4 ms·
Yes, command line version will be always available, this is just an additional mode built on top of it, it's using in fact the same API interface as CLI version
by intense_feel 3y ago
Yes, command line version will be always available, this is just an additional mode built on top of it, it's using in fact the same API interface as CLI version to spawn scans and parses out the JSON output format into persistent DB with some postprocessing to be more suitable for web app.
- pabs3 3y agoAre you using SARIF for the JSON output? It is a standard for static analysis tool output. https://sarifweb.azurewebsites.net/ https://sarifweb.azurewebsites.net/
- intense_feel 3y agoSARIF is implemented as a separate output format and is supported. the "json" one contains more information such as taint traces (even unconfirmed ones that haven't reached sinks), anomaly tags, static behaviour etc... main json format is intended to capture as much data as possible so it can be analyzed later as the original intention is to hunt for malware, anomalies and doing research in general on top of the whole PyPI repository. I found SARIF to be more "practical" or actionable in terms of what needs to be done in fixing the source code or vulnerabilities found vs research oriented such as "this piece of code is doing network communication". Due to this differences it was added as a separate format which is a subset and reformatted (to the SARIF standard) "json" output format
- pabs3 3y agoGreat approach, thanks for that.