mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
42 lines
1.4 KiB
YAML
42 lines
1.4 KiB
YAML
name: SafeDep vet OSS suite
|
|
description: |
|
|
Customized filter suite for vet vetting dry.
|
|
tags:
|
|
- general
|
|
- safedep-vet
|
|
filters:
|
|
- name: critical-or-high-vulns
|
|
check_type: CheckTypeVulnerability
|
|
summary: Critical or high risk vulnerabilities were found
|
|
value: |
|
|
vulns.critical.exists(p, true) || vulns.high.exists(p, true)
|
|
- name: low-popularity
|
|
check_type: CheckTypePopularity
|
|
summary: Component popularity is low by Github stars count
|
|
value: |
|
|
projects.exists(p, (p.type == "GITHUB") && (p.stars < 10))
|
|
- name: risky-oss-licenses
|
|
check_type: CheckTypeLicense
|
|
summary: Risky OSS license was detected
|
|
value: |
|
|
licenses.exists(p, p == "GPL-2.0") ||
|
|
licenses.exists(p, p == "GPL-2.0-only") ||
|
|
licenses.exists(p, p == "GPL-3.0") ||
|
|
licenses.exists(p, p == "GPL-3.0-only") ||
|
|
licenses.exists(p, p == "BSD-3-Clause OR GPL-2.0")
|
|
- name: ossf-unmaintained
|
|
check_type: CheckTypeMaintenance
|
|
summary: Component appears to be unmaintained
|
|
value: |
|
|
scorecard.scores["Maintained"] == 0
|
|
- name: osv-malware
|
|
check_type: CheckTypeMalware
|
|
summary: Malicious (malware) component detected
|
|
value: |
|
|
vulns.all.exists(v, v.id.startsWith("MAL-"))
|
|
- name: ossf-dangerous-workflow
|
|
check_type: CheckTypeSecurityScorecard
|
|
summary: Component release pipeline appear to use dangerous workflows
|
|
value: |
|
|
scorecard.scores["Dangerous-Workflow"] == 0
|