Software Detection Method, System, Device, Equipment, Medium and Program Product

Connecting the SCA tool platform and the continuous integration tool platform through the open source governance platform, using API and OpenAPI to achieve automated detection of open source software, solving the problems of strong invasiveness and poor flexibility of SCA plug-ins in the existing technology, and improving detection efficiency and flexibility.

CN119512538BActive Publication Date: 2025-07-22GUOTAI JUNAN SECURITIES CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411575709.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-06
Publication Date
2025-07-22
Estimated Expiration
2044-11-06

AI Technical Summary

Technical Problem

In the prior art, when integrating the SCA tool platform with the continuous integration tool platform, it is necessary to deploy SCA plug-ins on the Devops platform, resulting in strong invasiveness and poor flexibility, making it difficult to achieve automated detection of open source software.

Method used

Through the open source governance platform as the intermediate layer, the API and OpenAPI are used to connect the SCA tool platform and the continuous integration tool platform to realize SCA detection, avoiding direct integration of the Devops platform, and users detect by calling the OpenAPI of the SCA tool platform.

Benefits of technology

It improves the flexibility and automation of the SCA tool platform for open source software detection, reduces manual deployment and management costs, and enhances detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119512538B_ABST
    Figure CN119512538B_ABST
Patent Text Reader

Abstract

The present application provides a software detection method, system, device, equipment, medium and program product. The method includes: the continuous integration tool platform obtains the compressed package of the target open-source software after compilation and packaging, and calls the interface of the open-source governance platform to send an SCA detection request for the target open-source software. After receiving the SCA detection request, the open-source governance platform verifies the legality of the SCA detection request based on the encrypted identity information; if the legality verification of the SCA detection request passes, it calls the interface of the SCA tool platform to upload the compressed package of the target open-source software and initiate the SCA detection of the target open-source software. The method of the present application, under the connection of the open-source governance platform, realizes the automatic detection of the target open-source software without integrating the continuous integration tool platform and the SCA tool platform, and improves the efficiency of security and quality detection of the target open-source software.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of software security technology, and in particular, to a software detection method, system, device, equipment, medium and program product. Background Art

[0002] During the development and testing of open-source software, in order to ensure that the use of open-source software complies with security and quality standards, it is necessary to set quality access control for open-source software. In the process of setting quality access control for open-source software, security quality detection is an important part. Among them, security quality detection mainly needs to consider factors such as the vulnerability level and license risk level of open-source software.

[0003] Currently, it is mainly achieved by deploying an SCA plugin of a Software Composition Analysis (SCA) tool platform on the Devops platform to perform security quality detection on open-source software. Among them, the SCA tool platform is mainly used to identify the vulnerability level and license risk level of open-source software. During the process of the Devops platform initiating detection on open-source software through the SCA plugin, the SCA plugin is invasive to the Devops platform. It is necessary to deploy an SCA plugin process on the Devops platform, and the SCA plugin has poor flexibility. The Devops platform needs to call the SCA plugin by inputting command-line parameters to achieve detection, making the Devops platform limited by the parameters supported by the SCA plugin and difficult to achieve automated detection of the target open-source software by the SCA plugin.

[0004] Therefore, realizing the automated detection of the target open-source software by the SCA tool platform, thereby improving the efficiency of security quality detection of open-source software, is an urgent problem to be solved. Summary of the Invention

[0005] This application provides a software detection method, system, device, equipment, medium and program product to solve the problem of automated detection of the target open-source software by the SCA tool platform.

[0006] In a first aspect, this application provides a software detection method, which is applied to an open-source governance platform. The method includes:

[0007] Receiving an SCA detection request of a target open-source software sent by a continuous integration tool platform by calling an interface of the open-source governance platform; the SCA detection request carries a compressed package of the target open-source software and encrypted identity information;

[0008] Based on the encrypted identity information, performing a legality verification on the SCA detection request;

[0009] If the legitimacy verification of the SCA detection request passes, call the interface of the SCA tool platform to upload the compressed package of the target open-source software, and initiate the SCA detection of the target open-source software.

[0010] In a possible way, after the legitimacy verification of the SCA detection request passes, the method further includes:

[0011] Receive the query request sent by the continuous integration tool platform through the call interface; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the query request includes: encrypted identity information;

[0012] Based on the encrypted identity information, perform legitimacy verification on the query request;

[0013] If the legitimacy verification of the query request passes, call the interface of the SCA tool platform to send the query request;

[0014] Receive the query result returned by the SCA tool platform;

[0015] Send the query result to the continuous integration tool platform.

[0016] In a possible way, the method further includes:

[0017] Receive the quality gate determination request of the target open-source software sent by the continuous integration tool platform through the call interface; the quality gate determination request carries the SCA detection result of the target open-source software and the encrypted identity information;

[0018] Based on the encrypted identity information, perform legitimacy verification on the quality gate determination request;

[0019] If the legitimacy verification of the quality gate determination request passes, obtain the quality gate determination result of the target open-source software through the quality gate decision tree model and the SCA detection result; the quality gate decision tree model at least includes: vulnerability risk decision tree, license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training the decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and marking results provided by the large model;

[0020] Send the quality gate determination result to the continuous integration tool platform.

[0021] In a possible way, the method further includes:

[0022] Receive the email notification request sent by the continuous integration tool platform through the call interface; the email notification request is used to request to feedback the SCA detection result and the quality gate determination result of the target open-source software to the target address through email; the email notification request includes the encrypted identity information;

[0023] Based on the encrypted identity information, perform a legality verification on the email notification request;

[0024] If the legality verification of the email notification request passes, send an email containing the SCA detection result and the quality gate determination result of the target open-source software to the target address.

[0025] In a second aspect, the present application provides a software detection method, which is applied to a continuous integration tool platform, and the method includes:

[0026] Obtain the compressed package of the target open-source software after compilation and packaging;

[0027] Call the interface of the open-source governance platform to send an SCA detection request for the target open-source software; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; the SCA detection request is used to trigger the open-source governance platform to call the SCA tool platform to perform an SCA detection on the target open-source software after the legality verification of the SCA detection request based on the encrypted identity information passes.

[0028] In a possible way, the method further includes:

[0029] Call the interface of the open-source governance platform to send a query request; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the query request includes: encrypted identity information;

[0030] Receive the query result obtained by the open-source governance platform calling the SCA tool platform after the legality verification of the query request based on the encrypted identity information passes.

[0031] In a possible way, the method further includes:

[0032] Call the interface of the open-source governance platform to send a quality gate determination request for the target open-source software; the quality gate determination request carries the SCA detection result of the target open-source software and the encrypted identity information;

[0033] Receive the quality gate determination result of the target open-source software obtained by the open-source governance platform through the quality gate decision tree model and the SCA detection result after verifying the legality of the quality gate determination request based on the encrypted identity information; the quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training the decision tree in advance using a training data set, and the training data set is constructed by marking based on the reference classification marking results provided by the large model.

[0034] In a possible way, the method further includes:

[0035] Call the interface of the open-source governance platform to send an email notification request; the email notification request is used to request to feedback the SCA detection result and the quality gate determination result of the target open-source software to the target address through email; the email notification request includes the encrypted identity information.

