coinbase / salus

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.
23 stars 1 forks source link

Support CWE in SARIF where available #821

Closed joshuaostrom-cb closed 1 year ago

joshuaostrom-cb commented 1 year ago

Normalizing the usage of SARIF messageStrings:cwe.

Currently npm audit and gosec scanners use this field. This PR expand this to additional scanners.

** CVE info available - marked accordingly. This PR also documents the available fields across SARIF adapters. The gosec CWE has been normalized to use the CWE and not the URL