core/adapters/tool.semgrep.adapter.ts

core/adapters/tool.semgrep.adapter.ts is a file in GovLab Quality. 31 lines of code and 8 definitions.

import { commandHint, semgrepFailed } from "#configuration/strings/tool.strings";
import { messageScan, scanTool } from "#core/adapters/tool.adapter";
import type { RunResult } from "#types/finding.types";
import type { RunnerContext } from "#types/tool.types";
import { SUCCESS_STATUSES } from "#configuration/constants/tool.constants";
import { commandOf } from "#core/lexers/invocation.lexer";
import { defineTool } from "#core/registries/tool.registry";
import { exitDetail } from "#core/selectors/failure.selector";
import { parseSemgrepOutput } from "#core/parsers/tool.semgrep.parser";
import { toolAdvisory } from "#core/factories/tool.factory";
import { toolSetting } from "#core/resolvers/tool.resolver";

const TOOL = "semgrep";
const DEFAULTS = { command: TOOL, config: "" };

const runSemgrep = async function runSemgrep(context: RunnerContext): Promise<RunResult> {
    const { command, config } = await toolSetting(context.root, TOOL, DEFAULTS);
    const { bin, prefix } = commandOf(command, TOOL);
    const advisory = toolAdvisory(context, TOOL, commandHint(TOOL, bin));
    const spec = messageScan(
        advisory,
        SUCCESS_STATUSES,
        (result) => parseSemgrepOutput(result.stdout, context.ecosystem),
        (exit) => semgrepFailed(exit.status, exitDetail(exit)),
    );
    const configArgs = config.length > 0 ? ["--config", config] : [];
    return scanTool(
        advisory,
        { args: [...prefix, ...configArgs, "--json", "--quiet", ...context.paths], bin, cwd: context.root },
        spec,
    );
};

defineTool({ ecosystems: ["csharp"], run: runSemgrep, tool: TOOL });