awslabs / awslabs/simple-code-scanning-pipeline
Normalize outputs for findings so that they can be sent to DSR tool in a consistent format/schema
- Dominant language
- TypeScript
- Stars
- 19
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
Cole Hubbard's work on the Probe tool is useful here. Work with him to align on a common standard so that our tools are interoperable.
Possible formats to base this on:
- https://github.com/oasis-tcs/sarif-spec
- https://schema.ocsf.io/classes/security_finding?extensions=
- https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html (very resource-focused, probably not a great option)
Contributor guide
Research direction
No files, tests, or entry points are named. Start by reviewing the Probe tool's finding output and compare it with the SARIF, OCSF Security Finding, and AWS Security Hub formats listed in the issue. Completion requires an agreed common schema and a defined interoperability validation path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100