THINK FIRST·CODE LATER

← All labs

SBOM vulnerability scanner

Problem

Scan StudyBuddy's software bill of materials against security advisories.

Input:

SBOM
<lines: component version>
ADVISORIES
<lines: id component introduced fixed severity>

Versions are dotted numbers such as 2.14.1 (compare them part by part numerically; missing parts count as 0, so 2.15 = 2.15.0). A component version is affected by an advisory if introduced <= version < fixed. Severity is CRITICAL, HIGH, MEDIUM or LOW.

Output: for each SBOM line (in order) either component version: OK or component version: VULNERABLE followed by one line per matching advisory (in advisory order): id SEVERITY -> upgrade to >= fixed. Then:

Findings: n (critical c, high h, medium m, low l)
Build: FAIL|PASS

The build fails if there is at least one CRITICAL or HIGH finding.

Input:

SBOM
log4j-core 2.14.1
gson 2.10.1
commons-text 1.9
ADVISORIES
CVE-2021-44228 log4j-core 2.0 2.15.0 CRITICAL
CVE-2021-45046 log4j-core 2.0 2.16.0 CRITICAL
CVE-2022-42889 commons-text 1.5 1.10.0 CRITICAL
CVE-2022-25647 gson 0.0 2.8.9 HIGH

Output:

log4j-core 2.14.1: VULNERABLE
  CVE-2021-44228 CRITICAL -> upgrade to >= 2.15.0
  CVE-2021-45046 CRITICAL -> upgrade to >= 2.16.0
gson 2.10.1: OK
commons-text 1.9: VULNERABLE
  CVE-2022-42889 CRITICAL -> upgrade to >= 1.10.0
Findings: 3 (critical 3, high 0, medium 0, low 0)
Build: FAIL

Write it here or in your IDE, then paste it. Compile and test it yourself before comparing. Your code stays in your browser — it is never sent to or stored on the server.