Class: Bundler::Audit::CLI

Inherits:
Thor
  • Object
show all
Defined in:
lib/bundler/audit/cli.rb

Constant Summary collapse

CRITICALITY_MAP =
{
  :low    => ["Low"],
  :medium => ["Medium", :yellow],
  :high   => ["High", [:red, :bold]],
}

Instance Method Summary collapse

Instance Method Details

#checkObject



38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
# File 'lib/bundler/audit/cli.rb', line 38

def check
  begin
    scanner  = Scanner.new
  rescue ArgumentError
    print_setup_instructions
    exit 1
  end
  vulnerable = false

  # attempt update the database before doing a scan
  scanner.database.update!

  scanner.scan(:ignore => options.ignore) do |result|
    vulnerable = true

    case result
    when Scanner::InsecureSource
      print_warning "Insecure Source URI found: #{result.source}"
    when Scanner::UnpatchedGem
      print_advisory result.gem, result.advisory
    end
  end

  if vulnerable
    say "Unpatched versions found!", :red
    exit 1
  else
    say "No unpatched versions found", :green
  end
end


106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
# File 'lib/bundler/audit/cli.rb', line 106

def print_advisory(gem, advisory)
  print_affected_gem(gem)

  say "Advisory: ", :red
  say advisory.id

  say "Criticality: ", :red
  say *(CRITICALITY_MAP[advisory.criticality] || "Unknown")

  say "URL: ", :red
  say advisory.url

  print_advisory_details advisory
  print_advisory_solution advisory

  say
end


143
144
145
146
147
148
149
150
151
152
153
154
# File 'lib/bundler/audit/cli.rb', line 143

def print_advisory_details(advisory)
  if options.verbose?
    say "Description:", :red
    say

    print_wrapped advisory.description, :indent => 2
    say
  else
    say "Title: ", :red
    say advisory.title
  end
end


156
157
158
159
160
161
162
163
164
# File 'lib/bundler/audit/cli.rb', line 156

def print_advisory_solution(advisory)
  unless advisory.patched_versions.empty?
    say "Solution: upgrade to ", :red
    say advisory.patched_versions.join(', ')
  else
    say "Solution: ", :red
    say "remove or disable this gem until a patch is available!", [:red, :bold]
  end
end


135
136
137
138
139
140
141
# File 'lib/bundler/audit/cli.rb', line 135

def print_affected_gem(gem)
  say "Name: ", :red
  say gem.name

  say "Version: ", :red
  say gem.version
end


126
127
128
129
130
131
132
133
# File 'lib/bundler/audit/cli.rb', line 126

def print_setup_instructions
  say ""
  print_warning "You don't have a copy of the Ruby vulnerabilities database yet."
  print_warning "To get the database, please run:"
  say ""
  print_warning "  #{$0} update"
  say ""
end


102
103
104
# File 'lib/bundler/audit/cli.rb', line 102

def print_warning(message)
  say message, :yellow
end

#say(message = "", color = nil) ⇒ Object (protected)



97
98
99
100
# File 'lib/bundler/audit/cli.rb', line 97

def say(message="", color=nil)
  color = nil unless $stdout.tty?
  super(message.to_s, color)
end

#updateObject



70
71
72
73
74
75
# File 'lib/bundler/audit/cli.rb', line 70

def update
  say "Updating ruby-advisory-db ..."

  Database.update!
  puts "ruby-advisory-db: #{Database.new.size} advisories"
end

#versionObject



78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
# File 'lib/bundler/audit/cli.rb', line 78

def version
  cmd = File.basename($0)
  advisories = nil
  begin
    database = Database.new
    advisories = " (advisories: #{database.size})"
  rescue ArgumentError
    # Don't have a database yet.
  end

  say "#{cmd} #{VERSION}#{advisories}", :bold
  if advisories.nil?
    print_setup_instructions
    exit 1
  end
end