updates
This commit is contained in:
@@ -0,0 +1,176 @@
|
||||
# This file is part of CycloneDX Python Library
|
||||
#
|
||||
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||
# you may not use this file except in compliance with the License.
|
||||
# You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
# Copyright (c) OWASP Foundation. All Rights Reserved.
|
||||
|
||||
|
||||
"""
|
||||
Set of classes and methods for outputting our libraries internal Bom model to CycloneDX documents in varying formats
|
||||
and according to different versions of the CycloneDX schema standard.
|
||||
"""
|
||||
|
||||
import os
|
||||
from abc import ABC, abstractmethod
|
||||
from itertools import chain
|
||||
from random import random
|
||||
from typing import TYPE_CHECKING, Any, Iterable, Literal, Mapping, Optional, Type, Union, overload
|
||||
|
||||
from ..schema import OutputFormat, SchemaVersion
|
||||
|
||||
if TYPE_CHECKING: # pragma: no cover
|
||||
from ..model.bom import Bom
|
||||
from ..model.bom_ref import BomRef
|
||||
from .json import Json as JsonOutputter
|
||||
from .xml import Xml as XmlOutputter
|
||||
|
||||
|
||||
class BaseOutput(ABC):
|
||||
|
||||
def __init__(self, bom: 'Bom', **kwargs: int) -> None:
|
||||
super().__init__(**kwargs)
|
||||
self._bom = bom
|
||||
self._generated: bool = False
|
||||
|
||||
@property
|
||||
@abstractmethod
|
||||
def schema_version(self) -> SchemaVersion:
|
||||
... # pragma: no cover
|
||||
|
||||
@property
|
||||
@abstractmethod
|
||||
def output_format(self) -> OutputFormat:
|
||||
... # pragma: no cover
|
||||
|
||||
@property
|
||||
def generated(self) -> bool:
|
||||
return self._generated
|
||||
|
||||
@generated.setter
|
||||
def generated(self, generated: bool) -> None:
|
||||
self._generated = generated
|
||||
|
||||
def get_bom(self) -> 'Bom':
|
||||
return self._bom
|
||||
|
||||
def set_bom(self, bom: 'Bom') -> None:
|
||||
self._bom = bom
|
||||
|
||||
@abstractmethod
|
||||
def generate(self, force_regeneration: bool = False) -> None:
|
||||
... # pragma: no cover
|
||||
|
||||
@abstractmethod
|
||||
def output_as_string(self, *,
|
||||
indent: Optional[Union[int, str]] = None,
|
||||
**kwargs: Any) -> str:
|
||||
... # pragma: no cover
|
||||
|
||||
def output_to_file(self, filename: str, allow_overwrite: bool = False, *,
|
||||
indent: Optional[Union[int, str]] = None,
|
||||
**kwargs: Any) -> None:
|
||||
# Check directory writable
|
||||
output_filename = os.path.realpath(filename)
|
||||
output_directory = os.path.dirname(output_filename)
|
||||
if not os.access(output_directory, os.W_OK):
|
||||
raise PermissionError(output_directory)
|
||||
if os.path.exists(output_filename) and not allow_overwrite:
|
||||
raise FileExistsError(output_filename)
|
||||
with open(output_filename, mode='wb') as f_out:
|
||||
f_out.write(self.output_as_string(indent=indent).encode('utf-8'))
|
||||
|
||||
|
||||
@overload
|
||||
def make_outputter(bom: 'Bom', output_format: Literal[OutputFormat.JSON],
|
||||
schema_version: SchemaVersion) -> 'JsonOutputter':
|
||||
... # pragma: no cover
|
||||
|
||||
|
||||
@overload
|
||||
def make_outputter(bom: 'Bom', output_format: Literal[OutputFormat.XML],
|
||||
schema_version: SchemaVersion) -> 'XmlOutputter':
|
||||
... # pragma: no cover
|
||||
|
||||
|
||||
@overload
|
||||
def make_outputter(bom: 'Bom', output_format: OutputFormat,
|
||||
schema_version: SchemaVersion) -> Union['XmlOutputter', 'JsonOutputter']:
|
||||
... # pragma: no cover
|
||||
|
||||
|
||||
def make_outputter(bom: 'Bom', output_format: OutputFormat, schema_version: SchemaVersion) -> BaseOutput:
|
||||
"""
|
||||
Helper method to quickly get the correct output class/formatter.
|
||||
|
||||
Pass in your BOM and optionally an output format and schema version (defaults to XML and latest schema version).
|
||||
|
||||
|
||||
Raises error when no instance could be made.
