1
0
mirror of https://github.com/securego/gosec.git synced 2025-01-18 02:58:22 +02:00
gosec/output/formatter.go

217 lines
5.2 KiB
Go
Raw Normal View History

2016-07-20 12:02:01 +02:00
// (c) Copyright 2016 Hewlett Packard Enterprise Development LP
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package output
import (
"encoding/csv"
2016-07-26 01:39:55 +02:00
"encoding/json"
2018-01-26 05:16:49 +02:00
"encoding/xml"
2016-10-18 07:36:35 +02:00
htmlTemplate "html/template"
2016-07-20 12:02:01 +02:00
"io"
2019-03-11 22:13:48 +02:00
"strconv"
"strings"
2016-10-18 07:36:35 +02:00
plainTemplate "text/template"
2016-07-20 12:02:01 +02:00
"github.com/securego/gosec"
"gopkg.in/yaml.v2"
2016-07-20 12:02:01 +02:00
)
// ReportFormat enumerates the output format for reported issues
2016-07-20 12:02:01 +02:00
type ReportFormat int
const (
// ReportText is the default format that writes to stdout
2016-07-20 12:02:01 +02:00
ReportText ReportFormat = iota // Plain text format
// ReportJSON set the output format to json
ReportJSON // Json format
// ReportCSV set the output format to csv
ReportCSV // CSV format
2018-01-26 05:16:49 +02:00
2018-01-27 06:14:35 +02:00
// ReportJUnitXML set the output format to junit xml
ReportJUnitXML // JUnit XML format
2016-07-20 12:02:01 +02:00
)
var text = `Results:
{{range $filePath,$fileErrors := .Errors}}
Golang errors in file: [{{ $filePath }}]:
{{range $index, $error := $fileErrors}}
> [line {{$error.Line}} : column {{$error.Column}}] - {{$error.Err}}
{{end}}
{{end}}
2016-07-20 12:02:01 +02:00
{{ range $index, $issue := .Issues }}
2018-04-16 07:44:54 +02:00
[{{ $issue.File }}:{{ $issue.Line }}] - {{ $issue.RuleID }}: {{ $issue.What }} (Confidence: {{ $issue.Confidence}}, Severity: {{ $issue.Severity }})
2016-07-20 12:02:01 +02:00
> {{ $issue.Code }}
{{ end }}
Summary:
Files: {{.Stats.NumFiles}}
Lines: {{.Stats.NumLines}}
Nosec: {{.Stats.NumNosec}}
Issues: {{.Stats.NumFound}}
`
2017-04-26 02:57:12 +02:00
type reportInfo struct {
Errors map[string][]gosec.Error `json:"Golang errors"`
Issues []*gosec.Issue
Stats *gosec.Metrics
2017-04-26 02:57:12 +02:00
}
2017-12-13 09:39:00 +02:00
// CreateReport generates a report based for the supplied issues and metrics given
// the specified format. The formats currently accepted are: json, csv, html and text.
