Standard code auditing method and device and computer equipment
By receiving code databases and scanning rule files, generating configuration files, and using Codeql tools to automatically detect vulnerabilities, the problem of low efficiency in traditional code auditing is solved, achieving efficient and standardized code auditing and outputting unified structured reports.
Patent Information
- Application Number
- CN202510847236.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-10-24
AI Technical Summary
Traditional code auditing methods are inefficient and unstandardized. Relying on manual line-by-line auditing can easily miss vulnerabilities and produce inconsistent results.
By receiving a code database and scanning rule files, a configuration file is generated. Vulnerabilities are automatically detected using code auditing tools, and a structured audit report is output. Static analysis is performed using Codeql tools to generate audit results in SARIF format.
It enables efficient and standardized code auditing, improves detection speed and quality, ensures the coverage and authority of vulnerability detection, and outputs unified structured reports.
Smart Images

Figure CN120832673A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of code audit, in particular to a compliance code audit method and device and computer equipment. BACKGROUND
[0002] With the deep integration of cloud computing, big data and Internet of Things technology, Internet infrastructure has penetrated into key areas such as finance, government affairs and medical treatment, and its security is directly related to the stable operation of social economy. In this context, code audit, as a core link of the software security life cycle, aims to identify potential security vulnerabilities, logical errors and non-compliance with best practices in code, so as to correct them in time and help enterprises establish a more stable defense system to resist increasingly complex network security challenges.
[0003] However, the traditional manual audit mode is facing severe challenges. Auditors usually adopt a combination of line-by-line reading and experience judgment to conduct code audit. However, in the face of a large amount of code content and missing items, it is time-consuming and laborious, and vulnerabilities are easy to be missed. In addition, the professional level of auditors is uneven, which may lead to inconsistent detection results.
[0004] At present, there is no effective solution to the problems of low code audit efficiency and non-standardization in the related art. SUMMARY
[0005] A compliance code audit method, device and computer equipment are provided in the present embodiment to solve the problems of low code audit efficiency and non-standardization in the related art.
[0006] In a first aspect, a compliance code audit method is provided in the present embodiment, which comprises:
[0007] receiving a code database and a scanning rule file; the code database is obtained based on source code to be audited; the scanning rule file is obtained based on a general defect enumeration database;
[0008] generating a configuration file based on the path of the code database and the scanning rule file;
[0009] based on the configuration file, running a code audit tool to audit the vulnerability items corresponding to the code database by using the scanning rule file, and outputting the audit result.
[0010] In some embodiments, based on the configuration file, running a code audit tool to audit the vulnerability items corresponding to the code database by using the scanning rule file, and outputting the audit result, comprises:
[0011] parsing the configuration file to obtain paths of the code database and the scan rule file;
[0012] traversing each of the scan rule files, and based on each of the scan rule files, invoking and running the code audit tool;
[0013] auditing, by using the scan rule file, a vulnerability item corresponding to the code database, and outputting an audit result.
[0014] In some embodiments, the method further comprises: based on the audit result, generating a structured audit report; and the audit result is a static analysis result interchange format.
[0015] In some embodiments, based on the audit result, generating a structured audit report comprises:
[0016] parsing the audit result to extract target data;
[0017] saving the target data in the form of a structure of Go language to obtain structure data;
[0018] converting the structure data into a character-separated value format to obtain the structured audit report.
[0019] In some embodiments, a result item in the structured audit report comprises:
[0020] a tool used, a risk level of a vulnerability item, a common vulnerability enumeration number of the vulnerability item, a name of the vulnerability item, a code analysis description of the vulnerability item, a code location of the vulnerability item, and a code line number of the vulnerability item.
[0021] In some embodiments, the code audit tool is a Codeql tool.
[0022] In some embodiments, the method further comprises:
[0023] obtaining source code to be audited, and compiling, based on the Codeql tool, the source code to obtain a code database;
[0024] generating a scan rule file based on a query rule of the Codeql tool and a common vulnerability enumeration database.
[0025] In a second aspect, a compliance code audit device is provided in the embodiments, and the device comprises:
[0026] a data receiving module configured to receive a code database and a scan rule file; the code database is obtained based on source code to be audited; and the scan rule file is obtained based on a common vulnerability enumeration database;
[0027] The configuration module is configured to generate a configuration file based on the code database and the path of the scanning rule file;
[0028] The audit module is configured to run a code audit tool based on the configuration file to audit the vulnerability items corresponding to the code database by using the scanning rule file, and output an audit result.
