Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🧹 use bom for vuln scanning #1167

Merged
merged 2 commits into from
Mar 14, 2024
Merged

🧹 use bom for vuln scanning #1167

merged 2 commits into from
Mar 14, 2024

Conversation

chris-rock
Copy link
Member

depends on mondoohq/cnquery#3533

This PR refactors the data gathering and uses cnquery bom data gathering instead. This simplifies the code and reduces the different ways we gather data.

Copy link
Contributor

github-actions bot commented Mar 11, 2024

Test Results

  1 files  ±0   24 suites  ±0   18s ⏱️ +2s
298 tests ±0  297 ✅ ±0  1 💤 ±0  0 ❌ ±0 
299 runs  ±0  298 ✅ ±0  1 💤 ±0  0 ❌ ±0 

Results for commit 02c91e3. ± Comparison against base commit db72822.

♻️ This comment has been updated with latest results.

apps/cnspec/cmd/vuln.go Outdated Show resolved Hide resolved
apps/cnspec/cmd/vuln.go Show resolved Hide resolved
apps/cnspec/cmd/vuln.go Outdated Show resolved Hide resolved
Copy link
Contributor

@czunker czunker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM:

Target:     debian:buster-CVE-2023-38408@b9bb5a146596
=======================================================

┌─ Advisories ─────────────────────────┐
│ Critical: ███ 14.3%                  │
│ High:     ████████████ 42.9%         │
│ Medium:   ███ 14.3%                  │
│ Low:      ███ 14.3%                  │
│ None:     ███ 14.3%                  │
└──────────────────────────────────────┘

┌─ Packages ───────────────────────────┐
│ Total:    ███████████████████ 109    │
│ Critical: ███ 1                      │
│ High:     ███████████████████ 5      │
│ Medium:   0                          │
│ Low:      ███ 1                      │
└──────────────────────────────────────┘

  ■   SCORE  PACKAGE         INSTALLED               FIXED                   AVAILABLE               ADVISORY    
  ■   9.8    openssh-client  1:7.9p1-10+deb10u2      1:7.9p1-10+deb10u4      1:7.9p1-10+deb10u4                  
  ├─  9.8    openssh-client  1:7.9p1-10+deb10u2      1:7.9p1-10+deb10u3      1:7.9p1-10+deb10u4      DLA-3532-1  
  ╰─  7      openssh-client  1:7.9p1-10+deb10u2      1:7.9p1-10+deb10u4      1:7.9p1-10+deb10u4      DLA-3694-1  
  ■   8.8    libncursesw6    6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5              
  ╰─  8.8    libncursesw6    6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5  DLA-3682-1  
  ■   8.8    libtinfo6       6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5              
  ╰─  8.8    libtinfo6       6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5  DLA-3682-1  
  ■   8.8    ncurses-base    6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5              
  ╰─  8.8    ncurses-base    6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5  DLA-3682-1  
  ■   8.8    ncurses-bin     6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5              
  ╰─  8.8    ncurses-bin     6.1+20181013-2+deb10u4  6.1+20181013-2+deb10u5  6.1+20181013-2+deb10u5  DLA-3682-1  
  ■   7.5    libgnutls30     3.6.7-4+deb10u10        3.6.7-4+deb10u12        3.6.7-4+deb10u12                    
  ├─  7.5    libgnutls30     3.6.7-4+deb10u10        3.6.7-4+deb10u12        3.6.7-4+deb10u12        DLA-3740-1  
  ╰─  5.9    libgnutls30     3.6.7-4+deb10u10        3.6.7-4+deb10u11        3.6.7-4+deb10u12        DLA-3660-1  
  ■   3.3    tar             1.30+dfsg-6             1.30+dfsg-6+deb10u1     1.30+dfsg-6+deb10u1                 
  ╰─  3.3    tar             1.30+dfsg-6             1.30+dfsg-6+deb10u1     1.30+dfsg-6+deb10u1     DLA-3755-1  
  ■   0      tzdata          2021a-0+deb10u11        2021a-0+deb10u12        2021a-0+deb10u12                    
  ╰─  0      tzdata          2021a-0+deb10u11        2021a-0+deb10u12        2021a-0+deb10u12        DLA-3684-1  

Thanks @chris-rock

@chris-rock chris-rock merged commit df8df20 into main Mar 14, 2024
12 checks passed
@chris-rock chris-rock deleted the chris-rock/bom-vuln branch March 14, 2024 12:46
@github-actions github-actions bot locked and limited conversation to collaborators Mar 14, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants