161 lines
4.6 KiB
PHP
161 lines
4.6 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Models;
|
|
|
|
use Illuminate\Database\Eloquent\Model;
|
|
use Illuminate\Database\Eloquent\Relations\BelongsTo;
|
|
|
|
final class SecurityReport extends Model
|
|
{
|
|
protected $fillable = [
|
|
'status',
|
|
'started_at',
|
|
'finished_at',
|
|
'composer_critical',
|
|
'composer_high',
|
|
'composer_medium',
|
|
'composer_low',
|
|
'composer_unknown',
|
|
'npm_critical',
|
|
'npm_high',
|
|
'npm_moderate',
|
|
'npm_low',
|
|
'npm_info',
|
|
'npm_unknown',
|
|
'total_critical',
|
|
'total_high',
|
|
'total_medium',
|
|
'total_low',
|
|
'total_unknown',
|
|
'composer_outdated_count',
|
|
'npm_outdated_count',
|
|
'summary',
|
|
'composer_audit',
|
|
'composer_outdated',
|
|
'npm_audit',
|
|
'npm_outdated',
|
|
'error_message',
|
|
'triggered_by',
|
|
'user_id',
|
|
];
|
|
|
|
protected function casts(): array
|
|
{
|
|
return [
|
|
'started_at' => 'datetime',
|
|
'finished_at' => 'datetime',
|
|
'summary' => 'array',
|
|
'composer_audit' => 'array',
|
|
'composer_outdated' => 'array',
|
|
'npm_audit' => 'array',
|
|
'npm_outdated' => 'array',
|
|
];
|
|
}
|
|
|
|
public function user(): BelongsTo
|
|
{
|
|
return $this->belongsTo(User::class);
|
|
}
|
|
|
|
public function hasCriticalFindings(): bool
|
|
{
|
|
return $this->total_critical > 0;
|
|
}
|
|
|
|
public function hasHighFindings(): bool
|
|
{
|
|
return $this->total_high > 0;
|
|
}
|
|
|
|
public function hasDangerFindings(): bool
|
|
{
|
|
return $this->hasCriticalFindings() || $this->hasHighFindings();
|
|
}
|
|
|
|
public function getRiskLabelAttribute(): string
|
|
{
|
|
if ($this->total_critical > 0) {
|
|
return 'Critical';
|
|
}
|
|
|
|
if ($this->total_high > 0) {
|
|
return 'High';
|
|
}
|
|
|
|
if ($this->total_medium > 0) {
|
|
return 'Medium';
|
|
}
|
|
|
|
if ($this->total_low > 0) {
|
|
return 'Low';
|
|
}
|
|
|
|
return 'Clean';
|
|
}
|
|
|
|
/**
|
|
* @return array<int, array<string, mixed>>
|
|
*/
|
|
public function composerAdvisories(): array
|
|
{
|
|
$advisories = $this->composer_audit['advisories'] ?? [];
|
|
$items = [];
|
|
|
|
foreach ($advisories as $package => $packageAdvisories) {
|
|
if (! is_array($packageAdvisories)) {
|
|
continue;
|
|
}
|
|
|
|
foreach ($packageAdvisories as $advisory) {
|
|
if (! is_array($advisory)) {
|
|
continue;
|
|
}
|
|
|
|
$items[] = [
|
|
'package' => (string) $package,
|
|
'severity' => strtolower((string) ($advisory['severity'] ?? 'unknown')),
|
|
'title' => (string) ($advisory['title'] ?? $advisory['advisoryId'] ?? 'Unknown advisory'),
|
|
'cve' => (string) ($advisory['cve'] ?? $advisory['link'] ?? ''),
|
|
'affected_versions' => (string) ($advisory['affectedVersions'] ?? $advisory['affected_versions'] ?? ''),
|
|
'reported_at' => (string) ($advisory['reportedAt'] ?? ''),
|
|
'link' => (string) ($advisory['link'] ?? ''),
|
|
];
|
|
}
|
|
}
|
|
|
|
return $items;
|
|
}
|
|
|
|
/**
|
|
* @return array<int, array<string, mixed>>
|
|
*/
|
|
public function npmVulnerabilities(): array
|
|
{
|
|
$vulnerabilities = $this->npm_audit['vulnerabilities'] ?? [];
|
|
$items = [];
|
|
|
|
foreach ($vulnerabilities as $package => $vulnerability) {
|
|
if (! is_array($vulnerability)) {
|
|
continue;
|
|
}
|
|
|
|
$via = collect((array) ($vulnerability['via'] ?? []))
|
|
->first(fn (mixed $item): bool => is_array($item));
|
|
|
|
$items[] = [
|
|
'package' => (string) $package,
|
|
'severity' => strtolower((string) ($vulnerability['severity'] ?? 'unknown')),
|
|
'title' => is_array($via) ? (string) ($via['title'] ?? 'Unknown advisory') : 'Unknown advisory',
|
|
'cve' => is_array($via) ? (string) ($via['cve'] ?? '') : '',
|
|
'range' => (string) ($vulnerability['range'] ?? ''),
|
|
'fix_available' => is_array($vulnerability['fixAvailable'] ?? null) ? (string) (($vulnerability['fixAvailable']['name'] ?? '') . '@' . ($vulnerability['fixAvailable']['version'] ?? '')) : ((bool) ($vulnerability['fixAvailable'] ?? false) ? 'Yes' : ''),
|
|
'url' => is_array($via) ? (string) ($via['url'] ?? '') : '',
|
|
];
|
|
}
|
|
|
|
return $items;
|
|
}
|
|
}
|