Files
compliance-scanner-agent/docs/reference/glossary.md
T
Sharang ParnerkarandClaude Opus 4.8 5ad9d2d77c
CI / Check (push) Skipped
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped
CI / Check (pull_request) Failing after 1m55s
docs: rebrand Certifai -> Prüfwerk (user-facing name)
The product is renamed Certifai -> Prüfwerk. This changes only the user-facing
brand text in the documentation (docs/**, VitePress title/name). It does NOT
touch functional identifiers that happen to contain "certifai" (the Docker
network, Keycloak realm/client, Harbor image project, the compliance-* crate
names, or the repo name) — those are infra-coupled and need a separate,
coordinated migration.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EgxGHn22YEfQz5fLHSHkLv
2026-09-02 09:53:45 +02:00

3.5 KiB

Glossary

A reference of key terms used throughout Prüfwerk.

Security Terms

SAST (Static Application Security Testing) Analysis of source code to find vulnerabilities without running the application. Prüfwerk uses Semgrep for SAST scanning.

DAST (Dynamic Application Security Testing) Testing a running application by sending crafted requests and analyzing responses. Finds vulnerabilities that only appear at runtime.

SBOM (Software Bill of Materials) A complete inventory of all software components (libraries, packages, frameworks) that your application depends on, including versions and licenses.

CVE (Common Vulnerabilities and Exposures) A standardized identifier for publicly known security vulnerabilities. Each CVE has a unique ID (e.g. CVE-2024-1234) and is tracked in the National Vulnerability Database.

False Positive A finding that is flagged as a vulnerability by a scanner but is not actually a security issue in context. For example, a SQL injection warning on a query that uses parameterized statements correctly.

Triage The process of reviewing a security finding and deciding what to do with it: confirm it as real, mark it as a false positive, or accept the risk and ignore it.

Fingerprint A unique hash generated for each finding based on the scanner, file path, line number, and vulnerability type. Used for deduplication so the same issue is not reported twice.

Confidence Score A value from 0.0 to 1.0 assigned by the AI triage engine, indicating how certain the LLM is about its assessment of a finding.

CWE (Common Weakness Enumeration) A community-developed list of software and hardware weakness types. Findings often reference a CWE ID to categorize the type of vulnerability.

CVSS (Common Vulnerability Scoring System) A standardized framework for rating the severity of security vulnerabilities on a scale of 0.0 to 10.0.

License Terms

Copyleft License A license that requires derivative works to be distributed under the same license terms. Examples: GPL-2.0, GPL-3.0, AGPL-3.0, LGPL-2.1, LGPL-3.0, MPL-2.0.

Permissive License A license that allows broad freedom to use, modify, and distribute software with minimal restrictions. Examples: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC.

Standards and Formats

CycloneDX An OWASP standard for SBOM formats. Prüfwerk supports export in CycloneDX 1.5 JSON format.

SPDX (Software Package Data Exchange) A Linux Foundation standard for communicating software bill of materials information. Prüfwerk supports export in SPDX 2.3 format.

Tools

Semgrep An open-source static analysis tool that finds bugs and enforces code standards using pattern-matching rules. Used by Prüfwerk for SAST scanning.

Syft An open-source tool for generating SBOMs from container images and filesystems. Used by Prüfwerk to extract dependency information.

OSV.dev Google's open distributed vulnerability database, queried by package URL. Prüfwerk uses it (together with NVD) to match SBOM components against known vulnerabilities.

Protocols

MCP (Model Context Protocol) An open standard that allows LLM-powered tools to connect to external data sources and call tools. Prüfwerk exposes security data through MCP so AI assistants can query findings, SBOMs, and DAST results.

PKCE (Proof Key for Code Exchange) An extension to the OAuth 2.0 authorization code flow that prevents authorization code interception attacks. Used in Prüfwerk's authentication flow.