[0029] In a third aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the compliance code audit method in the first aspect when executing the computer program.
[0030] In a fourth aspect, the present application further provides a computer readable storage medium. The computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the compliance code audit method in the first aspect.
[0031] Compared with the related art, in the embodiment provided in the present application, the compliance code audit method, device and computer device are provided. The code database and the scanning rule file are received. The code database is obtained based on the source code to be audited. The scanning rule file is obtained based on the general defect enumeration database. A configuration file is generated based on the path of the code database and the scanning rule file. A code audit tool is run based on the configuration file to audit the vulnerability items corresponding to the code database by using the scanning rule file, and an audit result is output. A structured audit report is generated based on the audit result. The problems of low efficiency and non-standard of traditional manual line-by-line audit are solved. The present application provides a standardized process to output a unified audit report. The automatic call of the automatic tool is realized. The vulnerability is detected efficiently. The standard of the vulnerability detection is standardized by the general defect enumeration database. The coverage and authority of the vulnerability detection are ensured. The audit speed and quality are improved.
[0032] Details of one or more embodiments of the present application are presented in the following drawings and description to make other features, objects and advantages of the present application more apparent. BRIEF DESCRIPTION OF DRAWINGS
[0033] The drawings described herein are used to provide further understanding of the present application, and form a part of the present application. The schematic embodiments of the present application and the description thereof are used to explain the present application, and do not constitute an improper limitation on the present application. In the drawings:
[0034] Figure 1 It is a hardware structure block diagram of the terminal for the compliance code audit method in the embodiments of the present application;
[0035] Figure 2A flowchart of a compliance code auditing method in an embodiment of the present application;
[0036] Figure 3 A flowchart of generating a structured audit report based on an audit result in an embodiment of the present application;
[0037] Figure 4 A flowchart of a compliance code auditing method in a preferred embodiment of the present application;
[0038] Figure 5 A structural block diagram of a compliance code auditing device in an embodiment of the present application.
[0039] The reference signs: 102, processor; 104, memory; 106, transmission device; 108, input and output device; 51, data receiving module; 52, configuration module; 53, audit module. DETAILED DESCRIPTION
[0040] In order to more clearly understand the purpose, technical solutions and advantages of the present application, the present application is described and explained below in conjunction with the drawings and embodiments.
[0041] Unless otherwise defined, technical terms or scientific terms used in the present application shall have the general meaning understood by a person with ordinary skill in the art to which the present application belongs. In the present application, "one", "a", "an", "the", "these" and similar words do not represent a quantitative limitation, and they can be singular or plural. In the present application, the terms "include", "contain", "have" and any variants thereof have the purpose of covering non-exclusive inclusion; for example, a process, method and system, product or device containing a series of steps or modules (units) are not limited to the listed steps or modules (units), but can include steps or modules (units) not listed, or can include other steps or modules (units) inherent to the process, method, product or device. In the present application, the terms "connected", "connected", "coupled" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. In the present application, "multiple" means two or more. The association between the associated objects is described by the term "and / or", which means that there can be three relationships, for example, "A and / or B" can mean that A exists alone, A and B exist together, and B exists alone. In general, the character " / " represents an "or" relationship between the associated objects. In the present application, the terms "first", "second", "third" and the like are only used to distinguish similar objects, and do not represent a specific order of the objects.
[0042] The method embodiments provided in the present embodiment can be executed in a terminal, a computer or a similar computing device. For example, it can be run on a terminal,Figure 1 is a hardware structure block diagram of a terminal of the compliance code auditing method of the present embodiment. As shown in Figure 1 , the terminal can include one or more (only one is shown in Figure 1 ) processors 102 and a memory 104 for storing data, wherein the processor 102 can include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal can also include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above terminal. For example, the terminal can also include more or less components than those shown in Figure 1 , or have a different configuration from that shown in Figure 1 .
[0043] The memory 104 can be used to store computer programs, such as software programs of application software and modules, such as the computer program corresponding to the compliance code auditing method in the present embodiment. The processor 102 performs various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the terminal through a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0044] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by a communication provider of the terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC) which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module which is used to communicate with the Internet in a wireless manner.
