Skip to content

Commit

Permalink
Merge pull request mercedes-benz#2782 from zigfridus/feature-345-summ…
Browse files Browse the repository at this point in the history
…ary-in-reports

Feature 345 summary in reports (part 2)
  • Loading branch information
de-jcup authored Jan 30, 2024
2 parents b6c4fcb + 03f1b0a commit 67273af
Show file tree
Hide file tree
Showing 30 changed files with 4,173 additions and 418 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,17 @@ public class SecHubReportMetaData {

private Map<String, String> labels = new LinkedHashMap<>();

private SecHubReportSummary summary = new SecHubReportSummary();

public Map<String, String> getLabels() {
return labels;
}

public SecHubReportSummary getSummary() {
return summary;
}

public void setSummary(SecHubReportSummary summary) {
this.summary = summary;
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
// SPDX-License-Identifier: MIT
package com.mercedesbenz.sechub.commons.model;

import com.fasterxml.jackson.annotation.JsonIgnoreProperties;

@JsonIgnoreProperties(ignoreUnknown = true)
public class SecHubReportMetaDataSummary {

private long total = 0;
private long red = 0;
private long yellow = 0;
private long green = 0;
private SecHubReportMetaDataSummaryDetails details = new SecHubReportMetaDataSummaryDetails();

public void reportScanHelper(SecHubFinding finding) {
incrementColors(finding);
details.detailsHelper(finding);
}

protected void incrementColors(SecHubFinding finding) {
Severity severity = finding.getSeverity();
switch (severity) {
case HIGH, CRITICAL -> incrementRedCount();
case MEDIUM -> incrementYellowCount();
case UNCLASSIFIED, INFO, LOW -> incrementGreenCount();
}
incrementTotalCount();
}

protected void incrementRedCount() {
this.red++;
}

protected void incrementYellowCount() {
this.yellow++;
}

protected void incrementGreenCount() {
this.green++;
}

protected void incrementTotalCount() {
this.total++;
}

public long getTotal() {
return total;
}

public long getRed() {
return red;
}

public long getYellow() {
return yellow;
}

public long getGreen() {
return green;
}

public SecHubReportMetaDataSummaryDetails getDetails() {
return details;
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
// SPDX-License-Identifier: MIT
package com.mercedesbenz.sechub.commons.model;

import java.io.IOException;
import java.util.*;

import org.slf4j.Logger;
import org.slf4j.LoggerFactory;

import com.fasterxml.jackson.annotation.JsonIgnoreProperties;
import com.fasterxml.jackson.annotation.JsonInclude;
import com.fasterxml.jackson.core.JsonParser;
import com.fasterxml.jackson.core.JsonProcessingException;
import com.fasterxml.jackson.databind.DeserializationContext;
import com.fasterxml.jackson.databind.JsonNode;
import com.fasterxml.jackson.databind.annotation.JsonDeserialize;
import com.fasterxml.jackson.databind.deser.std.StdDeserializer;

@JsonInclude(JsonInclude.Include.NON_EMPTY)
@JsonIgnoreProperties(ignoreUnknown = true)
public class SecHubReportMetaDataSummaryDetails {

private static final Logger LOG = LoggerFactory.getLogger(SecHubReportMetaDataSummaryDetails.class);

@JsonDeserialize(using = TreeMapDeserializer.class)
Map<String, SeverityDetails> high = new TreeMap<>();

@JsonDeserialize(using = TreeMapDeserializer.class)
Map<String, SeverityDetails> medium = new TreeMap<>();

@JsonDeserialize(using = TreeMapDeserializer.class)
Map<String, SeverityDetails> low = new TreeMap<>();

public void detailsHelper(SecHubFinding finding) {
switch (finding.getSeverity()) {
case HIGH, CRITICAL -> detailsFiller(high, finding);
case MEDIUM -> detailsFiller(medium, finding);
case UNCLASSIFIED, LOW, INFO -> detailsFiller(low, finding);
}
}

protected void detailsFiller(Map<String, SeverityDetails> helperMap, SecHubFinding finding) {
Integer cweId = finding.getCweId();
String name = finding.getName() != null ? finding.getName() : "no_name";
SeverityDetails severityDetails = helperMap.get(name);
if (severityDetails != null) {
severityDetails.incrementCount();
} else {
helperMap.put(name, new SeverityDetails(cweId, name));
}
}

public List<SeverityDetails> getHigh() {
return new ArrayList<>(high.values());
}

public List<SeverityDetails> getMedium() {
return new ArrayList<>(medium.values());
}

public List<SeverityDetails> getLow() {
return new ArrayList<>(low.values());
}

@JsonIgnoreProperties(ignoreUnknown = true)
public class SeverityDetails {
private Integer cweId;
private String name;
private long count;

SeverityDetails(Integer cweId, String name) {
this.cweId = cweId;
this.name = name;
this.count = 1;
}

public void incrementCount() {
this.count++;
}

public Integer getCweId() {
return cweId;
}

public String getName() {
return name;
}

public long getCount() {
return count;
}
}

private static class TreeMapDeserializer extends StdDeserializer<Map<String, SeverityDetails>> {

public TreeMapDeserializer() {
this(null);
}

protected TreeMapDeserializer(Class<?> vc) {
super(vc);
}

@Override
public TreeMap<String, SeverityDetails> deserialize(JsonParser jsonParser, DeserializationContext deserializationContext)
throws IOException, JsonProcessingException {
TreeMap<String, SeverityDetails> treeMap = new TreeMap<>();
JsonNode node = jsonParser.getCodec().readTree(jsonParser);
node.fields().forEachRemaining(entry -> {
try {
String key = entry.getKey();
SeverityDetails value = entry.getValue().traverse(jsonParser.getCodec()).readValueAs(SeverityDetails.class);
treeMap.put(key, value);
} catch (IOException e) {
LOG.debug("JSON deserialization failed \n" + e);
}
});
return treeMap;
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
// SPDX-License-Identifier: MIT
package com.mercedesbenz.sechub.commons.model;

import com.fasterxml.jackson.annotation.JsonIgnoreProperties;

@JsonIgnoreProperties(ignoreUnknown = true)
public class SecHubReportSummary {

SecHubReportMetaDataSummary codeScan = new SecHubReportMetaDataSummary();
SecHubReportMetaDataSummary infraScan = new SecHubReportMetaDataSummary();
SecHubReportMetaDataSummary licenseScan = new SecHubReportMetaDataSummary();
SecHubReportMetaDataSummary secretScan = new SecHubReportMetaDataSummary();
SecHubReportMetaDataSummary webScan = new SecHubReportMetaDataSummary();

public SecHubReportMetaDataSummary getCodeScan() {
return codeScan;
}

public void setCodeScan(SecHubReportMetaDataSummary codeScan) {
this.codeScan = codeScan;
}

public SecHubReportMetaDataSummary getInfraScan() {
return infraScan;
}

public void setInfraScan(SecHubReportMetaDataSummary infraScan) {
this.infraScan = infraScan;
}

public SecHubReportMetaDataSummary getWebScan() {
return webScan;
}

public void setWebScan(SecHubReportMetaDataSummary webScan) {
this.webScan = webScan;
}

public SecHubReportMetaDataSummary getLicenseScan() {
return licenseScan;
}

public void setLicenseScan(SecHubReportMetaDataSummary licenseScan) {
this.licenseScan = licenseScan;
}

public SecHubReportMetaDataSummary getSecretScan() {
return secretScan;
}

public void setSecretScan(SecHubReportMetaDataSummary secretScan) {
this.secretScan = secretScan;
}

}
Loading

0 comments on commit 67273af

Please sign in to comment.