Code security scanning method and device, computer equipment and storage medium

By receiving project release requests, obtaining metadata, packaging, scanning and displaying security information configuration lists, the inefficiency and high risk of code security scanning in the microservice architecture is solved, and efficient and secure code scanning and management are achieved.

CN120337222APending Publication Date: 2025-07-18GUANGZHOU BAIHUI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510259100.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing code security scanning methods are inefficient, complex in management and high security risks in microservice architecture, and cannot manage security vulnerabilities in a timely and unified manner, resulting in untimely and costly vulnerabilities repair.

Method used

Receive project release requests, obtain project metadata information, package it into a preset project compression package, call the code security scanning platform to scan, divide vulnerability levels according to security thresholds, configure security rules to generate a security information configuration list and display it.

Benefits of technology

It realizes efficient and secure code scanning, reduces vulnerability exposure time, improves security and management efficiency, and reduces maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337222A_ABST
    Figure CN120337222A_ABST
Patent Text Reader

Abstract

The invention relates to a code security scanning method, which comprises the following steps of: receiving a project release request of a project developer, and obtaining project metadata information; according to the project metadata information, packaging the project into a project compression package in a preset format; calling a preset code security scanning platform to perform security scanning on the project compression package to obtain security vulnerability information; performing security level division on the security vulnerability information according to a preset security threshold; configuring different levels of security vulnerability information according to a preset security rule; after matching the security vulnerability information of different levels with the project metadata information, generating a security information configuration list; and displaying the security information configuration list on a preset interface. The purpose of efficiently and safely scanning codes is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of microservice software development, and in particular, to a code security scanning method, apparatus, computer device, and storage medium. Background Art

[0002] With the continuous increase in software development complexity, modern software projects increasingly rely on third-party libraries and frameworks. Although these dependencies facilitate development, they may also introduce known security vulnerabilities, thereby posing potential security risks to applications. To address this issue, existing code security scanning tools such as Dependency-Check are widely used, which can detect whether there are known security vulnerabilities in the dependencies of Java projects.

[0003] However, existing security scanning methods have many deficiencies. First, security scanning usually requires developers to trigger manually, which is not only time-consuming but also prone to omission due to negligence. Second, although Dependency-Check can be integrated into the project through pom.xml, this integration method is not flexible enough and requires developers to explicitly add this tool in the code. Especially in the microservice architecture, with numerous projects, it is difficult to quickly promote this tool to all projects. In addition, existing security scanning results are often only known to project developers, and security team members cannot obtain these key information in real time, resulting in the inability to manage security vulnerabilities in a timely and unified manner, increasing the exposure time of security risks. Finally, in the microservice architecture, due to the large number and dispersion of projects, there is a lack of a centralized management platform to uniformly update and maintain scanning rules, which not only increases the complexity of management but also significantly improves the maintenance cost, may lead to inconsistencies in security policies, and increases the risk of security vulnerabilities being ignored or repaired late.

[0004] Therefore, based on the above problems, a code scanning method that can ensure code security and efficiency is an urgent need in this field. Summary of the Invention

[0005] The embodiments of the present invention propose a code security scanning method, apparatus, computer device, and storage medium to solve the problems of low efficiency and high security risks existing in current code security scanning methods due to management complexity.

[0006] In a first aspect, the embodiments of the present invention provide a code security scanning method, the method comprising:

[0007] Receiving a project release request from a project developer and obtaining project metadata information;

[0008] Packing the project into a project compression package in a preset format according to the project metadata information;

[0009] Call a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information;

[0010] Classify the security vulnerability information according to a preset security threshold;

[0011] Configure the security vulnerability information of different levels according to preset security rules;

[0012] After matching the security vulnerability information of different levels with the project metadata information, generate a security information configuration list;

[0013] Display the security information configuration list on a preset interface.

[0014] In a second aspect, an embodiment of the present invention further provides a code security scanning device, and the device includes:

[0015] A project release request receiving module, configured to receive a project release request from a project developer and obtain project metadata information;

[0016] A packaging module, configured to package the project into a project compressed package in a preset format according to the project metadata information;

[0017] A security scanning module, configured to call a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information;

[0018] A security level classification module, configured to classify the security vulnerability information according to a preset security threshold;

[0019] A security vulnerability information configuration module, configured to configure the security vulnerability information of different levels according to preset security rules;

[0020] A security information configuration list generation module, configured to generate a security information configuration list after matching the security vulnerability information of different levels with the project metadata information;

[0021] A display module, configured to display the security information configuration list on a preset interface.

[0022] In a third aspect, an embodiment of the present invention further provides a computer device, and the computer device includes:

[0023] One or more processors;

[0024] A memory, configured to store one or more programs,

[0025] When the one or more programs are executed by the one or more processors, the one or more processors implement the code security scanning method described in any one of the first aspect.

[0026] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the code security scanning method described in any one of the first aspect is implemented.

[0027] In this embodiment, a project release request from a project developer is received, and project metadata information is obtained; according to the project metadata information, the project is packaged into a project compressed package in a preset format; a preset code security scanning platform is called to perform a security scan on the project compressed package to obtain security vulnerability information; the security vulnerability information is classified into security levels according to a preset security threshold; different levels of the security vulnerability information are configured according to preset security rules; after matching different levels of the security vulnerability information with the project metadata information, a security information configuration list is generated; and the security information configuration list is displayed on a preset interface. The purpose of efficiently and securely performing code scanning is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 It is a flowchart of a code security scanning method provided in Embodiment 1 of the present invention;

[0029] Figure 2 It is an example diagram of code security scanning timing provided in Embodiment 1 of the present invention;

[0030] Figure 3 It is an example diagram of the model relationship of a code scanning platform provided in Embodiment 1 of the present invention;

[0031] Figure 4 It is an example diagram of the system architecture provided in Embodiment 1 of the present invention;

[0032] Figure 5 It is an example diagram of a security vulnerability display interface provided in Embodiment 1 of the present invention;

[0033] Figure 6 It is a schematic structural diagram of a code security scanning device provided in Embodiment 2 of the present invention;

[0034] Figure 7 It is a schematic structural diagram of a computer device provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0035] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of description, only the parts related to the present invention rather than all the structures are shown in the drawings.

[0036] Embodiment 1

[0037] Figure 1 It is a flowchart of a code security scanning method provided by Embodiment 1 of the present invention, which specifically includes the following steps:

[0038] Step 101: Receive the project release request from the project developer and obtain the project metadata information.

[0039] In the embodiment of the present invention, as Figure 2 shown, on the user interface of the project release platform, developers are allowed to input or upload project files to trigger a release request. When the system receives the project release request through the API interface, it will automatically extract or request the developer to provide the project metadata information, such as the project name, version number, responsible person ID, dependency library list, etc.

[0040] In practical applications, in a microservices architecture, CI / CD (Continuous Integration and Continuous Deployment) is the key to ensuring the rapid and reliable release of services. The microservices release platform CICD supports developers to automatically build, package, and deploy to the external network after code submission. The release platform provides the project metadata information to the code security scanning platform, including the project name, the number of project versions, the latest version number, the project responsible person, and provides the packaged version package for the scanning platform to perform security scanning, and provides an interface to receive the scanning results. If the code security situation of this version of the project does not meet the release requirements, the release of this version is prohibited at the release platform end. If the project code passes the security scanning, the project code is allowed to be released to the external network.

[0041] Step 102: Package the project into a project compressed package in a preset format according to the project metadata information.

[0042] In the embodiment of the present invention, the system uses the Jenkins server to automatically package the project files and related resources into a compressed package in a preset format according to the project metadata information. The packaging process can be achieved through the continuous integration (CI) function of Jenkins.

[0043] In practical applications, an open-source dependency library security scanning tool is built into the underlying layer of the dependency library security scanning platform. This tool is used to scan the compressed package generated by the project packaging and build, and generate a report in json format.

[0044] Understandably, the platform can call applicable tools to package project data. In the embodiments of the present invention, no specific limitations are imposed on the project packaging tools and data packet formats.

[0045] Step 103: Call a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information.

[0046] In the embodiments of the present invention, as Figure 2 shown, the system sends the packaged project compressed package to a preset code security scanning platform. This platform uses the Dependency-Check tool or other similar tools to perform a security scan on the compressed package, detects whether there are known security vulnerabilities in the dependent libraries, and generates a report containing detailed vulnerability information.