[0045] In the present embodiment, a compliance code auditing method is provided, Figure 2 is a flowchart of the compliance code auditing method of the present embodiment, as shown in Figure 2 , the flowchart includes the following steps:
[0046] Step S210, receiving a code database and a scanning rule file; the code database is obtained based on source code to be audited; the scanning rule file is obtained based on a common weakness enumeration database.
[0047] Specifically, the code database and the scanning rule file are provided by a user, and the user makes the code database and the scanning rule file in advance before performing auditing. The code database is a queryable relational database, and is used to store source code to be audited. The scanning rule file is used to query the code database, so as to find code defects. The scanning rule file is generated based on a common weakness enumeration database (CWE). The common weakness enumeration database provides a directory of common vulnerabilities in software and hardware of an organization technology stack, includes detailed descriptions of common weaknesses and guides security coding standards, and is an internationally recognized software defect classification standard. The scanning rule file converts CWE entries into executable scanning rules, and ensures uniform detection standards.
[0048] Step S220, generating a configuration file based on paths of the code database and the scanning rule file.
[0049] Specifically, the paths of the required database and the scanning rule are specified in the form of the configuration file, so as to query vulnerabilities item by item.
[0050] Step S230, running a code auditing tool based on the configuration file, so as to audit a vulnerability item corresponding to the code database by using the scanning rule file, and output an auditing result.
[0051] Specifically, each CWE-specific scanning rule file is read in the form of traversal. At this time, the code auditing tool obtains corresponding commands through the scanning rule file, calls related commands, queries the code database, and finally outputs the query result in a preset format, to obtain a standardized auditing result. The auditing result completely records an auditing track of each vulnerability item, and can also be used for further analysis.
[0052] The code audit tool can adopt a static code analysis tool, for example, Semgrep, Codeql, or ESLint, etc. Semgrep is a lightweight, open-source static code analysis tool that focuses on code security, quality detection, and pattern matching analysis. It quickly scans code through a rule language (similar to regular expressions) and supports multiple programming languages and frameworks. Codeql is a code analysis engine developed by GitHub for automatically performing security checks. It allows users to query code as data to discover vulnerabilities in code repositories. It supports multiple languages (such as Java, Go, C / C++, Javascript, Ruby, Python), and provides a unified reusable QL language for security researchers to conduct vulnerability mining. ESLint is also an open-source project that can be used to find and fix problems in JavaScript code. Users can run ESLint in text editors or continuous integration pipelines and customize rules and parsers.
[0053] In the embodiment, the code audit tool is run based on the configuration file to audit the vulnerability items corresponding to the code database by using the scan rule files, and output the audit results. Based on the audit results, a structured audit report is generated. The embodiment provides a standardized process to output a unified audit report, automatically calls the code audit tool in a packaged form, efficiently detects vulnerabilities, and ensures the coverage and authority of vulnerability detection by standardizing vulnerability detection through the general defect enumeration database, thereby improving the speed and quality of auditing.
[0054] In some embodiments, the code audit tool is run based on the configuration file to audit the vulnerability items corresponding to the code database by using the scan rule files, and output the audit results, including:
[0055] Step S231, parse the configuration file to obtain the paths of the code database and the scan rule files.
[0056] Step S232, traverse each scan rule file, and based on each scan rule file, call and run the code audit tool.
[0057] Step S233, audit the vulnerability items corresponding to the code database by using the scan rule files, and output the audit results.
[0058] Specifically, the scan rule file is recorded in the form of a directory, constituting a scan rule library. All scan rule files (extension. ql) based on the CWE vulnerability classification can be identified by performing a depth-first search and recursively traversing the scan rule library directory, and the paths thereof are stored as a path array. Subsequently, the array is traversed, and for each file path, the Codeql engine is called to perform code database analysis, load the specified CWE rule, and perform special auditing on the target code library, and finally generate a standard structured audit result.
[0059] In the embodiment, all CWE corresponding scan rule files in the rule library are automatically discovered by recursive traversal, without the need for manual maintenance of the rule list, thereby improving query efficiency and reducing the risk of errors. Based on the path array, distributed scanning can be achieved (each CWE rule as an independent task), which greatly improves the efficiency compared with serial scanning.
