Documentation
¶
Overview ¶
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. * * This product includes software developed at Datadog (https://www.datadoghq.com) Copyright 2024 Datadog, Inc.
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. * * This product includes software developed at Datadog (https://www.datadoghq.com) Copyright 2024 Datadog, Inc.
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. * * This product includes software developed at Datadog (https://www.datadoghq.com) Copyright 2024 Datadog, Inc.
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. * * This product includes software developed at Datadog (https://www.datadoghq.com) Copyright 2024 Datadog, Inc.
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. * * This product includes software developed at Datadog (https://www.datadoghq.com) Copyright 2024 Datadog, Inc.
Index ¶
- Constants
- Variables
- func PtrStringToString(v *string) string
- func RemoteModuleCallKey(root, source, version, moduleName string) string
- func RemoteModuleKey(root, source, version string) string
- func ShouldSkipVulnerability(command model.CommentsCommands, queryID, legacyQueryID string) bool
- type Inspector
- func (c *Inspector) DecodeQueryResults(ctx context.Context, qCtx *QueryContext, ctxTimeout context.Context, ...) ([]model.Vulnerability, error)
- func (c *Inspector) EnableCoverageReport()
- func (c *Inspector) GetCoverageReport() cover.Report
- func (c *Inspector) GetFailedQueries() map[string]error
- func (c *Inspector) Inspect(ctx context.Context, scanID string, files model.FileMetadatas, ...) ([]model.Vulnerability, error)
- func (c *Inspector) LenQueriesByPlat(platforms []string) int
- func (c *Inspector) SetExternalModulePaths(paths []string)
- func (c *Inspector) SetRemoteModuleDirectories(sourceToDir map[string]string)
- func (c *Inspector) TransformJsonencodeInPayload(ctx context.Context, value ast.Value) ast.Value
- type PreparedQuery
- type QueryContext
- type QueryLoader
- type QueryResult
- type Tracker
- type VulnerabilityBuilder
Constants ¶
const ( UndetectedVulnerabilityLine = -1 DefaultQueryID = utils.DefaultQueryID DefaultQueryName = utils.DefaultQueryName DefaultExperimental = utils.DefaultExperimental DefaultQueryDescription = utils.DefaultQueryDescription DefaultQueryDescriptionID = utils.DefaultQueryDescriptionID DefaultQueryURI = utils.DefaultQueryURI )
Default values for inspector
Variables ¶
var DefaultVulnerabilityBuilder = func(ctx context.Context, qCtx *QueryContext, tracker Tracker, v interface{}, detector *dec.DetectLine, useOldSeverities bool, queryDuration time.Duration) (*model.Vulnerability, error) { contextLogger := logger.FromContext(ctx) vObj, ok := v.(map[string]interface{}) if !ok { return &model.Vulnerability{}, ErrInvalidResult } vObj = mergeWithMetadata(vObj, qCtx.Query.Metadata.Metadata) var err error var output []byte output, err = json.Marshal(vObj) if err != nil { return &model.Vulnerability{}, errors.Wrap(err, "failed to marshall query output") } var fileID *string fileID, err = mapKeyToString(ctx, vObj, "documentId", false) if err != nil { return &model.Vulnerability{}, errors.Wrap(err, "failed to recognize file id") } file, ok := qCtx.Files[*fileID] if !ok { return &model.Vulnerability{}, errors.New("failed to find file from query response") } logWithFields := contextLogger.With(). Str("scanID", qCtx.scanID). Str("fileName", file.FilePath). Str("queryName", qCtx.Query.Metadata.Query). Logger() linesVulne := model.VulnerabilityLines{ Line: -1, VulnLines: &[]model.CodeLine{}, LineWithVulnerability: "", } searchKey := "" if s, ok := vObj["searchKey"]; ok { searchKey = s.(string) intDoc := file.LineInfoDocument vulsSplit := strings.Split(searchKey, ".") if file.Kind == model.KindINI { vulsSplit, searchKey = sanitizeINIKey(vulsSplit) } if strings.Contains(vulsSplit[len(vulsSplit)-1], "RefMetadata") { return &model.Vulnerability{}, ErrNoResult } searchKey, _ = modifyVulSearchKeyReference(intDoc, searchKey, vulsSplit) vObj["searchKey"] = searchKey linesVulne = detector.DetectLine(ctx, file, searchKey) } else { logWithFields.Error().Msg("Saving result. failed to detect line") } lineNumber := 0 if !slices.Contains([]model.FileKind{model.KindHELM, model.KindTerraform}, file.Kind) && len(file.ResolvedFiles) == 0 { searchLineCalc := &searchLineCalculator{ lineNr: -1, vObj: vObj, file: file, detector: detector, linesVulne: linesVulne, } lineNumber, linesVulne = calculeSearchLine(ctx, searchLineCalc) } if linesVulne.Line == -1 { logWithFields.Warn().Msgf("Failed to detect line, query response %s", searchKey) linesVulne.Line = 1 } searchValue := "" if s, ok := vObj["searchValue"]; ok { searchValue = s.(string) } overrideKey := "" if s, ok := vObj["overrideKey"]; ok { overrideKey = s.