json:"audio_tokens,omitempty"`
AcceptedPredictionTokens int64 `json:"accepted_prediction_tokens,omitempty"`
RejectedPredictionTokens int64 `json:"rejected_prediction_tokens,omitempty"`
TotalTokens int64 `json:"total_tokens"`
ReasoningEffort string `json:"reasoning_effort,omitempty"`
ResponseID string `json:"response_id"`
// Cost estimation
InputCostUSD float64 `json:"input_cost_usd"`
OutputCostUSD float64 `json:"output_cost_usd"`
TotalCostUSD float64 `json:"total_cost_usd"`
}
TokenUsage represents token usage statistics from an API call
func (*TokenUsage) CalculateCost ¶
func (tu *TokenUsage) CalculateCost()
CalculateCost estimates the cost of a token usage
type UnifiedOutput ¶
type UnifiedOutput struct {
QueryFile string `json:"query_file"`
Database string `json:"codeql_db"`
SrcDir string `json:"src_dir,omitempty"`
Results []UnifiedResult `json:"results"`
}
UnifiedOutput represents the standard output format for all commands
func ReadUnifiedResultsFromFile ¶
func ReadUnifiedResultsFromFile(filename string) (*UnifiedOutput, error)
ReadUnifiedResultsFromFile reads UnifiedOutput from a JSON file
func ReadUnifiedResultsFromStdin ¶
func ReadUnifiedResultsFromStdin() (*UnifiedOutput, error)
ReadUnifiedResultsFromStdin reads UnifiedOutput from stdin
type UnifiedResult ¶
type UnifiedResult struct {
// Base finding from CodeQL (always present)
CodeQLResult codeql.CodeQLResult `json:"query"`
SourceCode codeql.SourceCode `json:"source"`
// Optional call validation results (present when --validate-calls is enabled)
CallValidation *codeql.CallValidation `json:"calls,omitempty"`
// Optional ranking results (present after rank command)
Rank *RankInfo `json:"rank,omitempty"`
// Dynamic results with custom keys (for template-defined output keys)
DynamicResults map[string]interface{} `json:"-"`
// contains filtered or unexported fields
}
UnifiedResult represents a finding that can be progressively enriched
func (*UnifiedResult) GetDynamicResult ¶
func (ur *UnifiedResult) GetDynamicResult(key string) (interface{}, bool)
GetDynamicResult gets a dynamic result by key
func (*UnifiedResult) MarshalJSON ¶
func (ur *UnifiedResult) MarshalJSON() ([]byte, error)
MarshalJSON implements custom JSON marshaling for UnifiedResult
func (*UnifiedResult) SetDynamicResult ¶
func (ur *UnifiedResult) SetDynamicResult(key string, value interface{})
SetDynamicResult sets a dynamic result with the specified key
func (*UnifiedResult) UnmarshalJSON ¶
func (ur *UnifiedResult) UnmarshalJSON(data []byte) error
UnmarshalJSON implements custom JSON unmarshaling for UnifiedResult
type WorkProcessor ¶
type WorkProcessor[TIn, TOut any] interface { Process(ctx context.Context, input TIn) (TOut, error) }
WorkProcessor defines the interface for processing work items
type WorkResult ¶
WorkResult represents the result of processing with its original index
type WorkerPool ¶
type WorkerPool[TIn, TOut any] struct { // contains filtered or unexported fields }
WorkerPool manages concurrent processing of work items
func NewWorkerPool ¶
func NewWorkerPool[TIn, TOut any](concurrency int) *WorkerPool[TIn, TOut]
NewWorkerPool creates a new worker pool with the specified concurrency
func (*WorkerPool[TIn, TOut]) ProcessItems ¶
func (wp *WorkerPool[TIn, TOut]) ProcessItems( ctx context.Context, items []TIn, processor WorkProcessor[TIn, TOut], taskName string, ) ([]TOut, error)
ProcessItems processes items concurrently while preserving order