semgrep-s3-scanner
Version:
Run semgrep scans using rules stored in S3
95 lines (94 loc) • 4.42 kB
JavaScript
var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
var desc = Object.getOwnPropertyDescriptor(m, k);
if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
desc = { enumerable: true, get: function() { return m[k]; } };
}
Object.defineProperty(o, k2, desc);
}) : (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
o[k2] = m[k];
}));
var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
Object.defineProperty(o, "default", { enumerable: true, value: v });
}) : function(o, v) {
o["default"] = v;
});
var __importStar = (this && this.__importStar) || (function () {
var ownKeys = function(o) {
ownKeys = Object.getOwnPropertyNames || function (o) {
var ar = [];
for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
return ar;
};
return ownKeys(o);
};
return function (mod) {
if (mod && mod.__esModule) return mod;
var result = {};
if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
__setModuleDefault(result, mod);
return result;
};
})();
var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {
function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
return new (P || (P = Promise))(function (resolve, reject) {
function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
step((generator = generator.apply(thisArg, _arguments || [])).next());
});
};
Object.defineProperty(exports, "__esModule", { value: true });
const commander_1 = require("commander");
const s3_service_1 = require("../services/s3.service");
const child_process_1 = require("child_process");
const util_1 = require("util");
const path = __importStar(require("path"));
const fs = __importStar(require("fs"));
const execAsync = (0, util_1.promisify)(child_process_1.exec);
const program = new commander_1.Command();
program
.name('semgrep-s3-scanner')
.description('Run semgrep scans using rules from S3')
.version('1.0.0');
program
.command('scan')
.description('Run semgrep scan with rules from S3')
.option('-b, --bucket <bucket>', 'S3 bucket name', 'semgrep-rules')
.option('-p, --prefix <prefix>', 'Rules prefix in S3', 'rules/')
.option('-t, --target <target>', 'Target directory or file to scan', '.')
.option('-o, --output <output>', 'Output file for the report', 'semgrep-report.json')
.option('-f, --format <format>', 'Output format (json, sarif)', 'json')
.action((options) => __awaiter(void 0, void 0, void 0, function* () {
try {
console.log('Initializing S3 scanner...');
const s3 = new s3_service_1.S3Service(options.bucket, options.prefix);
console.log('Downloading rules from S3...');
const rulesDir = path.join(process.cwd(), '.semgrep-rules');
yield s3.downloadAllRules(rulesDir);
console.log('Running semgrep scan...');
const formatFlag = options.format === 'sarif' ? '--sarif' : '--json';
const cmd = `semgrep scan --config ${rulesDir} ${options.target} ${formatFlag} > ${options.output}`;
yield execAsync(cmd);
console.log(`Scan completed! Report saved to ${options.output}`);
// Generate markdown report
console.log('Generating markdown report...');
const reportScript = path.join(__dirname, '../../scripts/report.js');
console.log('Report script path:', reportScript);
yield execAsync(`node ${reportScript} ${options.output}`);
console.log('Markdown report generated!');
// Cleanup
if (fs.existsSync(rulesDir)) {
fs.rmSync(rulesDir, { recursive: true, force: true });
}
}
catch (error) {
console.error('Error:', error);
process.exit(1);
}
}));
program.parse();
;