Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Critical Severity - AST 21466 #644

Merged
merged 33 commits into from
Aug 2, 2024
Merged
Show file tree
Hide file tree
Changes from 12 commits
Commits
Show all changes
33 commits
Select commit Hold shift + click to select a range
1272770
support to critical severity in consoleSummary, markdown, and html re…
igorlombacx Oct 19, 2023
7e535a7
updating critical severity usages
igorlombacx Oct 23, 2023
4a6b925
Merge branch 'main' into FEATURE/AST-21466-CRITICAL-SEVERITY
igorlombacx Oct 23, 2023
4e6bb39
critical severity for sarif and sonar
igorlombacx Oct 24, 2023
3aa617e
Merge branch 'main' into FEATURE/AST-21466-CRITICAL-SEVERITY
igorlombacx Oct 26, 2023
7b16c63
updating securities map
igorlombacx Oct 26, 2023
a972764
adding the check for CVSS3 feature flag
tiagobcx Nov 2, 2023
609ee49
changing critical triage message
tiagobcx Nov 3, 2023
69e7d6c
changing critical triage message
tiagobcx Nov 3, 2023
5fc25fa
merge with main
tiagobcx Jan 22, 2024
9aab42e
Feature/ast 37694 test critical severity (#696)
PravinGadankush Apr 4, 2024
9815a8e
Revert "Feature/ast 37694 test critical severity (#696)"
pedrompflopes May 17, 2024
c7db597
merge with main
tiagobcx May 23, 2024
362f464
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
tiagobcx Jun 20, 2024
f122d4f
adding N/A message
tiagobcx Jul 12, 2024
af85739
merge with main and new NA behaviour
tiagobcx Jul 15, 2024
bb10bbf
merge with main and new NA behaviour
tiagobcx Jul 15, 2024
d5164f4
fixing linter + triage
tiagobcx Jul 16, 2024
fe8eb09
fixing tests + linter
tiagobcx Jul 16, 2024
55c7a72
fixing unit tests
tiagobcx Jul 16, 2024
3f25f94
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
tiagobcx Jul 16, 2024
988da3b
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
tiagobcx Jul 16, 2024
36c129f
adding new test for critical
tiagobcx Jul 18, 2024
d9a84bd
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
OrShamirCM Jul 23, 2024
34bc8d4
Update pr_test.go
tiagobcx Jul 25, 2024
9de3497
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
tamarleviCm Jul 29, 2024
f544812
Update results-mock.go
tiagobcx Jul 30, 2024
b22006c
Merge branch 'main' into feature/AST-21466-CRITICAL-SEVERITY
pedrompflopes Jul 31, 2024
14ef4d7
adding na to containers and apisec
tiagobcx Jul 31, 2024
b0622e2
adding na to containers and apisec
tiagobcx Jul 31, 2024
186fd82
adding na to containers and apisec
tiagobcx Jul 31, 2024
c7327ac
changing ssh repo
tiagobcx Aug 1, 2024
51c946b
changing ssh repo
tiagobcx Aug 2, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions internal/commands/predicates.go
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ func triageUpdateSubCommand(resultsPredicatesWrapper wrappers.ResultsPredicatesW
--similarity-id <SimilarityID>
--project-id <ProjectID>
--state <TO_VERIFY|NOT_EXPLOITABLE|PROPOSED_NOT_EXPLOITABLE|CONFIRMED|URGENT>
--severity <HIGH|MEDIUM|LOW|INFO>
--severity <CRITICAL|HIGH|MEDIUM|LOW|INFO>
tiagobcx marked this conversation as resolved.
Show resolved Hide resolved
--comment <Comment(Optional)>
--scan-type <SAST|IAC-SECURITY>
`,
Expand Down Expand Up @@ -142,7 +142,10 @@ func runTriageUpdate(resultsPredicatesWrapper wrappers.ResultsPredicatesWrapper)
state, _ := cmd.Flags().GetString(params.StateFlag)
comment, _ := cmd.Flags().GetString(params.CommentFlag)
scanType, _ := cmd.Flags().GetString(params.ScanTypeFlag)