2019-03-11 22:13:48 +02:00
func CreateReport(w io.Writer, format, rootPath string, issues []*gosec.Issue, metrics *gosec.Metrics, errors map[string][]gosec.Error) error {
2017-04-26 02:57:12 +02:00
data := &reportInfo{
Errors: errors,
2017-04-26 02:57:12 +02:00
Issues: issues,
Stats: metrics,
}
2016-07-26 01:39:55 +02:00
var err error
2016-07-20 12:02:01 +02:00
switch format {
case "json":
2016-07-26 01:39:55 +02:00
err = reportJSON(w, data)
case "yaml":
err = reportYAML(w, data)
2016-07-26 01:39:55 +02:00
case "csv":
err = reportCSV(w, data)
2018-01-27 06:19:38 +02:00
case "junit-xml":
err = reportJUnitXML(w, data)
2016-10-18 07:36:35 +02:00
case "html":
err = reportFromHTMLTemplate(w, html, data)
2016-07-20 12:02:01 +02:00
case "text":
2016-10-18 07:36:35 +02:00
err = reportFromPlaintextTemplate(w, text, data)
2019-03-11 22:13:48 +02:00
case "sonarqube":
err = reportSonarqube(rootPath, w, data)
2016-07-20 12:02:01 +02:00
default:
2016-10-18 07:36:35 +02:00
err = reportFromPlaintextTemplate(w, text, data)
2016-07-26 01:39:55 +02:00
}
return err
}
2019-03-11 22:13:48 +02:00
func reportSonarqube(rootPath string, w io.Writer, data *reportInfo) error {
var sonarIssues []sonarIssue
for _, issue := range data.Issues {
lines := strings.Split(issue.Line, "-")
startLine, _ := strconv.Atoi(lines[0])
endLine := startLine
if len(lines) > 1 {
endLine, _ = strconv.Atoi(lines[1])
}
s := sonarIssue{
2019-03-11 22:16:30 +02:00
EngineID: "gosec",
RuleID: issue.RuleID,
2019-03-11 22:13:48 +02:00
PrimaryLocation: location{
Message: issue.What,
FilePath: strings.Replace(issue.File, rootPath+"/", "", 1),
TextRange: textRange{StartLine: startLine, EndLine: endLine},
},
Type: "VULNERABILITY",
Severity: getSonarSeverity(issue.Severity.String()),
EffortMinutes: 5,
}
sonarIssues = append(sonarIssues, s)
}
raw, err := json.MarshalIndent(sonarIssues, "", "\t")
if err != nil {
panic(err)
}
_, err = w.Write(raw)
if err != nil {
panic(err)
}
return err
}
2017-04-26 02:57:12 +02:00
func reportJSON(w io.Writer, data *reportInfo) error {
2016-07-26 01:39:55 +02:00
raw, err := json.MarshalIndent(data, "", "\t")
if err != nil {
panic(err)
2016-07-20 12:02:01 +02:00
}
2016-07-26 01:39:55 +02:00
_, err = w.Write(raw)
if err != nil {
panic(err)
}
return err
}
func reportYAML(w io.Writer, data *reportInfo) error {
raw, err := yaml.Marshal(data)
if err != nil {
return err
}
_, err = w.Write(raw)
return err
}
2017-04-26 02:57:12 +02:00
func reportCSV(w io.Writer, data *reportInfo) error {
out := csv.NewWriter(w)
defer out.Flush()
for _, issue := range data.Issues {
err := out.Write([]string{
issue.File,
2017-10-01 02:31:39 +02:00
issue.Line,
issue.What,
issue.Severity.String(),
issue.Confidence.String(),
issue.Code,
})
if err != nil {
return err
}
}
return nil
}
2018-01-27 06:19:38 +02:00
func reportJUnitXML(w io.Writer, data *reportInfo) error {
2018-01-27 06:14:35 +02:00
groupedData := groupDataByRules(data)
junitXMLStruct := createJUnitXMLStruct(groupedData)
2018-01-26 05:16:49 +02:00
raw, err := xml.MarshalIndent(junitXMLStruct, "", "\t")
2018-01-26 05:16:49 +02:00
if err != nil {
2018-01-30 03:54:30 +02:00
return err
2018-01-26 05:16:49 +02:00
}
2018-01-27 06:14:35 +02:00
xmlHeader := []byte("<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n")
raw = append(xmlHeader, raw...)
2018-01-26 05:16:49 +02:00
_, err = w.Write(raw)
if err != nil {
2018-01-30 03:54:30 +02:00
return err
2018-01-26 05:16:49 +02:00
}
2018-01-30 03:54:30 +02:00
return nil
2018-01-26 05:16:49 +02:00
}
2017-04-26 02:57:12 +02:00
func reportFromPlaintextTemplate(w io.Writer, reportTemplate string, data *reportInfo) error {
t, e := plainTemplate.New("gosec").Parse(reportTemplate)
2016-10-18 07:36:35 +02:00
if e != nil {
return e
}
return t.Execute(w, data)
}
2017-04-26 02:57:12 +02:00
func reportFromHTMLTemplate(w io.Writer, reportTemplate string, data *reportInfo) error {
t, e := htmlTemplate.New("gosec").Parse(reportTemplate)
2016-07-20 12:02:01 +02:00
if e != nil {
return e
}
return t.Execute(w, data)
}