[0036] In a possible way, the method further includes:

[0037] When the quality gate determination result is passed, deploy the target open-source software;

[0038] When the quality gate determination result is not passed, perform development and repair on the target open-source software, compile and package it, and then re-detect it.

[0039] In a third aspect, the present application provides a software detection method, which is applied to an SCA tool platform, and the method includes:

[0040] Receive the compressed package of the target open-source software uploaded by the open-source governance platform by calling the interface of the SCA tool platform, and a trigger instruction for performing SCA detection on the target open-source software;

[0041] Based on the compressed package, perform SCA detection on the target open-source software.

[0042] In a possible way, the method further includes:

[0043] Receive a query request sent by the open-source governance platform by calling the interface of the SCA tool platform; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software;

[0044] Obtain a query result based on the query request;

[0045] Return the query result to the open-source governance platform.

[0046] Fourthly, the present application provides a software detection method, which includes:

[0047] The continuous integration tool platform obtains the compressed package of the target open-source software;

[0048] The continuous integration tool platform calls the interface of the open-source governance platform to send an SCA detection request for the target open-source software; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information;

[0049] The open-source governance platform performs a legality verification on the SCA detection request based on the encrypted identity information;

[0050] If the legality verification of the SCA detection request passes, the open-source governance platform calls the interface of the SCA tool platform to upload the compressed package of the target open-source software and initiate the SCA detection of the target open-source software;

[0051] The SCA tool platform performs SCA detection on the target open-source software based on the compressed package.

[0052] Fourthly, the present application provides a software detection system, which includes: a continuous integration tool platform, an open-source governance platform, and an SCA tool platform; wherein,

[0053] The continuous integration tool platform deploys a target script for executing the method described in any item of the second aspect by running the target script;

[0054] The open-source governance platform is used to execute the method described in any item of the first aspect;

[0055] The SCA tool platform is used to execute the method described in any item of the third aspect.

[0056] Fifthly, the present application provides a software detection device, which is applied to the open-source governance platform, and the device includes:

[0057] A receiving module, configured to receive an SCA detection request for the target open-source software sent by the continuous integration tool platform by calling the interface of the open-source governance platform; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information;

[0058] A verification module, configured to perform a legality verification on the SCA detection request based on the encrypted identity information;

[0059] A calling module, if the legality verification of the SCA detection request passes, calls the interface of the SCA tool platform to upload the compressed package of the target open-source software and initiate the SCA detection of the target open-source software.

[0060] In a sixth aspect, the present application provides a software detection device, which is applied to a continuous integration tool platform. The device includes:

[0061] An acquisition module, which acquires the compressed package of the target open-source software after compilation and packaging;

[0062] An invocation module, which invokes an interface of an open-source governance platform to send an SCA detection request for the target open-source software; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; the SCA detection request is used to trigger the open-source governance platform to call an SCA tool platform to perform SCA detection on the target open-source software after passing the legitimacy verification of the SCA detection request based on the encrypted identity information.

[0063] In a seventh aspect, the present application provides a software detection device, which is applied to an SCA tool platform. The device includes:

[0064] A receiving module, which receives the compressed package of the target open-source software uploaded by the open-source governance platform through invoking the interface of the SCA tool platform, and a trigger instruction for performing SCA detection on the target open-source software;

[0065] A detection module, which performs SCA detection on the target open-source software based on the compressed package.

[0066] In an eighth aspect, the present application provides an electronic device, which includes: a processor and a memory communicatively connected to the processor;

[0067] The memory stores computer-executable instructions;

[0068] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of the first aspect, the second aspect or the third aspect.

[0069] In a ninth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of the first aspect, the second aspect or the third aspect.

[0070] In a tenth aspect, the present application provides a computer program product, including a computer program, which when executed by a processor, implements the method according to any one of the first aspect, the second aspect or the third aspect.

[0071] In the embodiment of the present application, the connection between the SCA tool platform and the continuous integration tool platform is realized through the open source governance platform. Compared with the method of manually deploying and managing SCA plugins on the Devops platform in the prior art, the invasiveness of the SCA plugins to the continuous integration tool platform is avoided. Regardless of how the target open source software changes, the user only needs to directly call the OpenAPI of the SCA tool platform to achieve the security and quality detection of the target open source software by the SCA tool platform, which increases the flexibility of the SCA tool platform to detect the target open source software and realizes the automatic detection of the target open source software by the SCA tool platform. Description of the Drawings

[0072] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0073] Figure 1 Schematic diagram of the connection relationship between the Devops platform, the open source governance platform and the SCA tool platform provided by the embodiment of the present application;

[0074] Figure 2 Schematic diagram of the process of a software detection method provided by the embodiment of the present application;

[0075] Figure 3 Flowchart of an RSA encryption algorithm;

[0076] Figure 4 Schematic diagram of the process of querying the SCA detection status and detection results provided by the embodiment of the present application;

[0077] Figure 5 Schematic diagram of the process of quality access control determination for the target open source software provided by the embodiment of the present application;

[0078] Figure 6 Schematic diagram of the process of classifying and labeling the training dataset provided by this embodiment;

[0079] Figure 7 Schematic diagram of the process of the continuous integration tool taking different measures according to different quality access control determination results provided by the embodiment of the present application;

[0080] Figure 8 Schematic diagram of the shell script of the continuous integration tool platform provided by the embodiment of the present application;

[0081] Figure 9 Schematic diagram of the structure of the first software detection device provided by the embodiment of the present application;

[0082] Figure 10 Schematic diagram of the structure of the second software detection device provided by the embodiment of the present application;

[0083] Figure 11 This is a schematic structural diagram of the third software detection device provided by the embodiments of the present application;

[0084] Figure 12 This is a schematic structural diagram of an electronic device provided by the embodiments of the present application. Specific embodiments

[0085] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0086] In the development and testing process of open-source software, since open-source software usually involves multiple developers, multiple branches, and frequent updates, a strict quality control mechanism is required to ensure the reliability and stability of the software. Currently, in order to ensure the reliability and stability of the software, a continuous integration tool platform is usually used to set quality gates for open-source software.

[0087] The continuous integration tool platform can cover the research and development life cycle, including code construction, scanning, testing, deployment, and going online, by defining a pipeline. Among them, the testing function of the continuous integration tool platform can include using quality gates to control the quality of the software. If the gate requirements are not met, the continuous integration tool platform pipeline is not allowed to execute further. Common continuous integration tool platforms can be Devops platforms, Jenkins platforms, and TeamCity platforms, etc.

[0088] In the process of setting quality gates for open-source software using a continuous integration tool platform, security quality detection is an important part. Security quality detection focuses on specifically detecting the security of open-source software, including detecting the vulnerability risks of open-source software and detecting the license risk levels.

[0089] Currently, since the SCA tool platform can detect the vulnerability risks and license risks in the open-source software used in source code, artifact packages, and binary files, it has the ability to detect open-source software and can ensure the speed and accuracy of detecting open-source software. Therefore, the prior art usually integrates a continuous integration tool platform with an SCA tool platform to achieve security quality detection of open-source software.

[0090] In the prior art, take the integration of the Devops platform as a continuous integration tool platform and the SCA tool platform to achieve the security and quality detection of open-source software as an example. First, install and configure the SCA plugin on the Devops platform, that is, install and configure the SCA plugin as a component or extension of the Devops platform. Secondly, the Devops platform calls the functions of the SCA plugin through command-line parameters. The Devops platform uses the SCA plugin to perform SCA detection and obtains the SCA detection result, which can reflect the security and quality situation, so as to achieve the integration of the Devops platform and the SCA tool platform.

[0091] In this method, users need to manually input command-line parameters to call the SCA plugin, which limits the user's ability to update the SCA plugin in a timely manner according to different requirements, and the SCA plugin has poor flexibility.

[0092] In addition, in this prior art, the SCA plugin is invasive to the Devops platform, and additional deployment and management operations need to be performed on the Devops platform to maintain the integration relationship between the SCA plugin and the Devops platform, which increases the manual deployment and management costs.

[0093] Furthermore, because the Devops platform can only call the SCA plugin by inputting command-line parameters, the flexibility of the SCA plugin is limited. If the SCA plugin does not support some new detection requirements or parameters, the Devops platform may not be able to directly meet these requirements by modifying the command-line parameters, which limits the utilization degree of the functions of the SCA plugin by the Devops platform.

[0094] The open-source management platform is a comprehensive platform that can not only be used to effectively manage open-source software and its related resources, but also comprehensively cover and optimize the management process. This platform integrates a variety of key functions, including but not limited to user authentication and permission management, organizational structure management, code repository hosting, artifact library management, integration of continuous integration tool platform and SCA tool platform, etc.

[0095] The open-source governance platform also has other functions, such as ledger management, process management, report management, formulation and execution of security policies, and construction of knowledge bases and a series of additional functions. The open-source management platform aims to provide an efficient, secure and easy-to-use environment for managing the entire life cycle of open-source software.

[0096] Therefore, in this application, the SCA tool platform and the continuous integration tool platform are associated through the open-source governance platform, so as to achieve SCA detection without integrating the two. Take the continuous integration tool platform as the Devops platform as an example. Figure 1Schematic diagram of the connection relationship between the Devops platform, the open source governance platform, and the SCA tool platform provided by the embodiments of the present application.

[0097] As Figure 1 shown, the open source governance platform is used as the middle layer between the SCA tool platform and the Devops platform. An interface capable of interacting with the Devops and an interface for interacting with the SCA tool platform are provided on the open source governance platform.

[0098] Optionally, the interface for the open source governance platform to interact with the Devops platform can be an Application Programming Interface (API), and the interface for the open source governance platform to interact with the SCA tool platform can be an Open Application Programming Interface (OpenAPI). The main difference between API and OpenAPI lies in the degree of openness and access rights. OpenAPI is a completely free API that is fully open to the public and can be used without authorization.

[0099] Furthermore, the API for the open source governance platform to interact with the Devops platform includes, but is not limited to, the input and output parameters exchanged between platforms, communication protocols, and authentication mechanisms set to verify the legitimacy of requests, etc. The OpenAPI for the open source governance platform to interact with the SCA tool platform can include the operation content of the SCA tool platform for performing security and quality detection on the target open source software, and the sequence of execution steps of the operation content. For example, OpenAPI can carry any one or more tasks such as initiating detection, obtaining detection results, generating reports, and downloading reports, and carry the execution sequence of the above tasks.

[0100] By encapsulating and orchestrating OpenAPI during the development stage, users do not need to manually input command lines to call the SCA plugin to implement the security and quality detection of the target open source software by the SCA tool platform. Instead, they can use the API of the open source governance platform to connect the SCA tool platform and the continuous integration tool platform, and directly call the OpenAPI of the SCA tool platform to implement the security and quality detection of the target open source software by the SCA tool platform. This enhances the flexibility of the SCA tool platform in detecting the target open source software, reduces the manual deployment and management costs, and realizes the automated detection of the target open source software by the SCA tool platform.

[0101] The following uses specific embodiments to elaborate in detail on the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0102] Figure 2 This is a schematic flowchart of a software detection method provided by an embodiment of the present application. This method mainly involves a continuous integration tool, an open source governance platform, and an SCA tool platform. As Figure 2 shown, this method includes:

[0103] S101. The continuous integration tool platform obtains a compressed package of the target open source software.

[0104] Optionally, the compressed package of the target open source software may be a compressed package of the target open source software after compilation and packaging.

[0105] Optionally, the compressed package of the target open source software may be pre-uploaded by the user to the continuous integration tool platform, or directly developed by the user using the continuous integration tool platform, or obtained from an external storage address or storage medium. The present application does not make any limitations in this regard.

[0106] S102. The continuous integration tool platform calls the interface of the open source governance platform to send an SCA detection request for the target open source software. The SCA detection request carries the compressed package of the target open source software and encrypted identity information.

[0107] Optionally, the encrypted identity information carried by the SCA detection request may be a token encrypted using an encryption algorithm (Rivest-Shamir-Adleman, RSA). The token can be used for identity authentication, thereby preventing the target open source software from being illegally called. The token encrypted using the RSA public key can ensure that the identity information of the target open source software is not leaked.

[0108] Figure 3 This is a flowchart of an RSA encryption algorithm. As Figure 3 shown, the continuous integration tool platform uses the public key of RSA to encrypt the plaintext into ciphertext. Among them, the plaintext may include any one or more of the system source of the target open source software, the expiration time, etc. The present application does not make any limitations in this regard. The system source of the target open source software may be the operating system or platform on which the target open source software is based; the expiration time may be the validity period of a certain component in the target open source software. After the expiration time, the software may no longer run properly or need to update the license to continue using.

[0109] The continuous integration tool platform can send an SCA detection request for the target open source software by calling the interface of the open source governance platform. The SCA detection request may carry the compressed package of the target open source software and encrypted identity information. Optionally, the encrypted identity information may also be carried by the compressed package of the target open source software itself.

[0110] Optionally, the SCA detection request for the target open-source software may also carry any one or more of the project identifier (projectId), task identifier (taskID), etc. Among them, projectId can be used to identify each target open-source software, and the target open-source software can be determined through the project identifier. taskID can be used to identify the security quality detection task corresponding to this SCA detection request. Through taskID, the SCA tool platform can clarify the security quality detection content required for the target open-source software.

[0111] The continuous integration tool platform can write the API of the open-source governance platform into the command-line script (shell script) plugin to implement the call to the open-source governance platform. Alternatively, the continuous integration tool platform can also directly write the API call of the open-source governance platform in the source code.

[0112] S103. The open-source governance platform verifies the legality of the SCA detection request based on the encrypted identity information.

[0113] Exemplarily, as Figure 3 shown, the open-source governance platform decrypts the ciphertext using the private key of RSA. By verifying the system source of the target open-source software of the SCA detection request, it can be confirmed whether the SCA detection request comes from a trusted and known operating system or platform. Different operating systems or platforms may be subject to different compliance regulations. Verifying the system source can ensure that the SCA detection request complies with relevant compliance requirements, thereby avoiding potential legal risks and compliance issues.

[0114] By verifying the expiration time of the SCA detection request, potential security risks of the target open-source software can be prevented, because beyond the expiration time, the target open-source software may introduce potential security compliance risks.

[0115] Therefore, if the system source of the SCA detection request is correct and the expiration time has not expired, it indicates that the target open-source software meets the relevant security compliance requirements and has relevant permissions, and the SCA detection request is determined to be legal; otherwise, it indicates that the target open-source software does not meet the relevant security compliance requirements and / or does not have relevant permissions, and the SCA detection request is determined to be illegal.

