mirror of
https://github.com/Alfresco/alfresco-ng2-components.git
synced 2026-09-09 18:03:21 +00:00
[AAE-46514] - Reduced functions in smaller pieces
This commit is contained in:
@@ -488,9 +488,11 @@ async function main() {
|
|||||||
process.exit(0);
|
process.exit(0);
|
||||||
}
|
}
|
||||||
|
|
||||||
main().catch(error => {
|
try {
|
||||||
|
await main();
|
||||||
|
} catch (error) {
|
||||||
console.error('\n❌ Security check crashed unexpectedly:', error.message);
|
console.error('\n❌ Security check crashed unexpectedly:', error.message);
|
||||||
console.error(' Blocking installation as a precaution.');
|
console.error(' Blocking installation as a precaution.');
|
||||||
console.error(' Set ADF_SKIP_SECURITY_CHECK=1 to bypass.\n');
|
console.error(' Set ADF_SKIP_SECURITY_CHECK=1 to bypass.\n');
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
}
|
||||||
|
|||||||
@@ -168,7 +168,9 @@ async function main() {
|
|||||||
console.log('='.repeat(70) + '\n');
|
console.log('='.repeat(70) + '\n');
|
||||||
}
|
}
|
||||||
|
|
||||||
main().catch(error => {
|
try {
|
||||||
|
await main();
|
||||||
|
} catch (error) {
|
||||||
console.error('Post-install failed:', error.message);
|
console.error('Post-install failed:', error.message);
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
}
|
||||||
|
|||||||
@@ -118,6 +118,10 @@ function writeCache(threats, ranges) {
|
|||||||
// SECURITY PROVIDERS
|
// SECURITY PROVIDERS
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
|
|
||||||
|
const MALWARE_KEYWORDS = ['malware', 'malicious', 'compromised', 'supply chain', 'backdoor'];
|
||||||
|
const OSV_BATCH_SIZE = 1000;
|
||||||
|
const OSV_TIMEOUT_MS = 30000;
|
||||||
|
|
||||||
function splitIntoBatches(items, batchSize) {
|
function splitIntoBatches(items, batchSize) {
|
||||||
const batches = [];
|
const batches = [];
|
||||||
for (let index = 0; index < items.length; index += batchSize) {
|
for (let index = 0; index < items.length; index += batchSize) {
|
||||||
@@ -126,6 +130,62 @@ function splitIntoBatches(items, batchSize) {
|
|||||||
return batches;
|
return batches;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function buildOSVQueryPayload(dependencies) {
|
||||||
|
return {
|
||||||
|
queries: dependencies.map(dep => ({
|
||||||
|
package: { name: dep.name, ecosystem: 'npm' },
|
||||||
|
version: dep.version
|
||||||
|
}))
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
function isMalwareVulnerability(vulnerability) {
|
||||||
|
const summary = [vulnerability.summary || '', vulnerability.details || ''].join(' ').toLowerCase();
|
||||||
|
return MALWARE_KEYWORDS.some(keyword => summary.includes(keyword));
|
||||||
|
}
|
||||||
|
|
||||||
|
function extractMaliciousPackages(vulnerability) {
|
||||||
|
const packages = [];
|
||||||
|
|
||||||
|
for (const affected of vulnerability.affected || []) {
|
||||||
|
const isNpmPackage = affected.package?.ecosystem === 'npm' && affected.package?.name;
|
||||||
|
if (isNpmPackage) {
|
||||||
|
for (const version of affected.versions || []) {
|
||||||
|
packages.push(`${affected.package.name}@${version}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return packages;
|
||||||
|
}
|
||||||
|
|
||||||
|
function processOSVResults(results, maliciousSet) {
|
||||||
|
for (const result of results) {
|
||||||
|
for (const vulnerability of result.vulns || []) {
|
||||||
|
if (isMalwareVulnerability(vulnerability)) {
|
||||||
|
const packages = extractMaliciousPackages(vulnerability);
|
||||||
|
packages.forEach(pkg => maliciousSet.add(pkg));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function queryOSVBatch(dependencies) {
|
||||||
|
const response = await fetch('https://api.osv.dev/v1/querybatch', {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify(buildOSVQueryPayload(dependencies)),
|
||||||
|
signal: AbortSignal.timeout(OSV_TIMEOUT_MS)
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!response.ok) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
const data = await response.json();
|
||||||
|
return data.results || [];
|
||||||
|
}
|
||||||
|
|
||||||
async function fetchOSV(projectDependencies) {
|
async function fetchOSV(projectDependencies) {
|
||||||
if (!projectDependencies?.length) {
|
if (!projectDependencies?.length) {
|
||||||
return new Set();
|
return new Set();
|
||||||
@@ -134,44 +194,14 @@ async function fetchOSV(projectDependencies) {
|
|||||||
const malicious = new Set();
|
const malicious = new Set();
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const batches = splitIntoBatches(projectDependencies, 1000);
|
const batches = splitIntoBatches(projectDependencies, OSV_BATCH_SIZE);
|
||||||
|
|
||||||
for (const batch of batches) {
|
for (const batch of batches) {
|
||||||
const response = await fetch('https://api.osv.dev/v1/querybatch', {
|
const results = await queryOSVBatch(batch);
|
||||||
method: 'POST',
|
processOSVResults(results, malicious);
|
||||||
