# detected

The detected analyser breaches once per entry in a map-shaped input, whenever that entry is present. It is designed to pair with the file:fingerprint fact, where each map entry is a detected framework and its likelihood score.

# Plugin fields

detected has no plugin-specific fields — there is nothing to configure beyond the common ones below.

No inverse polarity

Like drift, detected has no toggle to invert the assertion. The presence of an entry is itself the assertion failure, so an empty input passes.

# Common fields

Field Description Required Default
name The name of the policy - this is the yaml key in the config file when defining the policy. Yes -
description The description of the policy - if specified, it will be used as the heading for the policy in the output. No ""
input The input for the policy - used to select the fact plugin to use. Yes -
severity The severity of the policy when breached (low, normal, high, critical) No normal
breach-format The breach template for the policy. The table below shows the available fields. No Empty breach template
remediation The remediation for the policy. The table below shows the available fields. No Empty remediation

# Breach template

WARNING

TODO: Add information on how to use go template variables.

Field Description Required Default
type The type of breach. Yes ""
key-label The label for the key. No ""
key The key. No ""
value-label The label for the value. No ""
value The value. No ""

# Remediation

Field Description Required Default
plugin The plugin to use for remediation. No "command"
msg The message to display when remediation completes successfully. No "remediation successful"
... Any fields required by the plugin. No -

# Input format

Requires map-string (framework label → score). An empty map produces no breaches. Other formats are treated as a no-op.

# Breach output

One KeyValueBreach per map entry, labelled framework / likelihood.

Map keys are sorted before breaches are emitted. Go randomises map iteration order, and this analyser is typically used with multi-label input (several detected frameworks), so without sorting the breach order — and any test asserting on it — would be non-deterministic.

# Example

analyse:
  application-type:
    detected:
      description: Detected application frameworks
      input: app-fingerprint

Source: examples/app-type.yml — see also the sca:application_type recipe.