UNPKG

auditjs

Version:

Audit dependencies to identify known vulnerabilities and maintenance problems

63 lines 2.81 kB
"use strict"; /* * Copyright 2019-Present Sonatype Inc. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. * You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ var __importDefault = (this && this.__importDefault) || function (mod) { return (mod && mod.__esModule) ? mod : { "default": mod }; }; Object.defineProperty(exports, "__esModule", { value: true }); exports.filterVulnerabilities = void 0; const fs_1 = require("fs"); const path_1 = __importDefault(require("path")); const OssIndexServerResult_1 = require("../Types/OssIndexServerResult"); const whitelistFilePathPwd = path_1.default.join(process.cwd(), 'auditjs.json'); const filterVulnerabilities = async (results, whitelistFilePath = whitelistFilePathPwd) => { const resolved = path_1.default.resolve(whitelistFilePath); try { const stat = (0, fs_1.statSync)(resolved); if (!stat.isFile()) { throw new Error(`Allowlist path is not a regular file: ${resolved}`); } } catch (e) { if (!(e instanceof Error && 'code' in e && e.code === 'ENOENT')) { throw e; } // File doesn't exist — return original results (same as before) return results; } try { const json = (0, fs_1.readFileSync)(resolved, { flag: 'r+' }); const whitelist = JSON.parse(json.toString()); const whiteListSet = new Set(whitelist.ignore.map((exclusion) => exclusion.id)); const newResults = results.map((result) => { if (result.vulnerabilities && result.vulnerabilities.length) { const vulns = result.vulnerabilities.filter((vuln) => !whiteListSet.has(vuln.id)); return new OssIndexServerResult_1.OssIndexServerResult({ ...result, vulnerabilities: vulns, }); } return result; }); return newResults; } catch (e) { const err = e instanceof Error ? e : new Error(String(e)); throw new Error(`There was an issue excluding vulnerabilities likely based on your whitelist, please check ${whitelistFilePath}, to ensure it is valid JSON, and review stack trace for more information, stack trace: ${err.stack}`); } }; exports.filterVulnerabilities = filterVulnerabilities; //# sourceMappingURL=VulnerabilityExcluder.js.map