[0116] S104. If the legality verification of the SCA detection request passes, the open-source governance platform calls the interface of the SCA tool platform to upload the compressed package of the target open-source software and initiates the SCA detection of the target open-source software.

[0117] Optionally, the SCA detection may include vulnerability matching and / or license matching for the target open-source software.

[0118] Among them, vulnerability matching can be to compare the vulnerabilities of the target open-source software with a known open-source vulnerability database. Through vulnerability matching, security vulnerabilities in the target open-source software can be discovered in a timely manner, so that they can be repaired in a timely manner to avoid security risks.

[0119] License matching can be to compare the licenses in the target open-source software with known licenses. Through license matching, it is ensured that the components included in the software meet their license requirements, thus avoiding potential security risks.

[0120] S105. The SCA tool platform performs SCA detection on the target open-source software based on the compressed package.

[0121] As described above, the SCA tool platform can detect the vulnerabilities of the target open-source software by matching the vulnerabilities of the target open-source software from the vulnerability library based on the compressed package of the target open-source software, or extract the license of the target open-source software, and classify the risks of the license through license matching, so as to detect the risk level of the license of the target open-source software.

[0122] In the embodiment of the present application, the connection between the SCA tool platform and the continuous integration tool platform is realized through the open-source governance platform. Compared with the method of manually deploying and managing SCA plugins on the Devops platform in the prior art, the invasiveness of the SCA plugins to the continuous integration tool platform is avoided. Regardless of how the target open-source software changes, the user only needs to directly call the OpenAPI of the SCA tool platform to implement the security quality detection of the SCA tool platform for the target open-source software, which increases the flexibility of the SCA tool platform and realizes the automatic detection of the SCA tool platform for the target open-source software.

[0123] During the process of the SCA tool platform detecting the compressed package of the target open-source software, the continuous integration tool platform can query the SCA detection status and / or SCA detection results. Figure 4 This is a schematic flowchart of the process for querying the SCA detection status and detection results provided by the embodiment of the present application. As Figure 4 shown, the method includes:

[0124] S201. Call the interface of the open-source governance platform to send a query request. The query request is used to query the SCA detection status and / or SCA detection results of the target open-source software. The query request includes: encrypted identity information.

[0125] Correspondingly, the open-source governance platform receives the query request.

[0126] Optionally, the SCA detection status of the target open-source software can be detection statuses such as detection started, detecting, detection completed, etc. The SCA detection result of the target open-source software can include the vulnerability detection result and the license risk detection result of the target open-source software.

[0127] Optionally, the encrypted identity information included in the query request is consistent with the above-mentioned encrypted identity information. Through the encrypted identity information, the identity information security of the target open-source software can be ensured, and the identity information of the target open-source software is guaranteed not to be leaked.

[0128] Optionally, the continuous integration tool platform can write the API of the open-source governance platform into a command-line script (shell script) plugin to implement the call to the open-source governance platform. Alternatively, the continuous integration tool platform can also directly write the API call of the open-source governance platform in the source code.

[0129] S202. The open-source governance platform verifies the legality of the query request based on the encrypted identity information.

[0130] The process of the open-source governance platform verifying the legality of the query request based on the encrypted identity information is the same as the process of the open-source governance platform verifying the legality of the SCA detection request based on the encrypted identity information above, and will not be elaborated here.

[0131] S203. If the legality verification of the query request passes, the open-source governance platform calls the interface of the SCA tool platform to send the query request.

[0132] Correspondingly, the SCA tool platform receives the query request.

[0133] Optionally, the open-source governance platform can implement the call to the SCA tool platform through the OpenAPI of the SCA tool platform.

[0134] S204. The SCA tool platform obtains the query result based on the query request.

[0135] Optionally, the query result of the SCA tool platform corresponds to the query request, that is, it can include the SCA detection status and / or the SCA detection result. The SCA detection status of the target open-source software can be detection statuses such as detection started, detecting, detection completed, etc. The SCA detection result of the target open-source software can include the vulnerability detection result and the license risk detection result of the target open-source software.

[0136] S205. The SCA tool platform returns the query result to the open-source governance platform.

[0137] Correspondingly, the open-source governance platform receives the query result.

[0138] Optionally, the SCA tool platform can return the above query results to the open source governance platform through OpenAPI.

[0139] S206. The open source governance platform sends the query results to the continuous integration tool platform.

[0140] Correspondingly, the continuous integration tool platform receives the query results.

[0141] Optionally, the open source governance platform can return the above query results to the continuous integration tool platform through the API.

[0142] The above describes how the continuous integration tool platform obtains the query results by initiating a query to the open source governance platform. Optionally, after the open source governance platform calls the interface of the SCA tool platform to upload the compressed package of the target open source software and initiates the SCA detection of the target open source software, it can also actively report the query results to the continuous integration tool platform by itself.

[0143] In this implementation manner, the query results can be obtained by the open source governance platform from the SCA tool platform by initiating a query, or can be actively reported by the SCA tool platform to the open source governance platform.

[0144] In the embodiments of the present application, the open source governance platform is used to implement the query of the SCA detection status and / or SCA detection results by the continuous integration tool platform, which is convenient for the continuous integration tool platform to continuously track the detection status and results of the SCA tool platform for open source software, and is convenient for carrying out subsequent processes.

[0145] After the continuous integration tool platform obtains the detection results of the target open source software, it can judge the quality gate of the target open source software based on the detection results. The quality gate is used to control the quality of the software. If the gate requirements are not met, the continuous integration tool platform pipeline is not allowed to execute further, so as to realize the risk control of the target open source software.

[0146] The determination of the quality gate of the target open source software can be performed by the continuous integration tool platform itself or by the open source governance platform. The following takes the open source governance platform as an example for description.

[0147] Figure 5 It is a schematic flowchart of the process for determining the quality gate of the target open source software provided by the embodiments of the present application. As Figure 5 shown, the method includes:

[0148] S301. The continuous integration tool platform calls the interface of the open source governance platform to send a quality gate determination request for the target open source software.

[0149] Correspondingly, the open-source governance platform receives the quality gate determination request. Among them, the quality gate determination request carries the SCA detection result of the target open-source software and encrypted identity information.

[0150] Optionally, the quality gate determination can be to determine whether the target open-source software meets the quality standards and security requirements based on the vulnerability level and / or license risk level of the target open-source software.

[0151] Optionally, when determining whether the target open-source software meets the quality standards and security requirements based on the vulnerability level and / or license risk level of the target open-source software, the interfaces called by the continuous integration tool platform to the open-source governance platform can be the same or different.

[0152] For example, the interface called to determine whether the target open-source software meets the quality standards and security requirements based on the vulnerability level of the target open-source software and the interface called to determine whether the target open-source software meets the quality standards and security requirements based on the license risk level of the target open-source software can be the same interface or two different interfaces. This application does not make any limitations in this regard.

[0153] S302. The open-source governance platform performs a legality verification on the quality gate determination request based on the encrypted identity information.

[0154] The process of the open-source governance platform performing a legality verification on the quality gate determination request based on the encrypted identity information is the same as the process of the open-source governance platform performing a legality verification on the SCA detection request based on the encrypted identity information as described above, and will not be elaborated here.

