Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
196 changes: 196 additions & 0 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@
"@oclif/plugin-help": "^6.2.29",
"@oclif/plugin-update": "^4.6.45",
"graphql": "^16.11.0",
"ora": "^8.2.0",
"packageurl-js": "^2.0.1",
"terminal-link": "^4.0.0",
"update-notifier": "^7.3.1"
Expand Down
29 changes: 18 additions & 11 deletions src/commands/scan/eol.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import fs from 'node:fs';
import path from 'node:path';
import { Command, Flags, ux } from '@oclif/core';
import ora from 'ora';
import terminalLink from 'terminal-link';
import { batchSubmitPurls } from '../../api/nes/nes.client.ts';
import type { ScanResult } from '../../api/types/hd-cli.types.js';
Expand Down Expand Up @@ -70,20 +71,23 @@ export default class ScanEol extends Command {

private async getScan(flags: Record<string, string>, config: Command['config']): Promise<ScanResult> {
if (flags.purls) {
ux.action.start(`Scanning purls from ${flags.purls}`);
const purls = this.getPurlsFromFile(flags.purls);
return batchSubmitPurls(purls);
return this.scanPurls(purls);
}

const sbom = await ScanSbom.loadSbom(flags, config);
return this.scanSbom(sbom);
}

private getPurlsFromFile(filePath: string): string[] {
const spinner = ora().start(`Loading purls from \`${filePath}\``);
try {
const purlsFileString = fs.readFileSync(filePath, 'utf8');
return parsePurlsFile(purlsFileString);
const purls = parsePurlsFile(purlsFileString);
spinner.succeed(`Loaded purls from \`${filePath}\``);
return purls;
} catch (error) {
spinner.fail(`Failed to read purls from \`${filePath}\``);
this.error(`Failed to read purls file. ${getErrorMessage(error)}`);
}
}
Expand All @@ -100,21 +104,24 @@ export default class ScanEol extends Command {
}

private async scanSbom(sbom: Sbom): Promise<ScanResult> {
let scan: ScanResult;
let purls: string[];

try {
purls = await extractPurls(sbom);
const purls = await extractPurls(sbom);
return this.scanPurls(purls);
} catch (error) {
this.error(`Failed to extract purls from sbom. ${getErrorMessage(error)}`);
}
}

private async scanPurls(purls: string[]): Promise<ScanResult> {
const spinner = ora().start('Scanning for EOL packages');
try {
scan = await batchSubmitPurls(purls);
const scan = await batchSubmitPurls(purls);
spinner.succeed('Scan completed');
return scan;
} catch (error) {
this.error(`Failed to submit scan to NES from sbom. ${getErrorMessage(error)}`);
spinner.fail('Scanning failed');
this.error(`Failed to submit scan to NES. ${getErrorMessage(error)}`);
}

return scan;
}

private async saveReport(components: InsightsEolScanComponent[], createdOn?: string): Promise<void> {
Expand Down
22 changes: 14 additions & 8 deletions src/commands/scan/sbom.ts
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
import { spawn } from 'node:child_process';
import fs from 'node:fs';
import { join, resolve } from 'node:path';
import { Command, Flags, ux } from '@oclif/core';
import { Command, Flags } from '@oclif/core';
import ora from 'ora';
import { filenamePrefix } from '../../config/constants.ts';
import type { Sbom } from '../../service/eol/cdx.svc.ts';
import { createSbom, validateIsCycloneDxSbom } from '../../service/eol/eol.svc.ts';
Expand Down Expand Up @@ -73,22 +74,31 @@ export default class ScanSbom extends Command {
}
let sbom: Sbom;
const path = dir || process.cwd();

const spinner = ora();
if (!background) {
spinner.start(flags.file ? 'Loading SBOM file' : 'Generating SBOM');
}

if (file) {
sbom = this._getSbomFromFile(file);
ux.action.stop();
} else if (background) {
this._getSbomInBackground(path);
this.log(`The scan is running in the background. The file will be saved at ${path}/${filenamePrefix}.sbom.json`);
ux.action.stop();
return;
} else {
sbom = await this._getSbomFromScan(path);
ux.action.stop();
if (save) {
this._saveSbom(path, sbom);
}
}

if (sbom) {
spinner.succeed(flags.file ? 'Loaded SBOM file' : 'Generated SBOM');
} else {
spinner.fail(flags.file ? 'Failed to load SBOM file' : 'Failed to generate SBOM');
}

if (!save) {
this.log(JSON.stringify(sbom, null, 2));
}
Expand All @@ -107,8 +117,6 @@ export default class ScanSbom extends Command {
this.error(`Path is not a directory: ${dir}`);
}

ux.action.start(`Scanning ${dir}`);

const options = this.getScanOptions();
const sbom = await createSbom(dir, options);
if (!sbom) {
Expand Down Expand Up @@ -149,8 +157,6 @@ export default class ScanSbom extends Command {
this.error(`SBOM file not found: ${file}`);
}

ux.action.start(`Loading sbom from ${file}`);

const fileContent = fs.readFileSync(file, {
encoding: 'utf8',
flag: 'r',
Expand Down