
PjFord (Community Member) asked a question.
Hi All;
I'm trying to streamline things here, rather than having multiple sbom generator I'd like to use 1 maybe 2. I tried following the directions here ( https://docs.veracode.com/r/Generating_a_Software_Bill_of_Materials_SBOM_for_Upload_Scans ) but no happiness ensued.
It seems that generating an sbom requires Security Lead permissions. Seems silly to me.
The problem in my case it that a corporation has the license, and several divisions all use the license. If I had the security lead I would be able to access the other divisions results. It seem to me that team members can access more useful and exploitable information than an sbom could leak.
Can Veracode add a role that isn't security lead that can generate sboms? A bit more granularity in the permissions seems reasonable doesn't it?
If anyone can suggest a work around or a good sbom generator that would be great!
.png)
hello @PjFord (Community Member)
Have you tested generate SBOM from container security CLI? maybe you can use sbom flag and pointing to your repositories like bellow
./veracode sbom --source https://github.com/veracode/veracode-sca --type repo
I this case, you only need the Veracode API Keys and ID and you can use differents formats like Cyclonedx and spdx-json.
More information to install: Install the Veracode CLI | Veracode Docs
and about SBOM flag option: veracode sbom | Veracode Docs
Thanks for the pointer. So I'm working on a script to combine these two commands;
#!/usr/bin/env zsh
#get the vulnerabilities
veracode scan --source $1 --type directory -f json -o $1.json
#generate the sbom
veracode sbom --source $1 --type directory -f cyclonedx-json > $1.sbom
#end of file
The issue now is to combine the sbom with the vulnerabilities, here is a sample of what I need
{
"bomFormat" : "CycloneDX",
"specVersion" : "1.4",
"serialNumber" : "urn:uuid:abcdef123-dddd-4d4_a1b2c34d-deadface",
"version" : 1,
"metadata" : {
"timestamp" : "2022-11-24T19:05:27Z",
"tools" : [
{
"vendor" : "OWASP",
"name" : "Dependency-Track",
"version" : "4.6.2"
}
],
"component" : {
"name" : "Cloud / mongo2es",
"version" : "SNAPSHOT",
"type" : "application",
"bom-ref" : "abunchOfAlphanumericChars"
}
},
"components" : [
{
"name" : "PyYAML",
"version" : "3.12",
"purl" : "pkg:pypi/pyyaml@3.12",
"type" : "library",
"bom-ref" : "deadbeef-cafe-face-babe-deadbabeface"
}
],
"vulnerabilities" : [
{
"bom-ref" : "bec9b12b-eff4-4a29-af37-6ba09b727b9b",
"id" : "CVE-2017-18342",
"source" : {
"name" : "NVD",
"url" : "https://nvd.nist.gov/"
},
"ratings" : [
{
"source" : {
"name" : "NVD",
"url" : "https://nvd.nist.gov/"
},
"score" : 9.8,
"severity" : "critical",
"method" : "CVSSv3",
"vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"cwes" : [
502
],
"description" : "In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.",
"affects" : [
{
"ref" : "deadbeef-cafe-face-babe-deadbabeface"
}
]
}
]
}
Any ideas?