Matching Semantics
How consumers should interpret paths, platforms, and content indicators.
Schema version 1 keeps matching simple.
- Multiple
match.pathsentries are alternatives. - A path matcher applies only to its listed platforms.
- A matching path identifies a candidate artifact.
content.containsandcontent.regexprovide additional evidence for a path.- Consumers may use path-only matching or path plus content verification.
- Environment variables are not expanded inside the database.
Platforms
Supported platforms are:
windowslinuxmacos
Linux and macOS remain distinct even when they currently share the same path.
Content Matching
contains is literal substring evidence. regex is regular-expression
evidence validated by the LOLPaths validator. Content matching does not require
YARA.