UNPKG

semgrep-s3-scanner

Version:

Run semgrep scans using rules stored in S3

95 lines (94 loc) 4.42 kB
#!/usr/bin/env node "use strict"; var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) { if (k2 === undefined) k2 = k; var desc = Object.getOwnPropertyDescriptor(m, k); if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) { desc = { enumerable: true, get: function() { return m[k]; } }; } Object.defineProperty(o, k2, desc); }) : (function(o, m, k, k2) { if (k2 === undefined) k2 = k; o[k2] = m[k]; })); var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) { Object.defineProperty(o, "default", { enumerable: true, value: v }); }) : function(o, v) { o["default"] = v; }); var __importStar = (this && this.__importStar) || (function () { var ownKeys = function(o) { ownKeys = Object.getOwnPropertyNames || function (o) { var ar = []; for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k; return ar; }; return ownKeys(o); }; return function (mod) { if (mod && mod.__esModule) return mod; var result = {}; if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]); __setModuleDefault(result, mod); return result; }; })(); var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) { function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); } return new (P || (P = Promise))(function (resolve, reject) { function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } } function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } } function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); } step((generator = generator.apply(thisArg, _arguments || [])).next()); }); }; Object.defineProperty(exports, "__esModule", { value: true }); const commander_1 = require("commander"); const s3_service_1 = require("../services/s3.service"); const child_process_1 = require("child_process"); const util_1 = require("util"); const path = __importStar(require("path")); const fs = __importStar(require("fs")); const execAsync = (0, util_1.promisify)(child_process_1.exec); const program = new commander_1.Command(); program .name('semgrep-s3-scanner') .description('Run semgrep scans using rules from S3') .version('1.0.0'); program .command('scan') .description('Run semgrep scan with rules from S3') .option('-b, --bucket <bucket>', 'S3 bucket name', 'semgrep-rules') .option('-p, --prefix <prefix>', 'Rules prefix in S3', 'rules/') .option('-t, --target <target>', 'Target directory or file to scan', '.') .option('-o, --output <output>', 'Output file for the report', 'semgrep-report.json') .option('-f, --format <format>', 'Output format (json, sarif)', 'json') .action((options) => __awaiter(void 0, void 0, void 0, function* () { try { console.log('Initializing S3 scanner...'); const s3 = new s3_service_1.S3Service(options.bucket, options.prefix); console.log('Downloading rules from S3...'); const rulesDir = path.join(process.cwd(), '.semgrep-rules'); yield s3.downloadAllRules(rulesDir); console.log('Running semgrep scan...'); const formatFlag = options.format === 'sarif' ? '--sarif' : '--json'; const cmd = `semgrep scan --config ${rulesDir} ${options.target} ${formatFlag} > ${options.output}`; yield execAsync(cmd); console.log(`Scan completed! Report saved to ${options.output}`); // Generate markdown report console.log('Generating markdown report...'); const reportScript = path.join(__dirname, '../../scripts/report.js'); console.log('Report script path:', reportScript); yield execAsync(`node ${reportScript} ${options.output}`); console.log('Markdown report generated!'); // Cleanup if (fs.existsSync(rulesDir)) { fs.rmSync(rulesDir, { recursive: true, force: true }); } } catch (error) { console.error('Error:', error); process.exit(1); } })); program.parse();