Scan StudyBuddy's software bill of materials against security advisories.
Input:
SBOM
<lines: component version>
ADVISORIES
<lines: id component introduced fixed severity>
Versions are dotted numbers such as 2.14.1 (compare them part by part numerically; missing parts count as 0, so 2.15 = 2.15.0). A component version is affected by an advisory if introduced <= version < fixed. Severity is CRITICAL, HIGH, MEDIUM or LOW.
Output: for each SBOM line (in order) either component version: OK or component version: VULNERABLE followed by one line per matching advisory (in advisory order): id SEVERITY -> upgrade to >= fixed. Then:
Findings: n (critical c, high h, medium m, low l)
Build: FAIL|PASS
The build fails if there is at least one CRITICAL or HIGH finding.
Input:
SBOM
log4j-core 2.14.1
gson 2.10.1
commons-text 1.9
ADVISORIES
CVE-2021-44228 log4j-core 2.0 2.15.0 CRITICAL
CVE-2021-45046 log4j-core 2.0 2.16.0 CRITICAL
CVE-2022-42889 commons-text 1.5 1.10.0 CRITICAL
CVE-2022-25647 gson 0.0 2.8.9 HIGH
Output:
log4j-core 2.14.1: VULNERABLE
CVE-2021-44228 CRITICAL -> upgrade to >= 2.15.0
CVE-2021-45046 CRITICAL -> upgrade to >= 2.16.0
gson 2.10.1: OK
commons-text 1.9: VULNERABLE
CVE-2022-42889 CRITICAL -> upgrade to >= 1.10.0
Findings: 3 (critical 3, high 0, medium 0, low 0)
Build: FAIL