Skip to content

Conversation

@abhisek
Copy link
Member

@abhisek abhisek commented Sep 5, 2024

This PR actually introduces two non-breaking changes.

  1. Support scanning Java archive
  2. Introduce new --manifest and -M scan flag to evolve beyond just scanning lockfiles

-M also support embedded type so that we can specify different paths with different manifest / lockfile type. Example

./vet scan -M jar:$HOME/demo-client-java/build/libs/demo-client-java-0.0.1-SNAPSHOT.jar

Here we are explicitly stating that the path should be treated as jar (supported parser)

Screenshot 2024-09-05 at 6 01 52 PM

Fix #238

@github-actions
Copy link

github-actions bot commented Sep 5, 2024

vet Summary Report

This report is generated by vet

Policy Checks

  • ✅ Vulnerability
  • ✅ Malware
  • ✅ License
  • ❌ Popularity
  • ❌ Maintenance
  • ❌ Security Posture
  • ✅ Threats

New Packages

Packages Violating Policy

[Go] google.golang.org/genproto/googleapis/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component release pipeline appear to use dangerous workflows

[Go] github.com/mitchellh/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/pierrec/lz4/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/nwaples/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/scylladb/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/anchore/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] google.golang.org/genproto/googleapis/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component release pipeline appear to use dangerous workflows

[Go] github.com/magiconair/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/containerd/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/opencontainers/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/becheran/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/spf13/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/facebookincubator/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/sagikazarmark/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/xo/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/klauspost/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/pkg/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/mitchellh/hashstructure/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/anchore/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/wagoodman/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/wagoodman/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/pborman/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/dsnet/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/subosito/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/docker/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/anchore/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/iancoleman/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/sylabs/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/docker/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/hashicorp/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/anchore/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/therootcompany/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/sagikazarmark/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/acobaugh/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/anchore/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component popularity is low by Github stars count
  • ⚡ Use an alternative package that is popular

[Go] github.com/vifraa/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/saintfish/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/google/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/ulikunitz/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

[Go] github.com/xi2/[email protected] 🔗

  • ➡️ Found in manifest go.mod
  • ⚠️ Component appears to be unmaintained

@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Sep 5, 2024

Deploying safedep-vet with  Cloudflare Pages  Cloudflare Pages

Latest commit: a69cd67
Status: ✅  Deploy successful!
Preview URL: https://4184e618.safedep-vet.pages.dev
Branch Preview URL: https://feat-238-add-jar-scanning-su.safedep-vet.pages.dev

View logs

@abhisek abhisek self-assigned this Sep 5, 2024
@abhisek abhisek force-pushed the feat/238-add-jar-scanning-support branch from 7e1a5a5 to 2c02e6f Compare September 5, 2024 12:33
@abhisek abhisek requested a review from c0d3G33k September 5, 2024 12:33
@abhisek abhisek force-pushed the feat/238-add-jar-scanning-support branch 4 times, most recently from 04414be to 058235e Compare September 7, 2024 10:11
refactor: Parser target resolver to re-use from lockfile and directory reader

feat: Add support for scope based parse target resolution

refactor: Dir reader to use config struct

test: Fix directory reader tests

refactor: Rename parser utils to resolver

doc: Add jar scanning example in README.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for enumerating Java JAR for Packages

3 participants