PjFord (Community Member) asked a question.

Why does sbom generation require security lead permission

Hi All;

I'm trying to streamline things here, rather than having multiple sbom generator I'd like to use 1 maybe 2. I tried following the directions here ( https://docs.veracode.com/r/Generating_a_Software_Bill_of_Materials_SBOM_for_Upload_Scans ) but no happiness ensued.

It seems that generating an sbom requires Security Lead permissions. Seems silly to me.

The problem in my case it that a corporation has the license, and several divisions all use the license. If I had the security lead I would be able to access the other divisions results. It seem to me that team members can access more useful and exploitable information than an sbom could leak.

Can Veracode add a role that isn't security lead that can generate sboms? A bit more granularity in the permissions seems reasonable doesn't it?

If anyone can suggest a work around or a good sbom generator that would be great!


lucas.ferreira and AK82 like this.
  • hello @PjFord (Community Member)​ 

     

    Have you tested generate SBOM from container security CLI? maybe you can use sbom flag and pointing to your repositories like bellow

    ./veracode sbom --source https://github.com/veracode/veracode-sca --type repo

    I this case, you only need the Veracode API Keys and ID and you can use differents formats like Cyclonedx and spdx-json.

     

    More information to install: Install the Veracode CLI | Veracode Docs

    and about SBOM flag option: veracode sbom | Veracode Docs

    Expand Post
  • PjFord (Community Member)

    Thanks for the pointer. So I'm working on a script to combine these two commands;

    #!/usr/bin/env zsh

     

    #get the vulnerabilities

    veracode scan --source $1 --type directory -f json -o $1.json

    #generate the sbom

    veracode sbom --source $1 --type directory -f cyclonedx-json > $1.sbom

    #end of file

     

    The issue now is to combine the sbom with the vulnerabilities, here is a sample of what I need

    {

     "bomFormat" : "CycloneDX",

     "specVersion" : "1.4",

     "serialNumber" : "urn:uuid:abcdef123-dddd-4d4_a1b2c34d-deadface",

     "version" : 1,

     "metadata" : {

      "timestamp" : "2022-11-24T19:05:27Z",

      "tools" : [

       {

        "vendor" : "OWASP",

        "name" : "Dependency-Track",

        "version" : "4.6.2"

       }

      ],

      "component" : {

       "name" : "Cloud / mongo2es",

       "version" : "SNAPSHOT",

       "type" : "application",

       "bom-ref" : "abunchOfAlphanumericChars"

      }

     },

     "components" : [

      {

       "name" : "PyYAML",

       "version" : "3.12",

       "purl" : "pkg:pypi/pyyaml@3.12",

       "type" : "library",

       "bom-ref" : "deadbeef-cafe-face-babe-deadbabeface"

      }

     ],

     "vulnerabilities" : [

      {

       "bom-ref" : "bec9b12b-eff4-4a29-af37-6ba09b727b9b",

       "id" : "CVE-2017-18342",

       "source" : {

        "name" : "NVD",

        "url" : "https://nvd.nist.gov/"

       },

       "ratings" : [

        {

         "source" : {

          "name" : "NVD",

          "url" : "https://nvd.nist.gov/"

         },

         "score" : 9.8,

         "severity" : "critical",

         "method" : "CVSSv3",

         "vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"

        }

       ],

       "cwes" : [

        502

       ],

       "description" : "In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.",

       "affects" : [

        {

         "ref" : "deadbeef-cafe-face-babe-deadbabeface"

        }

       ]

      }

     ]

    }

     

    Any ideas?

     

     

    Expand Post

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.