Draft: Create vulnerability scanning SBOM scanner
requested to merge otovar/create-continuous-scanner-class into 371055-add-service-to-match-sbom-components-to-advisories
What does this MR do and why?
This MR introduces an SBOM scanner class that orchestrates the creation of the security reports when supplied with an SBOM. The overall process looks like the following:
- A scanner instance is created and initialized with a CI SBOM report a.k.a. a parsed CycloneDX object.
- The scanner then fetches the advisories for a component using the
PackageAdvisories
class. - A security report builder is initialized, and the component with the advisories is added using the report builder.
- The
#report
method then returns a security report that was built. - Additionally, any scan metrics are updated as well to reflect what package manager was used and if the scan succeeded/failed.
This MR is the first in a series of related changes:
- Draft: Add service to match SBOM components and... (!126954 - closed)
-
Draft: Create vulnerability scanning SBOM scanner (!127370 - closed)
👈 - Draft: Trigger vulnerability scanning on Cyclon... (!127396 - closed)
- Draft: Exclude gemnasium security reports when ... (!127443 - closed)
Closes #408257 (closed)
Screenshots or screen recordings
Screenshots are required for UI changes, and strongly recommended for all other merge requests.
Before | After |
---|---|
How to set up and validate locally
Numbered steps to set up and validate the change are strongly suggested.
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
-
I have evaluated the MR acceptance checklist for this MR.
Edited by Oscar Tovar