Skip to content

Rules

Rules

Invoke-TrexRule is the module’s trex scan --rules, and ConvertTo-TrexSarif its --sarif. The examples are on pattern files.

Get-TrexRule

Lists the rules declared for the session, in a library, or in the rule files named, in declaration order.

Alias: Get-TxRule

Get-TrexRule [[-Name] <string>] [-RuleFile <string[]>] [-Library <Library>] [<CommonParameters>]
ParameterTypePipelineDescription
-LibraryTrex.LibraryLists a library’s rules in place of the session’s.
-NamestringOnly rules whose name matches; wildcards apply.
-RuleFilestring[]Pattern files, or directories of .trex files, imported for this call over the atoms in force; a file already imported is read in place of that import.

Writes Trex.Rule.

Invoke-TrexRule

Scans the rules declared in pattern files over text, files or directories, and writes each finding as a Trex.Finding.

A rule fires on each match of its pattern, or on each record holding it where the rule names a record or a pattern the record must not hold; its message is rendered from the match, and its fix, where it has one, renders what replaces the match. -Fix writes the fixes into the files, asking first under -Confirm and saying what it would do under -WhatIf, and with -Interactive puts each fix to the person first, as Edit-TrexText -Interactive puts a change; -Diff writes the unified diff the fixes would make instead.

-Json writes every finding as the trex command’s scan --rules --json writes them, one array after the last input; -Sarif one SARIF 2.1.0 document for every finding, -GitHub one GitHub workflow annotation each, and -Format a report template rendered at each, which reads ${rule}, ${severity}, ${message} and ${fix} beside the registers. -Count writes how many findings each file holds, as the trex command’s --count does, -FilesWithMatches and -FilesWithoutMatch the path of each file holding a finding or none, and -RequireMatch an error when no input held a finding.

-Head, -Tail and -Lines scan only the first lines of each input, its last, or a range of them, counted in records of -Unit where it names one: a finding counts only where it lies wholly inside, and stands at the input’s own line and offset; -Fix and -Diff change only that part. -First and -Last are -Head and -Tail. -Follow scans what each file gains as it grows, after its tail, its open range or the whole of it, writing each finding once nothing that arrives later can change it, -Json as one object a string, until the pipeline is stopped or -MaxCount has written all it will from each file.

Alias: Invoke-TxRule

Invoke-TrexRule [-InputObject] <string> [-RuleFile <string[]>] [-Library <Library>] [-MaxCount <uint>] [-Json] [-Sarif] [-GitHub] [-Format <string>] [-Count] [-RequireMatch] [-Head <uint>] [-Tail <uint>] [-Lines <Object>] [-Unit <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Invoke-TrexRule -Path <string[]> [-RuleFile <string[]>] [-Library <Library>] [-MaxCount <uint>] [-Fix] [-Diff] [-Context <uint>] [-Interactive] [-ShowSkipped] [-Json] [-Sarif] [-GitHub] [-Format <string>] [-Count] [-FilesWithMatches] [-FilesWithoutMatch] [-RequireMatch] [-Hidden] [-NoIgnore] [-Binary] [-Include <string[]>] [-Head <uint>] [-Tail <uint>] [-Lines <Object>] [-Unit <string>] [-Follow] [-WhatIf] [-Confirm] [<CommonParameters>]
Invoke-TrexRule -LiteralPath <string[]> [-RuleFile <string[]>] [-Library <Library>] [-MaxCount <uint>] [-Fix] [-Diff] [-Context <uint>] [-Interactive] [-ShowSkipped] [-Json] [-Sarif] [-GitHub] [-Format <string>] [-Count] [-FilesWithMatches] [-FilesWithoutMatch] [-RequireMatch] [-Hidden] [-NoIgnore] [-Binary] [-Include <string[]>] [-Head <uint>] [-Tail <uint>] [-Lines <Object>] [-Unit <string>] [-Follow] [-WhatIf] [-Confirm] [<CommonParameters>]
ParameterTypePipelineDescription
-BinaryswitchReads files that hold a NUL byte, which a walk treats as binary.
-ContextuintLines of context around each change in a diff; 3 when absent.
-CountswitchWrites how many findings each file holds, as a Trex.MatchCount for every file read, none included; over text, one count of every string, after the last.
-DiffswitchWrites the unified diff the fixes would make, and nothing to the files.
-FilesWithMatchesswitchWrites the path of each file holding a finding.
-FilesWithoutMatchswitchWrites the path of each file holding no finding.
-FixswitchWrites the fixes into the files.
-FollowswitchAfter each file’s -Tail, its open -Lines range or the whole of it, scans what it gains as it grows, writing each finding once nothing that arrives later can change it, until the pipeline is stopped.
-FormatstringA report template to write at each finding in place of the finding.
-GitHubswitchWrites each finding as a GitHub workflow annotation.
-HeaduintScans the first this many lines of each input, or records of -Unit, reading a file no further.
-HiddenswitchReads hidden files and directories a walk would skip.
-Includestring[]Keeps a walked file only when a glob matches it, or drops it for a glob that starts with !.
-InputObjectstringby valueThe text to scan; each string piped in is scanned on its own.
-InteractiveswitchWith -Fix, puts each fix to the person before it is written, as Edit-TrexText -Interactive puts a change.
-JsonswitchWrites every finding as the trex command’s scan --rules --json writes them: one array after the last input, each object naming the rule, its severity and message, where the finding stands, its text, registers and fix, the rule’s metadata, and the path of a file.
-LibraryTrex.LibraryThe atoms, rules among them, to read in place of the session’s.
-LinesobjectScans a range of lines, or records of -Unit, counted from one: "100..200", "100..", "..200", "7", or PowerShell’s 100..200.
-LiteralPathstring[]by nameFiles or directories to scan, read as written, as Get-ChildItem pipes them.
-MaxCountuintWrites at most this many findings of each input.
-NoIgnoreswitchReads files an ignore rule excludes.
-Pathstring[]Files or directories to scan; wildcards expand.
-RequireMatchswitchWrites an error after the last input when no input held a finding, for a script that stops on one.
-RuleFilestring[]Pattern files, or directories of .trex files, imported for this call over the atoms in force; a file already imported is read in place of that import.
-SarifswitchWrites every finding as one SARIF 2.1.0 document.
-ShowSkippedswitchLists where each fix a template answer skipped stands, beside the count -Interactive always says.
-TailuintScans the last this many lines of each input, or records of -Unit, reading a file backward from its end.
-UnitstringWhat -Head, -Tail and -Lines count: a line when absent, or a unit Find-TrexRecord reads, such as paragraph or block.

Writes Trex.Finding, string, Trex.MatchCount.

ConvertTo-TrexSarif

Renders findings as one SARIF 2.1.0 document, for a CI system or an editor that reads one.

The rules the document lists are the findings’ own, in the order they first appear. A finding with no file carries no location URI and no fix, since a fix in SARIF names the file it changes.

Alias: ConvertTo-TxSarif

ConvertTo-TrexSarif [-Finding] <Finding[]> [<CommonParameters>]
ParameterTypePipelineDescription
-FindingTrex.Finding[]by valueThe findings to render.

Writes string.