Module: PWN::Reports::SARIF

Defined in:
lib/pwn/reports/sarif.rb

Overview

SARIF 2.1.0 writer for finding export.

Class Method Summary collapse

Class Method Details

.authors ⇒ Object



53
54
55
# File 'lib/pwn/reports/sarif.rb', line 53

public_class_method def self.authors
  "AUTHOR(S):\n  0day Inc. <[email protected]>\n"
end

.generate(opts = {}) ⇒ Object



9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
# File 'lib/pwn/reports/sarif.rb', line 9

public_class_method def self.generate(opts = {})
  path = PWN::Reports.resolve_path(opts.merge(ext: 'sarif.json'))
  payload = PWN::Reports.package_evidence(payload: PWN::Reports.report_payload(opts), path: path)
  remaining = payload[:findings].dup
  results = Array(payload[:priorities]).map do |priority|
    if priority[:kind] == 'chain'
      chain = priority.except(:kind)
      members = chain[:finding_ids].flat_map { |id| payload[:findings].select { |row| row['id'].to_s == id.to_s } }
      result = result_row(row: { 'id' => "attack-chain:#{chain[:finding_ids].join('->')}", 'severity' => chain[:combined_severity], 'title' => chain[:title] })
      result.merge(properties: { chain: chain, constituent_findings: members })
    else
      index = remaining.index do |finding|
        finding['id'].to_s == priority[:finding_ids].first.to_s && finding['title'].to_s == priority[:title].to_s && finding['severity'].to_s == priority[:combined_severity].to_s
      end
      result_row(row: index ? remaining.delete_at(index) : {})
    end
  end
  doc = {
    version: '2.1.0',
    '$schema' => 'https://json.schemastore.org/sarif-2.1.0.json',
    runs: [
      {
        tool: { driver: { name: 'pwn', version: (defined?(PWN::VERSION) ? PWN::VERSION : '0') } },
        results: results
      }
    ]
  }
  File.write(path, ::JSON.pretty_generate(doc))
  path
end

.help ⇒ Object



57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# File 'lib/pwn/reports/sarif.rb', line 57

public_class_method def self.help
  puts "USAGE:
    # Write a SARIF 2.1 document from a findings hash.
    #{self}.generate(
      results_hash: 'required - Hash with :findings Array',
      dir_path: 'optional - output directory',
      report_name: 'optional - basename without extension',
      path: 'optional - exact output path'
    )

    # Print the AUTHOR(S) string for this module.
    #{self}.authors
  "
  constants.sort
end