mirror of
https://github.com/kubescape/kubescape.git
synced 2026-04-15 06:58:11 +00:00
+14








72f9c6d81b
* Fix issue for scanning list obj * Fix go mod in httphandler pkg * Broken links fix in roadmap.md Planning, backlog, and wishlist links were not taking to the required section. * override infoMap only if it's not nil * improved icon of kubescape in readme * Support scanning several files * gramatical improvements * docs(readme): Star → star * Fix issues according to review * Handle with issues caused by updating opa-utils * Fix scanning ListObj following reviews * Update core/pkg/resourcehandler/filesloader.go Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> * Update completion.go * Added fixed control input * update go.mod * Print chart name log when fail to generate * Change formatting to %s * Added resource prioritization information, raw resource will be sent on the result object * Merging typo fixes from master (#772) * greetings * Update aws.sh simplified the comment * typo: In the title and h1 element Their was a typo in index.html file. * punctuation changes * docs : added gitpod badge in readme.md * fixed typos * some grammar mistake is corrected inPULL_REQUEST_TEMPLATE.md file * Updated README.md file Added link to CONTRIBUTING.md file in a line in README. * Added link to code of conduct file I have added link to the code of conduct file and fixed some problems in the Readme file. * Fixed readme * Added alpine tag Adding alpine tag instead of latest and removing repeating commands * roadmap.md file is modified * Automatically Close "Typo" labelled Issue * build.py is modified * modified PR template * Fixed some typos in feature_request.md "." at the end of the headings were missing and all the text were in same line. Now this gives a clear and concise view of the texts. * fixed the typo in docs/index.html Found and fixed typo in the 'alt' attribute of img tag * Update PULL_REQUEST_TEMPLATE.md Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> * update logger version (#773) * Fixed: Kubescape fails to authenticate remote private Github repo (#721) * grammar error fixer in CONTRIBUTING.md * scanning private git repository is available * giturl to gitapi * NO TOKEN error functionality added * Used GetToken method of giturl.IGitAPPI for auth Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> * bump opa-utils to 181 * Option to force enable color output (closes #560) (#767) * Option to force enable color output (closes #560) (cherry picked from commit 4f951781ee8dd6bb451ac7d159787f47e4b07379) * Update go.mod * Update host scanner image (#774) * update logger version * update scanner image Co-authored-by: Moshe-Rappaport-CA <moshep@armosec.io> Co-authored-by: Moshe Rappaport <89577611+Moshe-Rappaport-CA@users.noreply.github.com> Co-authored-by: Om Raut <33827410+om2137@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> Co-authored-by: Chirag Arora <84070677+Chirag8023@users.noreply.github.com> Co-authored-by: shm12 <shmuelb@armosec.io> Co-authored-by: Amir Malka <amirm@armosec.io> Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Aditya Pratap Singh <adityapratapsingh51@gmail.com>
120 lines
3.9 KiB
Go
120 lines
3.9 KiB
Go
package cautils
|
|
|
|
import (
|
|
"github.com/kubescape/k8s-interface/workloadinterface"
|
|
"github.com/kubescape/opa-utils/reporthandling"
|
|
helpersv1 "github.com/kubescape/opa-utils/reporthandling/helpers/v1"
|
|
"github.com/kubescape/opa-utils/reporthandling/results/v1/reportsummary"
|
|
)
|
|
|
|
func ReportV2ToV1(opaSessionObj *OPASessionObj) *reporthandling.PostureReport {
|
|
report := &reporthandling.PostureReport{}
|
|
|
|
frameworks := []reporthandling.FrameworkReport{}
|
|
|
|
if len(opaSessionObj.Report.SummaryDetails.Frameworks) > 0 {
|
|
for _, fwv2 := range opaSessionObj.Report.SummaryDetails.Frameworks {
|
|
fwv1 := reporthandling.FrameworkReport{}
|
|
fwv1.Name = fwv2.GetName()
|
|
fwv1.Score = fwv2.GetScore()
|
|
fwv1.ControlReports = append(fwv1.ControlReports, controlReportV2ToV1(opaSessionObj, fwv2.GetName(), fwv2.Controls)...)
|
|
frameworks = append(frameworks, fwv1)
|
|
|
|
}
|
|
} else {
|
|
fwv1 := reporthandling.FrameworkReport{}
|
|
fwv1.Name = ""
|
|
|
|
fwv1.ControlReports = append(fwv1.ControlReports, controlReportV2ToV1(opaSessionObj, "", opaSessionObj.Report.SummaryDetails.Controls)...)
