Prune generated/vendored trees from the scanners
cfn-lint, semgrep, and checkov were scanning synthesized/vendored output (cdk.out, node_modules, .venv/venv, .aws-sam, dist, build). On CDK repos this explodes the find/xargs arg list and stalls the scan, and flagging synthesized templates is wrong. Prune those trees in the cfn-lint find, and pass --exclude / --skip-path to semgrep / checkov.
This commit is contained in:
parent
dbe2f8c186
commit
c6ecc621be
1 changed files with 5 additions and 3 deletions
|
|
@ -43,7 +43,9 @@ note_missing() { echo " [MISSING] $1 — not run. Install: $2" >&2; }
|
|||
|
||||
# --- cfn-lint (installed): lint SAM/CFN templates. Normalize to findings. ---
|
||||
if command -v cfn-lint >/dev/null; then
|
||||
TPLS="$(scope_paths | xargs -I{} find {} -type f \( -name '*.yaml' -o -name '*.yml' \) 2>/dev/null \
|
||||
# Prune generated/vendored trees (cdk.out, node_modules, …): scanning synthesized output is
|
||||
# wrong and, on CDK repos, explodes the arg list / stalls the scanners.
|
||||
TPLS="$(scope_paths | xargs -I{} find {} \( -type d \( -name cdk.out -o -name node_modules -o -name .git -o -name .aws-sam -o -name .venv -o -name venv -o -name dist -o -name build \) -prune \) -o \( -type f \( -name '*.yaml' -o -name '*.yml' \) -print \) 2>/dev/null \
|
||||
| xargs -I{} sh -c 'grep -lE "AWSTemplateFormatVersion|Transform: *AWS::Serverless" "{}" 2>/dev/null || true')"
|
||||
if [ -n "$TPLS" ]; then
|
||||
# shellcheck disable=SC2086
|
||||
|
|
@ -67,7 +69,7 @@ SCOPE_PATHS="$(scope_paths)"
|
|||
# --- semgrep (SAST: injection/authz/xss/secrets) ---
|
||||
if command -v semgrep >/dev/null; then
|
||||
# shellcheck disable=SC2086
|
||||
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off $SCOPE_PATHS 2>/dev/null)"; then
|
||||
if SG="$(semgrep --config p/security-audit --config p/secrets --config p/javascript --json --metrics=off --exclude cdk.out --exclude node_modules --exclude .venv --exclude venv --exclude .aws-sam --exclude dist --exclude build $SCOPE_PATHS 2>/dev/null)"; then
|
||||
NORM="$(echo "$SG" | jq '[.results[] | {
|
||||
id: ("semgrep-" + (.check_id|split(".")|last) + "-" + (.start.line|tostring)),
|
||||
title: ((.check_id|split(".")|last) + ": " + ((.extra.message // "")[0:120])),
|
||||
|
|
@ -109,7 +111,7 @@ else note_missing gitleaks "brew install gitleaks"; fi
|
|||
if command -v checkov >/dev/null; then
|
||||
CKALL="$TMP/ck.json"; echo '[]' > "$CKALL"
|
||||
for p in $SCOPE_PATHS; do
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" -o json --compact --quiet 2>/dev/null || true)"
|
||||
if [ -d "$p" ]; then RAW="$(checkov -d "$p" --skip-path cdk.out --skip-path node_modules --skip-path .venv --skip-path venv --skip-path .aws-sam --skip-path dist --skip-path build -o json --compact --quiet 2>/dev/null || true)"
|
||||
else RAW="$(checkov -f "$p" -o json --compact --quiet 2>/dev/null || true)"; fi
|
||||
[ -z "$RAW" ] && continue
|
||||
FC="$(echo "$RAW" | jq '[ (if type=="array" then .[] else . end).results.failed_checks // [] ] | add // []' 2>/dev/null || echo '[]')"
|
||||
|
|
|
|||
Reference in a new issue