headers: { 'Content-Type': 'application/json' },
|
|
||||||
body: JSON.stringify({
|
|
||||||
queries: batch.map(dep => ({
|
|
||||||
package: { name: dep.name, ecosystem: 'npm' },
|
|
||||||
version: dep.version
|
|
||||||
}))
|
|
||||||
}),
|
|
||||||
signal: AbortSignal.timeout(30000)
|
|
||||||
});
|
|
||||||
|
|
||||||
if (!response.ok) continue;
|
|
||||||
|
|
||||||
const data = await response.json();
|
|
||||||
for (const result of data.results || []) {
|
|
||||||
for (const vuln of result.vulns || []) {
|
|
||||||
const summary = [vuln.summary || '', vuln.details || ''].join(' ').toLowerCase();
|
|
||||||
const isMalware = ['malware', 'malicious', 'compromised', 'supply chain', 'backdoor']
|
|
||||||
.some(keyword => summary.includes(keyword));
|
|
||||||
|
|
||||||
if (isMalware && vuln.affected) {
|
|
||||||
for (const affected of vuln.affected) {
|
|
||||||
if (affected.package?.ecosystem === 'npm' && affected.package?.name) {
|
|
||||||
for (const version of affected.versions || []) {
|
|
||||||
malicious.add(`${affected.package.name}@${version}`);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
// Ignore errors
|
// Network errors are non-fatal
|
||||||
}
|
}
|
||||||
|
|
||||||
return malicious;
|
return malicious;
|
||||||
@@ -454,9 +484,11 @@ async function main() {
|
|||||||
console.log('='.repeat(70) + '\n');
|
console.log('='.repeat(70) + '\n');
|
||||||
}
|
}
|
||||||
|
|
||||||
main().catch(error => {
|
try {
|
||||||
|
await main();
|
||||||
|
} catch (error) {
|
||||||
console.error('\n❌ Security check crashed unexpectedly:', error.message);
|
console.error('\n❌ Security check crashed unexpectedly:', error.message);
|
||||||
console.error(' Blocking installation as a precaution.');
|
console.error(' Blocking installation as a precaution.');
|
||||||
console.error(' Set ADF_SKIP_SECURITY_CHECK=1 to bypass.\n');
|
console.error(' Set ADF_SKIP_SECURITY_CHECK=1 to bypass.\n');
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
}
|
||||||
|
|||||||
@@ -36,32 +36,51 @@ function isMalwareRelated(text) {
|
|||||||
return MALWARE_KEYWORDS.some(keyword => lowerText.includes(keyword.toLowerCase()));
|
return MALWARE_KEYWORDS.some(keyword => lowerText.includes(keyword.toLowerCase()));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function formatRangeWithUpperBound(introduced, upperVersion, upperOperator) {
|
||||||
|
if (introduced === '0') {
|
||||||
|
return `${upperOperator} ${upperVersion}`;
|
||||||
|
}
|
||||||
|
return `>= ${introduced}, ${upperOperator} ${upperVersion}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function formatOpenEndedRange(introduced) {
|
||||||
|
if (introduced === null || introduced === '0') {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
return `>= ${introduced}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function processRangeEvent(event, introduced) {
|
||||||
|
if (event.introduced !== undefined) {
|
||||||
|
return { introduced: event.introduced, range: null };
|
||||||
|
}
|
||||||
|
|
||||||
|
if (event.fixed !== undefined && introduced !== null) {
|
||||||
|
return { introduced: null, range: formatRangeWithUpperBound(introduced, event.fixed, '<') };
|
||||||
|
}
|
||||||
|
|
||||||
|
if (event.last_affected !== undefined && introduced !== null) {
|
||||||
|
return { introduced: null, range: formatRangeWithUpperBound(introduced, event.last_affected, '<=') };
|
||||||
|
}
|
||||||
|
|
||||||
|
return { introduced, range: null };
|
||||||
|
}
|
||||||
|
|
||||||
function extractRangesFromEvents(events) {
|
function extractRangesFromEvents(events) {
|
||||||
const ranges = [];
|
const ranges = [];
|
||||||
let introduced = null;
|
let introduced = null;
|
||||||
|
|
||||||
for (const event of events) {
|
for (const event of events) {
|
||||||
if (event.introduced !== undefined) {
|
const result = processRangeEvent(event, introduced);
|
||||||
introduced = event.introduced;
|
introduced = result.introduced;
|
||||||
} else if (event.fixed !== undefined && introduced !== null) {
|
if (result.range) {
|
||||||
if (introduced === '0') {
|
ranges.push(result.range);
|
||||||
ranges.push(`< ${event.fixed}`);
|
|
||||||
} else {
|
|
||||||
ranges.push(`>= ${introduced}, < ${event.fixed}`);
|
|
||||||
}
|
|
||||||
introduced = null;
|
|
||||||
} else if (event.last_affected !== undefined && introduced !== null) {
|
|
||||||
if (introduced === '0') {
|
|
||||||
ranges.push(`<= ${event.last_affected}`);
|
|
||||||
} else {
|
|
||||||
ranges.push(`>= ${introduced}, <= ${event.last_affected}`);
|
|
||||||
}
|
|
||||||
introduced = null;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (introduced !== null && introduced !== '0') {
|
const openEndedRange = formatOpenEndedRange(introduced);
|
||||||
ranges.push(`>= ${introduced}`);
|
if (openEndedRange) {
|
||||||
|
ranges.push(openEndedRange);
|
||||||
}
|
}
|
||||||
|
|
||||||
return ranges;
|
return ranges;
|
||||||
|
|||||||
Reference in New Issue
Block a user