[0047] In practical applications, by parsing the json report through the code scanning platform, information such as the project name, report time, dependent library name, vulnerability ID, and vulnerability hazard level is obtained for display on the code scanning platform. The usage method of this tool is:

[0048] . / dependency-check / bin / dependency-check.sh -n --project "Project_name" --scan "v20250101.Project_name.tar.gz" -f JSON -o / data / json

[0049] Project_name is the project name, obtained from the release platform; v20250101.Project_name.tar.gz is the code compressed package; / data / json is the report storage path.

[0050] As Figure 3 shown in the structure diagram of the code security scanning platform, it shows how the platform organizes and manages security vulnerability information in different microservices, their versions, and dependent libraries.

[0051] Among them, the root node of the graph represents the core platform of the entire system, responsible for managing and executing code security scanning tasks. Multiple branches extend from the root node, and each branch represents a microservice (such as Microservice A, Microservice B, etc.). These microservices are the objects of code security scanning. Taking Microservice A as an example, it is further divided into different versions (such as Version 1, Version 2, etc.). Under each version, the libraries it depends on are listed (such as Dependent Library A, Dependent Library B, etc.). These dependent libraries may contain known security vulnerabilities. Taking Dependent Library A as an example, it is further divided into specific vulnerabilities found in this library (such as Vulnerability A, Vulnerability B, Vulnerability C, etc.).

[0052] Further, each vulnerability node represents a specific security issue, and this vulnerability information is discovered and recorded by the code security scanning platform during the scanning process. On the branch of microservice A, the information of the project name and the person in charge is also marked, and this information helps to identify and manage the context of each microservice.

[0053] Step 104: Classify the security vulnerability information according to a preset security threshold;

[0054] In the embodiment of the present invention, the system classifies the vulnerabilities in the scanning results according to a preset security threshold (such as the CVE score) to determine the severity of each vulnerability.

[0055] Preferably, in another embodiment of the present invention, step 104 may further include:

[0056] Sub-step A1: Classify the security vulnerability information into high-risk vulnerability information, ordinary vulnerability information, and non-threat vulnerability information according to a preset security threshold.

[0057] Specifically, the system classifies the vulnerability information into three levels: high-risk, ordinary, and non-threat. This classification is based on the potential impact and exploitation possibility of the vulnerabilities.

[0058] Step 105: Configure the security vulnerability information of different levels according to a preset security rule;

[0059] In the embodiment of the present invention, the system processes the vulnerability information of different levels according to a preset security rule (such as the enterprise security policy) to decide whether to allow the release of the project containing these vulnerabilities.

[0060] Preferably, in another embodiment of the present invention, step 105 may further include:

[0061] Sub-step B1: Prohibit the release of the project compressed package containing the high-risk vulnerability information, and send a notice of prohibition of release to the developer.

[0062] Specifically, for CVE vulnerabilities with a high severity level and a possible major threat to system security, the administrator can set a rule prohibiting release to ensure that the versions containing these vulnerabilities do not enter the production environment.

[0063] Sub-step B2: Prohibit the release of the project compressed package containing the ordinary vulnerability information, and send vulnerability warning information to the developer.

[0064] Specifically, for CVE vulnerabilities that need attention but do not pose an immediate threat, the administrator can configure an alarm notification to remind the development team to pay attention and prepare corresponding repair measures.

[0065] Sub-step B3: Allow the release of the project compressed package containing the non-threatening vulnerability information, and add the non-threatening vulnerability information to the preset whitelist.

[0066] Specifically, for those CVE vulnerabilities that have been evaluated and confirmed not to have an actual impact on system security, the administrator can choose to add them to the whitelist, so as to ignore these vulnerabilities during the security scanning process and avoid unnecessary alarms and interferences.

[0067] In practical applications, the Dependency-Check tool can update the virus database through the command. / dependency-check.sh --updateonly. After the tool is integrated into the dependency library security scanning platform, it is automatically updated by the platform built-in to achieve more frequent updates of the virus database to the latest version.

[0068] Preferably, in another embodiment of the present invention, the metadata information at least includes the project version number, the latest version number, the project leader ID, and the call library information.

[0069] Specifically, the release platform provides the project metadata information for the code security scanning platform, including the project name, the project version number, the latest version number, the project leader identity information, and the call library information.

[0070] Project version number: The total number of versions experienced by the microservice project from initial development to date.

[0071] Latest version number: The version identifier automatically generated by the release platform when the project is built in the microservice release platform.

