Commit a8d909f
Sync v1.4.1 to 1.x (#143)
* replace scanner example (#84)
* Write CSV with no vulns (#86)
* reproducing issue - test 1
* resolve issue 85 - test 2
* test 3
* test fix
---------
Co-authored-by: Michael Long <[email protected]>
* testing CSV with no vulns
* test against main branch
* Write Dockerfile CSV and Markdown on no vulns (#88)
Co-authored-by: Michael Long <[email protected]>
* Set example workflows to main branch for testing
* Display 'no vulns found' for Dockerfiles (#92)
Co-authored-by: Michael Long <[email protected]>
* Tweak dockerfile report (#93)
Co-authored-by: Michael Long <[email protected]>
* Omit Dockerfile table on no vulns (#94)
Co-authored-by: Michael Long <[email protected]>
* Updated workflows to v1.x - testing auto-updates (#96)
Co-authored-by: Michael Long <[email protected]>
* update README (#97)
Co-authored-by: Michael Long <[email protected]>
* Extend vulnerability severity providers (#98)
* Add severity providers: GHSA, GitLab
* Add severity providers: GHSA, GitLab
* Add REDHAT_CVE and UBUNTU_CVE providers
* rename GHSA to GITHUB
---------
Co-authored-by: Michael Long <[email protected]>
* Add platform argument for container image scans (#102)
* add --platform support for multi-arch containers
* test multi-arch images on current branch
* test actions against sbomgen 1.5.1-beta
* fix --platform parsing error
* fix platform parsing bug
* test workflows on sbomgen latest (1.5.2)
* Validate --platform input
* Add more test cases, and revert workflow definitions
* fix typo in platform arg
---------
Co-authored-by: Michael Long <[email protected]>
* Improve severity rating consistency (#112)
* fix severity rating mismatch
* temporarily add a test workflow
* Fix type issue: float provided, expected string
* Rename workflow / job name
* Add severity comparison logic
* Revise severity sorting and selection logic
* return default values on error
* skip EPSS ratings for severity column
* debugging unknown ratings
* fix ratings with unknown name
* Verify AMAZON_INSPECTOR renders correctly
* fix failing test
* temporarily disable failing tests
* pass unit test: test_parse_inspector_scan_result
* pass unit tests
* change '-f' to '--failfast' for clarity
* Remove unused type cast
* refactor csv test
* severity is rendered as 'other' not 'unknown'
* test build on all actions
* normalize dockerfile findings severity rating
* debugging dockerfile severity
* debugging
* Normalize Dockerfile severity 'info' to 'other'
* restore test actions
* minor comment update
* Remove develop workflow
* Address PR feedback
* test workflows against refactor
* handle edge case CVE-2025-22871
* fix missing severity edge case
* debugging epss
* debugging
* fix flawed test
* added test case for absent severity rating
* revert workflows to v1
---------
Co-authored-by: Michael Long <[email protected]>
* v1.3.0 (#123)
* Feature request 91 (#115)
* FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts
* Revert "FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts"
This reverts commit bc532d4.
* FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts
* FR-91: Fix unit tests
* FR-91: Fix typo in unit tests
* Revert "FR-91: Fix typo in unit tests"
This reverts commit e645542.
* Revert "FR-91: Fix unit tests"
This reverts commit f9157c9.
* Revert "FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts"
This reverts commit 812c685.
* FR-91: Change orchestrator to only find fixed vulnerabilities if flag show-only-fixed-vulnerabilities is present
* FR-91: Fixed missing variable
* FR-91: Fixed typo
* FR-91: Fixed typo
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* Add unit test for get_vuln_count
* Fix unit test for get_vuln_count
---------
Co-authored-by: Maria Carolina Conceição <[email protected]>
* Clarify license of inspector-sbomgen dependency (#121)
Co-authored-by: Michael Long <[email protected]>
* [v1.3.0] Only trigger vuln threshold on fixable vulns (#122)
* Add --threshold-fixable-only to CLI
* implemented business logic
* changed 'threshold_fixable_only' from str to bool
* Added more test coverage and CLI refinements
* debugging failing unit test
* test threshold-fixable-only in workflow
* test threshold-fixable-only in workflow
* debugging CI/CD
* debugging CI/CD
* debugging
* debugging
* debugging
* debugging
* removed debug log showing CLI arguments
* add missing argument, fixed_vuln_counts
* simplify get_fixed_vuln_counts() return values
* refactor return types in get_scan_result()
* refactor
* refine get_fixed_vuln_counts()
* update test_get_fixed_vuln_counts()
* testing case sensitivity
* revert 'TRUE' to 'true'
* use debug log when vuln doesnt have rating
* integrate --show-only-fixable-vulns (part 1)
* integrate only show fixable vulns
* test example workflows
* fix CLI input arguments
* remove leading '-' character for conditional inclusion
* add a no-op CLI arg (workaround)
* enable new arguments in workflows
* fix failing test
* update workflows for prod
---------
Co-authored-by: Michael Long <[email protected]>
* set workflows to v1.3.0 for burn-in
---------
Co-authored-by: CarolMebiom <[email protected]>
Co-authored-by: Maria Carolina Conceição <[email protected]>
Co-authored-by: Michael Long <[email protected]>
* Sync main to v1.3.0 (#126)
* Feature request 91 (#115)
* FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts
* Revert "FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts"
This reverts commit bc532d4.
* FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts
* FR-91: Fix unit tests
* FR-91: Fix typo in unit tests
* Revert "FR-91: Fix typo in unit tests"
This reverts commit e645542.
* Revert "FR-91: Fix unit tests"
This reverts commit f9157c9.
* Revert "FR-91: Add cli arg only fixable vulnerability; use the variable in get_vuln_counts"
This reverts commit 812c685.
* FR-91: Change orchestrator to only find fixed vulnerabilities if flag show-only-fixed-vulnerabilities is present
* FR-91: Fixed missing variable
* FR-91: Fixed typo
* FR-91: Fixed typo
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* FR-91: Another fix
* Add unit test for get_vuln_count
* Fix unit test for get_vuln_count
---------
Co-authored-by: Maria Carolina Conceição <[email protected]>
* Clarify license of inspector-sbomgen dependency (#121)
Co-authored-by: Michael Long <[email protected]>
* [v1.3.0] Only trigger vuln threshold on fixable vulns (#122)
* Add --threshold-fixable-only to CLI
* implemented business logic
* changed 'threshold_fixable_only' from str to bool
* Added more test coverage and CLI refinements
* debugging failing unit test
* test threshold-fixable-only in workflow
* test threshold-fixable-only in workflow
* debugging CI/CD
* debugging CI/CD
* debugging
* debugging
* debugging
* debugging
* removed debug log showing CLI arguments
* add missing argument, fixed_vuln_counts
* simplify get_fixed_vuln_counts() return values
* refactor return types in get_scan_result()
* refactor
* refine get_fixed_vuln_counts()
* update test_get_fixed_vuln_counts()
* testing case sensitivity
* revert 'TRUE' to 'true'
* use debug log when vuln doesnt have rating
* integrate --show-only-fixable-vulns (part 1)
* integrate only show fixable vulns
* test example workflows
* fix CLI input arguments
* remove leading '-' character for conditional inclusion
* add a no-op CLI arg (workaround)
* enable new arguments in workflows
* fix failing test
* update workflows for prod
---------
Co-authored-by: Michael Long <[email protected]>
* set workflows to v1.3.0 for burn-in
---------
Co-authored-by: CarolMebiom <[email protected]>
Co-authored-by: Maria Carolina Conceição <[email protected]>
Co-authored-by: Michael Long <[email protected]>
* Verify v1 tag works
* Verify action against 1.x
* v1.4.0 (#133)
* Use aws-cli instead of amazonlinux to speed up container build time (#128)
* Change Dockerfile source image to aws-cli
* Set WORKDIR back to default value
---------
Co-authored-by: Joshua-Grisham_SSCSpace <[email protected]>
* set workflows to develop for aws-cli runtime tests
* add explicit permissions to GitHub Actions workflows (#130)
* Measuring installation time (#131) (#132)
* measuring installation time
* Change workflows to point to v1.4.0 branch
---------
Co-authored-by: Joshua Grisham <[email protected]>
Co-authored-by: Joshua-Grisham_SSCSpace <[email protected]>
* (v1.4.1 hotfix) Fix multi-arch container image scanning (#138)
* added multi-arch image workflow
* disable scan validator
* debugging multi arch CICD
* added 'platform' argument to action.yml
* set action version to investigation branch
* test amd64 images
* test multi-arch matrix
* verify workaround
* Add multi-platform validation to prevent regression of platform argument
- Add validate_multi_platform_image_support.py script to validate SBOM architecture matches expected platform
- Update test_multi_arch_images.yml workflow to validate platform argument is correctly passed through to inspector-sbomgen
* re-enable inspector scan validation
* remove inspector-scan validator, not applicable
* remove boilerplate
* test action against multi-arch fix
* revert test workflows to v1.4.0
* remove emoji characters from console logs
* update workflows to v1.4.1 (#139)
* update multi arch test to v1.4.1 (#140)
* update version.txt to v1.4.1
---------
Co-authored-by: clueleaf <[email protected]>
Co-authored-by: Michael Long <[email protected]>
Co-authored-by: CarolMebiom <[email protected]>
Co-authored-by: Maria Carolina Conceição <[email protected]>
Co-authored-by: Joshua Grisham <[email protected]>
Co-authored-by: Joshua-Grisham_SSCSpace <[email protected]>1 parent 4239046 commit a8d909f
File tree
16 files changed
+151
-13
lines changed- .github/workflows
- validator
16 files changed
+151
-13
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
55 | | - | |
| 55 | + | |
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
36 | | - | |
| 36 | + | |
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
51 | | - | |
| 51 | + | |
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
39 | | - | |
| 39 | + | |
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
| 35 | + | |
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
35 | | - | |
| 35 | + | |
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
| |||
0 commit comments