# detected
The detected analyser breaches once per entry in a map-shaped input,
whenever that entry is present. It is designed to pair with the
file:fingerprint fact, where each map entry is
a detected framework and its likelihood score.
# Plugin fields
detected has no plugin-specific fields — there is nothing to configure beyond
the common ones below.
No inverse polarity
Like drift, detected has no toggle to invert the assertion. The
presence of an entry is itself the assertion failure, so an empty input passes.
# Common fields
| Field | Description | Required | Default |
|---|---|---|---|
| name | The name of the policy - this is the yaml key in the config file when defining the policy. | Yes | - |
| description | The description of the policy - if specified, it will be used as the heading for the policy in the output. | No | "" |
| input | The input for the policy - used to select the fact plugin to use. | Yes | - |
| severity | The severity of the policy when breached (low, normal, high, critical) | No | normal |
| breach-format | The breach template for the policy. The table below shows the available fields. | No | Empty breach template |
| remediation | The remediation for the policy. The table below shows the available fields. | No | Empty remediation |
# Breach template
WARNING
TODO: Add information on how to use go template variables.
| Field | Description | Required | Default |
|---|---|---|---|
| type | The type of breach. | Yes | "" |
| key-label | The label for the key. | No | "" |
| key | The key. | No | "" |
| value-label | The label for the value. | No | "" |
| value | The value. | No | "" |
# Remediation
| Field | Description | Required | Default |
|---|---|---|---|
| plugin | The plugin to use for remediation. | No | "command" |
| msg | The message to display when remediation completes successfully. | No | "remediation successful" |
| ... | Any fields required by the plugin. | No | - |
# Input format
Requires map-string (framework label → score). An empty map produces no
breaches. Other formats are treated as a no-op.
# Breach output
One KeyValueBreach per map entry, labelled framework / likelihood.
Map keys are sorted before breaches are emitted. Go randomises map iteration order, and this analyser is typically used with multi-label input (several detected frameworks), so without sorting the breach order — and any test asserting on it — would be non-deterministic.
# Example
analyse:
application-type:
detected:
description: Detected application frameworks
input: app-fingerprint
Source: examples/app-type.yml — see also the
sca:application_type recipe.
← allowed:list drift →