[0155] S303. If the legality verification of the quality gate determination request passes, the quality gate determination result of the target open-source software is obtained through the quality gate decision tree model and the SCA detection result. The quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree. The vulnerability risk decision tree and the license risk decision tree are obtained by training the decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and marking results provided by the large model.

[0156] Optionally, the quality gate determination result can be passed or not passed.

[0157] Optionally, the quality gate decision tree model can be implemented through the following principle:

[0158] First, construct the training dataset D, the feature set A, and the threshold z, and generate the decision tree T. Table 1 shows the feature set of the security vulnerabilities of the target software. For the vulnerability risk decision tree, the feature set A includes features such as "business system level", "whether it faces the Internet", "whether there is a public opinion proof for the vulnerability (Proof of Concept, POC)", "whether the vulnerability can be exploited", and "vulnerability hazard level".

[0159] Table 1

[0160]

[0161] Table 2

[0162]

[0163] Table 2 shows the feature set of the license risk. For the license risk decision tree, the feature set A includes features such as "business system level", "whether it provides services externally", "license risk level", "system distribution method", and "open source software usage scenario".

[0164] Among them, the Open Source Initiative (OSI) is an organization that defines "open source" and formulates open source protocol standards, and maintains the Open Source Definition (OSD) and the list of open source licenses it recognizes. Licenses that conform to the OSI open source definition are recognized as open source licenses, which allow the software to be freely used, modified, and shared.

[0165] Software Package Data Exchange (SPDX) is an internationally common format for software bill of materials.

[0166] The General Public License (GPL) is a mandatory license that requires any derivative work that uses or modifies GPL-licensed software to also use the GPL license.

[0167] The above training dataset D can be classified and labeled by security experts and compliance experts in combination with the suggestions of the large model for the training data.

[0168] The above training dataset D can be classified and labeled by security experts in combination with the suggestions of the large model for the training dataset D of the vulnerability detection results, and the labeling conclusion can be to repair or not to repair; it can be classified and labeled by compliance experts in combination with the suggestions of the large model for the training dataset D of the license detection results, and the labeling conclusion can be to replace or not to replace.

[0169] Figure 6This is a schematic diagram of the process for classifying and labeling a training dataset provided in this embodiment. Optionally, the number of samples in the training dataset D can be 500. Among them, the training sample set can be 400, and the validation sample set can be 100. It should be noted that this application does not limit the number of samples in the training dataset and the division of the number of training sample sets and validation sample sets.

[0170] As Figure 6 shown, the process of classifying and labeling the training dataset is as follows:

[0171] 1. Select 10 representative open-source software. For example, it can be a management system, an Internet-facing system, a trading system, etc. It should be noted that the number of open-source software here is not limited.

[0172] 2. The SCA tool platform detects the compressed packages of 10 open-source software.

[0173] 3. Obtain the vulnerability detection results and license detection results of each open-source software.

[0174] Exemplarily, each vulnerability detection result includes: business system level, whether it is Internet-facing, whether it is customer-facing, whether it involves core securities trading, business service time, whether there is a public POC for the vulnerability, whether the vulnerability can be exploited, vulnerability hazard level, attack type.

[0175] Each license detection result includes: business system level, whether it provides services externally, license risk level, OSI certification, FSF license, SPDX certification, GPL compatibility.

[0176] 4. Security experts classify and label the open-source software with vulnerability detection results in combination with the suggestions of the large model, and the labeling conclusion can be to repair or not to repair.

[0177] Exemplarily, the suggestions of the large model for the vulnerability detection results can include any one or more of the following:

[0178] Business system level of the vulnerability: [Important],

[0179] Whether it is Internet-facing: [Yes],

[0180] Whether it is customer-facing: [Yes],

[0181] Whether it involves core securities trading: [Yes],

[0182] Business service time: [7*24],

[0183] Whether there is a public POC for the vulnerability: [Yes],

[0184] Whether the vulnerability can be exploited: [Yes],

[0185] Vulnerability hazard level:

Ultra-critical

[0186] Attack type:

Remote

[0187] Security experts combine the suggestions of the above-mentioned large model to output a conclusion on whether to repair or not.

[0188] 5. Compliance experts classify and label the open-source software with license detection results in combination with the suggestions of the large model. The labeling conclusion can be replacement or non-replacement.

[0189] Exemplarily, the suggestions of the large model for license detection results can include any one or more of the following:

[0190] Business system level of the component:

Important

[0191] Whether to provide services externally:

Yes

[0192] License risk level:

High-risk

[0193] OSI certification:

Passed

[0194] FSF license:

Passed

[0195] SPDX certification:

Passed

[0196] GPL compatibility:

Failed

[0197] Compliance experts combine the suggestions of the above-mentioned large model to output a conclusion on replacement or non-replacement.

[0198] It should be noted that this application does not limit the order of execution of step 4 and step 5. Step 4 can be executed first, and then step 5. Or, step 5 can be executed first, and then step 4. Or, step 4 and step 5 can be carried out simultaneously.

[0199] After classifying and labeling the training dataset D, use the classified and labeled training dataset D to train the quality gate decision tree model. Among them, the quality gate decision tree model at least includes: vulnerability risk decision tree, license risk decision tree. The specific steps are as follows:

[0200] 1. If all instances in D belong to the same class C k (k represents that the sample D itself is divided into k categories according to the results), then T is a single-node tree, and the class C k is used as the class label of this node, and T is returned.

[0201] 2. If the set of feature A is empty, then T is a single-node tree, and the class C with the largest number of instances in D k is used as the class label of this node, and T is returned.

[0202] 3. Calculate the information gain of each feature \(a\) in \(A\) for \(D\) according to the information gain algorithm formula: \(A\) g = Gain(\(D,a\)), defined as the difference between the information entropy Ent(\(D\)) of set \(D\) and the conditional information entropy Ent(\(D|a\)) of \(D\) given feature \(a\). That is, the information entropy is calculated by formula (1), and the conditional entropy is calculated by formula (2):

[0203]

[0204] where \(D\) v represents the number of samples contained in the \(v\)-th branch node of attribute \(a\).

[0205] \(C\) kv represents the number of samples contained in the \(k\)-th category among the number of samples contained in the \(v\)-th branch node of attribute \(a\).

[0206] Select the \(A\) with the largest information gain g .

[0207] 4. If the information gain \(A\) of \(a\) g is less than the threshold \(z\), then set \(T\) as a single-node tree and use the class \(C\) with the largest number of instances in \(D\) k as the class label of this node, and return \(T\).

[0208] 5. If the information gain \(A\) of \(a\) g is greater than the threshold \(z\), then for each value \(a\) of \(a\) i , according to \(a = a\) i divide \(D\) into several non-empty subsets \(D\) i , use the class with the largest number of instances in \(D\) i as the label to construct child nodes. A tree \(T\) is formed by the node and its child nodes, and return \(T\).

[0209] 6. For the \(i\)-th child node, use \(D\) i as the training set and \((A - a)\) as the feature set, and recursively call steps 1 - 5 to obtain the subtree \(T\) i , and return \(T\) i .

