@gpzhang2001/sharpkit-reporting
v0.2.2
Published
Vulnerability/dependency reporting tools + sharpkit_runs artifacts (run.json, vuln markdown, csv/json, SARIF 2.1.0)
Readme
@gpzhang2001/sharpkit-reporting
漏洞/依赖报告五工具 + sharpkit_runs/ 产物体系(run.json、SARIF 2.1.0、逐漏洞 Markdown)。
工具
- create_vulnerability_report:23 参数全量移植;severity/CVSS 由 8 指标
cvss_breakdown计算(v3.1 公式与 Pythoncvss包对拍:6.42×ISC / Scope C 7.52 公式 + 1.08 总分乘数、Roundup1);code_locations 规范化 + fix_verification/上下文依赖校验;broad CWE 拒绝 - create_dependency_report:CVE×package 一报告;advisory/contextual 双评分(contextual 缺一即弃,strix 语义);manifest_path/reachability 证据运行时强制
- update_vulnerability_report:白名单 + 依赖字段丢弃(confidence→rationale 等 4 对)+ update_history(含 previous_* 捕获)+ 跨类字段拒绝 + 依赖重评级需 contextual reasoning
- list_reports:过滤器 AND 组合、severity rank 排序、compact 摘要(280 字符预览)/全量两种
- get_report:
vuln-NNNN精确查找
产物体系
每次增改触发全量落盘(state.py _save_artifacts 顺序):vulnerabilities/*.md(增量渲染)→ vulnerabilities.csv(\r\n、大写 severity、公式注入防护、rank+时间排序)→ vulnerabilities.json → findings.sarif(空结果也写,覆盖陈旧文件)→ run.json(最后写)。全部原子写(同目录临时文件 + rename,无 fsync,strix 语义)。
SARIF 2.1.0:CWE→CVE→id→slug 规则 ID、GitHub security-severity、STRIDE 标签(CWE 映射全量移植)、物理+SECURITY.md 合成位置、PR 建议 fixes、确定性 sha256 partialFingerprints、strix 命名空间属性(PoC 脚本体永不出境,只带 description + script_available 标志)。
去重
依赖发现走确定性快路径(CVE×package×ecosystem、不同 manifest=两个发现、legacy 词边界匹配);动态发现的 LLM judge 为 Config 注入回调,judge 失败/缺席一律判非重复。
Golden 测试
tests/golden/ 存放原版 strix 代码(uv run)对同一输入生成的产物;golden.test.ts 断言 TS 输出逐字节一致——md×2/csv/json/sarif/run.json 共 6 项。过程捕获并修正了两处偏差:code location 段的 2 空格缩进 + Suggested Fix 空行、元数据行序(dependency 块在 CVE/CWE 之前、Advisory CVSS ≠ CVSS 才显示)。
测试
tests/reporting.test.ts:CVSS 数学(与 Python cvss 包 5 向量对拍:9.8/6.5/4.4/0.0/10.0)、state(字段序/依赖丢弃/history/hydrate)、normalizers、dedupe 快路径。
