
OWASP / CAPSEC के Common Weakness Enumeration डेटाबेस पर आधारित एक कमांड लाइन CWE खोज उपकरण।
OWASP / CAPSEC के Common Weakness Enumeration डेटाबेस पर आधारित एक कमांड लाइन CWE खोज उपकरण।
आधिकारिक OWASP CWE टूलकिट पृष्ठ
यदि आपके पास Node.js वातावरण है, तो आप npx टूल का उपयोग करके cwe-tool को इस प्रकार आमंत्रित कर सकते हैं:
npx cwe-tool [...command-line options...]
docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test
git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool .
ऊपर -t image name आपकी पसंद का एक इमेज नाम हो सकता है!
Docker के साथ उदाहरण चलाएं
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test
Github पैकेज रजिस्ट्री से इमेज पुल करें और खोज चलाएं
docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test
CWE टूल का आउटपुट JSON है ताकि डेटा का प्रसंस्करण या बाद में जांच की जा सके।
कमांड-लाइन विकल्पों का सारांश:
| कमांड-लाइन तर्क | विवरण | कार्यान्वित |
|---|---|---|
--id | इसके ID द्वारा CWE डेटा प्राप्त करें. | ✅ |
--parent-id | जब --id और --parent-id दोनों प्रदान किए जाते हैं, तो केवल वे CWE ids लौटाता है जो पैरेंट id को संतुष्ट करते हैं. | ✅ PRs का स्वागत है |
--indirect | जब --parent-id के साथ निर्दिष्ट किया जाता है, तो ट्री के मूल तक सभी अप्रत्यक्ष पैरेंट्स को पुनर्प्राप्त करता है. | ✅ |
--search | स्ट्रिंग खोज सभी मिलान CWE शीर्षकों को लौटाता है | ✅ |
--show-membership | सभी CWE IDs को उनके CWE श्रेणी सदस्यता संबंधों के साथ लौटाता है | ❌ PRs का स्वागत है |
npx cwe-tool --id 22
निम्नलिखित कमांड सभी CWE IDs को फ़िल्टर करता है कि क्या वे किसी दिए गए पैरेंट ID के लिए ट्री में किसी प्रत्यक्ष या अप्रत्यक्ष संबंध को संतुष्ट करते हैं।
npx cwe-tool --id 22 --parent-id 167 --indirect
आउटपुट निम्नलिखित JSON है: