Repository navigation
Inputs and Analysis
Hooray builds normalized inventories from supported ecosystem files, including Cargo, npm, Yarn, pnpm, pip, Poetry, Pipenv, Ruby gems, Go modules, Swift packages, Dart packages, CocoaPods, PHP Composer, Conda environments, Helm chart dependencies, and NuGet assets. It preserves package URLs, versions, scopes, provenance, locations, checksums, licenses, and dependency edges when the source format provides them.
Important parsing behavior:
- Python hash/options and environment markers are not included in the package version.
- Go dependencies come from selected
go.modrequirements;go.sumhistory does not create installed components. - Root license files are attributed only when they can be mapped to the project root component; they are never copied to every dependency.
CycloneDX JSON is validated and normalized. Component license choices, SPDX expressions, dependency relationships, duplicate package URLs, metadata roots, scopes, and optional fields are preserved or rejected deterministically when contradictory. SPDX 2.x JSON documents are detected by a top-level spdxVersion key and routed through the same normalized inventory flow; unsupported SPDX versions fail closed.
Supported inputs include bounded ZIP/TAR artifacts, OCI image layouts, OCI image archives, and Docker image archives. Processing rejects traversal paths, unsafe links, malformed digests, invalid manifests, excessive entries, and expansion beyond configured limits. OCI expansion is limited cumulatively across all layers, including overwritten or whiteouted data.
No archive member or container command is executed.
- Vulnerabilities from OSV, including affected-range applicability and fixed-version extraction.
- License findings for valid, invalid, missing, and recognized file-based evidence.
- Secret patterns and high-entropy contextual assignments with redacted evidence.
- Focused SAST rules for supported language families.
- Terraform, Dockerfile, Kubernetes, CloudFormation, and service-config checks covering nginx/Apache TLS and server-token directives, PostgreSQL
pg_hba.conf/postgresql.conf, Redis, andsshd_config. - Exact malware digest matches when a signature database is supplied, plus conservative archive/polyglot indicators.
- Operational-risk findings derived only from explicit provenance evidence.
The graph classifies immediate children of project roots as direct dependencies and deeper reachable nodes as transitive. Shortest and bounded alternative paths are deterministic. Graph construction and traversal are bounded against cycles, deep chains, and path explosion.
OSV ranges are evaluated against the component version. A package query match alone does not prove impact. Applicability can be affected, not_affected, fixed, or unknown. Upgrade guidance is not emitted for fixed or not-affected findings. Supported package ecosystems receive ecosystem-aware version comparison and safe command guidance where a generic action is valid.
Project and scanner reads use bounded file handles and do not follow symbolic links on Linux/Android. Input bytes, archive bytes, entries, paths, files, concurrency, and output are constrained through Configuration.