Skip to content

Commit df0ffea

Browse files
Update expected SARIF output for vulnerability rules in Trivy tests. Adjusted rule indices for existing vulnerabilities and added a new entry for eslint vulnerability CVE-2025-50537.
1 parent 7fe9d0f commit df0ffea

File tree

1 file changed

+36
-9
lines changed

1 file changed

+36
-9
lines changed

plugins/tools/trivy/test/expected.sarif

Lines changed: 36 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@
3434
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2021-33203\nSeverity: MEDIUM\nFixed Version: 2.2.24, 3.1.12, 3.2.4\nLink: [CVE-2021-33203](https://avd.aquasec.com/nvd/cve-2021-33203)"
3535
},
3636
"ruleId": "CVE-2021-33203",
37-
"ruleIndex": 7
37+
"ruleIndex": 8
3838
},
3939
{
4040
"level": "error",
@@ -61,7 +61,7 @@
6161
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2022-36359\nSeverity: HIGH\nFixed Version: 3.2.15, 4.0.7\nLink: [CVE-2022-36359](https://avd.aquasec.com/nvd/cve-2022-36359)"
6262
},
6363
"ruleId": "CVE-2022-36359",
64-
"ruleIndex": 4
64+
"ruleIndex": 5
6565
},
6666
{
6767
"level": "error",
@@ -115,7 +115,7 @@
115115
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2024-45231\nSeverity: MEDIUM\nFixed Version: 5.1.1, 5.0.9, 4.2.16\nLink: [CVE-2024-45231](https://avd.aquasec.com/nvd/cve-2024-45231)"
116116
},
117117
"ruleId": "CVE-2024-45231",
118-
"ruleIndex": 8
118+
"ruleIndex": 9
119119
},
120120
{
121121
"level": "warning",
@@ -142,7 +142,34 @@
142142
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2025-48432\nSeverity: MEDIUM\nFixed Version: 5.2.2, 5.1.10, 4.2.22\nLink: [CVE-2025-48432](https://avd.aquasec.com/nvd/cve-2025-48432)"
143143
},
144144
"ruleId": "CVE-2025-48432",
145-
"ruleIndex": 9
145+
"ruleIndex": 10
146+
},
147+
{
148+
"level": "warning",
149+
"locations": [
150+
{
151+
"message": {
152+
"text": "package-lock.json: eslint@9.3.0"
153+
},
154+
"physicalLocation": {
155+
"artifactLocation": {
156+
"uri": "package-lock.json",
157+
"uriBaseId": "ROOTPATH"
158+
},
159+
"region": {
160+
"endColumn": 1,
161+
"endLine": 633,
162+
"startColumn": 1,
163+
"startLine": 584
164+
}
165+
}
166+
}
167+
],
168+
"message": {
169+
"text": "Package: eslint\nInstalled Version: 9.3.0\nVulnerability CVE-2025-50537\nSeverity: MEDIUM\nFixed Version: 9.26.0\nLink: [CVE-2025-50537](https://avd.aquasec.com/nvd/cve-2025-50537)"
170+
},
171+
"ruleId": "CVE-2025-50537",
172+
"ruleIndex": 2
146173
},
147174
{
148175
"level": "error",
@@ -169,7 +196,7 @@
169196
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2025-57833\nSeverity: HIGH\nFixed Version: 4.2.24, 5.1.12, 5.2.6\nLink: [CVE-2025-57833](https://avd.aquasec.com/nvd/cve-2025-57833)"
170197
},
171198
"ruleId": "CVE-2025-57833",
172-
"ruleIndex": 5
199+
"ruleIndex": 6
173200
},
174201
{
175202
"level": "note",
@@ -223,7 +250,7 @@
223250
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2025-64458\nSeverity: HIGH\nFixed Version: 5.2.8, 5.1.14, 4.2.26\nLink: [CVE-2025-64458](https://avd.aquasec.com/nvd/cve-2025-64458)"
224251
},
225252
"ruleId": "CVE-2025-64458",
226-
"ruleIndex": 6
253+
"ruleIndex": 7
227254
},
228255
{
229256
"level": "error",
@@ -250,7 +277,7 @@
250277
"text": "Package: django\nInstalled Version: 1.11.29\nVulnerability CVE-2025-64459\nSeverity: CRITICAL\nFixed Version: 5.2.8, 5.1.14, 4.2.26\nLink: [CVE-2025-64459](https://avd.aquasec.com/nvd/cve-2025-64459)"
251278
},
252279
"ruleId": "CVE-2025-64459",
253-
"ruleIndex": 3
280+
"ruleIndex": 4
254281
},
255282
{
256283
"level": "warning",
@@ -277,7 +304,7 @@
277304
"text": "Package: js-yaml\nInstalled Version: 4.1.0\nVulnerability CVE-2025-64718\nSeverity: MEDIUM\nFixed Version: 4.1.1, 3.14.2\nLink: [CVE-2025-64718](https://avd.aquasec.com/nvd/cve-2025-64718)"
278305
},
279306
"ruleId": "CVE-2025-64718",
280-
"ruleIndex": 2
307+
"ruleIndex": 3
281308
}
282309
],
283310
"tool": {
@@ -292,4 +319,4 @@
292319
}
293320
],
294321
"version": "2.1.0"
295-
}
322+
}

0 commit comments

Comments
 (0)