[0072] Project leader identity information: The unique identity identification number of the project leader to ensure that the relevant person in charge can be quickly contacted for repair when a security vulnerability is discovered.

[0073] Call library information: The specific information of the external libraries relied on by each project, including library names, version numbers, etc. Identifying the external library information relied on by the project can also obtain the description of known security vulnerabilities, so that project developers can make timely repairs after learning the vulnerability information.

[0074] Among them, the security vulnerability description in the call library information includes the possible impact description of the existence of the vulnerability.

[0075] It can be understood that the above data is obtained by the security scanning platform by parsing the json report generated after the Dependency-Check tool runs. The specific content of the data can be set and adjusted by relevant technical personnel according to actual needs, and the embodiments of the present invention do not specifically limit this.

[0076] Step 106: After matching the security vulnerability information at different levels with the project metadata information, generate a security information configuration list.

[0077] In the embodiment of the present invention, by directly integrating the Dependency-Check tool with the release platform, directly scan the already packaged version package, and match the dependencies in the version package with vulnerabilities. The system associates the vulnerability information with the project's metadata information (such as version number, person in charge, etc.) to generate a detailed security information configuration list. These information can be stored in a database for easy retrieval and analysis, and finally displayed on the display interface according to the visitors with different access permissions to ensure the security of the data.

[0078] Preferably, in another embodiment of the present invention, step 106 may further include:

[0079] Sub-step C1: Match the number of call libraries, the latest version number, the project leader ID, and the call library information in the project compressed package containing the security vulnerability information to generate a security information configuration list.

[0080] Specifically, the system records in detail the call library information, project version, and person in charge information associated with each vulnerability to generate a security information configuration list for easy tracking and management.

[0081] As Figure 4 shown, the entire process from when the developer initiates a packaging request to finally notifying the scanning situation in the release platform part is described.

[0082] First, the developer initiates a packaging request through the user interface of the release platform. This request may include the source code of the project and related configuration information. After receiving the packaging request, the release platform calls the Jenkins server to perform the actual packaging operation. Jenkins is an automation server used to automate various tasks, including building, testing, and deployment.

[0083] Then, after the Jenkins server finishes packaging, it returns the generated project compressed package (code package) to the release platform. The release platform obtains the packaged code package from the Jenkins server and prepares for the next security scan. The release platform sends the obtained code package to the code scanning platform and calls the Dependency-Check tool to perform a security scan by identifying known security vulnerabilities in the project dependencies.

[0084] Finally, after the code scanning platform uses the Dependency-Check tool to scan the code package, it returns the scanning results (including the discovered security vulnerability information) to the publishing platform. The publishing platform notifies the developers of the scanning situation according to the scanning results in an appropriate manner (such as email, SMS, system notification, etc.), including whether there are security vulnerabilities and subsequent operation suggestions.

[0085] Among them, the whole process aims to ensure that the code undergoes security checks before release to reduce potential security risks.

[0086] Step 107: Display the security information configuration list on a preset interface.

[0087] In the embodiment of the present invention, the system displays the security information configuration list on a preset user interface, enabling developers to view and manage the security of their projects.

[0088] Preferably, in another embodiment of the present invention, step 107 may further include:

[0089] Sub-step D1: Receive an access request for the security information configuration list.

[0090] Specifically, the system extracts the user's identity information from the access request, such as the username, ID, or other unique identifiers, to verify the access permission. The project roles are divided into security personnel and developers. As the administrator of this platform, the security personnel can see the vulnerability situation and repair situation of the scanned projects across the platform.

[0091] Sub-step D2: Obtain the identity information in the access request.

[0092] Specifically, the system extracts the user's identity information from the access request to verify the access permission.

[0093] Sub-step D3: Match the access permission information of the identity information according to the preset access permission.

[0094] Specifically, the system determines the data range that the user can access according to the user's identity information and the preset access permission rules. The access permission can be based on the user's role, project ownership, or other security policies.

[0095] Sub-step D4: Display the security information configuration list according to the access permission information.

[0096] Specifically, the system displays the corresponding content of the security information configuration list according to the user's access permission. The displayed content may include detailed information about the vulnerabilities, repair status, associated project metadata, etc.

[0097] Such as Figure 5As shown in the figure, security personnel, as the administrators of this platform, can view the vulnerability situation and repair situation of the scanned projects across the entire platform. Developers can only view the vulnerability situation of the projects they own, ensuring that the security vulnerabilities of the projects are not visible to other non-project personnel.