// check if the current tenant has critical severity available
if !wrappers.FeatureFlags[wrappers.CVSSV3Enabled] && strings.EqualFold(severity, "critical") {
return errors.Errorf("%s", "Critical severity is not available for your tenant.This severity status will be enabled shortly")
}
predicate := &wrappers.PredicateRequest{
SimilarityID: similarityID,
ProjectID: projectID,
Expand Down
52 changes: 32 additions & 20 deletions internal/commands/result.go
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ const (
failedListingResults = "Failed listing results"
failedListingCodeBashing = "Failed codebashing link"
mediumLabel = "medium"
criticalLabel = "critical"
highLabel = "high"
lowLabel = "low"
infoLabel = "info"
Expand All @@ -43,6 +44,7 @@ const (
lowSonar = "MINOR"
mediumSonar = "MAJOR"
highSonar = "CRITICAL"
criticalSonar = "BLOCKER"
infoLowSarif = "note"
mediumSarif = "warning"
highSarif = "error"
Expand All @@ -51,6 +53,7 @@ const (
lowCx = "LOW"
mediumCx = "MEDIUM"
highCx = "HIGH"
criticalCx = "CRITICAL"
codeBashingKey = "cb-url"
failedGettingBfl = "Failed getting BFL"
notAvailableString = "N/A"
Expand Down Expand Up @@ -115,19 +118,22 @@ var filterResultsListFlagUsage = fmt.Sprintf(
),
)

// Follows: over 9.0 is critical, 7.0 to 8.9 is high, 4.0 to 6.9 is medium and 3.9 or less is low.
var securities = map[string]string{
infoCx: "3.5",
lowCx: "6.5",
mediumCx: "8.5",
highCx: "9.5",
infoCx: "1.0",
tamarleviCm marked this conversation as resolved.
Show resolved Hide resolved
lowCx: "2.0",
mediumCx: "4.0",
highCx: "7.0",
criticalCx: "9.0",
}

// Match cx severity with sonar severity
var sonarSeverities = map[string]string{
infoCx: infoSonar,
lowCx: lowSonar,
mediumCx: mediumSonar,
highCx: highSonar,
infoCx: infoSonar,
lowCx: lowSonar,
mediumCx: mediumSonar,
highCx: highSonar,
criticalCx: criticalSonar,
}

func NewResultsCommand(
Expand Down Expand Up @@ -366,6 +372,7 @@ func convertScanToResultsSummary(scanInfo *wrappers.ScanResponseModel, resultsWr
ProjectID: scanInfo.ProjectID,
RiskStyle: "",
RiskMsg: "",
CriticalIssues: 0,
HighIssues: 0,
MediumIssues: 0,
LowIssues: 0,
Expand Down Expand Up @@ -428,7 +435,10 @@ func setNotAvailableNumberIfZero(summary *wrappers.ResultSummary, counter *int,
}

func setRiskMsgAndStyle(summary *wrappers.ResultSummary) {
if summary.HighIssues > 0 {
if summary.CriticalIssues > 0 {
summary.RiskStyle = criticalLabel
summary.RiskMsg = "Critical Risk"
} else if summary.HighIssues > 0 {
summary.RiskStyle = highLabel
summary.RiskMsg = "High Risk"
} else if summary.MediumIssues > 0 {
Expand Down Expand Up @@ -521,12 +531,13 @@ func writeConsoleSummary(summary *wrappers.ResultSummary) error {
}