(string) } platform := getStringFromMap(ctx, "platform", "", overrideKey, vObj, &logWithFields) resourceType := PtrStringToString(mustMapKeyToString(ctx, vObj, "resourceType")) if strings.EqualFold(platform, "ansible") { resourceType = utils.NormalizeAnsibleResourceType(resourceType) } queryID := getStringFromMap(ctx, "id", DefaultQueryID, overrideKey, vObj, &logWithFields) legacyQueryID := getOptionalStringKey(ctx, "legacyId", DefaultQueryID, overrideKey, vObj, &logWithFields) severity := getResolvedSeverity(ctx, vObj, &logWithFields, overrideKey, useOldSeverities) return &model.Vulnerability{ ID: 0, ScanID: qCtx.scanID, FileID: file.ID, FileName: linesVulne.ResolvedFile, QueryName: getStringFromMap(ctx, "queryName", DefaultQueryName, overrideKey, vObj, &logWithFields), QueryID: queryID, LegacyQueryID: legacyQueryID, Experimental: getBoolFromMap(ctx, "experimental", DefaultExperimental, overrideKey, vObj, &logWithFields), QueryURI: getStringFromMap(ctx, "descriptionUrl", DefaultQueryURI, overrideKey, vObj, &logWithFields), Category: getStringFromMap(ctx, "category", "", overrideKey, vObj, &logWithFields), Description: getStringFromMap(ctx, "descriptionText", "", overrideKey, vObj, &logWithFields), DescriptionID: getStringFromMap(ctx, "descriptionID", DefaultQueryDescriptionID, overrideKey, vObj, &logWithFields), Severity: severity, Platform: platform, CWE: getStringFromMap(ctx, "cwe", "", overrideKey, vObj, &logWithFields), Line: linesVulne.Line, VulnerabilityLocation: model.ResourceLocation{ Start: linesVulne.VulnerablilityLocation.Start, End: linesVulne.VulnerablilityLocation.End, }, RemediationLocation: model.ResourceLocation{ Start: linesVulne.RemediationLocation.Start, End: linesVulne.RemediationLocation.End, }, VulnLines: linesVulne.VulnLines, ResourceType: resourceType, ResourceName: PtrStringToString(mustMapKeyToString(ctx, vObj, "resourceName")), SearchKey: searchKey, SearchLine: lineNumber, SearchValue: searchValue, Value: mustMapKeyToString(ctx, vObj, "value"), Output: string(output), CloudProvider: getOptionalStringKey(ctx, "cloudProvider", "", overrideKey, vObj, &logWithFields), Remediation: PtrStringToString(mustMapKeyToString(ctx, vObj, "remediation")), RemediationType: PtrStringToString(mustMapKeyToString(ctx, vObj, "remediationType")), QueryDuration: queryDuration, LineWithVulnerability: linesVulne.LineWithVulnerability, ResourceSource: linesVulne.ResourceSource, FileSource: linesVulne.FileSource, BlockLocation: linesVulne.BlockLocation, ModuleCallChain: file.ModuleCallChain, Frameworks: append(extractDefaultFrameworks(ctx, qCtx.Query.Metadata.Metadata, qCtx.FlagEvaluator), extractCustomFrameworks(ctx, qCtx.Query.Metadata.Metadata, qCtx.FlagEvaluator)...), }, nil }
DefaultVulnerabilityBuilder defines a vulnerability builder to execute default actions of scan
var ErrInvalidResult = errors.New("query: invalid result format")
ErrInvalidResult - error representing invalid result
var ErrNoResult = errors.New("query: not result")
ErrNoResult - error representing when a query didn't return a result
Functions ¶
func PtrStringToString ¶
PtrStringToString - converts a pointer to string to a string
func RemoteModuleCallKey ¶ added in v1.8.0
func RemoteModuleKey ¶ added in v1.8.0
func ShouldSkipVulnerability ¶
func ShouldSkipVulnerability(command model.CommentsCommands, queryID, legacyQueryID string) bool
ShouldSkipVulnerability verifies if the vulnerability in question should be ignored through comment commands
Types ¶
type Inspector ¶
type Inspector struct {
QueryLoader *QueryLoader
// contains filtered or unexported fields
}
Inspector represents a list of compiled queries, a builder for vulnerabilities, an information tracker a flag to enable coverage and the coverage report if it is enabled
func NewInspector ¶
func NewInspector( ctx context.Context, queriesSource source.QueriesSource, vb VulnerabilityBuilder, tracker Tracker, queryParameters *source.QueryInspectorParameters, ruleConfigs map[string]config.IacRuleConfig, repoPath string, useOldSeverities bool, needsLog bool, numWorkers int, flagEvaluator featureflags.FlagEvaluator, fsys vfs.FS, disableRuleIsolation bool, useRulesCache bool, ) (*Inspector, error)
NewInspector initializes a inspector, compiling and loading queries for scan and its tracker
func (*Inspector) DecodeQueryResults ¶
func (c *Inspector) DecodeQueryResults( ctx context.Context, qCtx *QueryContext, ctxTimeout context.Context, results rego.ResultSet, queryDuration time.Duration) ([]model.Vulnerability, error)
DecodeQueryResults decodes the results into []model.Vulnerability
func (*Inspector) EnableCoverageReport ¶
func (c *Inspector) EnableCoverageReport()
EnableCoverageReport enables the flag to create a coverage report
func (*Inspector) GetCoverageReport ¶
GetCoverageReport returns the scan coverage report
func (*Inspector) GetFailedQueries ¶
GetFailedQueries returns a map of failed queries and the associated error. It returns a copy taken under failedQueriesMu so callers can read the result safely even if a scan is still writing to the underlying map.