|
||||
|
||||
:param bom: Bom
|
||||
:param output_format: OutputFormat
|
||||
:param schema_version: SchemaVersion
|
||||
:return: BaseOutput
|
||||
"""
|
||||
if TYPE_CHECKING: # pragma: no cover
|
||||
BY_SCHEMA_VERSION: Mapping[SchemaVersion, Type[BaseOutput]] # noqa:N806
|
||||
if OutputFormat.JSON is output_format:
|
||||
from .json import BY_SCHEMA_VERSION
|
||||
elif OutputFormat.XML is output_format:
|
||||
from .xml import BY_SCHEMA_VERSION
|
||||
else:
|
||||
raise ValueError(f'Unexpected output_format: {output_format!r}')
|
||||
|
||||
klass = BY_SCHEMA_VERSION.get(schema_version, None)
|
||||
if klass is None:
|
||||
raise ValueError(f'Unknown {output_format.name}/schema_version: {schema_version!r}')
|
||||
return klass(bom)
|
||||
|
||||
|
||||
class BomRefDiscriminator:
|
||||
|
||||
def __init__(self, bomrefs: Iterable['BomRef'], prefix: str = 'BomRef') -> None:
|
||||
# do not use dict/set here, different BomRefs with same value have same hash and would shadow each other
|
||||
self._bomrefs = tuple((bomref, bomref.value) for bomref in bomrefs)
|
||||
self._prefix = prefix
|
||||
|
||||
def __enter__(self) -> None:
|
||||
self.discriminate()
|
||||
|
||||
def __exit__(self, exc_type: Any, exc_val: Any, exc_tb: Any) -> None:
|
||||
self.reset()
|
||||
|
||||
def discriminate(self) -> None:
|
||||
known_values = []
|
||||
for bomref, _ in self._bomrefs:
|
||||
value = bomref.value
|
||||
if value is None or value in known_values:
|
||||
value = self._make_unique()
|
||||
bomref.value = value
|
||||
known_values.append(value)
|
||||
|
||||
def reset(self) -> None:
|
||||
for bomref, original_value in self._bomrefs:
|
||||
bomref.value = original_value
|
||||
|
||||
def _make_unique(self) -> str:
|
||||
return f'{self._prefix}{str(random())[1:]}{str(random())[1:]}' # nosec B311
|
||||
|
||||
@classmethod
|
||||
def from_bom(cls, bom: 'Bom', prefix: str = 'BomRef') -> 'BomRefDiscriminator':
|
||||
return cls(chain(
|
||||
map(lambda c: c.bom_ref, bom._get_all_components()),
|
||||
map(lambda s: s.bom_ref, bom.services),
|
||||
map(lambda v: v.bom_ref, bom.vulnerabilities)
|
||||
), prefix)
|
||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,142 @@
|
||||
# This file is part of CycloneDX Python Library
|
||||
#
|
||||
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||
# you may not use this file except in compliance with the License.
|
||||
# You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
# Copyright (c) OWASP Foundation. All Rights Reserved.
|
||||
|
||||
from abc import abstractmethod
|
||||
from json import dumps as json_dumps, loads as json_loads
|
||||
from typing import TYPE_CHECKING, Any, Dict, Literal, Optional, Type, Union
|
||||
|
||||
from ..exception.output import FormatNotSupportedException
|
||||
from ..schema import OutputFormat, SchemaVersion
|
||||
from ..schema.schema import (
|
||||
SCHEMA_VERSIONS,
|
||||
BaseSchemaVersion,
|
||||
SchemaVersion1Dot0,
|
||||
SchemaVersion1Dot1,
|
||||
SchemaVersion1Dot2,
|
||||
SchemaVersion1Dot3,
|
||||
SchemaVersion1Dot4,
|
||||
SchemaVersion1Dot5,
|
||||
SchemaVersion1Dot6,
|
||||
)
|
||||
from . import BaseOutput, BomRefDiscriminator
|
||||
|
||||
if TYPE_CHECKING: # pragma: no cover
|
||||
from ..model.bom import Bom
|
||||
|
||||
|
||||
class Json(BaseOutput, BaseSchemaVersion):
|
||||
|
||||
def __init__(self, bom: 'Bom') -> None:
|
||||
super().__init__(bom=bom)
|
||||
self._bom_json: Dict[str, Any] = dict()
|
||||
|
||||
@property
|
||||
def schema_version(self) -> SchemaVersion:
|
||||
return self.schema_version_enum
|
||||
|
||||
@property
|
||||
def output_format(self) -> Literal[OutputFormat.JSON]:
|
||||
return OutputFormat.JSON
|
||||
|
||||
def generate(self, force_regeneration: bool = False) -> None:
|
||||
if self.generated and not force_regeneration:
|
||||
return
|
||||
|
||||
schema_uri: Optional[str] = self._get_schema_uri()
|
||||
if not schema_uri:
|
||||
raise FormatNotSupportedException(
|
||||
f'JSON is not supported by CycloneDX in schema version {self.schema_version.to_version()}')
|
||||
|
||||
_json_core = {
|
||||
'$schema': schema_uri,
|
||||
'bomFormat': 'CycloneDX',
|
||||
'specVersion': self.schema_version.to_version()
|
||||
}
|
||||
_view = SCHEMA_VERSIONS.get(self.schema_version_enum)
|
||||
bom = self.get_bom()
|
||||
bom.validate()
|
||||
with BomRefDiscriminator.from_bom(bom):
|
||||
bom_json: Dict[str, Any] = json_loads(
|
||||
bom.as_json( # type:ignore[attr-defined]
|
||||
view_=_view))
|
||||
bom_json.update(_json_core)
|
||||
self._bom_json = bom_json
|
||||
self.generated = True
|
||||
|
||||
def output_as_string(self, *,
|
||||
indent: Optional[Union[int, str]] = None,
|
||||
**kwargs: Any) -> str:
|
||||
self.generate()
|
||||
return json_dumps(self._bom_json,
|
||||
indent=indent)
|
||||
|
||||
@abstractmethod
|
||||
def _get_schema_uri(self) -> Optional[str]:
|
||||
... # pragma: no cover
|
||||
|
||||
|
||||
class JsonV1Dot0(Json, SchemaVersion1Dot0):
|
||||
|
||||
def _get_schema_uri(self) -> None:
|
||||
return None
|
||||
|
||||
|
||||
class JsonV1Dot1(Json, SchemaVersion1Dot1):
|
||||
|
||||
def _get_schema_uri(self) -> None:
|
||||
return None
|
||||
|
||||
|
||||
class JsonV1Dot2(Json, SchemaVersion1Dot2):
|
||||
|
||||
def _get_schema_uri(self) -> str:
|
||||
return 'http://cyclonedx.org/schema/bom-1.2b.schema.json'
|
||||
|
||||
|
||||
class JsonV1Dot3(Json, SchemaVersion1Dot3):
|
||||
|
||||
def _get_schema_uri(self) -> str:
|
||||
return 'http://cyclonedx.org/schema/bom-1.3a.schema.json'
|
||||
|
||||
|
||||
class JsonV1Dot4(Json, SchemaVersion1Dot4):
|
||||
|
||||
def _get_schema_uri(self) -> str:
|
||||
return 'http://cyclonedx.org/schema/bom-1.4.schema.json'
|
||||
|
||||
|
||||
class JsonV1Dot5(Json, SchemaVersion1Dot5):
|
||||
|
||||
def _get_schema_uri(self) -> str:
|
||||
return 'http://cyclonedx.org/schema/bom-1.5.schema.json'
|
||||
|
||||
|
||||
class JsonV1Dot6(Json, SchemaVersion1Dot6):
|
||||
|
||||
def _get_schema_uri(self) -> str:
|
||||
return 'http://cyclonedx.org/schema/bom-1.6.schema.json'
