forked from DependencyTrack/dependency-track
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathFindingPackagingFormat.java
More file actions
117 lines (103 loc) · 4.8 KB
/
Copy pathFindingPackagingFormat.java
File metadata and controls
117 lines (103 loc) · 4.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
/*
* This file is part of Dependency-Track.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* SPDX-License-Identifier: Apache-2.0
* Copyright (c) OWASP Foundation. All Rights Reserved.
*/
package org.dependencytrack.integrations;
import alpine.model.About;
import alpine.model.ConfigProperty;
import org.dependencytrack.model.Finding;
import org.dependencytrack.model.Project;
import org.dependencytrack.persistence.QueryManager;
import org.dependencytrack.util.DateUtil;
import org.json.JSONObject;
import java.util.Date;
import java.util.List;
import java.util.UUID;
import static org.dependencytrack.model.ConfigPropertyConstants.GENERAL_BASE_URL;
public class FindingPackagingFormat {
/** FPF is versioned. If the format changes, the version needs to be bumped. */
private static final String FPF_VERSION = "1.4";
private static final String FIELD_APPLICATION = "application";
private static final String FIELD_VERSION = "version";
private static final String FIELD_TIMESTAMP = "timestamp";
private static final String FIELD_BASE_URL = "baseUrl";
private static final String FIELD_UUID = "uuid";
private static final String FIELD_DESCRIPTION = "description";
private static final String FIELD_NAME = "name";
private static final String FIELD_PURL = "purl";
private static final String FIELD_CPE = "cpe";
private static final String FIELD_META = "meta";
private static final String FIELD_PROJECT = "project";
private static final String FIELD_FINDINGS = "findings";
private final JSONObject payload;
public FindingPackagingFormat(final UUID projectUuid, final List<Finding> findings) {
payload = initialize(projectUuid, findings);
}
public JSONObject getDocument() {
return payload;
}
private JSONObject initialize(final UUID projectUuid, final List<Finding> findings) {
try (QueryManager qm = new QueryManager()) {
final Project project = qm.getObjectByUuid(Project.class, projectUuid);
final About about = new About();
final ConfigProperty baseUrl = qm.getConfigProperty(GENERAL_BASE_URL.getGroupName(), GENERAL_BASE_URL.getPropertyName());
/*
Create a generic meta object containing basic Dependency-Track information
This is useful for file-based parsing systems that needs to be able to
identify what type of file it is, and what type of system generated it.
*/
final JSONObject meta = new JSONObject();
meta.put(FIELD_APPLICATION, about.getApplication());
meta.put(FIELD_VERSION, about.getVersion());
meta.put(FIELD_TIMESTAMP, DateUtil.toISO8601(new Date()));
if (baseUrl != null && baseUrl.getPropertyValue() != null) {
meta.put(FIELD_BASE_URL, baseUrl.getPropertyValue());
}
/*
Findings are specific to a given project. This information is useful for
systems outside of Dependency-Track so that they can perform mappings as
well as not have to perform additional queries back to Dependency-Track
to discover basic project information.
*/
final JSONObject projectJson = new JSONObject();
projectJson.put(FIELD_UUID, project.getUuid());
projectJson.put(FIELD_NAME, project.getName());
if (project.getVersion() != null) {
projectJson.put(FIELD_VERSION, project.getVersion());
}
if (project.getDescription() != null) {
projectJson.put(FIELD_DESCRIPTION, project.getDescription());
}
if (project.getPurl() != null) {
projectJson.put(FIELD_PURL, project.getPurl());
}
if (project.getCpe() != null) {
projectJson.put(FIELD_CPE, project.getCpe());
}
/*
Add the meta and project objects along with the findings array
to a root json object and return.
*/
final JSONObject root = new JSONObject();
root.put(FIELD_VERSION, FPF_VERSION);
root.put(FIELD_META, meta);
root.put(FIELD_PROJECT, projectJson);
root.put(FIELD_FINDINGS, findings);
return root;
}
}
}