fmt.Printf(" Total Results: %d \n", summary.TotalIssues)
fmt.Printf(" -------------------------------------- \n")
fmt.Printf(" | High: %*d| \n", defaultResultsPaddingSize, summary.HighIssues)
fmt.Printf(" | Medium: %*d| \n", defaultResultsPaddingSize, summary.MediumIssues)
fmt.Printf(" | Low: %*d| \n", defaultResultsPaddingSize, summary.LowIssues)
fmt.Printf(" | Info: %*d| \n", defaultResultsPaddingSize, summary.InfoIssues)
fmt.Printf(" -------------------------------------- \n")
fmt.Printf(" ----------------------------------- \n")
fmt.Printf(" | Critical: %*d| \n", defaultPaddingSize, summary.CriticalIssues)
fmt.Printf(" | High: %*d| \n", defaultPaddingSize, summary.HighIssues)
fmt.Printf(" | Medium: %*d| \n", defaultPaddingSize, summary.MediumIssues)
fmt.Printf(" | Low: %*d| \n", defaultPaddingSize, summary.LowIssues)
fmt.Printf(" | Info: %*d| \n", defaultPaddingSize, summary.InfoIssues)
fmt.Printf(" ----------------------------------- \n")

if summary.KicsIssues == notAvailableNumber {
fmt.Printf(" | IAC-SECURITY: %*s| \n", defaultPaddingSize, notAvailableString)
Expand Down Expand Up @@ -851,6 +862,7 @@ func createReport(format,
return writeHTMLSummary(summaryRpt, summary)
}
if printer.IsFormat(format, printer.FormatSummaryJSON) {
targetFile = fmt.Sprintf("%s_summary", targetFile)
summaryRpt := createTargetName(targetFile, targetPath, printer.FormatJSON)
convertNotAvailableNumberToZero(summary)
return exportJSONSummaryResults(summaryRpt, summary)
Expand Down Expand Up @@ -1533,16 +1545,16 @@ func findProperties(result *wrappers.ScanResult) wrappers.SarifProperties {
sarifProperties.Description = findDescriptionText(result)
sarifProperties.SecuritySeverity = securities[result.Severity]
sarifProperties.Tags = []string{"security", "checkmarx", result.Type}

return sarifProperties
}

func findSarifLevel(result *wrappers.ScanResult) string {
level := map[string]string{
infoCx: infoLowSarif,
lowCx: infoLowSarif,
mediumCx: mediumSarif,
highCx: highSarif,
infoCx: infoLowSarif,
lowCx: infoLowSarif,
mediumCx: mediumSarif,
highCx: highSarif,
criticalCx: highSarif,
}
return level[result.Severity]
}
Expand Down
2 changes: 1 addition & 1 deletion internal/params/flags.go
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ const (
PresetName = "sast-preset-name"
Threshold = "threshold"
ThresholdFlagUsage = "Local build threshold. Format <engine>-<severity>=<limit>. " +
"Example: scan --threshold \"sast-high=10;sca-high=5;iac-security-low=10\""
"Example: scan --threshold \"sast-critical=1;sast-high=10;sca-high=5;iac-security-low=10\""
KeyValuePairSize = 2
WaitDelayDefault = 5
SimilarityIDFlag = "similarity-id"
Expand Down
10 changes: 10 additions & 0 deletions internal/wrappers/feature-flags.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ import (

const tenantIDClaimKey = "tenant_id"
const PackageEnforcementEnabled = "PACKAGE_ENFORCEMENT_ENABLED"
const CVSSV3Enabled = "CVSS_V3_ENABLED"

var FeatureFlagsBaseMap = []CommandFlags{
{
Expand All @@ -17,6 +18,15 @@ var FeatureFlagsBaseMap = []CommandFlags{
},
},
},
{
CommandName: "cx triage update",
FeatureFlags: []FlagBase{
{
Name: CVSSV3Enabled,
Default: false,
},
},
},
}

var FeatureFlags = map[string]bool{}
Expand Down
6 changes: 5 additions & 1 deletion internal/wrappers/mock/results-mock.go
Original file line number Diff line number Diff line change
Expand Up @@ -145,8 +145,12 @@ func (r ResultsMockWrapper) GetScanSummariesByScanIDS(params map[string]string)
Severity: "high",
Counter: 1,
},
{
Severity: "critical",
Counter: 1,
},
},
TotalCounter: 4,
TotalCounter: 5,
FilesScannedCounter: 1,
},
KicsCounters: wrappers.KicsCounters{
Expand Down
30 changes: 25 additions & 5 deletions internal/wrappers/results-summary.go
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ import (

type ResultSummary struct {
TotalIssues int
CriticalIssues int
HighIssues int
MediumIssues int
LowIssues int
Expand Down Expand Up @@ -181,6 +182,10 @@ const summaryTemplateHeader = `{{define "SummaryTemplate"}}
.bg-red {
background-color: #f1605d;
}