[0060] In some embodiments, the method further comprises: based on the audit result, generating a structured audit report; and the audit result is in a static analysis result interchange format.
[0061] Specifically, the specified code auditing tool outputs the audit result in a static analysis result interchange format. The static analysis result interchange format (SARIF) is a specification for describing static analysis results, used to exchange and understand static analysis reports between different tools. The SARIF format can carry extremely rich scan result information, which is crucial for in-depth understanding of vulnerabilities, debugging queries, or integration into advanced platforms. For example, by specifying the “— format” parameter of Codeql, the sarifv2.1.0 format is specified. Further, a result directory is generated under the directory of the current project, and the sarifv format audit result is stored as a process file in the result directory. Traversing the files under the result directory, parsing the process file, and converting the audit result into a structured audit report, help to visualize the output of the audit result and improve the readability of the audit result.
[0062] In some embodiments, based on the audit result, a structured audit report is generated, including: Figure 3
[0063] Step S241, parsing the audit result to extract the target data.
[0064] Specifically, the audit result is a sarifv file in JSON format, which contains original, complete, standardized and extremely informative scan results. By parsing the sarifv file, the required saved data, i.e., target data, such as specific attributes of a vulnerability item, including but not limited to the risk level of the vulnerability item, the Common Vulnerability and Enumeration Number (CVE) of the vulnerability item, the name of the vulnerability item, and the code analysis description of the vulnerability item, are read.
[0065] In step S242, the target data is saved in the form of a Go language structure body to obtain structure body data.
[0066] Specifically, the JSON format of the sarifv file is a weakly-typed data structure, and direct operation may cause type errors. The Go language structure body provides strong type constraints for JSON data, avoiding mismatched field types. In addition to serving as a type-safe data hub, the Go structure body also serves as the core of the structured conversion engine.
[0067] In step S243, the structure body data is converted into a character-separated value format to obtain a structured audit report.
[0068] Specifically, the character-separated value format (Comma Separated Values, CSV) is a file format used to store tabular data, usually in plain text form. Each record in a CSV file consists of multiple fields, which are separated by specific characters.
[0069] In this embodiment, by further format conversion processing of the audit result, the vulnerability items used by the entire code audit tool and their results are highlighted in the result file, and the audit process of the entire code audit tool is refined and accurately displayed.
[0070] In some embodiments, the result items in the structured audit report include: the tool used, the risk level of the vulnerability item, the CVE of the vulnerability item, the name of the vulnerability item, the code analysis description of the vulnerability item, the code location of the vulnerability item, and the code line number of the vulnerability item.
[0071] Specifically, the attributes of the above-mentioned result items are introduced as follows:
[0072] Tool, indicating the tool used, for example, the code audit tool used by this item is the Codeql tool, and the value of Tool is Codeql.
[0073] Severity, indicating the risk level of the vulnerability item when the vulnerability exists, and the value is info when the vulnerability does not exist.
[0074] A Common Weakness Enumeration (Cwe) of the vulnerability item, indicating a unified Cwe number of the current vulnerability item.
[0075] A name (Code) of the vulnerability item, which is the name of the specific vulnerability item.
[0076] A code analysis description (Description) of the vulnerability item, which is a specific code analysis description of the vulnerability item, and is beneficial to the reader to quickly understand the harm of the vulnerability item and the possible risk to the current code.
[0077] A code location (Location) of the vulnerability item, indicating the code location of the vulnerability item when the vulnerability item exists, and the value is a file path.
[0078] A code line number (Line) of the vulnerability item, indicating a specific code line number.
[0079] In some embodiments, the code auditing tool is a Codeql tool. Specifically, Codeql is a static code analysis tool that supports multiple language programming (such as Java, Go, C / C++, Javascript, Ruby, Python), supports Android, and provides a unified reusable QL language for security researchers to conduct vulnerability mining.
[0080] In some embodiments, the method further comprises:
[0081] Step S250, obtaining the source code to be audited, and compiling the source code based on the Codeql tool to obtain a code database.
[0082] Step S260, generating a scanning rule file based on the query rule of the Codeql tool and the common weakness enumeration database.
