|
| 1 | +#!/bin/bash |
| 2 | +# |
| 3 | +# This script builds the requirements.json file based on |
| 4 | +# - the base-requirements.json as base file, |
| 5 | +# - the denied-arguments.tsv as rules to exclude application from their arguments (main classes, System properties, application arguments), |
| 6 | +# - the denied-environment-variables.tsv as rules to exclude applications from their exported environment variables. |
| 7 | +# |
| 8 | + |
| 9 | +log-json() { |
| 10 | + local JSON=$1 |
| 11 | + echo "Logging JSON" |
| 12 | + echo "$JSON" | jq |
| 13 | +} |
| 14 | + |
| 15 | +# |
| 16 | +# Initialize requirements from base file |
| 17 | +# |
| 18 | +JSON=$(cat base-requirements.json) |
| 19 | + |
| 20 | +# |
| 21 | +# Append deny list entries based on arguments |
| 22 | +# |
| 23 | +while read -r ENTRY; do |
| 24 | + # Skip comments or empty lines |
| 25 | + if [[ -z $ENTRY || $ENTRY == \#* ]]; then |
| 26 | + continue |
| 27 | + fi |
| 28 | + # Take first word |
| 29 | + IDENTIFIER=$(echo "$ENTRY" | awk '{print $1}') |
| 30 | + # Take second word |
| 31 | + ARGUMENT=$(echo "$ENTRY" | awk '{print $2}') |
| 32 | + # Take the rest as description |
| 33 | + DESCRIPTION=$(echo "$ENTRY" | awk '{for(i=3;i<=NF;++i) printf "%s%s", $i, (i<NF)?" ":""}') |
| 34 | + # Build deny list entry |
| 35 | + DENY_ENTRY=$(cat <<-END |
| 36 | + { |
| 37 | + "id": "$IDENTIFIER", |
| 38 | + "description": "$DESCRIPTION", |
| 39 | + "os": null, |
| 40 | + "cmds": ["**/java"], |
| 41 | + "args": [{ |
| 42 | + "args": ["$ARGUMENT"], |
| 43 | + "position": null |
| 44 | + }], |
| 45 | + "envars": null |
| 46 | + } |
| 47 | +END |
| 48 | + ) |
| 49 | + JSON=$(echo "$JSON" | jq ".deny += [$DENY_ENTRY]") |
| 50 | +done < denied-arguments.tsv |
| 51 | + |
| 52 | +# |
| 53 | +# Append deny list entries based on environment variables |
| 54 | +# |
| 55 | +while read -r ENTRY; do |
| 56 | + # Skip comments or empty lines |
| 57 | + if [[ -z $ENTRY || $ENTRY == \#* ]]; then |
| 58 | + continue |
| 59 | + fi |
| 60 | + # Take first word |
| 61 | + IDENTIFIER=$(echo "$ENTRY" | awk '{print $1}') |
| 62 | + # Take second word |
| 63 | + ENVIRONMENT_VARIABLE=$(echo "$ENTRY" | awk '{print $2}') |
| 64 | + # Take the rest as description |
| 65 | + DESCRIPTION=$(echo "$ENTRY" | awk '{for(i=3;i<=NF;++i) printf "%s%s", $i, (i<NF)?" ":""}') |
| 66 | + # Build deny list entry |
| 67 | + DENY_ENTRY=$(cat <<-END |
| 68 | + { |
| 69 | + "id": "$IDENTIFIER", |
| 70 | + "description": "$DESCRIPTION", |
| 71 | + "os": null, |
| 72 | + "cmds": ["**/java"], |
| 73 | + "args": [], |
| 74 | + "envars": { |
| 75 | + "$ENVIRONMENT_VARIABLE": null |
| 76 | + } |
| 77 | + } |
| 78 | +END |
| 79 | + ) |
| 80 | + JSON=$(echo "$JSON" | jq ".deny += [$DENY_ENTRY]") |
| 81 | +done < denied-environment-variables.tsv |
| 82 | + |
| 83 | +log-json "$JSON" |
| 84 | +echo "$JSON" > requirements.json |
0 commit comments