From f7666b86c1e7aafa23525ba816b844b37e6178b3 Mon Sep 17 00:00:00 2001 From: stacknil Date: Tue, 28 Apr 2026 18:05:18 +0800 Subject: [PATCH] release sbom-diff-and-risk v0.5.1 --- tools/sbom-diff-and-risk/README.md | 2 +- .../RELEASE_NOTES_v0.5.1.md | 7 + .../examples/sample-provenance-report.sarif | 300 ++++----- .../examples/sample-sarif.sarif | 600 +++++++++--------- .../examples/sample-scorecard-report.sarif | 200 +++--- tools/sbom-diff-and-risk/pyproject.toml | 108 ++-- .../src/sbom_diff_risk/__init__.py | 10 +- 7 files changed, 617 insertions(+), 610 deletions(-) create mode 100644 tools/sbom-diff-and-risk/RELEASE_NOTES_v0.5.1.md diff --git a/tools/sbom-diff-and-risk/README.md b/tools/sbom-diff-and-risk/README.md index 81d0a05..c1a6440 100644 --- a/tools/sbom-diff-and-risk/README.md +++ b/tools/sbom-diff-and-risk/README.md @@ -1,6 +1,6 @@ # sbom-diff-and-risk -v0.5.0 is the GitHub Release for the production PyPI decision gate. The TestPyPI dry-run is completed, production PyPI publishing is intentionally deferred, dependency analysis stays local and deterministic by default, and CLI analysis behavior is unchanged. +v0.5.1 is a release-only maintenance update for the GitHub Release checksum manifest path. It keeps CLI analysis behavior unchanged, keeps dependency analysis local and deterministic by default, preserves the completed TestPyPI dry-run story, and keeps production PyPI publishing intentionally deferred. `sbom-diff-and-risk` is a local, deterministic CLI for comparing two SBOMs or dependency manifests and producing JSON plus Markdown reports. diff --git a/tools/sbom-diff-and-risk/RELEASE_NOTES_v0.5.1.md b/tools/sbom-diff-and-risk/RELEASE_NOTES_v0.5.1.md new file mode 100644 index 0000000..6ade38e --- /dev/null +++ b/tools/sbom-diff-and-risk/RELEASE_NOTES_v0.5.1.md @@ -0,0 +1,7 @@ +## sbom-diff-and-risk v0.5.1 + +Release-only maintenance update. + +- Adds `sbom-diff-and-risk-SHA256SUMS.txt` to GitHub Release assets. +- Keeps CLI behavior unchanged. +- Keeps production PyPI deferred. diff --git a/tools/sbom-diff-and-risk/examples/sample-provenance-report.sarif b/tools/sbom-diff-and-risk/examples/sample-provenance-report.sarif index 227cee4..edd83ff 100644 --- a/tools/sbom-diff-and-risk/examples/sample-provenance-report.sarif +++ b/tools/sbom-diff-and-risk/examples/sample-provenance-report.sarif @@ -1,150 +1,150 @@ -{ - "$schema": "https://json.schemastore.org/sarif-2.1.0.json", - "version": "2.1.0", - "runs": [ - { - "tool": { - "driver": { - "name": "sbom-diff-risk", - "fullName": "sbom-diff-risk", - "version": "0.5.0", - "semanticVersion": "0.5.0", - "rules": [ - { - "id": "sdr.policy_violation.provenance_required", - "name": "policy_violation.provenance_required", - "shortDescription": { - "text": "Policy violation: provenance_required" - }, - "fullDescription": { - "text": "A configured provenance requirement was not satisfied for the component." - }, - "defaultConfiguration": { - "level": "error" - }, - "properties": { - "tags": [ - "supply-chain", - "policy", - "provenance" - ] - } - }, - { - "id": "sdr.policy_violation.unverified_provenance", - "name": "policy_violation.unverified_provenance", - "shortDescription": { - "text": "Policy violation: unverified_provenance" - }, - "fullDescription": { - "text": "PyPI attestations were present, but provenance could not be verified against publisher metadata." - }, - "defaultConfiguration": { - "level": "error" - }, - "properties": { - "tags": [ - "supply-chain", - "policy", - "provenance" - ] - } - } - ] - } - }, - "artifacts": [ - { - "location": { - "uri": "examples/requirements_before.txt", - "uriBaseId": "%SRCROOT%" - } - }, - { - "location": { - "uri": "examples/requirements_after.txt", - "uriBaseId": "%SRCROOT%" - } - } - ], - "properties": { - "sbom_diff_risk": { - "result_limit": 5000, - "total_candidate_results": 2, - "emitted_results": 2, - "omitted_results": 0, - "truncated": false, - "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", - "warning": null - } - }, - "results": [ - { - "ruleId": "sdr.policy_violation.provenance_required", - "level": "error", - "message": { - "text": "mystery-lib: Provenance required for new package; no attestations were published." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/requirements_after.txt", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.policy_violation.provenance_required", - "componentKey": "purl:pkg:pypi/mystery-lib" - }, - "properties": { - "policy_rule_id": "provenance_required", - "component_key": "purl:pkg:pypi/mystery-lib", - "component_name": "mystery-lib", - "result_kind": "policy_violation" - } - }, - { - "ruleId": "sdr.policy_violation.unverified_provenance", - "level": "error", - "message": { - "text": "legacy-lib: PyPI attestation publisher could not be verified by policy." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/requirements_after.txt", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.policy_violation.unverified_provenance", - "componentKey": "purl:pkg:pypi/legacy-lib" - }, - "properties": { - "policy_rule_id": "unverified_provenance", - "component_key": "purl:pkg:pypi/legacy-lib", - "component_name": "legacy-lib", - "result_kind": "policy_violation" - } - } - ], - "originalUriBaseIds": { - "%SRCROOT%": { - "uri": "file:///__PROJECT_ROOT__/" - } - } - } - ] -} +{ + "$schema": "https://json.schemastore.org/sarif-2.1.0.json", + "version": "2.1.0", + "runs": [ + { + "tool": { + "driver": { + "name": "sbom-diff-risk", + "fullName": "sbom-diff-risk", + "version": "0.5.1", + "semanticVersion": "0.5.1", + "rules": [ + { + "id": "sdr.policy_violation.provenance_required", + "name": "policy_violation.provenance_required", + "shortDescription": { + "text": "Policy violation: provenance_required" + }, + "fullDescription": { + "text": "A configured provenance requirement was not satisfied for the component." + }, + "defaultConfiguration": { + "level": "error" + }, + "properties": { + "tags": [ + "supply-chain", + "policy", + "provenance" + ] + } + }, + { + "id": "sdr.policy_violation.unverified_provenance", + "name": "policy_violation.unverified_provenance", + "shortDescription": { + "text": "Policy violation: unverified_provenance" + }, + "fullDescription": { + "text": "PyPI attestations were present, but provenance could not be verified against publisher metadata." + }, + "defaultConfiguration": { + "level": "error" + }, + "properties": { + "tags": [ + "supply-chain", + "policy", + "provenance" + ] + } + } + ] + } + }, + "artifacts": [ + { + "location": { + "uri": "examples/requirements_before.txt", + "uriBaseId": "%SRCROOT%" + } + }, + { + "location": { + "uri": "examples/requirements_after.txt", + "uriBaseId": "%SRCROOT%" + } + } + ], + "properties": { + "sbom_diff_risk": { + "result_limit": 5000, + "total_candidate_results": 2, + "emitted_results": 2, + "omitted_results": 0, + "truncated": false, + "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", + "warning": null + } + }, + "results": [ + { + "ruleId": "sdr.policy_violation.provenance_required", + "level": "error", + "message": { + "text": "mystery-lib: Provenance required for new package; no attestations were published." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/requirements_after.txt", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.policy_violation.provenance_required", + "componentKey": "purl:pkg:pypi/mystery-lib" + }, + "properties": { + "policy_rule_id": "provenance_required", + "component_key": "purl:pkg:pypi/mystery-lib", + "component_name": "mystery-lib", + "result_kind": "policy_violation" + } + }, + { + "ruleId": "sdr.policy_violation.unverified_provenance", + "level": "error", + "message": { + "text": "legacy-lib: PyPI attestation publisher could not be verified by policy." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/requirements_after.txt", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.policy_violation.unverified_provenance", + "componentKey": "purl:pkg:pypi/legacy-lib" + }, + "properties": { + "policy_rule_id": "unverified_provenance", + "component_key": "purl:pkg:pypi/legacy-lib", + "component_name": "legacy-lib", + "result_kind": "policy_violation" + } + } + ], + "originalUriBaseIds": { + "%SRCROOT%": { + "uri": "file:///__PROJECT_ROOT__/" + } + } + } + ] +} diff --git a/tools/sbom-diff-and-risk/examples/sample-sarif.sarif b/tools/sbom-diff-and-risk/examples/sample-sarif.sarif index a892db1..4b47a5b 100644 --- a/tools/sbom-diff-and-risk/examples/sample-sarif.sarif +++ b/tools/sbom-diff-and-risk/examples/sample-sarif.sarif @@ -1,300 +1,300 @@ -{ - "$schema": "https://json.schemastore.org/sarif-2.1.0.json", - "version": "2.1.0", - "runs": [ - { - "tool": { - "driver": { - "name": "sbom-diff-risk", - "fullName": "sbom-diff-risk", - "version": "0.5.0", - "semanticVersion": "0.5.0", - "rules": [ - { - "id": "sdr.major_upgrade", - "name": "major_upgrade", - "shortDescription": { - "text": "Version change is a parseable SemVer major upgrade." - }, - "fullDescription": { - "text": "Version change is a parseable SemVer major upgrade." - }, - "defaultConfiguration": { - "level": "note" - }, - "properties": { - "tags": [ - "supply-chain", - "sbom" - ] - } - }, - { - "id": "sdr.policy_violation.allow_sources", - "name": "policy_violation.allow_sources", - "shortDescription": { - "text": "Policy violation: allow_sources" - }, - "fullDescription": { - "text": "Component source host was not present in the configured allow_sources list." - }, - "defaultConfiguration": { - "level": "error" - }, - "properties": { - "tags": [ - "supply-chain", - "policy" - ] - } - }, - { - "id": "sdr.policy_violation.max_added_packages", - "name": "policy_violation.max_added_packages", - "shortDescription": { - "text": "Policy violation: max_added_packages" - }, - "fullDescription": { - "text": "Added package count exceeded the configured deterministic threshold." - }, - "defaultConfiguration": { - "level": "error" - }, - "properties": { - "tags": [ - "supply-chain", - "policy" - ] - } - }, - { - "id": "sdr.suspicious_source", - "name": "suspicious_source", - "shortDescription": { - "text": "Source provenance is missing or points to a suspicious scheme, path, or host." - }, - "fullDescription": { - "text": "Source provenance is missing or points to a suspicious scheme, path, or host." - }, - "defaultConfiguration": { - "level": "warning" - }, - "properties": { - "tags": [ - "supply-chain", - "sbom" - ] - } - }, - { - "id": "sdr.unknown_license", - "name": "unknown_license", - "shortDescription": { - "text": "License metadata is missing, empty, UNKNOWN, or NOASSERTION." - }, - "fullDescription": { - "text": "License metadata is missing, empty, UNKNOWN, or NOASSERTION." - }, - "defaultConfiguration": { - "level": "warning" - }, - "properties": { - "tags": [ - "supply-chain", - "sbom" - ] - } - } - ] - } - }, - "artifacts": [ - { - "location": { - "uri": "examples/sarif_before.json", - "uriBaseId": "%SRCROOT%" - } - }, - { - "location": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - } - } - ], - "properties": { - "sbom_diff_risk": { - "result_limit": 5000, - "total_candidate_results": 5, - "emitted_results": 5, - "omitted_results": 0, - "truncated": false, - "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", - "warning": null - } - }, - "results": [ - { - "ruleId": "sdr.suspicious_source", - "level": "error", - "message": { - "text": "Blocked by policy: mystery-lib 0.1.0 has suspicious or incomplete source provenance." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.suspicious_source", - "componentKey": "purl:pkg:pypi/mystery-lib" - }, - "properties": { - "component_key": "purl:pkg:pypi/mystery-lib", - "component_name": "mystery-lib", - "finding_bucket": "suspicious_source", - "policy_blocking": true, - "result_kind": "risk_finding", - "blocking_rule_id": "suspicious_source" - } - }, - { - "ruleId": "sdr.unknown_license", - "level": "error", - "message": { - "text": "Blocked by policy: mystery-lib 0.1.0 has missing or unknown license metadata." