chainsaw risk-weights
Show, preview, and apply per-signal risk-weight overrides
Show, preview, and apply per-signal risk-weight overrides
| Subcommand | What it does |
|---|---|
chainsaw risk-weights apply | Persist a previewed weight set (requires a fresh –simulate-id) |
chainsaw risk-weights preview | Preview the verdict-flip impact of a draft weight set |
chainsaw risk-weights show | Print current category + signal weights |
chainsaw risk-weights [command]
risk-weights is the CLI front-end for tuning the v2 risk engine’s per-signal weights with a mandatory simulate-then-confirm gate. The ‘preview’ subcommand returns a flip-impact projection (would-block / would-permit deltas plus sample flips) and a simulate_id; the ‘apply’ subcommand requires a fresh simulate_id from a recent preview.
The gate exists to prevent finger-fumble reclassifications: a single PUT with bad weights can flip thousands of packages from permit to block. preview-then-apply forces the operator to eyeball the impact before saving.
chainsaw risk-weights apply
Persist a previewed weight set (requires a fresh –simulate-id)
chainsaw risk-weights apply [flags]
apply PUTs the same –set values you previewed, attached to your preview’s simulate_id:
chainsaw risk-weights apply --simulate-id <id> --set vuln.cvss_high=70
The –set values must match the ones you previewed exactly — the server re-derives the simulate inputs hash from them and returns CHW-4830 if they drifted, if the preview is older than 1h, or if another operator saved different weights in between. Re-run ‘preview’ and apply the new id.
If the preview itself could not model the change – it returned a fallback reason instead of real projected impact – the server refuses the save with CHW-4834 rather than treating an empty projection as your consent. Fix the cause and re-preview, or pass –acknowledge-degraded-preview to save anyway; the waiver is recorded in the audit log against your user.
apply prints the weights the server read BACK from storage, so the output is proof the write landed rather than an echo of the request. Confirm independently with ‘chainsaw risk-weights show’.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--acknowledge-degraded-preview | bool | — | save even though the preview could not model the change (server answers CHW-4834 otherwise); the waiver is audited |
--set | stringSlice | — | same –set values used during preview (must match exactly) |
--simulate-id | string | — | simulate_id returned by a fresh ‘risk-weights preview’ run |
The global flags apply here too.
chainsaw risk-weights preview
Preview the verdict-flip impact of a draft weight set
chainsaw risk-weights preview [flags]
Preview prints projected verdict flips for the supplied draft weights. Use –set repeatedly to override individual signals:
chainsaw risk-weights preview \
--set vuln.cvss_high=70 \
--set sc.publisher_changed=50
Signal ids must exist in the engine registry — list them with ‘chainsaw risk-weights show’ or GET /api/risk/signals. A few signals that back instant-block enforcement (vuln.kev, sc.known_malicious, qual.checksum_mismatch) are not tunable and are rejected.
Prints the simulate_id, the would-block / would-permit / flip counts, and the first 10 sample flips. The simulate_id is required by ‘apply’ and expires after 1 hour.
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--set | stringSlice | — | signal weight override in the form <signalId>=<int>; repeat for multiple |
The global flags apply here too.
chainsaw risk-weights show
Print current category + signal weights
chainsaw risk-weights show