[0210] After constructing the decision tree \(T\), considering the complexity and accuracy of vulnerability and license risk identification, pruning operations need to be performed on the decision tree. The steps are as follows:

[0211] Decision tree pruning is often achieved by minimizing the overall loss function or cost function of the decision tree. Let the number of leaf nodes of tree \(T\) be \(|T|\), \(t\) be a leaf node of tree \(T\), and this leaf node has \(N\) t sample points, among which there are \(N\) tk sample points of class \(k\), \(k = 1, 2,..., K\), \(H\) t(T) is the empirical entropy at leaf node t, and α ≥ 0 is a parameter. Then, the loss function of decision tree learning can be obtained from Formulas (3) to (5):

[0212]

[0213] Furthermore,

[0214]

[0215] C α (T) = C(T) + α|T| (5)

[0216] Determine α and select the model with the minimum loss function, that is, the subtree T with the minimum loss function. α . Prune according to the following steps:

[0217] 1. Calculate the empirical entropy of each node.

[0218] 2. Recursively retract from the leaf nodes of the tree upwards. Let the overall trees before and after a set of leaf nodes retract to their parent node be T A and T B , and their corresponding loss function values be C α (T A ) and C α (T B ). If: C α (T A ) < C α (T B ), then prune, that is, change the parent node to a new leaf node.

[0219] 3. Return to Step 2 until it cannot continue, and obtain the subtree T with the minimum loss function. α .

[0220] S304. The open source governance platform sends the quality gate determination result to the continuous integration tool platform.

[0221] Correspondingly, the continuous integration tool platform receives the quality gate determination result.

[0222] Optionally, the open source governance platform can return the above quality gate determination result to the continuous integration tool platform through the API.

[0223] In the prior art, only one of the vulnerability level and the license risk level is selected as a consideration factor for the quality gate, and the refined control of the quality gate is ignored. Fixed thresholds are often used for all target open-source software, or different fixed thresholds are used for different target open-source software. The setting of the threshold depends on experience, and it is difficult to accurately perform security quality detection on the target open-source software. Compared with the prior art, the embodiment of the present application sets up a security quality gate for open-source software and uses a quality gate decision tree model. This model is trained based on a large amount of data and learns the characteristics of high-risk vulnerabilities and high-risk licenses, and can accurately identify high-risk vulnerabilities and high-risk licenses, improving the accuracy of security quality detection of the target open-source software.

[0224] Further, after receiving the quality gate determination result, the continuous integration tool platform will take different measures according to different quality gate determination results. Optionally, the continuous integration tool platform can call the shell script plugin and configure the shell script plugin into the continuous integration tool platform pipeline. Figure 7 The following is a schematic flowchart of the continuous integration tool provided by the embodiment of the present application taking different measures according to different quality gate determination results, and the specific steps are as follows:

[0225] 1. Compile and package the target open-source software to output a compressed package.

[0226] 2. Call the shell script plugin.

[0227] Among them, the shell script plugin includes the API of the open-source governance platform, and the specific execution process of this API is implemented by calling the OpenAPI of the SCA tool platform.

[0228] 3. Determine whether the quality gate is passed. If so, execute step 4. If not, execute step 5.

[0229] 4. Continue to deploy the target open-source software.

[0230] 5. For the quality detection result, develop and repair the target open-source software, and return to step 1 after the development and repair are completed.

[0231] As Figure 7 shown, when the quality gate determination result of the continuous integration tool platform is passed, the next step of the continuous integration tool platform pipeline is executed. When the quality gate determination result is not passed, the continuous integration tool platform develops, repairs, compiles, and packages the target open-source software. Optionally, the continuous integration tool platform can also send a prompt message to the target address to prompt the reason why the quality gate determination result is not passed, so that the user can develop, repair, compile, and package the target open-source software by himself.

[0232] Optionally, when the quality gate determination result is not passed, the target open-source software is developed and repaired, compiled and packaged, and then the above detection steps for the target open-source software are repeated.

[0233] The embodiments of the present application take different measures for different quality gate determination results, and can timely handle the existing vulnerability risks and license risks, improving the processing efficiency of the quality gate determination results.

[0234] Further, the shell script of the continuous integration tool platform can also include calling the interface of the open-source governance platform to send a mail notification request. Figure 8 The following are the main steps of the shell script of the continuous integration tool platform provided by the embodiments of the present application, as shown in the figure:

[0235] 1. Obtain parameters such as Token, projectId, and taskID.

[0236] 2. Call the detection API of the open-source governance platform.

[0237] 3. Determine whether the polling of the open-source governance platform API is completed. If so, execute step 4. If not, repeat step 3.

[0238] 4. Call the open-source governance platform to obtain the detection details.

[0239] 5. Call the open-source governance platform to obtain the quality gate determination result.

[0240] 6. Call the open-source governance platform to send a notification to the target address.

[0241] As Figure 8 shown, after calling the open-source governance platform to obtain the quality gate determination result, the interface of the open-source governance platform can be called to send a notification. Optionally, the notification can be a mail notification request for requesting to feedback the SCA detection result and / or quality gate determination result of the target open-source software to the target address by mail. The mail notification request includes encrypted identity information. Optionally, the mail notification request can carry the target address. Or, there is a mapping relationship between the target open-source software and the target address pre-stored in the open-source governance platform, or, there is a mapping relationship between the projectID and / or taskID corresponding to the target open-source software and the target address.

[0242] The embodiments of the present application can timely feedback the SCA detection result and quality gate determination result of the target open-source software to the target address by mail notification, which is beneficial for developers to process the target open-source software in time and improves work efficiency.

[0243] An embodiment of the present application further provides a software detection system, which includes: a continuous integration tool platform, an open source governance platform, and an SCA tool platform; wherein,

[0244] The continuous integration tool platform is deployed with a target script for executing the method performed by the continuous integration tool platform in the above embodiment by running the target script.

[0245] The open source governance platform is used to execute the method performed by the open source governance platform in the above embodiment.

[0246] The SCA tool platform is used to execute the method performed by the SCA tool platform in the above embodiment.

[0247] The above is the method embodiment provided by the present application. Next, the device provided by the present application will be described.

[0248] Figure 9 It is a schematic structural diagram of the first software detection device provided by the embodiment of the present application. As Figure 9 shown, this device can be applied to the open source governance platform. The software detection device 400 may include, for example: a receiving module 401, a verification module 402, and a calling module 403. Optionally, the device 400 may further include a sending module 404.

[0249] The receiving module 401 is configured to receive an SCA detection request of a target open source software sent by the continuous integration tool platform by calling the interface of the open source governance platform; the SCA detection request carries a compressed package of the target open source software and encrypted identity information.

[0250] The verification module 402 is configured to perform a legality verification on the SCA detection request based on the encrypted identity information.

[0251] The calling module 403 is configured to, when the legality verification of the SCA detection request passes, call the interface of the SCA tool platform to upload the compressed package of the target open source software and initiate an SCA detection of the target open source software.

[0252] Optionally, a receiving module 401 is configured to receive, after the verification module 402 passes the legality verification of the SCA detection request, a query request sent by the continuous integration tool platform through an invocation interface; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the query request includes: encrypted identity information. The verification module 402 is further configured to perform a legality verification on the query request based on the encrypted identity information. The invocation module 403 is further configured to, when the legality verification of the query request passes, send a query request by invoking an interface of the SCA tool platform; the receiving module 401 is further configured to receive a query result returned by the SCA tool platform. The sending module 404 is configured to send the query result to the continuous integration tool platform.

