|
1 | 1 | import logging |
| 2 | +import os |
| 3 | +import subprocess |
| 4 | +import tempfile |
2 | 5 | from secrets import token_urlsafe |
3 | 6 |
|
4 | 7 | from django.db import DatabaseError |
5 | 8 |
|
6 | 9 | from analyzer.manager.cve_manager import CVEObjectManager |
7 | 10 | from analyzer.models import Project, Report, Dependency |
| 11 | +from analyzer.parser.parser_manager import ParserManager |
8 | 12 | from analyzer.parser.types import ParseResult |
9 | 13 | from utilities.helperclass import hash_key |
10 | 14 |
|
@@ -138,3 +142,47 @@ def _update_dependencies(self, data: dict[str, ParseResult]): |
138 | 142 | logger.warning( |
139 | 143 | f"An error occurred while trying to create reports. Following exception occurred: {str(de)}." |
140 | 144 | f"Project id: {self.project.project_id}.") |
| 145 | + |
| 146 | + def run_dependency_checker(self): |
| 147 | + """ |
| 148 | + Clones the repository, runs the OWASP Dependency-Checker, and updates the project with the results. |
| 149 | + """ |
| 150 | + if not self.project.repository_url: |
| 151 | + logger.error(f"No repository URL configured for project {self.project.project_id}.") |
| 152 | + return |
| 153 | + |
| 154 | + with tempfile.TemporaryDirectory() as temp_dir: |
| 155 | + repo_path = os.path.join(temp_dir, "repo") |
| 156 | + |
| 157 | + # Clone the repository |
| 158 | + clone_cmd = ["git", "clone", self.project.repository_url, repo_path] |
| 159 | + if self.project.access_token: |
| 160 | + clone_cmd[1] = self.project.repository_url.replace("https://", f"https://{self.project.access_token}@") |
| 161 | + |
| 162 | + try: |
| 163 | + subprocess.run(clone_cmd, check=True) |
| 164 | + logger.info(f"Repository cloned successfully for project {self.project.project_id}.") |
| 165 | + except subprocess.CalledProcessError as e: |
| 166 | + logger.error(f"Failed to clone repository: {e}") |
| 167 | + return |
| 168 | + |
| 169 | + # Run OWASP Dependency-Checker |
| 170 | + output_file = os.path.join(temp_dir, "dependency-check-report.json") |
| 171 | + try: |
| 172 | + subprocess.run([ |
| 173 | + "dependency-check", "--project", self.project.project_name, |
| 174 | + "--out", temp_dir, "--format", "JSON", "--scan", repo_path |
| 175 | + ], check=True) |
| 176 | + logger.info(f"Dependency-Checker executed successfully for project {self.project.project_id}.") |
| 177 | + except subprocess.CalledProcessError as e: |
| 178 | + logger.error(f"Failed to run Dependency-Checker: {e}") |
| 179 | + return |
| 180 | + |
| 181 | + # Parse the results |
| 182 | + try: |
| 183 | + parser = ParserManager(output_file) |
| 184 | + parsed_data = parser.parse() |
| 185 | + self.update_project(parsed_data) |
| 186 | + logger.info(f"Project {self.project.project_id} updated successfully with new dependency data.") |
| 187 | + except Exception as e: |
| 188 | + logger.error(f"Failed to parse Dependency-Checker results: {e}") |
0 commit comments