awslabs / awslabs/simple-code-scanning-pipeline

Normalize outputs for findings so that they can be sent to DSR tool in a consistent format/schema

Open
#40 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
19
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Cole Hubbard's work on the Probe tool is useful here. Work with him to align on a common standard so that our tools are interoperable.

Possible formats to base this on:
- https://github.com/oasis-tcs/sarif-spec
- https://schema.ocsf.io/classes/security_finding?extensions=
- https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html (very resource-focused, probably not a great option)

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by reviewing the Probe tool's finding output and compare it with the SARIF, OCSF Security Finding, and AWS Security Hub formats listed in the issue. Completion requires an agreed common schema and a defined interoperability validation path.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.