feat(trivy): go mod update trivy v0.17.2 (#1235)

* feat(trivy): go mod update trivy v0.17.2

* wg.Wait

* fix reporting

* fix test case

* add gemfile.lock of redmine to integration test

* fix(test): add Pipfile.lock

* add poetry.lock to integration test

* add composer.lock to integration test

* add integration test case
This commit is contained in:
Kota Kanbe
2021-05-12 18:27:55 +09:00
committed by GitHub
parent 47652ef0fb
commit e553f8b4c5
27 changed files with 22061 additions and 50334 deletions

View File

@@ -40,13 +40,14 @@ func (lss LibraryScanners) Total() (total int) {
// LibraryScanner has libraries information
type LibraryScanner struct {
Type string
Path string
Libs []types.Library
}
// Scan : scan target library
func (s LibraryScanner) Scan() ([]VulnInfo, error) {
scanner, err := library.DriverFactory{}.NewDriver(filepath.Base(string(s.Path)))
scanner, err := library.NewDriver(s.Type)
if err != nil {
return nil, xerrors.Errorf("Failed to new a library driver: %w", err)
}

View File

@@ -386,6 +386,12 @@ func (r *ScanResult) SortForJSONOutput() {
})
r.Packages[k] = v
}
for i, v := range r.LibraryScanners {
sort.SliceStable(v.Libs, func(i, j int) bool {
return v.Libs[i].Name < v.Libs[j].Name
})
r.LibraryScanners[i] = v
}
for k, v := range r.ScannedCves {
sort.SliceStable(v.AffectedPackages, func(i, j int) bool {
@@ -425,7 +431,6 @@ func (r *ScanResult) SortForJSONOutput() {
sort.SliceStable(v.AlertDict.Ja, func(i, j int) bool {
return v.AlertDict.Ja[i].Title < v.AlertDict.Ja[j].Title
})
r.ScannedCves[k] = v
}
}