[0253] Optionally, the receiving module 401 is further configured to receive a quality gate determination request of the target open-source software sent by the continuous integration tool platform through an invocation interface; the quality gate determination request carries the SCA detection result of the target open-source software and the encrypted identity information; the verification module 402 is further configured to perform a legality verification on the quality gate determination request based on the encrypted identity information; if the legality verification of the quality gate determination request passes, obtain a quality gate determination result of the target open-source software through a quality gate decision tree model and the SCA detection result; the quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training a decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and labeling results provided by a large model. The sending module 404 is further configured to send the quality gate determination result to the continuous integration tool platform.

[0254] Optionally, the receiving module 401 is further configured to receive a mail notification request sent by the continuous integration tool platform through an invocation interface; the mail notification request is used to request to feedback the SCA detection result and the quality gate determination result of the target open-source software to a target address by mail; the mail notification request includes the encrypted identity information; the verification module 402 is further configured to perform a legality verification on the mail notification request based on the encrypted identity information; the sending module 404 is further configured to, when the legality verification of the mail notification request passes, send a mail containing the SCA detection result and the quality gate determination result of the target open-source software to the target address.

[0255] The software detection device 400 provided in the embodiments of the present application can be used to implement the actions performed by the open-source governance platform in any of the foregoing method embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here.

[0256] Figure 10 This is a schematic structural diagram of the second software detection device provided by an embodiment of this application. As Figure 10 shown, this device can be applied to a continuous integration tool platform. The software detection device 500 may include, for example: an acquisition module 501 and an invocation module 502. Optionally, the software detection device 500 may further include: a reception module 503.

[0257] The acquisition module 501 is configured to acquire a compressed package of a target open-source software after compilation and packaging;

[0258] The invocation module 502 is configured to invoke an interface of an open-source governance platform to send an SCA detection request for the target open-source software; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; the SCA detection request is used to trigger the open-source governance platform to call the SCA tool platform to perform SCA detection on the target open-source software after passing the legitimacy verification of the SCA detection request based on the encrypted identity information.

[0259] Optionally, the invocation module 502 is further configured to invoke the interface of the open-source governance platform to send a query request; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the query request includes: encrypted identity information. The reception module 503 is configured to receive the query result obtained by the open-source governance platform calling the SCA tool platform after passing the legitimacy verification of the query request based on the encrypted identity information.

[0260] Optionally, the invocation module 502 is further configured to invoke the interface of the open-source governance platform to send a quality gate determination request for the target open-source software; the quality gate determination request carries the SCA detection result of the target open-source software and the encrypted identity information; the reception module 503 is further configured to receive the quality gate determination result of the target open-source software obtained by the open-source governance platform through a quality gate decision tree model and the SCA detection result after passing the legitimacy verification of the quality gate determination request based on the encrypted identity information; the quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training a decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and marking results provided by a large model.

[0261] Optionally, the invocation module 502 is further configured to invoke the interface of the open-source governance platform to send an email notification request; the email notification request is used to request to feedback the SCA detection result and quality gate determination result of the target open-source software to a target address through email; the email notification request includes the encrypted identity information.

[0262] The software detection device 500 provided by the embodiments of the present application can be used to implement the actions performed by the continuous integration tool platform in any of the foregoing method embodiments. The implementation principles and technical effects are similar and will not be elaborated here.

[0263] Figure 11 It is a schematic structural diagram of a third software detection device provided by the embodiments of the present application. As Figure 11 shown, this device can be applied to the SCA tool platform. The software detection device 600 may include, for example: a receiving module 601 and a detection module 602. Optionally, the device 600 may further include, for example: an acquisition module 603 and a sending module 604.

[0264] The receiving module 601 is configured to receive the compressed package of the target open-source software uploaded by the open-source governance platform by invoking the interface of the SCA tool platform, and a trigger instruction for performing SCA detection on the target open-source software.

[0265] The detection module 602 is configured to perform SCA detection on the target open-source software based on the compressed package.

[0266] Optionally, the receiving module 601 is further configured to receive a query request sent by the open-source governance platform by invoking the interface of the SCA tool platform; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the acquisition module 603 is configured to obtain a query result based on the query request. The sending module 604 is configured to return the query result to the open-source governance platform.

[0267] The software detection device 600 provided by the embodiments of the present application can be used to implement the actions performed by the SCA tool platform in any of the foregoing method embodiments. The implementation principles and technical effects are similar and will not be elaborated here.

[0268] Figure 12 It is a schematic structural diagram of an electronic device provided by the embodiments of the present application. As Figure 12 shown, the electronic device 900 may include: a memory 901 and a processor 902. The electronic device may be, for example, the aforementioned open-source governance platform. Optionally, the electronic device may further include a transceiver 903. Among them, the memory 901 communicates with the processor 902; exemplarily, the memory 901, the processor 902, and the transceiver 903 may communicate through a communication bus 904. The memory 901 is used to store a computer program, and the processor 902 executes the computer program to implement the method of the above embodiments.

[0269] Optionally, the above-mentioned processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps in the method embodiments disclosed in conjunction with the present application can be directly implemented by a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0270] The embodiments of the present application also provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the methods in any of the above method embodiments.

[0271] The embodiments of the present application also provide a computer program product including a computer program, which, when executed by a processor, implements the methods in any of the above method embodiments.

[0272] All or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a readable memory. When the program is executed, it executes the steps including the above method embodiments; and the foregoing memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof.

[0273] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0274] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the processes Figure 1 or blocks Figure 1 specified in one or more of the blocks.

[0275] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes Figure 1 or blocks Figure 1 specified in one or more of the blocks.

[0276] Obviously, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

[0277] In the present application, the term "including" and its variations may mean non-limiting inclusion; the term "or" and its variations may mean "and / or". In the present application, terms such as "first" and "second" are used to distinguish similar objects and do not necessarily describe a particular order or sequence. In the present application, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

Claims

1. A software detection method, characterized in that, The method is applied to an open-source governance platform, on which there are interfaces for interacting with a continuous integration tool platform and an SCA tool platform; the method includes: Receiving an SCA detection request for a target open-source software sent by the continuous integration tool platform by invoking the interface of the open-source governance platform; the SCA detection request carries a compressed package of the target open-source software and encrypted identity information; Based on the encrypted identity information, verifying the legality of the SCA detection request; If the legality verification of the SCA detection request passes, invoking the interface of the SCA tool platform to upload the compressed package of the target open-source software to the SCA tool platform, so that the SCA tool platform performs SCA detection on the target open-source software based on the compressed package.

2. The method according to claim 1, characterized in that, After the legality verification of the SCA detection request passes, the method further includes: Receiving a query request sent by the continuous integration tool platform by invoking the interface; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; the query request includes: encrypted identity information; Based on the encrypted identity information, verifying the legality of the query request; If the legality verification of the query request passes, invoking the interface of the SCA tool platform to send the query request; Receiving the query result returned by the SCA tool platform; Sending the query result to the continuous integration tool platform.

