Skip to content

Commit 2cad8bd

Browse files
feat: wire cargo-deny output into weak_points emission
Implements issue #101: Add cargo-deny scanner integration that emits weak_points for license policy violations, security advisories, banned dependencies, and unknown sources. - Add 4 new WeakPointCategory variants: LicensePolicy, Advisory, BannedDep, UnknownSource - Create src/scan/cargodeny.rs with full cargo-deny integration - Parse JSON/SARIF output and map to WeakPoint structures - Severity mapping: Error->High, Warning->Medium, Note->Low - Code-to-category mapping for RUSTSEC, CVE, banned, license, etc. - Per estate policy: do_not_automate=true for all findings - Add sarif feature to Cargo.toml - Update panll and report/sarif matches for new categories Closes #101 Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
1 parent 0f5786c commit 2cad8bd

7 files changed

Lines changed: 451 additions & 0 deletions

File tree

‎Cargo.toml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,7 @@ ureq = { version = "3.3", optional = true }
3939
default = []
4040
signing = ["ed25519-dalek"]
4141
http = ["ureq"]
42+
sarif = []
4243
# Native GUI viewer (eframe/egui). Opt-in because eframe raises MSRV above the
4344
# 1.85.0 baseline; default builds remain pure-CLI and MSRV-clean.
4445
gui = ["eframe"]

‎src/lib.rs‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,7 @@ pub mod assemblyline;
2727
pub mod attack;
2828
pub mod attestation;
2929
pub mod axial;
30+
pub mod scan;
3031
#[cfg(feature = "http")]
3132
pub mod bridge;
3233
pub mod campaign;

‎src/panll/mod.rs‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -323,6 +323,10 @@ fn category_label(cat: WeakPointCategory) -> &'static str {
323323
WeakPointCategory::SupplyChain => "supply-chain",
324324
WeakPointCategory::InputBoundary => "input-boundary",
325325
WeakPointCategory::MutationGap => "mutation-gap",
326+
WeakPointCategory::LicensePolicy => "license-policy",
327+
WeakPointCategory::Advisory => "advisory",
328+
WeakPointCategory::BannedDep => "banned-dep",
329+
WeakPointCategory::UnknownSource => "unknown-source",
326330
}
327331
}
328332

‎src/report/sarif.rs‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -141,6 +141,10 @@ pub(crate) fn rule_id(category: &WeakPointCategory) -> &'static str {
141141
WeakPointCategory::SupplyChain => "PA023",
142142
WeakPointCategory::InputBoundary => "PA024",
143143
WeakPointCategory::MutationGap => "PA025",
144+
WeakPointCategory::LicensePolicy => "PA026",
145+
WeakPointCategory::Advisory => "PA027",
146+
WeakPointCategory::BannedDep => "PA028",
147+
WeakPointCategory::UnknownSource => "PA029",
144148
}
145149
}
146150

@@ -173,6 +177,10 @@ pub(crate) fn rule_name(category: &WeakPointCategory) -> &'static str {
173177
WeakPointCategory::SupplyChain => "supply-chain",
174178
WeakPointCategory::InputBoundary => "input-boundary",
175179
WeakPointCategory::MutationGap => "mutation-gap",
180+
WeakPointCategory::LicensePolicy => "license-policy",
181+
WeakPointCategory::Advisory => "advisory",
182+
WeakPointCategory::BannedDep => "banned-dep",
183+
WeakPointCategory::UnknownSource => "unknown-source",
176184
}
177185
}
178186

0 commit comments

Comments
 (0)