Class: Bundler::Audit::CLI

Inherits:
Thor
  • Object
show all
Defined in:
lib/bundler/audit/cli.rb

Constant Summary collapse

CRITICALITY_MAP =
{
  :low    => ["Low"],
  :medium => ["Medium", :yellow],
  :high   => ["High", [:red, :bold]],
}

Instance Method Summary collapse

Instance Method Details

#checkObject



38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
# File 'lib/bundler/audit/cli.rb', line 38

def check
  begin
    scanner  = Scanner.new
  rescue ArgumentError
    print_setup_instructions
    exit 1
  end

  # attempt update the database before doing a scan
  scanner.database.update!

  unpatched_versions = false
  insecure_sources = false
  scanner.scan(:ignore => options.ignore) do |result|

    case result
    when Scanner::InsecureSource
    insecure_sources = true
      print_warning "Insecure Source URI found: #{result.source}"
    when Scanner::UnpatchedGem
      unpatched_versions = true
      print_advisory result.gem, result.advisory
    end
  end

  if unpatched_versions
    say "Unpatched versions found!", :red
  else
    say "No unpatched versions found", :green
  end

  if insecure_sources
    say "Insecure sources found!", :red
  else
    say "No insecure sources found", :green
  end

  if unpatched_versions || insecure_sources
    exit 1
  end
end


117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
# File 'lib/bundler/audit/cli.rb', line 117

def print_advisory(gem, advisory)
  print_affected_gem(gem)

  say "Advisory: ", :red
  say advisory.id

  say "Criticality: ", :red
  say *(CRITICALITY_MAP[advisory.criticality] || "Unknown")

  say "URL: ", :red
  say advisory.url

  print_advisory_details advisory
  print_advisory_solution advisory

  say
end


154
155
156
157
158
159
160
161
162
163
164
165
# File 'lib/bundler/audit/cli.rb', line 154

def print_advisory_details(advisory)
  if options.verbose?
    say "Description:", :red
    say

    print_wrapped advisory.description, :indent => 2
    say
  else
    say "Title: ", :red
    say advisory.title
  end
end


167
168
169
170
171
172
173
174
175
# File 'lib/bundler/audit/cli.rb', line 167

def print_advisory_solution(advisory)
  unless advisory.patched_versions.empty?
    say "Solution: upgrade to ", :red
    say advisory.patched_versions.join(', ')
  else
    say "Solution: ", :red
    say "remove or disable this gem until a patch is available!", [:red, :bold]
  end
end


146
147
148
149
150
151
152
# File 'lib/bundler/audit/cli.rb', line 146

def print_affected_gem(gem)
  say "Name: ", :red
  say gem.name

  say "Version: ", :red
  say gem.version
end


137
138
139
140
141
142
143
144
# File 'lib/bundler/audit/cli.rb', line 137

def print_setup_instructions
  say ""
  print_warning "You don't have a copy of the Ruby vulnerabilities database yet."
  print_warning "To get the database, please run:"
  say ""
  print_warning "  #{$0} update"
  say ""
end


113
114
115
# File 'lib/bundler/audit/cli.rb', line 113

def print_warning(message)
  say message, :yellow
end

#say(message = "", color = nil) ⇒ Object (protected)



108
109
110
111
# File 'lib/bundler/audit/cli.rb', line 108

def say(message="", color=nil)
  color = nil unless $stdout.tty?
  super(message.to_s, color)
end

#updateObject



81
82
83
84
85
86
# File 'lib/bundler/audit/cli.rb', line 81

def update
  say "Updating ruby-advisory-db ..."

  Database.update!
  puts "ruby-advisory-db: #{Database.new.size} advisories"
end

#versionObject



89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
# File 'lib/bundler/audit/cli.rb', line 89

def version
  cmd = File.basename($0)
  advisories = nil
  begin
    database = Database.new
    advisories = " (advisories: #{database.size})"
  rescue ArgumentError
    # Don't have a database yet.
  end

  say "#{cmd} #{VERSION}#{advisories}", :bold
  if advisories.nil?
    print_setup_instructions
    exit 1
  end
end