docs: align tool inventory with what actually runs (no Grype, no ZAP/nuclei) #233
@@ -6,7 +6,7 @@ Control mapping connects the scanner's raw output — deterministic tool finding
|
|||||||
|
|
||||||
The design has one rule, borrowed from the ZeroFalse / IRIS line of research: **deterministic tools are the detectors; the LLM is only ever a grounded false-positive filter, never the thing that finds the issue.**
|
The design has one rule, borrowed from the ZeroFalse / IRIS line of research: **deterministic tools are the detectors; the LLM is only ever a grounded false-positive filter, never the thing that finds the issue.**
|
||||||
|
|
||||||
- A tool (semgrep, gitleaks, syft/osv, ZAP, nuclei) detects deterministically.
|
- A tool (semgrep, gitleaks, syft/osv, the DAST agents, the PLC linter) detects deterministically.
|
||||||
- An **authored, human-reviewed lookup table** (`control-map`) maps that detection to the control(s) it's evidence for.
|
- An **authored, human-reviewed lookup table** (`control-map`) maps that detection to the control(s) it's evidence for.
|
||||||
- The LLM enters last, to *confirm or refute* the mapping against the actual code — and every surviving verdict is anchored to a verbatim snippet by the grounding gate.
|
- The LLM enters last, to *confirm or refute* the mapping against the actual code — and every surviving verdict is anchored to a verbatim snippet by the grounding gate.
|
||||||
|
|
||||||
@@ -34,7 +34,7 @@ At scale, the **master-controls** corpus (breakpilot's deduped clusters, exporte
|
|||||||
|
|
||||||
```mermaid
|
```mermaid
|
||||||
flowchart TD
|
flowchart TD
|
||||||
T[Deterministic tools\nsemgrep · gitleaks · syft/osv · ZAP] --> F[Findings]
|
T[Deterministic tools\nsemgrep · gitleaks · syft/osv · DAST · PLC linter] --> F[Findings]
|
||||||
F --> B["Stage 5b — LUT triage\ncontrols_for(tool, cwe / rule_id)"]
|
F --> B["Stage 5b — LUT triage\ncontrols_for(tool, cwe / rule_id)"]
|
||||||
F --> C["Stage 5c — Semantic\nembed region+intent → top-K master controls"]
|
F --> C["Stage 5c — Semantic\nembed region+intent → top-K master controls"]
|
||||||
R[Repo source] --> D["Stage 5d — Grounded surface\nretrieve surface for absence-based controls"]
|
R[Repo source] --> D["Stage 5d — Grounded surface\nretrieve surface for absence-based controls"]
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ Filters can be combined. Results are paginated with 20 findings per page.
|
|||||||
| Severity | Color-coded badge: Critical (red), High (orange), Medium (yellow), Low (green), Info (blue) |
|
| Severity | Color-coded badge: Critical (red), High (orange), Medium (yellow), Low (green), Info (blue) |
|
||||||
| Title | Short description of the vulnerability (clickable) |
|
| Title | Short description of the vulnerability (clickable) |
|
||||||
| Type | SAST, SBOM, CVE, GDPR, OAuth, Secrets, or Code Review |
|
| Type | SAST, SBOM, CVE, GDPR, OAuth, Secrets, or Code Review |
|
||||||
| Scanner | Tool that found the issue (e.g. Semgrep, Grype) |
|
| Scanner | Tool that found the issue (e.g. Semgrep, Syft/OSV) |
|
||||||
| File | Source file path where the issue was found |
|
| File | Source file path where the issue was found |
|
||||||
| Status | Current triage status |
|
| Status | Current triage status |
|
||||||
|
|
||||||
@@ -73,7 +73,7 @@ If the finding has been pushed to an issue tracker (GitHub, GitLab, Gitea, Jira)
|
|||||||
| Type | Source | Description |
|
| Type | Source | Description |
|
||||||
|------|--------|-------------|
|
|------|--------|-------------|
|
||||||
| **SAST** | Semgrep | Code-level vulnerabilities found through static analysis |
|
| **SAST** | Semgrep | Code-level vulnerabilities found through static analysis |
|
||||||
| **SBOM** | Syft + Grype | Vulnerable dependencies identified in your software bill of materials |
|
| **SBOM** | Syft + OSV.dev/NVD | Vulnerable dependencies identified in your software bill of materials |
|
||||||
| **CVE** | NVD | Known CVEs matching your dependency versions |
|
| **CVE** | NVD | Known CVEs matching your dependency versions |
|
||||||
| **GDPR** | Custom rules | Personal data handling and consent issues |
|
| **GDPR** | Custom rules | Personal data handling and consent issues |
|
||||||
| **OAuth** | Custom rules | OAuth/OIDC misconfigurations and insecure token handling |
|
| **OAuth** | Custom rules | OAuth/OIDC misconfigurations and insecure token handling |
|
||||||
|
|||||||
+1
-1
@@ -6,7 +6,7 @@ The SBOM (Software Bill of Materials) feature provides a complete inventory of a
|
|||||||
|
|
||||||
A Software Bill of Materials is a list of every component (library, package, framework) that your software depends on, along with version numbers, licenses, and known vulnerabilities. SBOMs are increasingly required for compliance audits, customer security questionnaires, and supply chain transparency.
|
A Software Bill of Materials is a list of every component (library, package, framework) that your software depends on, along with version numbers, licenses, and known vulnerabilities. SBOMs are increasingly required for compliance audits, customer security questionnaires, and supply chain transparency.
|
||||||
|
|
||||||
Certifai generates SBOMs automatically during each scan using Syft for dependency extraction and Grype for vulnerability matching.
|
Certifai generates SBOMs automatically during each scan using Syft for dependency extraction and OSV.dev + NVD for vulnerability matching.
|
||||||
|
|
||||||
## Packages Tab
|
## Packages Tab
|
||||||
|
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ When a scan is triggered, Certifai runs through these phases in order:
|
|||||||
|
|
||||||
1. **Clone** -- pulls the latest code from the Git remote (or clones it for the first time)
|
1. **Clone** -- pulls the latest code from the Git remote (or clones it for the first time)
|
||||||
2. **SAST** -- runs static analysis using Semgrep with rules covering OWASP, GDPR, OAuth, secrets, and general security patterns
|
2. **SAST** -- runs static analysis using Semgrep with rules covering OWASP, GDPR, OAuth, secrets, and general security patterns
|
||||||
3. **SBOM** -- extracts all dependencies using Syft, identifying packages, versions, licenses, and known vulnerabilities via Grype
|
3. **SBOM** -- extracts all dependencies using Syft, identifying packages, versions, licenses, and known vulnerabilities via OSV.dev + NVD
|
||||||
4. **CVE Check** -- cross-references dependencies against the NVD database for known CVEs
|
4. **CVE Check** -- cross-references dependencies against the NVD database for known CVEs
|
||||||
5. **Graph Build** -- parses the codebase to construct a code knowledge graph of functions, classes, and their relationships
|
5. **Graph Build** -- parses the codebase to construct a code knowledge graph of functions, classes, and their relationships
|
||||||
6. **AI Triage** -- new findings are reviewed by an LLM that assesses severity, considers blast radius using the code graph, and generates remediation guidance
|
6. **AI Triage** -- new findings are reviewed by an LLM that assesses severity, considers blast radius using the code graph, and generates remediation guidance
|
||||||
@@ -52,7 +52,7 @@ A full scan runs multiple analysis engines, each producing different types of fi
|
|||||||
| Scan Type | What It Detects | Scanner |
|
| Scan Type | What It Detects | Scanner |
|
||||||
|-----------|----------------|---------|
|
|-----------|----------------|---------|
|
||||||
| **SAST** | Code-level vulnerabilities (injection, XSS, insecure crypto, etc.) | Semgrep |
|
| **SAST** | Code-level vulnerabilities (injection, XSS, insecure crypto, etc.) | Semgrep |
|
||||||
| **SBOM** | Dependency inventory, outdated packages, known vulnerabilities | Syft + Grype |
|
| **SBOM** | Dependency inventory, outdated packages, known vulnerabilities | Syft + OSV.dev/NVD |
|
||||||
| **CVE** | Known CVEs in dependencies cross-referenced against NVD | NVD API |
|
| **CVE** | Known CVEs in dependencies cross-referenced against NVD | NVD API |
|
||||||
| **GDPR** | Personal data handling issues, consent violations | Custom rules |
|
| **GDPR** | Personal data handling issues, consent violations | Custom rules |
|
||||||
| **OAuth** | OAuth/OIDC misconfigurations, insecure token handling | Custom rules |
|
| **OAuth** | OAuth/OIDC misconfigurations, insecure token handling | Custom rules |
|
||||||
|
|||||||
@@ -58,8 +58,8 @@ An open-source static analysis tool that finds bugs and enforces code standards
|
|||||||
**Syft**
|
**Syft**
|
||||||
An open-source tool for generating SBOMs from container images and filesystems. Used by Certifai to extract dependency information.
|
An open-source tool for generating SBOMs from container images and filesystems. Used by Certifai to extract dependency information.
|
||||||
|
|
||||||
**Grype**
|
**OSV.dev**
|
||||||
An open-source vulnerability scanner for container images and filesystems. Used by Certifai to match dependencies against known vulnerabilities.
|
Google's open distributed vulnerability database, queried by package URL. Certifai uses it (together with NVD) to match SBOM components against known vulnerabilities.
|
||||||
|
|
||||||
## Protocols
|
## Protocols
|
||||||
|
|
||||||
|
|||||||
@@ -24,15 +24,14 @@ Semgrep produces SAST-type findings with file paths, line numbers, and rule desc
|
|||||||
|
|
||||||
Syft output feeds into both the SBOM feature and the vulnerability scanning pipeline.
|
Syft output feeds into both the SBOM feature and the vulnerability scanning pipeline.
|
||||||
|
|
||||||
## Grype -- Vulnerability Scanning
|
## OSV.dev + NVD -- Vulnerability Matching
|
||||||
|
|
||||||
[Grype](https://github.com/anchore/grype) is an open-source vulnerability scanner that matches your dependencies against known vulnerability databases. It takes Syft's SBOM output and cross-references it against:
|
Certifai matches every SBOM component directly against two public vulnerability sources (no separate scanner binary):
|
||||||
|
|
||||||
- National Vulnerability Database (NVD)
|
- [OSV.dev](https://osv.dev/) -- batch queried by package URL (purl) for ecosystem advisories (npm, PyPI, crates.io, Go, Maven, ...)
|
||||||
- GitHub Advisory Database
|
- [NVD](https://nvd.nist.gov/) -- queried per CVE for the CVSS v3.1 base score, and by CPE for CODESYS runtime versions found in PLC projects
|
||||||
- OS-specific advisory databases
|
|
||||||
|
|
||||||
Grype produces SBOM-type findings with CVE identifiers, severity ratings, and links to advisories.
|
Matches are stored as CVE alerts with CVSS scores and re-checked hourly, so newly published CVEs against an unchanged dependency still raise a notification.
|
||||||
|
|
||||||
## Custom OAuth Scanner
|
## Custom OAuth Scanner
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user