[0098] According to Figure 2 It can be seen that during the entire CICD process of code security scanning, first, developers create a code version during the release. After Jenkins finishes packing the code, it immediately calls the scanning tool of the scanning platform. The scanning tool returns json data, which is processed and displayed by the code scanning platform, and the vulnerability situation is returned. If the release is prohibited due to this vulnerability, then after the developers repair the code, they enter the packing and release process again. After the vulnerability is repaired, the code is released to the external network during the release process.

[0099] In the embodiment of the present invention, a project release request from a project developer is received, and the project metadata information is obtained; according to the project metadata information, the project is packed into a project compression package in a preset format; a preset code security scanning platform is called to perform a security scan on the project compression package to obtain security vulnerability information; the security vulnerability information is classified into security levels according to a preset security threshold; different levels of the security vulnerability information are configured according to preset security rules; after matching different levels of the security vulnerability information with the project metadata information, a security information configuration list is generated; the security information configuration list is displayed on a preset interface. The purpose of efficient and secure code scanning is achieved.

[0100] It should be noted that for the method embodiments, for simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0101] Embodiment Two

[0102] Figure 6 The following is a structural block diagram of a code security scanning device provided by the second embodiment of the present invention, which specifically may include the following modules:

[0103] A project release request receiving module 201, which is used to receive a project release request from a project developer and obtain project metadata information.

[0104] A packing module 202, which is used to pack the project into a project compression package in a preset format according to the project metadata information.

[0105] The security scanning module 203 is used to call a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information.

[0106] The security level classification module 204 is used to classify the security vulnerability information according to a preset security threshold.

[0107] Preferably, in another embodiment of the present invention, the security level classification module 204 is further used for:

[0108] Classify the security vulnerability information into high-risk vulnerability information, ordinary vulnerability information, and non-threatening vulnerability information according to a preset security threshold.

[0109] The security vulnerability information configuration module 205 is used to configure the security vulnerability information of different levels according to preset security rules.

[0110] Preferably, in another embodiment of the present invention, the security vulnerability information configuration module 205 is further used for:

[0111] Prohibit the release of the project compressed package containing the high-risk vulnerability information, and send a notice of prohibited release to the developer;

[0112] Prohibit the release of the project compressed package containing the ordinary vulnerability information, and send vulnerability warning information to the developer;

[0113] Allow the release of the project compressed package containing the non-threatening vulnerability information, and add the non-threatening vulnerability information to a preset whitelist.

[0114] Preferably, in another embodiment of the present invention, the metadata information at least includes the project version number, the latest version number, the project leader ID, and the call library information.

[0115] The security information configuration list generation module 206 is used to generate a security information configuration list after matching the security vulnerability information of different levels with the project metadata information.

[0116] Preferably, in another embodiment of the present invention, the security information configuration list generation module 206 is further used for:

[0117] Match the number of call libraries, the latest version number, the project leader ID, and the call library information of the project compressed package containing the security vulnerability information to generate a security information configuration list.

[0118] The display module 207 is used to display the security information configuration list on a preset interface.

[0119] Preferably, in another embodiment of the present invention, the display module 207 is further used for:

[0120] Receive an access request for the security information configuration list;

[0121] Obtain the identity information in the access request;

[0122] Match the access permission information of the identity information according to the preset access permission;

[0123] Display the security information configuration list according to the access permission information.

[0124] The code security scanning device provided by the embodiments of the present invention can execute the code security scanning method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0125] Embodiment III

[0126] Figure 7 It is a schematic structural diagram of a computer device provided for Embodiment III of the present invention. Figure 7 It shows a block diagram of an exemplary computer device 12 suitable for implementing the embodiments of the present invention. Figure 7 The displayed computer device 12 is only an example, and should not bring any limitation to the functions and usage scope of the embodiments of the present invention.

[0127] As Figure 7 shown, the computer device 12 is presented in the form of a general-purpose computing device. The components of the computer device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 connecting different system components (including the system memory 28 and the processing unit 16).

[0128] The bus 18 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus structures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0129] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.