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.unknown_license", - "componentKey": "purl:pkg:pypi/mystery-lib" - }, - "properties": { - "component_key": "purl:pkg:pypi/mystery-lib", - "component_name": "mystery-lib", - "finding_bucket": "unknown_license", - "policy_blocking": true, - "result_kind": "risk_finding", - "blocking_rule_id": "unknown_license" - } - }, - { - "ruleId": "sdr.policy_violation.allow_sources", - "level": "error", - "message": { - "text": "mystery-lib: Source host 198.51.100.10 is not present in allow_sources." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.policy_violation.allow_sources", - "componentKey": "purl:pkg:pypi/mystery-lib" - }, - "properties": { - "policy_rule_id": "allow_sources", - "component_key": "purl:pkg:pypi/mystery-lib", - "component_name": "mystery-lib", - "result_kind": "policy_violation" - } - }, - { - "ruleId": "sdr.policy_violation.max_added_packages", - "level": "error", - "message": { - "text": "Added package count 1 exceeds max_added_packages=0." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.policy_violation.max_added_packages", - "componentKey": "global-policy-check" - }, - "properties": { - "policy_rule_id": "max_added_packages", - "component_key": null, - "component_name": null, - "result_kind": "policy_violation" - } - }, - { - "ruleId": "sdr.major_upgrade", - "level": "note", - "message": { - "text": "Version changed from 1.9.0 to 2.0.0 with a higher major version." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/sarif_after.json", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.major_upgrade", - "componentKey": "purl:pkg:pypi/requests" - }, - "properties": { - "component_key": "purl:pkg:pypi/requests", - "component_name": "requests", - "finding_bucket": "major_upgrade", - "policy_blocking": false, - "result_kind": "risk_finding" - } - } - ], - "originalUriBaseIds": { - "%SRCROOT%": { - "uri": "file:///__PROJECT_ROOT__/" - } - } - } - ] -} +{ + "$schema": "https://json.schemastore.org/sarif-2.1.0.json", + "version": "2.1.0", + "runs": [ + { + "tool": { + "driver": { + "name": "sbom-diff-risk", + "fullName": "sbom-diff-risk", + "version": "0.5.1", + "semanticVersion": "0.5.1", + "rules": [ + { + "id": "sdr.major_upgrade", + "name": "major_upgrade", + "shortDescription": { + "text": "Version change is a parseable SemVer major upgrade." + }, + "fullDescription": { + "text": "Version change is a parseable SemVer major upgrade." + }, + "defaultConfiguration": { + "level": "note" + }, + "properties": { + "tags": [ + "supply-chain", + "sbom" + ] + } + }, + { + "id": "sdr.policy_violation.allow_sources", + "name": "policy_violation.allow_sources", + "shortDescription": { + "text": "Policy violation: allow_sources" + }, + "fullDescription": { + "text": "Component source host was not present in the configured allow_sources list." + }, + "defaultConfiguration": { + "level": "error" + }, + "properties": { + "tags": [ + "supply-chain", + "policy" + ] + } + }, + { + "id": "sdr.policy_violation.max_added_packages", + "name": "policy_violation.max_added_packages", + "shortDescription": { + "text": "Policy violation: max_added_packages" + }, + "fullDescription": { + "text": "Added package count exceeded the configured deterministic threshold." + }, + "defaultConfiguration": { + "level": "error" + }, + "properties": { + "tags": [ + "supply-chain", + "policy" + ] + } + }, + { + "id": "sdr.suspicious_source", + "name": "suspicious_source", + "shortDescription": { + "text": "Source provenance is missing or points to a suspicious scheme, path, or host." + }, + "fullDescription": { + "text": "Source provenance is missing or points to a suspicious scheme, path, or host." + }, + "defaultConfiguration": { + "level": "warning" + }, + "properties": { + "tags": [ + "supply-chain", + "sbom" + ] + } + }, + { + "id": "sdr.unknown_license", + "name": "unknown_license", + "shortDescription": { + "text": "License metadata is missing, empty, UNKNOWN, or NOASSERTION." + }, + "fullDescription": { + "text": "License metadata is missing, empty, UNKNOWN, or NOASSERTION." + }, + "defaultConfiguration": { + "level": "warning" + }, + "properties": { + "tags": [ + "supply-chain", + "sbom" + ] + } + } + ] + } + }, + "artifacts": [ + { + "location": { + "uri": "examples/sarif_before.json", + "uriBaseId": "%SRCROOT%" + } + }, + { + "location": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + } + } + ], + "properties": { + "sbom_diff_risk": { + "result_limit": 5000, + "total_candidate_results": 5, + "emitted_results": 5, + "omitted_results": 0, + "truncated": false, + "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", + "warning": null + } + }, + "results": [ + { + "ruleId": "sdr.suspicious_source", + "level": "error", + "message": { + "text": "Blocked by policy: mystery-lib 0.1.0 has suspicious or incomplete source provenance." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.suspicious_source", + "componentKey": "purl:pkg:pypi/mystery-lib" + }, + "properties": { + "component_key": "purl:pkg:pypi/mystery-lib", + "component_name": "mystery-lib", + "finding_bucket": "suspicious_source", + "policy_blocking": true, + "result_kind": "risk_finding", + "blocking_rule_id": "suspicious_source" + } + }, + { + "ruleId": "sdr.unknown_license", + "level": "error", + "message": { + "text": "Blocked by policy: mystery-lib 0.1.0 has missing or unknown license metadata." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.unknown_license", + "componentKey": "purl:pkg:pypi/mystery-lib" + }, + "properties": { + "component_key": "purl:pkg:pypi/mystery-lib", + "component_name": "mystery-lib", + "finding_bucket": "unknown_license", + "policy_blocking": true, + "result_kind": "risk_finding", + "blocking_rule_id": "unknown_license" + } + }, + { + "ruleId": "sdr.policy_violation.allow_sources", + "level": "error", + "message": { + "text": "mystery-lib: Source host 198.51.100.10 is not present in allow_sources." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.policy_violation.allow_sources", + "componentKey": "purl:pkg:pypi/mystery-lib" + }, + "properties": { + "policy_rule_id": "allow_sources", + "component_key": "purl:pkg:pypi/mystery-lib", + "component_name": "mystery-lib", + "result_kind": "policy_violation" + } + }, + { + "ruleId": "sdr.policy_violation.max_added_packages", + "level": "error", + "message": { + "text": "Added package count 1 exceeds max_added_packages=0." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.policy_violation.max_added_packages", + "componentKey": "global-policy-check" + }, + "properties": { + "policy_rule_id": "max_added_packages", + "component_key": null, + "component_name": null, + "result_kind": "policy_violation" + } + }, + { + "ruleId": "sdr.major_upgrade", + "level": "note", + "message": { + "text": "Version changed from 1.9.0 to 2.0.0 with a higher major version." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/sarif_after.json", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.major_upgrade", + "componentKey": "purl:pkg:pypi/requests" + }, + "properties": { + "component_key": "purl:pkg:pypi/requests", + "component_name": "requests", + "finding_bucket": "major_upgrade", + "policy_blocking": false, + "result_kind": "risk_finding" + } + } + ], + "originalUriBaseIds": { + "%SRCROOT%": { + "uri": "file:///__PROJECT_ROOT__/" + } + } + } + ] +} diff --git a/tools/sbom-diff-and-risk/examples/sample-scorecard-report.sarif b/tools/sbom-diff-and-risk/examples/sample-scorecard-report.sarif index ca18b44..5fd9f34 100644 --- a/tools/sbom-diff-and-risk/examples/sample-scorecard-report.sarif +++ b/tools/sbom-diff-and-risk/examples/sample-scorecard-report.sarif @@ -1,100 +1,100 @@ -{ - "$schema": "https://json.schemastore.org/sarif-2.1.0.json", - "version": "2.1.0", - "runs": [ - { - "tool": { - "driver": { - "name": "sbom-diff-risk", - "fullName": "sbom-diff-risk", - "version": "0.5.0", - "semanticVersion": "0.5.0", - "rules": [ - { - "id": "sdr.policy_violation.scorecard_below_threshold", - "name": "policy_violation.scorecard_below_threshold", - "shortDescription": { - "text": "Policy violation: scorecard_below_threshold" - }, - "fullDescription": { - "text": "A mapped repository's OpenSSF Scorecard score was below the configured minimum threshold." - }, - "defaultConfiguration": { - "level": "warning" - }, - "properties": { - "tags": [ - "supply-chain", - "policy", - "scorecard" - ] - } - } - ] - } - }, - "artifacts": [ - { - "location": { - "uri": "examples/requirements_before.txt", - "uriBaseId": "%SRCROOT%" - } - }, - { - "location": { - "uri": "examples/requirements_after.txt", - "uriBaseId": "%SRCROOT%" - } - } - ], - "properties": { - "sbom_diff_risk": { - "result_limit": 5000, - "total_candidate_results": 1, - "emitted_results": 1, - "omitted_results": 0, - "truncated": false, - "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", - "warning": null - } - }, - "results": [ - { - "ruleId": "sdr.policy_violation.scorecard_below_threshold", - "level": "warning", - "message": { - "text": "requests: Scorecard score 6.0 is below minimum_scorecard_score=7.0 for repository github.com/psf/requests." - }, - "locations": [ - { - "physicalLocation": { - "artifactLocation": { - "uri": "examples/requirements_after.txt", - "uriBaseId": "%SRCROOT%" - }, - "region": { - "startLine": 1 - } - } - } - ], - "partialFingerprints": { - "ruleId": "sdr.policy_violation.scorecard_below_threshold", - "componentKey": "purl:pkg:pypi/requests" - }, - "properties": { - "policy_rule_id": "scorecard_below_threshold", - "component_key": "purl:pkg:pypi/requests", - "component_name": "requests", - "result_kind": "policy_violation" - } - } - ], - "originalUriBaseIds": { - "%SRCROOT%": { - "uri": "file:///__PROJECT_ROOT__/" - } - } - } - ] -} +{ + "$schema": "https://json.schemastore.org/sarif-2.1.0.json", + "version": "2.1.0", + "runs": [ + { + "tool": { + "driver": { + "name": "sbom-diff-risk", + "fullName": "sbom-diff-risk", + "version": "0.5.1", + "semanticVersion": "0.5.1", + "rules": [ + { + "id": "sdr.policy_violation.scorecard_below_threshold", + "name": "policy_violation.scorecard_below_threshold", + "shortDescription": { + "text": "Policy violation: scorecard_below_threshold" + }, + "fullDescription": { + "text": "A mapped repository's OpenSSF Scorecard score was below the configured minimum threshold." + }, + "defaultConfiguration": { + "level": "warning" + }, + "properties": { + "tags": [ + "supply-chain", + "policy", + "scorecard" + ] + } + } + ] + } + }, + "artifacts": [ + { + "location": { + "uri": "examples/requirements_before.txt", + "uriBaseId": "%SRCROOT%" + } + }, + { + "location": { + "uri": "examples/requirements_after.txt", + "uriBaseId": "%SRCROOT%" + } + } + ], + "properties": { + "sbom_diff_risk": { + "result_limit": 5000, + "total_candidate_results": 1, + "emitted_results": 1, + "omitted_results": 0, + "truncated": false, + "prioritization": "error results first, then warning, then note; direct mapped findings before policy-only checks; stable rule priority and component key tie-breakers.", + "warning": null + } + }, + "results": [ + { + "ruleId": "sdr.policy_violation.scorecard_below_threshold", + "level": "warning", + "message": { + "text": "requests: Scorecard score 6.0 is below minimum_scorecard_score=7.0 for repository github.com/psf/requests." + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "examples/requirements_after.txt", + "uriBaseId": "%SRCROOT%" + }, + "region": { + "startLine": 1 + } + } + } + ], + "partialFingerprints": { + "ruleId": "sdr.policy_violation.scorecard_below_threshold", + "componentKey": "purl:pkg:pypi/requests" + }, + "properties": { + "policy_rule_id": "scorecard_below_threshold", + "component_key": "purl:pkg:pypi/requests", + "component_name": "requests", + "result_kind": "policy_violation" + } + } + ], + "originalUriBaseIds": { + "%SRCROOT%": { + "uri": "file:///__PROJECT_ROOT__/" + } + } + } + ] +} diff --git a/tools/sbom-diff-and-risk/pyproject.toml b/tools/sbom-diff-and-risk/pyproject.toml index c5b4e8c..256ed6a 100644 --- a/tools/sbom-diff-and-risk/pyproject.toml +++ b/tools/sbom-diff-and-risk/pyproject.toml @@ -1,54 +1,54 @@ -[build-system] -requires = ["setuptools>=69"] -build-backend = "setuptools.build_meta" - -[project] -name = "sbom-diff-and-risk" -version = "0.5.0" -description = "Deterministic SBOM diff CLI with heuristic risk reporting." -readme = { file = "PYPI_DESCRIPTION.md", content-type = "text/markdown" } -requires-python = ">=3.11" -license = "MIT" -authors = [ - { name = "OpenAI Codex" } -] -keywords = ["sbom", "supply-chain", "cyclonedx", "spdx", "dependencies"] -classifiers = [ - "Development Status :: 3 - Alpha", - "Environment :: Console", - "Intended Audience :: Developers", - "Operating System :: OS Independent", - "Programming Language :: Python :: 3", - "Programming Language :: Python :: 3 :: Only", - "Programming Language :: Python :: 3.11", - "Topic :: Security", - "Topic :: Software Development :: Libraries :: Python Modules", -] -dependencies = [ - "packaging>=24.0", - "PyYAML>=6.0", -] - -[project.urls] -Homepage = "https://github.com/stacknil/scientific-computing-toolkit" -Repository = "https://github.com/stacknil/scientific-computing-toolkit" -Issues = "https://github.com/stacknil/scientific-computing-toolkit/issues" -Releases = "https://github.com/stacknil/scientific-computing-toolkit/releases" - -[project.optional-dependencies] -dev = [ - "pytest>=8.0", -] - -[project.scripts] -sbom-diff-risk = "sbom_diff_risk.cli:main" - -[tool.setuptools] -package-dir = { "" = "src" } - -[tool.setuptools.packages.find] -where = ["src"] - -[tool.pytest.ini_options] -addopts = "-ra" -testpaths = ["tests"] +[build-system] +requires = ["setuptools>=69"] +build-backend = "setuptools.build_meta" + +[project] +name = "sbom-diff-and-risk" +version = "0.5.1" +description = "Deterministic SBOM diff CLI with heuristic risk reporting." +readme = { file = "PYPI_DESCRIPTION.md", content-type = "text/markdown" } +requires-python = ">=3.11" +license = "MIT" +authors = [ + { name = "OpenAI Codex" } +] +keywords = ["sbom", "supply-chain", "cyclonedx", "spdx", "dependencies"] +classifiers = [ + "Development Status :: 3 - Alpha", + "Environment :: Console", + "Intended Audience :: Developers", + "Operating System :: OS Independent", + "Programming Language :: Python :: 3", + "Programming Language :: Python :: 3 :: Only", + "Programming Language :: Python :: 3.11", + "Topic :: Security", + "Topic :: Software Development :: Libraries :: Python Modules", +] +dependencies = [ + "packaging>=24.0", + "PyYAML>=6.0", +] + +[project.urls] +Homepage = "https://github.com/stacknil/scientific-computing-toolkit" +Repository = "https://github.com/stacknil/scientific-computing-toolkit" +Issues = "https://github.com/stacknil/scientific-computing-toolkit/issues" +Releases = "https://github.com/stacknil/scientific-computing-toolkit/releases" + +[project.optional-dependencies] +dev = [ + "pytest>=8.0", +] + +[project.scripts] +sbom-diff-risk = "sbom_diff_risk.cli:main" + +[tool.setuptools] +package-dir = { "" = "src" } + +[tool.setuptools.packages.find] +where = ["src"] + +[tool.pytest.ini_options] +addopts = "-ra" +testpaths = ["tests"] diff --git a/tools/sbom-diff-and-risk/src/sbom_diff_risk/__init__.py b/tools/sbom-diff-and-risk/src/sbom_diff_risk/__init__.py index 7f50f69..a665cc0 100644 --- a/tools/sbom-diff-and-risk/src/sbom_diff_risk/__init__.py +++ b/tools/sbom-diff-and-risk/src/sbom_diff_risk/__init__.py @@ -1,5 +1,5 @@ -"""sbom-diff-and-risk package.""" - -__all__ = ["__version__"] - -__version__ = "0.5.0" +"""sbom-diff-and-risk package.""" + +__all__ = ["__version__"] + +__version__ = "0.5.1"