Skip to content

Add SAST scanner endpoint - #27

Open
ymuft wants to merge 5 commits into
SasanLabs:mainfrom
ymuft:feat/sast-endpoint
Open

ymuft wants to merge 5 commits into
SasanLabs:mainfrom
ymuft:feat/sast-endpoint

Conversation

@ymuft

@ymuft ymuft commented Sep 17, 2026 •

Copy link
Copy Markdown

Summary

  • add a SAST ground-truth catalog for the current vulnerable PHP levels
  • expose GET /VulnerableApp-php/scanner/sast using the same response shape as VulnerableApp
  • register the route in Bootstrap
  • add integration checks for both the direct endpoint and the facade aggregate

The catalog keeps the vulnerable level/type mapping explicit while deriving each level's current method line with reflection, so line numbers stay aligned when source files move.

Validation

  • php -l on the changed PHP files
  • local catalog smoke test returns 17 rows with the expected fields
  • CI validates that the direct endpoint is parseable JSON and that the facade includes the VulnerableApp-php key

Closes #24

Summary by CodeRabbit

  • New Features

    • Added a static application security testing (SAST) scanner endpoint that returns detected vulnerability details, including CWE identifiers, affected files, line numbers, and vulnerability types.
    • Added routing support so the SAST results can be accessed through the application’s scanner interface.
  • Tests

    • Added automated validation checks to confirm SAST responses are available and follow the expected JSON structure.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

Review limit reached

Next included review available in 39 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9c2f1456-6ba0-485d-8df0-b0edeae6ddec

📥 Commits

Reviewing files that changed from the base of the PR and between a2d794c and de69240.

📒 Files selected for processing (2)
  • src/Scanner/SASTScanner.php
  • src/framework/Bootstrap.php

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a8e34461-ce19-4cf1-9b89-1765d98603a1

📥 Commits

Reviewing files that changed from the base of the PR and between b3cc5ce and a2d794c.

📒 Files selected for processing (3)
  • .github/workflows/php.yml
  • src/Scanner/SASTScanner.php
  • src/framework/Bootstrap.php

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The change adds a SAST scanner endpoint. It generates JSON rows from cataloged vulnerability methods, registers the endpoint, and adds workflow checks for direct and aggregated scanner responses.

Changes

SAST endpoint

Layer / File(s) Summary
SAST result generation
src/Scanner/SASTScanner.php
Adds a vulnerability catalog and uses reflection to generate rows with CWE, file path, line, source count, and type fields. The sast() method returns the rows as JSON.
Endpoint registration and validation
src/framework/Bootstrap.php, .github/workflows/php.yml
Loads SASTScanner, registers /VulnerableApp-php/scanner/sast, and validates direct and aggregated scanner responses in the PHP workflow.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Workflow
  participant Router
  participant SASTScanner
  Workflow->>Router: GET /VulnerableApp-php/scanner/sast
  Router->>SASTScanner: Invoke sast()
  SASTScanner-->>Router: Return SAST rows as JSON
  Router-->>Workflow: Return scanner response
  Workflow->>Workflow: Validate response fields and VulnerableApp-php key
Loading

Merge Risk: ⚪ Minimal · up to a2d79

The new endpoint returns the expected JSON row shape and is registered for facade consumption. No current merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 2 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: adding the SAST scanner endpoint and its supporting integration.
Linked Issues check ✅ Passed Issue #24 requires the SAST route, valid JSON, router registration, facade consumption, and the VulnerableApp-php facade key. src/framework/Bootstrap.php registers `/VulnerableApp-php/scanner/sast…
Out of Scope Changes check ✅ Passed The changes remain within issue #24. They add the SAST catalog and endpoint, register the route, and add syntax and integration checks for the endpoint and facade aggregation. No unrelated DAST or oth…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 2 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.


class SASTScanner
{
private const CATALOG = [

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it would be better if we have a csv file listing all the sast vulnerabilities and sast endpoint exposes it as Json file. you can look at https://github.com/SasanLabs/VulnerableApp/blob/master/src/main/resources/scanner/sast/expectedIssues.csv for more information.

"filePath" => "src/MagicHashVulnerability/MagicHash.php",
"methods" => ["level1", "level2"],
"cwe" => "CWE-704",
"type" => "Magic Hash Exploitation",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement /VulnerableApp-php/scanner/sast endpoint

2 participants