Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FAI-13813: Add Tromzo findings converter #1784

Merged
merged 3 commits into from
Nov 26, 2024
Merged

Conversation

chalenge
Copy link
Contributor

Description

  • Add Tromzo Findings converter
  • Add shared Vulnerabilities utility for mapping scores and generating keys for types

Type of change

  • Bug fix
  • New feature
  • Breaking change

Signed-off-by: Chalenge Masekera <[email protected]>
Signed-off-by: Chalenge Masekera <[email protected]>
Copy link

sonarcloud bot commented Nov 22, 2024

Quality Gate Failed Quality Gate failed

Failed conditions
10.2% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

vulnerability: vulnerabilityKey,
repository: GitHubCommon.parseRepositoryKey(
finding?.asset?.name,
'GitHub' // TODO - Figure out what source to use
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If the API response doesn't contain a field to determine the integration from which the vulnerability is coming, we might need to query repos from Faros Graph.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Will update in next PR. Merging to unblock

@chalenge chalenge merged commit 72fd1be into main Nov 26, 2024
6 of 7 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Nov 26, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants