auditjs
Version:
Audit dependencies to identify known vulnerabilities and maintenance problems
60 lines • 3.03 kB
JavaScript
;
/*
* Copyright 2019-Present Sonatype Inc.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {
function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
return new (P || (P = Promise))(function (resolve, reject) {
function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
step((generator = generator.apply(thisArg, _arguments || [])).next());
});
};
var __importDefault = (this && this.__importDefault) || function (mod) {
return (mod && mod.__esModule) ? mod : { "default": mod };
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.filterVulnerabilities = void 0;
const fs_1 = require("fs");
const path_1 = __importDefault(require("path"));
const OssIndexServerResult_1 = require("../Types/OssIndexServerResult");
const whitelistFilePathPwd = path_1.default.join(process.cwd(), 'auditjs.json');
const filterVulnerabilities = (results, whitelistFilePath = whitelistFilePathPwd) => __awaiter(void 0, void 0, void 0, function* () {
let json;
try {
json = (0, fs_1.readFileSync)(whitelistFilePath, { flag: 'r+' });
}
catch (e) {
return results;
}
try {
const whitelist = JSON.parse(json.toString());
const whiteListSet = new Set(whitelist.ignore.map((exclusion) => exclusion.id));
const newResults = results.map((result) => {
if (result.vulnerabilities && result.vulnerabilities.length) {
const vulns = result.vulnerabilities.filter((vuln) => !whiteListSet.has(vuln.id));
return new OssIndexServerResult_1.OssIndexServerResult(Object.assign(Object.assign({}, result), { vulnerabilities: vulns }));
}
return result;
});
return newResults;
}
catch (e) {
throw new Error(`There was an issue excluding vulnerabilities likely based on your whitelist, please check ${whitelistFilePath}, to ensure it is valid JSON, and review stack trace for more information, stack trace: ${e.stack}`);
}
});
exports.filterVulnerabilities = filterVulnerabilities;
//# sourceMappingURL=VulnerabilityExcluder.js.map