Class: ShieldAst::SAST
- Inherits:
-
Object
- Object
- ShieldAst::SAST
- Defined in:
- lib/shield_ast/sast.rb
Overview
Wraps the logic for running SAST scan using Opengrep.
Constant Summary collapse
- EXCLUDE_PATTERNS =
%w[**/spec/ **/test/ **/tests/ **/features/ **/__tests__/ **/vendor/ **/node_modules/ **/*_spec.rb **/*_test.rb **/*.spec.js **/*.test.js **/*.spec.ts **/*.test.ts **/*_test.py **/test_*.py **/*_test.go].freeze
Class Method Summary collapse
Class Method Details
.build_command(path) ⇒ Object
29 30 31 32 33 34 35 36 37 38 39 |
# File 'lib/shield_ast/sast.rb', line 29 def self.build_command(path) base_cmd = %w[opengrep scan --config p/r2c-ci --config p/secrets --json --disable-version-check] EXCLUDE_PATTERNS.each do |pattern| base_cmd.push("--exclude", pattern) end base_cmd.push(path) base_cmd end |
.scan(path) ⇒ Object
14 15 16 17 18 19 20 21 22 23 24 25 26 27 |
# File 'lib/shield_ast/sast.rb', line 14 def self.scan(path) cmd = build_command(path) stdout, stderr, status = Open3.capture3(*cmd) if status.success? JSON.parse(stdout) else warn "Opengrep SAST scan failed! Exit Code: #{status.exitstatus}\nError: #{stderr}" { "results" => [] } end rescue JSON::ParserError => e warn "Failed to parse Opengrep SAST output: #{e.message}" { "results" => [] } end |