mirror of
https://github.com/kubescape/kubescape.git
synced 2026-04-15 06:58:11 +00:00
+18









David Wertenteil
GitHub
Vlad Klokun
Moshe-Rappaport-CA
Moshe Rappaport
Om Raut
Kamal Nayan
Chirag Arora
shm12
Amir Malka
Krishna Agarwal
Saswata Senapati
Rahul Singh
deepuyadav004
kartik
Rounak-28
pwnb0y
Ben Hirschberg
Saptarshi Sarkar
Rahul Surwade
Suhas Gumma
TarangVerma
avikittu
satyam kale
Aditya Pratap Singh
Ashray Shetty
Anubhav Gupta
Meyazhagan
eb16440ba6
* Fix issue for scanning list obj * Fix go mod in httphandler pkg * Broken links fix in roadmap.md Planning, backlog, and wishlist links were not taking to the required section. * override infoMap only if it's not nil * improved icon of kubescape in readme * Support scanning several files * gramatical improvements * docs(readme): Star → star * Fix issues according to review * Handle with issues caused by updating opa-utils * Fix scanning ListObj following reviews * Update core/pkg/resourcehandler/filesloader.go Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> * Update completion.go * Added fixed control input * update go.mod * Print chart name log when fail to generate * Change formatting to %s * Added resource prioritization information, raw resource will be sent on the result object * Merging typo fixes from master (#772) * greetings * Update aws.sh simplified the comment * typo: In the title and h1 element Their was a typo in index.html file. * punctuation changes * docs : added gitpod badge in readme.md * fixed typos * some grammar mistake is corrected inPULL_REQUEST_TEMPLATE.md file * Updated README.md file Added link to CONTRIBUTING.md file in a line in README. * Added link to code of conduct file I have added link to the code of conduct file and fixed some problems in the Readme file. * Fixed readme * Added alpine tag Adding alpine tag instead of latest and removing repeating commands * roadmap.md file is modified * Automatically Close "Typo" labelled Issue * build.py is modified * modified PR template * Fixed some typos in feature_request.md "." at the end of the headings were missing and all the text were in same line. Now this gives a clear and concise view of the texts. * fixed the typo in docs/index.html Found and fixed typo in the 'alt' attribute of img tag * Update PULL_REQUEST_TEMPLATE.md Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> * update logger version * update logger version (#773) * Fixed: Kubescape fails to authenticate remote private Github repo (#721) * grammar error fixer in CONTRIBUTING.md * scanning private git repository is available * giturl to gitapi * NO TOKEN error functionality added * Used GetToken method of giturl.IGitAPPI for auth Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> * bump opa-utils to 181 * Option to force enable color output (closes #560) (#767) * Option to force enable color output (closes #560) (cherry picked from commit 4f951781ee8dd6bb451ac7d159787f47e4b07379) * Update go.mod * update scanner image * Update host scanner image (#774) * update logger version * update scanner image * remove windows exe extension * Remove windows extension build (#775) * update logger version * update scanner image * remove windows exe extension * commened out prioritization logic * Edit Junit output (#802) * Edit Junit output * Update go sum * Following review * update AdoptClusterName * Print line separator only if some controls failed (#813) * removed the extra 'download' word from the example (#810) it was confusing to understand the download command because there was an extra 'download' mentioned * Prioritization (#815) * removed commented out code * Added attack tracks information to prioritization algorithm * bump opa-utils * go mod tidy * go mod tidy * CR changes * Issue 613 cluster name (#783) * added --clusterName flag (#613) Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> * update flag name to --cluster-name Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> * Per 307 fail on severity counters (#831) * feat: fail on exceeding severity thresholds (#830) - Add support for severity counters - Add support for CLI flags that set severity thresholds - Terminate Kubescape with an exit code 1 if scan results exceed the severity thresholds * Update opa-utils pkg version Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> * Fix merge conflict * typo in .gitignore file (#833) * remove unsupported installation method * fixed welcome message * fixed merge * fixed attack tracks loading logic Signed-off-by: Anubhav Gupta <mail.anubhav06@gmail.com> Co-authored-by: Moshe-Rappaport-CA <moshep@armosec.io> Co-authored-by: Moshe Rappaport <89577611+Moshe-Rappaport-CA@users.noreply.github.com> Co-authored-by: Om Raut <33827410+om2137@users.noreply.github.com> Co-authored-by: Kamal Nayan <95926324+legendarykamal@users.noreply.github.com> Co-authored-by: Vlad Klokun <vladklokun@users.noreply.github.com> Co-authored-by: Chirag Arora <84070677+Chirag8023@users.noreply.github.com> Co-authored-by: shm12 <shmuelb@armosec.io> Co-authored-by: Amir Malka <amirm@armosec.io> Co-authored-by: Krishna Agarwal <dmkrishna.agarwal@gmail.com> Co-authored-by: Saswata Senapati <74651639+saswat16@users.noreply.github.com> Co-authored-by: Rahul Singh <110548934+rahuldhirendersingh@users.noreply.github.com> Co-authored-by: deepuyadav004 <deepuyadavze@gmail.com> Co-authored-by: kartik <97971066+kartikgajjar7@users.noreply.github.com> Co-authored-by: Rounak-28 <95576871+Rounak-28@users.noreply.github.com> Co-authored-by: pwnb0y <vickykr07@yahoo.com> Co-authored-by: Ben Hirschberg <59160382+slashben@users.noreply.github.com> Co-authored-by: Saptarshi Sarkar <saptarshi.programmer@gmail.com> Co-authored-by: Rahul Surwade <93492791+RahulSurwade08@users.noreply.github.com> Co-authored-by: Suhas Gumma <43647369+suhasgumma@users.noreply.github.com> Co-authored-by: TarangVerma <90996971+TarangVerma@users.noreply.github.com> Co-authored-by: avikittu <65793296+avikittu@users.noreply.github.com> Co-authored-by: satyam kale <satyamkale271@gmail.com> Co-authored-by: Aditya Pratap Singh <adityapratapsingh51@gmail.com> Co-authored-by: Ashray Shetty <ashrayshetty1999@gmail.com> Co-authored-by: Anubhav Gupta <mail.anubhav06@gmail.com> Co-authored-by: Meyazhagan <meyazhagan.ofcl@gmail.com>
152 lines
4.7 KiB
Go
152 lines
4.7 KiB
Go
package v2
|
|
|
|
import (
|
|
_ "embed"
|
|
"html/template"
|
|
"os"
|
|
"path/filepath"
|
|
"sort"
|
|
"strings"
|
|
|
|
logger "github.com/kubescape/go-logger"
|
|
"github.com/kubescape/go-logger/helpers"
|
|
"github.com/kubescape/kubescape/v2/core/cautils"
|
|
"github.com/kubescape/kubescape/v2/core/pkg/resultshandling/printer"
|
|
"github.com/kubescape/opa-utils/reporthandling/apis"
|
|
"github.com/kubescape/opa-utils/reporthandling/results/v1/reportsummary"
|
|
"github.com/kubescape/opa-utils/reporthandling/results/v1/resourcesresults"
|
|
)
|
|
|
|
const (
|
|
htmlOutputFile = "report"
|
|
htmlOutputExt = ".html"
|
|
)
|
|
|
|
//go:embed html/report.gohtml
|
|
var reportTemplate string
|
|
|
|
type HTMLReportingCtx struct {
|
|
OPASessionObj *cautils.OPASessionObj
|
|
ResourceTableView ResourceTableView
|
|
}
|
|
|
|
type HtmlPrinter struct {
|
|
writer *os.File
|
|
}
|
|
|
|
func NewHtmlPrinter() *HtmlPrinter {
|
|
return &HtmlPrinter{}
|
|
}
|
|
|
|
func (htmlPrinter *HtmlPrinter) SetWriter(outputFile string) {
|
|
if outputFile == "" {
|
|
outputFile = htmlOutputFile
|
|
}
|
|
if filepath.Ext(strings.TrimSpace(outputFile)) != htmlOutputExt {
|
|
outputFile = outputFile + htmlOutputExt
|
|
}
|
|
htmlPrinter.writer = printer.GetWriter(outputFile)
|
|
}
|
|
|
|
func (htmlPrinter *HtmlPrinter) ActionPrint(opaSessionObj *cautils.OPASessionObj) {
|
|
tplFuncMap := template.FuncMap{
|
|
"sum": func(nums ...int) int {
|
|
total := 0
|
|
for _, n := range nums {
|
|
total += n
|
|
}
|
|
return total
|
|
},
|
|
"float32ToInt": cautils.Float32ToInt,
|
|
"lower": strings.ToLower,
|
|
"sortByNamespace": func(resourceTableView ResourceTableView) ResourceTableView {
|
|
sortedResourceTableView := make(ResourceTableView, len(resourceTableView))
|
|
copy(sortedResourceTableView, resourceTableView)
|
|
|
|
sort.SliceStable(
|
|
sortedResourceTableView,
|
|
func(i, j int) bool {
|
|
return sortedResourceTableView[i].Resource.GetNamespace() < sortedResourceTableView[j].Resource.GetNamespace()
|
|
},
|
|
)
|
|
return sortedResourceTableView
|
|
},
|
|
"controlSeverityToString": apis.ControlSeverityToString,
|
|
"sortBySeverityName": func(controlSummaries map[string]reportsummary.ControlSummary) []reportsummary.ControlSummary {
|
|
sortedSlice := make([]reportsummary.ControlSummary, 0, len(controlSummaries))
|
|
for _, val := range controlSummaries {
|
|
sortedSlice = append(sortedSlice, val)
|
|
}
|
|
|
|
sort.SliceStable(
|
|
sortedSlice,
|
|
func(i, j int) bool {
|
|
//First sort by Severity descending
|
|
iSeverity := apis.ControlSeverityToInt(sortedSlice[i].GetScoreFactor())
|
|
jSeverity := apis.ControlSeverityToInt(sortedSlice[j].GetScoreFactor())
|
|
if iSeverity > jSeverity {
|
|
return true
|
|
}
|
|
if iSeverity < jSeverity {
|
|
return false
|
|
}
|
|
//And then by Name ascending
|
|
return sortedSlice[i].GetName() < sortedSlice[j].GetName()
|
|
},
|
|
)
|
|
|
|
return sortedSlice
|
|
},
|
|
}
|
|
tpl := template.Must(
|
|
template.New("htmlReport").Funcs(tplFuncMap).Parse(reportTemplate),
|
|
)
|
|
|
|
resourceTableView := buildResourceTableView(opaSessionObj)
|
|
reportingCtx := HTMLReportingCtx{opaSessionObj, resourceTableView}
|
|
err := tpl.Execute(htmlPrinter.writer, reportingCtx)
|
|
if err != nil {
|
|
logger.L().Error("failed to render template", helpers.Error(err))
|
|
}
|
|
}
|
|
|
|
func (htmlPrinter *HtmlPrinter) Score(score float32) {
|
|
return
|
|
}
|
|
|
|
func buildResourceTableView(opaSessionObj *cautils.OPASessionObj) ResourceTableView {
|
|
resourceTableView := make(ResourceTableView, 0)
|
|
for resourceID, result := range opaSessionObj.ResourcesResult {
|
|
if result.GetStatus(nil).IsFailed() {
|
|
resource := opaSessionObj.AllResources[resourceID]
|
|
ctlResults := buildResourceControlResultTable(result.AssociatedControls, &opaSessionObj.Report.SummaryDetails)
|
|
resourceTableView = append(resourceTableView, ResourceResult{resource, ctlResults})
|
|
}
|
|
}
|
|
|
|
return resourceTableView
|
|
}
|
|
|
|
func buildResourceControlResult(resourceControl resourcesresults.ResourceAssociatedControl, control reportsummary.IControlSummary) ResourceControlResult {
|
|
ctlSeverity := apis.ControlSeverityToString(control.GetScoreFactor())
|
|
ctlName := resourceControl.GetName()
|
|
ctlURL := resourceControl.GetID()
|
|
failedPaths := append(failedPathsToString(&resourceControl), fixPathsToString(&resourceControl)...)
|
|
|
|
return ResourceControlResult{ctlSeverity, ctlName, ctlURL, failedPaths}
|
|
}
|
|
|
|
func buildResourceControlResultTable(resourceControls []resourcesresults.ResourceAssociatedControl, summaryDetails *reportsummary.SummaryDetails) []ResourceControlResult {
|
|
var ctlResults []ResourceControlResult
|
|
for _, resourceControl := range resourceControls {
|
|
if resourceControl.GetStatus(nil).IsFailed() {
|
|
control := summaryDetails.Controls.GetControl(reportsummary.EControlCriteriaName, resourceControl.GetName())
|
|
ctlResult := buildResourceControlResult(resourceControl, control)
|
|
|
|
ctlResults = append(ctlResults, ctlResult)
|
|
}
|
|
}
|
|
|
|
return ctlResults
|
|
}
|