Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

🎉 Importing EPSS score from Snyk #9527

Closed
wants to merge 61 commits into from
Closed
Show file tree
Hide file tree
Changes from 3 commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
9b55262
:tada: update for snyk parser: added epss score import
quirinziessler Feb 12, 2024
a0e5c1b
flake8
quirinziessler Feb 12, 2024
4662f95
:pencil2:
quirinziessler Feb 12, 2024
5494156
Parse GitHub vulnerability version (#9462)
coheigea Feb 6, 2024
6e11b51
Fix SARIF parser with CodeQL rules (#9440)
ansereb Feb 6, 2024
77350af
finding sla expiration date field (part two) (#9494)
blakeaowens Feb 9, 2024
76c887b
Jira Server/DataCenter: Update meta methods (#9512)
Maffooch Feb 12, 2024
a110f86
Jira Webhook: Catch comments from other issue updates (#9513)
Maffooch Feb 12, 2024
5eb2d1b
Release Drafter: Try validating inputs
Maffooch Feb 12, 2024
a3403a4
Disallow duplicate tool types (#9530)
Maffooch Feb 12, 2024
6da78c5
Engagement Surveys: Add missing leading slash (#9531)
Maffooch Feb 12, 2024
b1aac23
Update versions in application files
Feb 12, 2024
ccb892d
Update versions in application files
Feb 12, 2024
5083abd
Fix "Overdue" tag still visible with closed issues (#9539)
FelixHernandez Feb 13, 2024
1b3ad30
Update google-sheets-sync.md with deprecation notice (#9495)
paulOsinski Feb 15, 2024
1a03c8c
Fix handling of incorrect if test import fail (#9544)
kiblik Feb 20, 2024
0359221
Labeler: Add sync-labels (#9565)
kiblik Feb 20, 2024
11d7ca6
Questionnaires: Correct nested object deletions (#9574)
Maffooch Feb 20, 2024
b11534c
Jira: Append labels and respect priority on update (#9571)
Maffooch Feb 20, 2024
396f188
Correct Endpoint "Hosts" views when the host field is `None` (#9560)
Maffooch Feb 20, 2024
80d5f50
Deduplication: Do not reopen original finding (#9558)
Maffooch Feb 20, 2024
029a7bc
Update versions in application files
Feb 20, 2024
36094da
Update versions in application files
Feb 20, 2024
343d8e8
Dojo_Group: Support for "RemoteUser" in model (#9405)
kiblik Feb 12, 2024
cc82809
Update rabbitmq:3.12.12-alpine Docker digest from 3.12.12 to 3.12.12-…
renovate[bot] Feb 13, 2024
a0939e7
remove flot-axis library (#9540)
FelixHernandez Feb 13, 2024
6c57bc4
use full url for helm-repos and alias in renovate.json (#9525)
rndmh3ro Feb 14, 2024
9c721a1
Update Helm release redis from 16.12.3 to ~16.13.0 (helm/defectdojo/C…
renovate[bot] Feb 15, 2024
81e1399
Update rabbitmq:3.12.12-alpine Docker digest from 3.12.12 to 3.12.12-…
renovate[bot] Feb 15, 2024
a9e49d7
Update postgres Docker tag from 16.1 to v16.2 (docker-compose.yml) (#…
renovate[bot] Feb 15, 2024
1dadb7b
Update Helm release mysql from 9.1.8 to ~9.19.0 (helm/defectdojo/Char…
renovate[bot] Feb 15, 2024
1fff040
Update Helm release rabbitmq from 11.2.2 to ~11.16.0 (helm/defectdojo…
renovate[bot] Feb 15, 2024
ac63f30
Update Helm release postgresql from 11.6.26 to ~11.9.0 (helm/defectdo…
renovate[bot] Feb 15, 2024
6f97da2
Update Helm release postgresql-ha from 9.1.9 to ~9.4.0 (helm/defectdo…
renovate[bot] Feb 15, 2024
e912bf7
Remove DD_USE_L10N (#9491)
kiblik Feb 15, 2024
123148e
API: removal of drf_yasg (OpenAPI 2.0 Swagger) (#9108)
kiblik Feb 15, 2024
b4b29d7
Drop filterwarnings "unclosed file" (#9498)
kiblik Feb 15, 2024
ce9fbb3
:bug: WFuzz: Generalize severity mapping (#9505)
manuel-sommer Feb 15, 2024
abe7d06
Remove useless noqa, be more specific for usefull noqa (#9510)
kiblik Feb 15, 2024
9ef3fff
:sparkles: add burp dastardly (#9514)
manuel-sommer Feb 15, 2024
8eff704
Remove filterwarnings for "invalid escape sequence" (#9496)
kiblik Feb 16, 2024
fa8cc50
:bug: fix mobsf deduplication and severity mapping (#9471)
manuel-sommer Feb 16, 2024
73565d7
Remove filterwarnings for "DateTimeField - timezone" (#9497)
kiblik Feb 16, 2024
c802303
Update Helm release postgresql-ha from 9.4.11 to v13 (helm/defectdojo…
renovate[bot] Feb 16, 2024
a878218
Remove handling of broken unittests (#9504)
kiblik Feb 16, 2024
5173a49
:tada: introducing EPSS score (#9516)
quirinziessler Feb 20, 2024
80d5d79
:tada: importing epss score from DependencyTrack output (#9521)
quirinziessler Feb 20, 2024
83eb26b
improved Sonatype parser (#9519)
reichertan Feb 20, 2024
7eee8dc
fix clair docs according to PR #9355 (#9523)
manuel-sommer Feb 20, 2024
560c334
:arrow_up: Bump openapitools/openapi-generator-cli from v7.2.0 to v7.…
dependabot[bot] Feb 20, 2024
99801d5
:tada: Importing EPSS score from AWS Inspector via AWS SecHub (#9529)
quirinziessler Feb 20, 2024
64966f2
:bug: fix kics, #7966 (#9542)
manuel-sommer Feb 20, 2024
afd0bcc
:bug: fix nessus severity (#9549)
manuel-sommer Feb 20, 2024
e2f49ed
:sparkles: Documentation for managing files (#9557)
manuel-sommer Feb 20, 2024
2ecc105
Update rabbitmq Docker tag from 3.12.12 to v3.12.13 (docker-compose.y…
renovate[bot] Feb 20, 2024
a2b9ecf
Bump nginx from 1.25.3-alpine to 1.25.4-alpine (#9580)
dependabot[bot] Feb 20, 2024
cfcc93f
Ignore warnings from polymorphic
Maffooch Feb 20, 2024
4cee3ff
Fix Flake8
Maffooch Feb 20, 2024
2aae31b
More warning handling
Maffooch Feb 20, 2024
f72e518
Fix Flake8 again...
Maffooch Feb 20, 2024
7040850
Update dependency ruff from 0.2.1 to v0.2.2 (requirements-lint.txt) (…
renovate[bot] Feb 21, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions dojo/tools/snyk/parser.py
Original file line number Diff line number Diff line change
Expand Up @@ -144,6 +144,10 @@ def get_item(self, vulnerability, test, target_file=None, upgrades=None):
if vulnerability.get("CVSSv3"):
finding.cvssv3 = CVSS3(vulnerability["CVSSv3"]).clean_vector()

if vulnerability.get("epssDetails") is not None:
finding.epss_score = vulnerability["epssDetails"]["probability"]
finding.epss_percentile = vulnerability["epssDetails"]["percentile"]

# manage CVE and CWE with idnitifiers
cwe_references = ""
if "identifiers" in vulnerability:
Expand Down
Loading
Loading