go. Run the equivalent command directly when working inside a single module.
Commands
Module-scoped commands must run inside the module’s directory.
go test ./... from the repo root does not reach the connectors unless go.work unifies them.Testing rules
Tests need no Docker, no network, and no credentials — that is the primary gate. CI runs the samego test on every module with GOWORK=off.
A connector is not mergeable until its adapter covers:
- Parsing — raw tool output →
Finding. - Severity mapping — every value the tool emits lands on the enum.
- Error mapping —
fatal:vsretryable:prefixes. - Cancellation —
Executereturns whenctx.Done()closes.
Building images
Each connector ships its own multi-stageDockerfile with the repo root as build context. Build it directly:
CGO_ENABLED=0), land a single binary on a minimal base image, create an unprivileged user, and USER it.
CI and publishing
The connector workflow is path-filtered tosdk/**, ports_scanner/**, vulnerabilities/**, url_discovery/**, scripts/**, and the workflow file itself.
- On push / pull request — discover every
<category>/<slug>/manifest.yaml, derive a build matrix fromslugandversion, run the full test suite, then build each image withpush: false. Nothing is published. - On manual dispatch — the same pipeline plus a push job that publishes
connector-<slug>:<version>and:latest. Adry_runinput builds and tests without publishing, and animage_taginput overrides the tag.
version field in manifest.yaml is meaningful: bumping it produces a new immutable image tag.
Design constraints
- The SDK is the only shared code. Anything tool-specific that leaks upward makes every connector heavier and the contract fuzzier.
manifest.jsonis derived. Regenerate it; never edit or patch it by hand.- The container is the boundary. Connectors run unprivileged with no inbound network surface.