3. The method according to claim 2, wherein The method further includes: Receiving a quality gate determination request for the target open-source software sent by the continuous integration tool platform by invoking the interface; the quality gate determination request carries the SCA detection result of the target open-source software and the encrypted identity information; Based on the encrypted identity information, verifying the legality of the quality gate determination request; If the legality verification of the quality gate determination request passes, obtaining the quality gate determination result of the target open-source software through a quality gate decision tree model and the SCA detection result; the quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training a decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and marking results provided by a large model; Sending the quality gate determination result to the continuous integration tool platform.

4. The method according to claim 3, characterized in that, The method further includes: Receiving a mail notification request sent by the continuous integration tool platform by invoking the interface; the mail notification request is used to request to feedback the SCA detection result and quality gate determination result of the target open-source software to a target address via mail; the mail notification request includes the encrypted identity information; Based on the encrypted identity information, verifying the legality of the mail notification request; If the legality verification of the mail notification request passes, sending a mail containing the SCA detection result and quality gate determination result of the target open-source software to the target address.

5. A software detection method, characterized in that, The method is applied to a continuous integration tool platform. An interface for interacting with the continuous integration tool platform and an interface for interacting with an SCA tool platform are set on the open source governance platform; the method includes: Obtain the compressed package of the target open source software after compilation and packaging; Call the interface of the open source governance platform to send an SCA detection request for the target open source software; the SCA detection request carries the compressed package of the target open source software and encrypted identity information; the SCA detection request is used to trigger the open source governance platform to call the interface of the SCA tool platform to upload the compressed package of the target open source software to the SCA tool platform after passing the legitimacy verification of the SCA detection request based on the encrypted identity information, so that the SCA tool platform performs SCA detection on the target open source software based on the compressed package.

6. The method according to claim 5, wherein The method further includes: Call the interface of the open source governance platform to send a query request; the query request is used to query the SCA detection status and / or SCA detection result of the target open source software; the query request includes: encrypted identity information; Receive the query result obtained by the open source governance platform calling the SCA tool platform after passing the legitimacy verification of the query request based on the encrypted identity information.

7. The method according to claim 6, wherein The method further includes: Call the interface of the open source governance platform to send a quality gate determination request for the target open source software; the quality gate determination request carries the SCA detection result of the target open source software and the encrypted identity information; Receive the quality gate determination result of the target open source software obtained by the open source governance platform through a quality gate decision tree model and the SCA detection result after passing the legitimacy verification of the quality gate determination request based on the encrypted identity information; the quality gate decision tree model at least includes: a vulnerability risk decision tree and a license risk decision tree; the vulnerability risk decision tree and the license risk decision tree are obtained by training a decision tree in advance using a training data set, and the training data set is constructed by labeling based on the reference classification and labeling results provided by a large model.

8. The method according to claim 7, wherein The method further includes: Call the interface of the open source governance platform to send an email notification request; the email notification request is used to request to feedback the SCA detection result and quality gate determination result of the target open source software to a target address via email; the email notification request includes the encrypted identity information.

9. The method according to claim 7, wherein The method further includes: Deploy the target open source software when the quality gate determination result is passed; When the quality gate determination result is not passed, perform development and repair on the target open source software, compile and package it, and then re-detect it.

10. A software detection method, characterized in that The method is applied to an SCA tool platform. An interface for interacting with a continuous integration tool platform and an interface for interacting with the SCA tool platform are set on the open source governance platform; the method includes: Receive the compressed package of the target open-source software uploaded by the open-source governance platform through the interface of the SCA tool platform when calling the SCA detection request passed by the legality verification, and a trigger instruction for performing SCA detection on the target open-source software; wherein, the SCA detection request is sent by the continuous integration tool platform to the open-source governance platform by calling the interface of the open-source governance platform; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; the encrypted identity information is used to verify whether the SCA detection request is legal; Based on the compressed package, perform SCA detection on the target open-source software.

11. The method according to claim 10, characterized in that, The method further includes: Receive a query request sent by the open-source governance platform by calling the interface of the SCA tool platform; the query request is used to query the SCA detection status and / or SCA detection result of the target open-source software; Obtain a query result based on the query request; Return the query result to the open-source governance platform.

12. A software detection method, characterized in that, The method includes: The continuous integration tool platform obtains the compressed package of the target open-source software; The continuous integration tool platform calls the interface of the open-source governance platform to send the SCA detection request of the target open-source software; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; The open-source governance platform verifies the legality of the SCA detection request based on the encrypted identity information; If the legality verification of the SCA detection request passes, the open-source governance platform calls the interface of the SCA tool platform to upload the compressed package of the target open-source software and initiate the SCA detection of the target open-source software; The SCA tool platform performs SCA detection on the target open-source software based on the compressed package.

13. A software detection system, characterized in that, The software detection system includes: a continuous integration tool platform, an open-source governance platform, and an SCA tool platform; wherein, The continuous integration tool platform is deployed with a target script for executing the method according to any one of claims 5-9 by running the target script; The open-source governance platform is used to execute the method according to any one of claims 1-4; The SCA tool platform is used to execute the method according to any one of claims 9-10.

14. A software detection device, characterized in that, The device is applied to the open-source governance platform, and interfaces for interacting with the continuous integration tool platform and interfaces for interacting with the SCA tool platform are set on the open-source governance platform; the device includes: A receiving module, configured to receive an SCA detection request of the target open-source software sent by the continuous integration tool platform by calling the interface of the open-source governance platform; the SCA detection request carries the compressed package of the target open-source software and encrypted identity information; A verification module, configured to verify the legality of the SCA detection request based on the encrypted identity information; A calling module, if the legality verification of the SCA detection request passes, calls the interface of the SCA tool platform to upload the compressed package of the target open-source software to the SCA tool platform, so that the SCA tool platform performs SCA detection on the target open-source software based on the compressed package.

15. A software detection device, characterized in that, The device is applied to a continuous integration tool platform, which interacts with the open source governance platform through an interface set on the open source governance platform. An interface for interacting with the SCA tool platform is also set on the open source governance platform; the device includes: An acquisition module, which acquires the compressed package of the target open source software after compilation and packaging; A calling module, which calls the interface of the open source governance platform to send an SCA detection request for the target open source software; the SCA detection request carries the compressed package of the target open source software and encrypted identity information; the SCA detection request is used to trigger the open source governance platform to call the interface of the SCA tool platform to upload the compressed package of the target open source software to the SCA tool platform after the legitimacy verification of the SCA detection request based on the encrypted identity information is passed, so that the SCA tool platform performs SCA detection on the target open source software based on the compressed package.

16. A software detection device, characterized in that, The device is applied to an SCA tool platform, and the device includes: A receiving module, which receives the compressed package of the target open source software uploaded by the open source governance platform calling the interface of the SCA tool platform based on the SCA detection request passed in terms of legitimacy verification, and a trigger instruction for performing SCA detection on the target open source software; wherein, the SCA detection request is sent by the continuous integration tool platform to the open source governance platform by calling the interface of the open source governance platform; the SCA detection request carries the compressed package of the target open source software and encrypted identity information; the encrypted identity information is used to verify whether the SCA detection request is legal; A detection module, which performs SCA detection on the target open source software based on the compressed package.

17. An electronic device, characterized in that, The electronic device includes: a processor and a memory communicatively connected to the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method according to any one of claims 1-11.

18. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the method according to any one of claims 1-11.

19. A computer program product, characterized in that, It includes a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1-11.

Citation Information

Patent Citations

  • Open source component security vulnerability detection system and method

    CN118862098A