|
|
frameworks = append(frameworks, fwv1)
|
|
fwv1.Score = opaSessionObj.Report.SummaryDetails.Score
|
|
}
|
|
|
|
// setup counters and score
|
|
for f := range frameworks {
|
|
// set counters
|
|
reporthandling.SetUniqueResourcesCounter(&frameworks[f])
|
|
}
|
|
|
|
report.FrameworkReports = frameworks
|
|
return report
|
|
}
|
|
|
|
func controlReportV2ToV1(opaSessionObj *OPASessionObj, frameworkName string, controls map[string]reportsummary.ControlSummary) []reporthandling.ControlReport {
|
|
controlRepors := []reporthandling.ControlReport{}
|
|
for controlID, crv2 := range controls {
|
|
crv1 := reporthandling.ControlReport{}
|
|
crv1.ControlID = controlID
|
|
crv1.BaseScore = crv2.ScoreFactor
|
|
crv1.Name = crv2.GetName()
|
|
crv1.Score = crv2.GetScore()
|
|
crv1.Control_ID = controlID
|
|
|
|
// TODO - add fields
|
|
crv1.Description = crv2.Description
|
|
crv1.Remediation = crv2.Remediation
|
|
|
|
rulesv1 := map[string]reporthandling.RuleReport{}
|
|
|
|
iter := crv2.ListResourcesIDs().All()
|
|
for iter.HasNext() {
|
|
resourceID := iter.Next()
|
|
if result, ok := opaSessionObj.ResourcesResult[resourceID]; ok {
|
|
for _, rulev2 := range result.ListRulesOfControl(crv2.GetID(), "") {
|
|
|
|
if _, ok := rulesv1[rulev2.GetName()]; !ok {
|
|
rulesv1[rulev2.GetName()] = reporthandling.RuleReport{
|
|
Name: rulev2.GetName(),
|
|
RuleStatus: reporthandling.RuleStatus{
|
|
Status: "success",
|
|
},
|
|
}
|
|
}
|
|
|
|
rulev1 := rulesv1[rulev2.GetName()]
|
|
status := rulev2.GetStatus(&helpersv1.Filters{FrameworkNames: []string{frameworkName}})
|
|
|
|
if status.IsFailed() || status.IsExcluded() {
|
|
|
|
// rule response
|
|
ruleResponse := reporthandling.RuleResponse{}
|
|
ruleResponse.Rulename = rulev2.GetName()
|
|
for i := range rulev2.Paths {
|
|
if rulev2.Paths[i].FailedPath != "" {
|
|
ruleResponse.FailedPaths = append(ruleResponse.FailedPaths, rulev2.Paths[i].FailedPath)
|
|
}
|
|
if rulev2.Paths[i].FixPath.Path != "" {
|
|
ruleResponse.FixPaths = append(ruleResponse.FixPaths, rulev2.Paths[i].FixPath)
|
|
}
|
|
}
|
|
ruleResponse.RuleStatus = string(status.Status())
|
|
if len(rulev2.Exception) > 0 {
|
|
ruleResponse.Exception = &rulev2.Exception[0]
|
|
}
|
|
|
|
if fullRessource, ok := opaSessionObj.AllResources[resourceID]; ok {
|
|
tmp := fullRessource.GetObject()
|
|
workloadinterface.RemoveFromMap(tmp, "spec")
|
|
ruleResponse.AlertObject.K8SApiObjects = append(ruleResponse.AlertObject.K8SApiObjects, tmp)
|
|
}
|
|
rulev1.RuleResponses = append(rulev1.RuleResponses, ruleResponse)
|
|
}
|
|
|
|
rulev1.ListInputKinds = append(rulev1.ListInputKinds, resourceID)
|
|
rulesv1[rulev2.GetName()] = rulev1
|
|
}
|
|
}
|
|
}
|
|
if len(rulesv1) > 0 {
|
|
for i := range rulesv1 {
|
|
crv1.RuleReports = append(crv1.RuleReports, rulesv1[i])
|
|
}
|
|
}
|
|
if len(crv1.RuleReports) == 0 {
|
|
crv1.RuleReports = []reporthandling.RuleReport{}
|
|
}
|
|
controlRepors = append(controlRepors, crv1)
|
|
}
|
|
return controlRepors
|
|
}
|