Class: ShieldAst::IaC

Inherits:
Object
  • Object
show all
Defined in:
lib/shield_ast/iac.rb

Overview

Wraps the logic for running Infrastructure as Code (IaC) scans using Opengrep.

Class Method Summary collapse

Class Method Details

.scan(path) ⇒ Object



9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# File 'lib/shield_ast/iac.rb', line 9

def self.scan(path)
  cmd = [
    "opengrep", "scan",
    "--config", "r/terraform",
    "--config", "r/kubernetes",
    "--config", "r/docker",
    "--config", "r/yaml",
    "--json", "--quiet",
    path
  ]

  stdout, _stderr, status = Open3.capture3(*cmd)

  if status.success? && !stdout.strip.empty?
    begin
      report = JSON.parse(stdout)
      return { "results" => report["results"] || [] }
    rescue JSON::ParserError
      return { "results" => [] }
    end
  end

  { "results" => [] }
end