[0083] Specifically, in order to further simplify manual operation, the steps of generating the code database and the scanning rule file are also integrated, and the user only needs to input the source code to be audited, that is, the Codeql tool can automatically form a queryable code database, and based on the preset common weakness enumeration database, a scanning rule file is automatically generated. Among them, Codeql can convert the source code to be audited into a queryable database, and reconstruct the database through internal modules to form a relational database. Query through the query file of the relational database, that is, the rule description file (.ql file). Codeql audits the source code through the above-mentioned database generated by the source code and the rule description file, and outputs the related vulnerability results.
[0084] The preferred embodiments will be described and explained below. Figure 4is a flowchart of the compliance code audit method of the preferred embodiment.
[0085] Firstly, the user inputs two data: code database and scanning rule file. The code database is a relational database obtained by compiling the source code to be audited by the code audit tool Codeql. The scanning rule file is a scanning rule based on the vulnerability detection of the general defect enumeration database.
[0086] Next, referring to Figure 4 The compliance code audit method of the preferred embodiment includes the following steps:
[0087] S1, receive the code database and the scanning rule file, both of which are in the form of a directory. The preferred embodiment specifies the path of the required code database and the path of the scanning rule by the form of a configuration file, forming a configuration file.
[0088] S2, identify all scanning rule files based on CWE vulnerability classification by recursively traversing the directory, and store their paths as a path array. Then traverse the array, for each file path, call the Codeql engine to perform code database analysis, load the specified CWE rule to conduct special audit on the target code library.
[0089] S3, specify the output format as sarifv2.1.0 by the “—format” parameter of Codeql, and generate a result directory under the current project directory. Store the sarifv format process file in the result directory.
[0090] S4, traverse the files under the result, process various data in the files by parsing the above-mentioned json format sarifv file, read the required saved data, and save it in the form of Go language structure, and then output it to the final CSV table form result file. The result file is a specific implementation of the process file for the entire code audit specification. The result file is output as an audit report.
[0091] In the preferred embodiment, the user only needs to provide the database to be tested and the file path of the vulnerability item to be tested, improving the efficiency of manual code audit. By unifying the audit results in the code audit output process (i.e. sarifv format process file), and further converting it into a structured audit report (i.e. process file in the form of a csv table), the vulnerability items and their results used by the entire code audit tool are represented, thus showing the entire code audit tool audit process. The preferred embodiment improves the code audit efficiency and result standardization.
[0092] In the present embodiment, a compliance code audit device is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and will not be described again. The terms "module", "unit", "sub-unit" and the like used below can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware, or a combination of software and hardware is also possible and is contemplated.
[0093] Figure 5 is a structural block diagram of the compliance code audit device of the present embodiment, as Figure 5 shown, the device comprises a data receiving module 51, a configuration module 52, and an audit module 53.
[0094] The data receiving module 51 is configured to receive a code database and a scanning rule file; the code database is obtained based on source code to be audited; and the scanning rule file is obtained based on a common vulnerability enumeration database.
[0095] The configuration module 52 is configured to generate a configuration file based on paths of the code database and the scanning rule file.
[0096] The audit module 53 is configured to run a code audit tool based on the configuration file, to audit vulnerability items corresponding to the code database by using the scanning rule file, and to output an audit result.
[0097] In some embodiments, the audit module 53 is further configured to parse the configuration file to obtain paths of the code database and the scanning rule file; to traverse each scanning rule file, and to call and run the code audit tool based on each scanning rule file; to audit vulnerability items corresponding to the code database by using the scanning rule file; and to output an audit result.
[0098] In some embodiments, the method further comprises a report generation module configured to generate a structured audit report based on the audit result; and the audit result is a static analysis result interchange format.
[0099] In some embodiments, the report generation module is further configured to parse the audit result to extract target data; to save the target data in the form of a Go language structure to obtain structure data; and to convert the structure data into a character-separated value format to obtain a structured audit report.
[0100] In some embodiments, the result items in the structured audit report comprise a tool used, a risk level of a vulnerability item, a common vulnerability enumeration number of the vulnerability item, a name of the vulnerability item, a code analysis description of the vulnerability item, a code location of the vulnerability item, and a code line number of the vulnerability item.
[0101] In some embodiments among them, the code audit tool is a Codeql tool.
[0102] In some embodiments among them, the method further comprises a data preparation module configured to obtain source code to be audited, compile the source code based on the Codeql tool to obtain a code database, and generate a scanning rule file based on a query rule of the Codeql tool and a general defect enumeration database.