func (*Inspector) Inspect ¶
func (c *Inspector) Inspect( ctx context.Context, scanID string, files model.FileMetadatas, platforms []string) ([]model.Vulnerability, error)
func (*Inspector) LenQueriesByPlat ¶
LenQueriesByPlat returns the number of queries by platforms
func (*Inspector) SetExternalModulePaths ¶ added in v1.8.0
func (*Inspector) SetRemoteModuleDirectories ¶ added in v1.8.0
type PreparedQuery ¶
type PreparedQuery struct {
OpaQuery rego.PreparedEvalQuery
Metadata model.QueryMetadata
}
PreparedQuery includes the opaQuery and its metadata
type QueryContext ¶
type QueryContext struct {
Ctx context.Context
Files map[string]*model.FileMetadata
Query *PreparedQuery
FlagEvaluator featureflags.FlagEvaluator
// contains filtered or unexported fields
}
QueryContext contains the context where the query is executed, which scan it belongs, basic information of query, the query compiled and its payload
type QueryLoader ¶
type QueryLoader struct {
QueriesMetadata []model.QueryMetadata
// contains filtered or unexported fields
}
QueryLoader is responsible for loading the queries for the inspector
func (*QueryLoader) LoadQuery ¶
func (q *QueryLoader) LoadQuery(ctx context.Context, query *model.QueryMetadata, modules []tfmodules.ParsedModule, baseStores map[string]storage.Store, baseDataHashes map[string]uint64, cacheEnabled bool) (*rego.PreparedEvalQuery, error)
LoadQuery loads the query into memory so it can be freed when not used anymore.
baseStores holds one shared, read-only inmem store per platform (the merged library + module input data for this scan); baseDataHashes holds a hash of each store's data. When the query carries no custom InputData it uses the shared base store, and its compiled *PreparedEvalQuery is served from / stored in the process-global preparedQueryCache — the cache key folds in the base data hash, so a compiled query (whose store bakes in this scan's data) is only reused by a later scan whose base data is byte-identical. This makes warm scans skip the expensive PrepareForEval compile even when Terraform module data is present, as long as that data is unchanged.
type QueryResult ¶
type QueryResult struct {
// contains filtered or unexported fields
}
type Tracker ¶
type Tracker interface {
TrackQueryLoad(queryAggregation int)
TrackQueryExecuting(queryAggregation int)
TrackQueryExecution(queryAggregation int)
FailedDetectLine()
GetOutputLines() int
}
Tracker wraps an interface that contain basic methods: TrackQueryLoad, TrackQueryExecution and FailedDetectLine TrackQueryLoad increments the number of loaded queries TrackQueryExecution increments the number of queries executed FailedDetectLine decrements the number of queries executed GetOutputLines returns the number of lines to be displayed in results outputs
type VulnerabilityBuilder ¶
type VulnerabilityBuilder func(ctx context.Context, qCtx *QueryContext, tracker Tracker, v interface{}, detector *detector.DetectLine, useOldSeverities bool, queryDuration time.Duration) (*model.Vulnerability, error)
VulnerabilityBuilder represents a function that will build a vulnerability
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package mock is a generated GoMock package.
|
Package mock is a generated GoMock package. |
|
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License.
|
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. |
|
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License.
|
* Unless explicitly stated otherwise all files in this repository are licensed under the Apache-2.0 License. |