[0130] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 can be used for reading and writing on non-removable, non-volatile magnetic media ( Figure 7 not shown, commonly referred to as a "hard disk drive"). Although Figure 7 not shown in the figure, a disk drive for reading and writing on removable non-volatile disks (such as "floppy disks") and an optical disk drive for reading and writing on removable non-volatile optical disks (such as CD-ROM, DVD-ROM or other optical media) can be provided. In these cases, each drive can be connected to the bus 18 through one or more data media interfaces. The memory 28 may include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0131] A program / utility 40 having a set (at least one) of program modules 42 can be stored, for example, in the memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 42 generally perform the functions and / or methods in the embodiments described in the present invention.

[0132] The computer device 12 can also communicate with one or more external devices 14 (such as a keyboard, a pointing device, a display 24, etc.), and can also communicate with one or more devices that enable a user to interact with the computer device 12, and / or communicate with any device that enables the computer device 12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 22. Moreover, the computer device 12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 20. As shown in the figure, the network adapter 20 communicates with other modules of the computer device 12 through the bus 18. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the computer device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0133] The processing unit 16 executes various functional applications and data processing by running the programs stored in the system memory 28, such as implementing the code security scanning method provided by the embodiments of the present invention.

[0134] Embodiment 4

[0135] Embodiment 4 of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, each process of the above code security scanning method is implemented, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.

[0136] Among them, the computer-readable storage medium may include, for example, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or component.

[0137] Note that the above is only the preferred embodiment of the present invention and the applied technical principles. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, more other equivalent embodiments can be included, and the scope of the present invention is determined by the scope of the appended claims.

Claims

1. A code security scanning method, characterized in that, The method includes: Receiving a project release request from a project developer and obtaining project metadata information; Packing the project into a project compressed package in a preset format according to the project metadata information; Invoking a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information; Classifying the security vulnerability information into security levels according to a preset security threshold; Configuring the security vulnerability information of different levels according to preset security rules; Generating a security information configuration list after matching the security vulnerability information of different levels with the project metadata information; Displaying the security information configuration list on a preset interface.

2. The method according to claim 1, wherein The classifying the security vulnerability information into security levels according to a preset security threshold includes: Classifying the security vulnerability information into high-risk vulnerability information, ordinary vulnerability information, and non-threat vulnerability information according to a preset security threshold.

3. The method according to claim 2, wherein The configuring the security vulnerability information of different levels according to preset security rules includes: Prohibiting the release of the project compressed package containing the high-risk vulnerability information and sending a notice of prohibited release to the developer; Prohibiting the release of the project compressed package containing the ordinary vulnerability information and sending vulnerability warning information to the developer; Allowing the release of the project compressed package containing the non-threat vulnerability information and adding the non-threat vulnerability information to a preset whitelist.

4. The method according to claim 1, characterized in that, The metadata information at least includes the project version number, the latest version number, the project leader ID, and the call library information.

5. The method according to claim 4, wherein The generating a security information configuration list after matching the security vulnerability information of different levels with the project metadata information includes: Matching the number of call libraries, the latest version number, the project leader ID, and the call library information of the project compressed package containing the security vulnerability information to generate a security information configuration list.

6. The method according to claim 1, wherein The displaying the security information configuration list on a preset interface includes: Receiving an access request to the security information configuration list; Obtaining the identity information in the access request; Matching the access permission information of the identity information according to preset access permissions; Displaying the security information configuration list according to the access permission information.

7. A code security scanning device, characterized in that The device includes: A project release request receiving module for receiving a project release request from a project developer and obtaining project metadata information; A packing module for packing the project into a project compressed package in a preset format according to the project metadata information; A security scanning module for invoking a preset code security scanning platform to perform a security scan on the project compressed package to obtain security vulnerability information; A security level classification module for classifying the security vulnerability information into security levels according to a preset security threshold; A security vulnerability information configuration module for configuring the security vulnerability information of different levels according to preset security rules; A security information configuration list generation module for generating a security information configuration list after matching the security vulnerability information of different levels with the project metadata information; A display module for displaying the security information configuration list on a preset interface.

8. The device according to claim 7, characterized in that, The security level classification module is further used for: Divide the security vulnerability information into high-risk vulnerability information, general vulnerability information, and non-threat vulnerability information according to a preset security threshold.

9. A computer device, characterized in that, The computer device includes: One or more processors; A memory for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the code security scanning method according to any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the code security scanning method according to any one of claims 1-6 is implemented.