|
||||
|
||||
|
||||
BY_SCHEMA_VERSION: Dict[SchemaVersion, Type[Json]] = {
|
||||
SchemaVersion.V1_6: JsonV1Dot6,
|
||||
SchemaVersion.V1_5: JsonV1Dot5,
|
||||
SchemaVersion.V1_4: JsonV1Dot4,
|
||||
SchemaVersion.V1_3: JsonV1Dot3,
|
||||
SchemaVersion.V1_2: JsonV1Dot2,
|
||||
SchemaVersion.V1_1: JsonV1Dot1,
|
||||
SchemaVersion.V1_0: JsonV1Dot0,
|
||||
}
|
||||
@@ -0,0 +1,135 @@
|
||||
# This file is part of CycloneDX Python Library
|
||||
#
|
||||
# Licensed under the Apache License, Version 2.0 (the "License");
|
||||
# you may not use this file except in compliance with the License.
|
||||
# You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
# Copyright (c) OWASP Foundation. All Rights Reserved.
|
||||
|
||||
|
||||
from typing import TYPE_CHECKING, Any, Dict, Literal, Optional, Type, Union
|
||||
from xml.dom.minidom import parseString as dom_parseString # nosec B408
|
||||
from xml.etree.ElementTree import Element as XmlElement, tostring as xml_dumps # nosec B405
|
||||
|
||||
from ..schema import OutputFormat, SchemaVersion
|
||||
from ..schema.schema import (
|
||||
SCHEMA_VERSIONS,
|
||||
BaseSchemaVersion,
|
||||
SchemaVersion1Dot0,
|
||||
SchemaVersion1Dot1,
|
||||
SchemaVersion1Dot2,
|
||||
SchemaVersion1Dot3,
|
||||
SchemaVersion1Dot4,
|
||||
SchemaVersion1Dot5,
|
||||
SchemaVersion1Dot6,
|
||||
)
|
||||
from . import BaseOutput, BomRefDiscriminator
|
||||
|
||||
if TYPE_CHECKING: # pragma: no cover
|
||||
from ..model.bom import Bom
|
||||
|
||||
|
||||
class Xml(BaseSchemaVersion, BaseOutput):
|
||||
def __init__(self, bom: 'Bom') -> None:
|
||||
super().__init__(bom=bom)
|
||||
self._bom_xml: str = ''
|
||||
|
||||
@property
|
||||
def schema_version(self) -> SchemaVersion:
|
||||
return self.schema_version_enum
|
||||
|
||||
@property
|
||||
def output_format(self) -> Literal[OutputFormat.XML]:
|
||||
return OutputFormat.XML
|
||||
|
||||
def generate(self, force_regeneration: bool = False) -> None:
|
||||
if self.generated and not force_regeneration:
|
||||
return
|
||||
|
||||
_view = SCHEMA_VERSIONS[self.schema_version_enum]
|
||||
bom = self.get_bom()
|
||||
bom.validate()
|
||||
xmlns = self.get_target_namespace()
|
||||
with BomRefDiscriminator.from_bom(bom):
|
||||
self._bom_xml = '<?xml version="1.0" ?>\n' + xml_dumps(
|
||||
bom.as_xml( # type:ignore[attr-defined]
|
||||
_view, as_string=False, xmlns=xmlns),
|
||||
method='xml', default_namespace=xmlns, encoding='unicode',
|
||||
# `xml-declaration` is inconsistent/bugged in py38,
|
||||
# especially on Windows it will print a non-UTF8 codepage.
|
||||
# Furthermore, it might add an encoding of "utf-8" which is redundant default value of XML.
|
||||
# -> so we write the declaration manually, as long as py38 is supported.
|
||||
xml_declaration=False)
|
||||
|
||||
self.generated = True
|
||||
|
||||
@staticmethod
|
||||
def __make_indent(v: Optional[Union[int, str]]) -> str:
|
||||
if isinstance(v, int):
|
||||
return ' ' * v
|
||||
if isinstance(v, str):
|
||||
return v
|
||||
return ''
|
||||
|
||||
def output_as_string(self, *,
|
||||
indent: Optional[Union[int, str]] = None,
|
||||
**kwargs: Any) -> str:
|
||||
self.generate()
|
||||
return self._bom_xml if indent is None else dom_parseString( # nosecc B318
|
||||
self._bom_xml).toprettyxml(
|
||||
indent=self.__make_indent(indent)
|
||||
# do not set `encoding` - this would convert result to binary, not string
|
||||
)
|
||||
|
||||
def get_target_namespace(self) -> str:
|
||||
return f'http://cyclonedx.org/schema/bom/{self.get_schema_version()}'
|
||||
|
||||
|
||||
class XmlV1Dot0(Xml, SchemaVersion1Dot0):
|
||||
|
||||
def _create_bom_element(self) -> XmlElement:
|
||||
return XmlElement('bom', {'xmlns': self.get_target_namespace(), 'version': '1'})
|
||||
|
||||
|
||||
class XmlV1Dot1(Xml, SchemaVersion1Dot1):
|
||||
pass
|
||||
|
||||
|
||||
class XmlV1Dot2(Xml, SchemaVersion1Dot2):
|
||||
pass
|
||||
|
||||
|
||||
class XmlV1Dot3(Xml, SchemaVersion1Dot3):
|
||||
pass
|
||||
|
||||
|
||||
class XmlV1Dot4(Xml, SchemaVersion1Dot4):
|
||||
pass
|
||||
|
||||
|
||||
class XmlV1Dot5(Xml, SchemaVersion1Dot5):
|
||||
pass
|
||||
|
||||
|
||||
class XmlV1Dot6(Xml, SchemaVersion1Dot6):
|
||||
pass
|
||||
|
||||
|
||||
BY_SCHEMA_VERSION: Dict[SchemaVersion, Type[Xml]] = {
|
||||
SchemaVersion.V1_6: XmlV1Dot6,
|
||||
SchemaVersion.V1_5: XmlV1Dot5,
|
||||
SchemaVersion.V1_4: XmlV1Dot4,
|
||||
SchemaVersion.V1_3: XmlV1Dot3,
|
||||
SchemaVersion.V1_2: XmlV1Dot2,
|
||||
SchemaVersion.V1_1: XmlV1Dot1,
|
||||
SchemaVersion.V1_0: XmlV1Dot0,
|
||||
}
|
||||
Reference in New Issue
Block a user