.bg-darkred {
background-color: #C54A50 !important;
}

.bg-sast {
background-color: #1165b4 !important;
Expand Down Expand Up @@ -294,6 +299,10 @@ const summaryTemplateHeader = `{{define "SummaryTemplate"}}
width: 24.5%;
}

.top-row .risk-level-tile.critical {
background-color: #C54A50;
color: #fcfdff;
}
.top-row .risk-level-tile.high {
background: #f1605d;
color: #fcfdff;
Expand Down Expand Up @@ -400,7 +409,9 @@ const summaryTemplateHeader = `{{define "SummaryTemplate"}}
margin: 0 3rem 2rem;
right: 40px;
}

.bar-chart .progress .progress-bar.bg-critical {
background-color: #C54A50 !important;
}
.bar-chart .progress .progress-bar.bg-danger {
background-color: #f1605d !important;
}
Expand Down Expand Up @@ -446,6 +457,9 @@ const summaryTemplateHeader = `{{define "SummaryTemplate"}}
font-size: 14px;
padding-left: 5px;
}
.severity-legend-dot.critical {
background-color: #C54A50;
}

.severity-engines-text,
.severity-legend-text {
Expand Down Expand Up @@ -614,6 +628,9 @@ const nonAsyncSummary = `<div class="top-row">
<div class="element">
<div class="total">Total Vulnerabilities</div>
<div>
<div class="legend"><span class="severity-legend-dot">critical</span>
<div class="severity-legend-text bg-darkred"></div>
</div>
<div class="legend"><span class="severity-legend-dot">high</span>
<div class="severity-legend-text bg-red"></div>
</div>
Expand All @@ -628,6 +645,7 @@ const nonAsyncSummary = `<div class="top-row">
<div id="total" class="total">{{.TotalIssues}}</div>
<div class="single-stacked-bar-chart bar-chart">
<div class="progress">
<div class="progress-bar bg-critical value" >{{.CriticalIssues}}</div>
<div class="progress-bar bg-danger value">{{.HighIssues}}</div>
<div class="progress-bar bg-warning value">{{.MediumIssues}}</div>
<div class="progress-bar bg-success value">{{.LowIssues}}</div>
Expand Down Expand Up @@ -698,7 +716,9 @@ const SummaryMarkdownCompletedTemplate = `
{{- /* The '-' symbol at the start of the line is used to strip leading white space */ -}}
{{- /* ResultSummary template */ -}}
{{ $emoji := "⚪" }}
{{ if eq .RiskMsg "High Risk" }}
{{ if eq .RiskMsg "Critical Risk" }}
{{ $emoji = "🔴" }}
{{ else if eq .RiskMsg "High Risk" }}
{{ $emoji = "🔴" }}
{{ else if eq .RiskMsg "Medium Risk" }}
{{ $emoji = "🟡" }}
Expand All @@ -718,9 +738,9 @@ const SummaryMarkdownCompletedTemplate = `

### Total Vulnerabilities: {{.TotalIssues}}

|🔴 High |🟡 Medium |⚪ Low |⚪ Info |
|:----------:|:------------:|:---------:|:----------:|
| {{.HighIssues}} | {{.MediumIssues}} | {{.LowIssues}} | {{.InfoIssues}} |
|🔴 Critical |🔴 High |🟡 Medium |⚪ Low |⚪ Info |
|:----------:|:----------:|:------------:|:---------:|:----------:|
| {{.CriticalIssues}} | {{.HighIssues}} | {{.MediumIssues}} | {{.LowIssues}} | {{.InfoIssues}} |
***

### Vulnerabilities per Scan Type
Expand Down