-
Notifications
You must be signed in to change notification settings - Fork 0
Configuration
Hooray accepts strict YAML (.yaml/.yml) or TOML (.toml). Unknown fields are rejected. --config FILE selects a file; documented HOORAY_* environment variables override values.
max_concurrency: 32
max_request_bytes: 1048576
max_input_bytes: 104857600
max_archive_bytes: 536870912
max_archive_entries: 100000
database_path: hooray.db
osv_url: https://api.osv.dev
osv_connect_timeout_secs: 10
osv_request_timeout_secs: 30
policy_path: hooray-policy.yaml
monitor_interval_secs: 300
api_bind: 127.0.0.1:8080
auth_bearer_sha256: null
offline: falseHOORAY_MAX_CONCURRENCYHOORAY_MAX_REQUEST_BYTESHOORAY_MAX_INPUT_BYTESHOORAY_MAX_ARCHIVE_BYTESHOORAY_MAX_ARCHIVE_ENTRIESHOORAY_DATABASE_PATHHOORAY_OSV_URLHOORAY_OSV_CONNECT_TIMEOUT_SECSHOORAY_OSV_REQUEST_TIMEOUT_SECSHOORAY_POLICY_PATHHOORAY_MONITOR_INTERVAL_SECSHOORAY_API_BINDHOORAY_AUTH_BEARER_SHA256HOORAY_OFFLINE
Boolean environment values accept only documented strict spellings; malformed values fail configuration loading.
auth_bearer_sha256 is the lowercase SHA-256 digest of the expected bearer token, not the token itself. A non-loopback api_bind is rejected unless authentication is configured. Tokens and their hashes are never echoed in API errors or debug output.
printf %s 'replace-with-a-long-random-token' | sha256sumClients send:
Authorization: Bearer replace-with-a-long-random-tokenoffline: true prevents vulnerability-provider calls. Local inventory, source, license, policy, reporting, and persistence still work. A policy file is still required when the configured path is used.
Limits are validated against zero, maximum, and overflow boundaries. Archive limits apply to cumulative image expansion. Report rendering has an independent 64 MiB output ceiling. API request bodies and concurrent scans are bounded.