summaryrefslogtreecommitdiff
path: root/lib/gitlab/ci/reports/security/scanner.rb
blob: c1de03cea440bb87efce7b47e8e3afbda2a9a894 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
# frozen_string_literal: true

module Gitlab
  module Ci
    module Reports
      module Security
        class Scanner
          ANALYZER_ORDER = {
            "bundler_audit" => 1,
            "retire.js" =>  2,
            "gemnasium" => 3,
            "gemnasium-maven" => 3,
            "gemnasium-python" => 3,
            "bandit" => 1,
            "semgrep" =>  2
          }.freeze

          attr_accessor :external_id, :name, :vendor, :version

          alias_method :key, :external_id

          def initialize(external_id:, name:, vendor:, version:)
            @external_id = external_id
            @name = name
            @vendor = vendor
            @version = version
          end

          def to_hash
            {
              external_id: external_id.to_s,
              name: name.to_s,
              vendor: vendor.presence
            }.compact
          end

          def ==(other)
            other.external_id == external_id
          end

          def <=>(other)
            sort_keys.compact <=> other.sort_keys.compact
          end

          protected

          def sort_keys
            @sort_keys ||= [order, external_id, name, vendor]
          end

          private

          def order
            ANALYZER_ORDER.fetch(external_id, Float::INFINITY)
          end
        end
      end
    end
  end
end