[0103] It should be noted that each of the above modules can be a functional module or a program module, and can be implemented by software or hardware. For the modules implemented by hardware, each of the above modules can be located in the same processor, or each of the above modules can be located in different processors in any combination.
[0104] In the embodiment, a computer device is also provided, which comprises a memory and a processor, the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the above method embodiments.
[0105] Optionally, the computer device can further comprise a transmission device and an input and output device, wherein the transmission device is connected with the processor, and the input and output device is connected with the processor.
[0106] It should be noted that the specific examples in the embodiment can refer to the examples described in the above embodiments and optional implementation manners, which will not be described herein again.
[0107] In addition, in combination with the compliance code audit method provided in the above embodiments, a storage medium can also be provided to implement the compliance code audit method in the embodiment. The storage medium stores a computer program, and the computer program is executed by a processor to implement any of the compliance code audit methods in the above embodiments.
[0108] It should be understood that the specific embodiments described herein are only used to explain the application, but not to limit it. According to the embodiments provided in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.
[0109] It is apparent that the drawings depicted are only a few example embodiments of the present application and that a person of ordinary skill in the art would be able to adapt the present application to other similar situations without paying creative labor. In addition, it is understood that, although the work done in developing the present application can be complex and long, certain modifications, such as design, manufacture or production, made by a person of ordinary skill in the art based on the technical content disclosed in the present application, should not be regarded as a lack of disclosure.
[0110] The word "embodiment" in the present application means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The presence of this phrase in various places in the specification does not necessarily mean the same embodiment, nor does it mean independence or alternatives to other embodiments. It is clear or implicitly understood by those of ordinary skill in the art that the embodiments described in the present application can be combined with other embodiments without conflict.
[0111] The above-described embodiments only express several implementation manners of the present application, which are described in detail and specifically, but should not be understood as a limitation on the scope of patent protection. It should be noted that, for those of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present application, which are all within the scope of protection of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A method of compliance code audit, characterized by, The method comprises: receiving a code database and a scanning rule file; the code database is obtained based on source code to be audited; the scanning rule file is obtained based on a common vulnerability enumeration database; generating a configuration file based on paths of the code database and the scanning rule file; based on the configuration file, running a code audit tool to audit vulnerability items corresponding to the code database by using the scanning rule file, and outputting an audit result.
2. The method of claim 1, wherein, based on the configuration file, running a code audit tool to audit vulnerability items corresponding to the code database by using the scanning rule file, and outputting an audit result, comprising: parsing the configuration file to obtain paths of the code database and the scanning rule file; traversing each of the scanning rule files, and based on each of the scanning rule files, calling and running the code audit tool; auditing vulnerability items corresponding to the code database by using the scanning rule file, and outputting an audit result.
3. The method of claim 1, wherein, The method further comprises: based on the audit result, generating a structured audit report; the audit result is a static analysis result interchange format.
4. The method of claim 3, wherein, based on the audit result, generating a structured audit report, comprising: parsing the audit result to extract target data; saving the target data in the form of a Go language structure to obtain structure data; converting the structure data into a character-separated value format to obtain a structured audit report.
5. The method of claim 3, wherein, The result items in the structured audit report include: the tool used, the risk level of the vulnerability item, the common vulnerability enumeration number of the vulnerability item, the name of the vulnerability item, the code analysis description of the vulnerability item, the code location of the vulnerability item, and the code line number of the vulnerability item.
6. The method of claim 1, wherein, The code audit tool is a Codeql tool.
7. The method of claim 6, wherein, The method further comprises: obtaining source code to be audited, and compiling the source code based on the Codeql tool to obtain a code database; based on the query rule of the Codeql tool and the common vulnerability enumeration database, generating a scanning rule file.
8. A compliance code audit apparatus, characterized by, The device comprises: a data receiving module for receiving a code database and a scanning rule file; the code database is obtained based on source code to be audited; the scanning rule file is obtained based on a common vulnerability enumeration database; a configuration module for generating a configuration file based on paths of the code database and the scanning rule file; an audit module for, based on the configuration file, running a code audit tool to audit vulnerability items corresponding to the code database by using the scanning rule file, and outputting an audit result. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the method of any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the method of any one of claims 1 to 7.