Команда сканирования

Запуск агента производится при помощи команды scan с возможными вариантами сканирования:

Опции запуска

Доступные и необходимые опции запуска агента для сканирования можно посмотреть при помощи флага help.

$ ./johnny scan --help
NAME:
   johnny scan - Run scan

USAGE:
   johnny scan [command [command options]]

COMMANDS:
   dir          Scan directory
   file         Scan file
   image        Scan image
   bom          Scan bom
   java         Scan java
   js           Scan js
   go           Scan go
   clang        Scan clang
   objective-c  Scan objective-c
   csharp       Scan csharp
   php          Scan php
   python       Scan python
   ruby         Scan ruby
   rust         Scan rust
   conda        Scan conda
   swift        Scan swift
   hex          Scan hex

OPTIONS:
   --alerts-format string                        Alerts format. Supported formats: coloredtable, table, text, csv, json. Default output to console. Supports multiformat. Example: 'coloredtable,csv>>csv.csv' (default: "coloredtable")
   --block-on-empty-result                       Block on empty result
   --bom-format string                           Bom format. Supported formats: cyclonedx_v1_4_json,cyclonedx_v1_5_json,cyclonedx_v1_6_ext_json,cyclonedx_v1_6_json,cyclonedx_v1_7_json (default: "cyclonedx_v1_6_json")
   --bom-path string                             Path for save bom file (default: "bom.json")
   --branch-or-tag string                        Reference to repository branch or tag (e.g. refs/tags/v1.0)
   --cg-lang string                              Language to parse call graph with. Supported languages: csharp,go,java,javascript,kotlin,python
   --cg-path string                              Path to call graph for vulnerability reachability analysis
   --cloud-resolve                               Activate cloud resolve
   --commit string                               Commit
   --create-project                              Create project in CodeScoring if not exists
   --create-project-categories                   Create project categories in CodeScoring if not exist
   --create-project-group                        Create group in CodeScoring if not exists
   --exclude-envs string                         Exclude the listed dependency environments (scopes) from the result, comma-separated, e.g. --exclude-envs=test,dev
   --format string, -f string                    Report format. Supported formats: coloredtable, table, text, junit, sarif, csv, gl-dependency-scanning-report, gl-code-quality-report. Default output to console. Supports multiformat. Example: 'coloredtable,junit>>junit.xml' (default: "coloredtable")
   --group-vulnerabilities-by string, -g string  Group vulnerabilities by. Supported kinds 'vulnerability', 'affect' (default: "vulnerability")
   --ignore string [ --ignore string ]           Ignore paths (--ignore first --ignore "/**/onem?re")
   --ignores-format string                       Displays the ignores of the specified project with formatting. Supported formats: coloredtable, table, text, csv, json. Default output to console. Supports multiformat. Example: 'coloredtable,csv>>csv.csv' (default: "coloredtable")
   --include-envs string                         Include only the listed dependency environments (scopes) in the result, comma-separated, e.g. --include-envs=compile,runtime
   --license string                              Project license code
   --no-summary                                  Do not print summary
   --no-wait                                     No wait analysis results
   --only-hashes                                 Search only for direct inclusion of dependencies using file hashes
   --policy-ignores                              Displays the ignores
   --project string                              Project name in CodeScoring
   --project-categories string                   Category names for created project in CodeScoring (comma-separated list)
   --project-group string                        Group for created or added project in CodeScoring
   --project-proprietor string                   Proprietor for created project in CodeScoring
   --reachability-format string                  Reachability paths format. Supported formats: json, text, table, coloredtable. Example: 'json>>reachability.json'
   --save-results                                Save results to CodeScoring. Used just together with project name
   --set-as-default-version                      Set branch or tag as the default project version in CodeScoring
   --sort-vulnerabilities-by string, -s string   Sort vulnerabilities by. Comma separated field names. For DESC - write field name with prefix '-'.
                                                 FieldNames: 'vulnerability', 'fixedversion', 'cvss2', 'cvss3', 'cwes', 'links', 'affect' (default: "-cvss4,-cvss3,-cvss2,fixedversion,vulnerability,cwes,links,affect")
   --stage string                                Policy stage (build, dev, source, stage, test, prod, proxy) (default: "build")
   --timeout int, -t int                         Timeout of analysis results waiting in seconds (default: 3600)
   --vex-file string                             Path to CycloneDX VEX file to apply before analysis
   --with-hashes                                 Search for direct inclusion of dependencies using file hashes
   --help, -h                                    show help

GLOBAL OPTIONS:
   --api_token string     API token for integration with CodeScoring server (required if api_url is set) (default: "api_token")
   --api_url string       CodeScoring server url (e.g. https://codescoring.mycompany.com) (required if api_token is set) (default: "api_url")
   --config string        config file (default: "codescoring-johnny-config.yaml")
   --localization string  Localization language (en|ru) (default: "en")
   --progress-bar string  Progress bar formats: spinner,text (default: "text")

В параметре --api_url должен быть указан полный адрес on-premise платформы. Значение для --api_token можно взять в профиле пользователя платформы.

Указание параметра --project позволит при сканировании применить политики, относящиеся к выбранному проекту.

Для указания пути к файлу сохранения SBOM необходимо добавить параметр --bom-path в запрос или назначить переменную bom-path в config-файле. По умолчанию SBOM сохраняется в директории запуска в файл bom.json.

Результаты работы

В зависимости от результата работы и параметров запуска агент возвращает соответствующий exit code:

  • 0 – успешное сканирование, проблемы не были выявлены;
  • 1 – в результате сканирования найдены проблемы, соответствующие настроенным политикам безопасности, необходимо действие пользователя;
  • 2 – ошибка сканирования;
  • 3 – пустой результат, не были найдены артефакты для анализа. Возвращается только если параметр --block-on-empty-result имеет значение true.

Ошибки резолва

2026.35.0 Если агенту не удалось разрешить зависимости для части манифестов, список таких манифестов выводится в конце результатов сканирования под заголовком Ошибки резолва. По нему можно проверить, всё ли необходимое для разрешения зависимостей есть в сборочном окружении.

Приоритет настроек

Поскольку параметры запуска агента можно настроить несколькими способами, при одновременном использовании двух и более способов агент будет принимать параметры в следующем порядке приоритетов:

  1. Значение команды scan-technology (если она используется);
  2. Значение флага команды;
  3. Значение переменной окружения;
  4. Значение из конфиг-файла.

Запуск без участия платформы

Если параметры --api_url и --api_token не заданы, запуск сканирования будет производиться без взаимодействия с платформой CodeScoring. В результате сканирования будет сгенерирован файл SBOM, содержащий только список компонентов и их версий без обогащения дополнительной информацией.

Страница была полезна?