Skip to content

Commit 4389a69

Browse files
Merge branch 'main' into improved-sbom-filename-extension-handling
2 parents e84e40f + 13004de commit 4389a69

22 files changed

Lines changed: 173 additions & 74 deletions

‎.github/workflows/codeql-analysis.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ jobs:
5151

5252
# Initializes the CodeQL tools for scanning.
5353
- name: Initialize CodeQL
54-
uses: github/codeql-action/init@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
54+
uses: github/codeql-action/init@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11
5555
with:
5656
languages: ${{ matrix.language }}
5757
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -76,4 +76,4 @@ jobs:
7676
# make release
7777

7878
- name: Perform CodeQL Analysis
79-
uses: github/codeql-action/analyze@b56ba49b26e50535fa1e7f7db0f4f7b4bf65d80d # v3.28.10
79+
uses: github/codeql-action/analyze@6bb031afdd8eb862ea3fc1848194185e076637e5 # v3.28.11

‎.github/workflows/formatting.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ jobs:
3636
run: |
3737
python cve_bin_tool/format_checkers.py
3838
- name: Create Pull Request
39-
uses: peter-evans/create-pull-request@dd2324fc52d5d43c699a5636bcf19fceaa70c284 # v7.0.7
39+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
4040
with:
4141
commit-message: "chore: update checkers table"
4242
title: "chore: update checkers table"

‎.github/workflows/sbom.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ jobs:
6262
cp cve-bin-tool-py${{ matrix.python }}.json sbom/cve-bin-tool-py${{ matrix.python }}.json
6363
- name: Create Pull Request
6464
if: ${{ steps.diff-sbom.outputs.changed }}
65-
uses: peter-evans/create-pull-request@dd2324fc52d5d43c699a5636bcf19fceaa70c284 # v7.0.7
65+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
6666
with:
6767
commit-message: "chore: update SBOM for Python ${{ matrix.python }}"
6868
title: "chore: update SBOM for Python ${{ matrix.python }}"

‎.github/workflows/scorecard.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
persist-credentials: false
2828

2929
- name: "Run analysis"
30-
uses: ossf/scorecard-action@62b2cac7ed8198b15735ed49ab1e5cf35480ba46 # v2.4.0
30+
uses: ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1
3131
with:
3232
results_file: results.sarif
3333
results_format: sarif

‎.github/workflows/update-js-dependencies.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ jobs:
5454
run: python -m pytest -v -n auto test/test_html.py
5555

5656
- name: Create Pull Request
57-
uses: peter-evans/create-pull-request@dd2324fc52d5d43c699a5636bcf19fceaa70c284 # v7.0.7
57+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
5858
with:
5959
commit-message: "chore: update js dependencies"
6060
title: "chore: update js dependencies"

‎.github/workflows/update-pre-commit.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ jobs:
4848
python .github/workflows/update-dev-requirements.py
4949
5050
- name: Create Pull Request
51-
uses: peter-evans/create-pull-request@dd2324fc52d5d43c699a5636bcf19fceaa70c284 # v7.0.7
51+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
5252
with:
5353
commit-message: "chore: update pre-commit config"
5454
title: "chore: update pre-commit config"

‎.github/workflows/update-spdx-header.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
sed -i "s/[0-9]\{4\}/$(date +%Y)/" spdx_header.txt
3434
3535
- name: Create Pull Request
36-
uses: peter-evans/create-pull-request@dd2324fc52d5d43c699a5636bcf19fceaa70c284 # v7.0.7
36+
uses: peter-evans/create-pull-request@271a8d0340265f705b14b6d32b9829c1cb33d45e # v7.0.8
3737
with:
3838
commit-message: 'chore: update spdx header'
3939
title: 'chore: update spdx header'

‎README.md‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@ If you want to try the latest code from
7575

7676
Pip will install the python requirements for you, but for some types of extraction we use system libraries. If you have difficulties extracting files, you may want to look at our [additional Requirements lists for Linux and Windows](#additional-requirements).
7777

78-
On first usage (and by default, once per day) The tool will download vulnerability data from [a set of known vulnerability data sources](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#data-sources). Due to reliability issues with NVD, as of release 3.3 we will be using our own NVD mirror at [https://cveb.in/](https://cveb.in/) by default rather than contacting NVD directly. If you wish to get data directly from the NVD servers you must [provide your own NVD_API_KEY](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#--nvd-api-key-nvd_api_key) to use their API.
78+
On first usage (and by default, once per day), the tool will download vulnerability data from [a set of known vulnerability data sources](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#data-sources). Due to reliability issues with NVD, as of release 3.3, we will be using our own NVD mirror at [https://cveb.in/](https://cveb.in/) by default rather than contacting NVD directly. If you wish to get data directly from the NVD servers, you must [provide your own NVD_API_KEY](https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#--nvd-api-key-nvd_api_key) to use their API.
7979

8080
If you are using a release prior to 3.3 that does not use our mirror, please use an NVD_API_KEY as described above.
8181

@@ -123,7 +123,7 @@ The [SBOM generation how-to guide](https://github.com/intel/cve-bin-tool/blob/ma
123123

124124
### Generating a VEX
125125

126-
As well as scanning VEX, CVE Binary Tool can be used to generate an VEX from a scan as follows:
126+
As well as scanning VEX, CVE Binary Tool can be used to generate a VEX from a scan as follows:
127127

128128
```bash
129129
cve-bin-tool --vex-type <vex_type> --vex-output <vex_filename> <other scan options as required>
@@ -137,7 +137,7 @@ The [VEX generation how-to guide](https://github.com/intel/cve-bin-tool/blob/mai
137137
### Triaging vulnerabilities
138138

139139
The `--vex-file` option can be used to add extra triage data like remarks, comments etc. while scanning a directory so that output will reflect this triage data and you can save time of re-triaging (Usage: `cve-bin-tool --vex-file test.json /path/to/scan`).
140-
The supported format is the [CycloneDX](https://cyclonedx.org/capabilities/vex/),[CSAF](https://oasis-open.github.io/csaf-documentation/) and [OpenVEX](https://edu.chainguard.dev/open-source/sbom/what-is-openvex/) VEX format which can be generated using the `--vex-output` option.
140+
The supported formats are the [CycloneDX](https://cyclonedx.org/capabilities/vex/), [CSAF](https://oasis-open.github.io/csaf-documentation/) and [OpenVEX](https://edu.chainguard.dev/open-source/sbom/what-is-openvex/) VEX formats which can be generated using the `--vex-output` option.
141141

142142
Typical usage:
143143

@@ -385,7 +385,7 @@ The tool does not guarantee that any vulnerabilities reported are actually prese
385385

386386
Users can add triage information to reports to mark issues as false positives, indicate that the risk has been mitigated by configuration/usage changes, and so on.
387387

388-
Triage details can be re-used on other projects so, for example, triage on a Linux base image could be applied to multiple containers using that image.
388+
Triage details can be reused on other projects so, for example, triage on a Linux base image could be applied to multiple containers using that image.
389389

390390
For more information and usage of triage information with the tool kindly have a look [here](https://cve-bin-tool.readthedocs.io/en/latest/triaging_process.html).
391391

@@ -508,6 +508,7 @@ Output:
508508
specify type of software bill of materials (sbom) to generate (default: spdx)
509509
<a href="https://github.com/intel/cve-bin-tool/blob/main/doc/MANUAL.md#--sbom-format">--sbom-format {tag,json,yaml}</a>
510510
specify format of software bill of materials (sbom) to generate (default: tag)
511+
--strip-scan-dir strip scan directory from sbom evidence location paths and CVE paths (useful with a firmware dump)
511512

512513
Vex Output:
513514
Arguments related to Vex output document.

‎cve_bin_tool/checkers/README.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ from cve_bin_tool.checkers import Checker
3535
class CurlChecker(Checker):
3636
```
3737

38-
Every checker may contain following 5 class attributes specific to product(ex: curl)
38+
Every checker may contain following 5 class attributes specific to product (ex: curl)
3939
you are making checker for:
4040

4141
1. CONTAINS_PATTERNS - list of commonly found strings in the binary of the product
@@ -45,7 +45,7 @@ you are making checker for:
4545
NVD.
4646
5. IGNORE_PATTERNS (optional) - list of patterns that could cause false positives (e.g. error messages that mention specific product/versions)
4747

48-
`CONTAINS_PATTERN`, `FILENAME_PATTERNS` and `VERSION_PATTERNS` supports regex to cover
48+
`CONTAINS_PATTERN`, `FILENAME_PATTERNS`, `VERSION_PATTERNS` and `IGNORE_PATTERNS` supports regex to cover
4949
wide range of use cases.
5050

5151
Once the checker is added, its name should also be added to `__init__.py` (so

‎cve_bin_tool/cli.py‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -348,9 +348,9 @@ def main(argv=None):
348348
help="specify format of software bill of materials (sbom) to generate (default: tag)",
349349
)
350350
output_group.add_argument(
351-
"--sbom-strip-root",
351+
"--strip-scan-dir",
352352
action="store_true",
353-
help="strip SBOM root from evidence location paths (useful when building SBOM from firmware dump)",
353+
help="strip scan directory from sbom evidence location paths and CVE paths (useful with a firmware dump)",
354354
default=False,
355355
)
356356
vex_output_group = parser.add_argument_group(
@@ -1250,7 +1250,7 @@ def main(argv=None):
12501250
sbom_type=args["sbom_type"],
12511251
sbom_format=args["sbom_format"],
12521252
sbom_root=sbom_root,
1253-
sbom_strip_root=args["sbom_strip_root"],
1253+
strip_scan_dir=args["strip_scan_dir"],
12541254
offline=args["offline"],
12551255
)
12561256

0 commit comments

Comments
 (0)