-
Notifications
You must be signed in to change notification settings - Fork 80
Add convert CCI list workflow #6336
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
jtquach1
wants to merge
107
commits into
master
Choose a base branch
from
add-convert-cci-list-workflow
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
107 commits
Select commit
Hold shift + click to select a range
a4eb287
Fix typo
jtquach1 e11c5c5
Fix crashing on CCIs who had no references to any NIST controls
jtquach1 a1c6c64
Generate CCI definitions alongside CCI to NIST file
jtquach1 29844bb
Rename xml2json to cciListXml2json
jtquach1 a8b7c67
Update CciNistMappingData with converted content from U_CCI_List.xml
jtquach1 dbd0229
Update frontend component, CciNistMapping used in converters, delete …
jtquach1 f8f812f
Add comment about GitHub-hosted wiki for cciListXml2json
jtquach1 9490959
Create GitHub workflow for pulling down U_CCI_List.xml and converting…
jtquach1 26aaec3
Fix cron syntax
jtquach1 063426d
Also add Prettier job to format CciNistMappingData.ts
jtquach1 fe981f7
Update author and email in commit changes step
jtquach1 067abfc
Update XCCDF mapper OpenSCAP ubuntu1804 expected JSON
jtquach1 051defa
Remove temporary file after updating CciNistMappingData.ts
jtquach1 d6abe03
Address review comments
jtquach1 99dc13e
Check that workflow runs
jtquach1 1827856
Remove step
jtquach1 4483383
Update xml-file parameter in publish-date step
jtquach1 8e56f8b
Add namespaces parameter to publish-date step and add debug commands
jtquach1 a50be6a
Update xpath
jtquach1 019f229
Try to fix xpath again
jtquach1 abf89e7
Try to fix path of input XML
jtquach1 0a371bb
Try to resolve 'a mapping was not expected' error
jtquach1 f6f0cd0
Remove env var
jtquach1 40a643e
Set env var with path to input XML in separate step
jtquach1 691f50e
Update paths to input and output XML files
jtquach1 ad21342
Move env attribute
jtquach1 4287473
Try to print result of previous step
jtquach1 7da7aff
Try to grab output of publish-date step from object
jtquach1 b2e9067
Update to proper branch
jtquach1 be0d023
Explicitly specify parent-most component in U_CCI_List.xml to grab ve…
jtquach1 6c2dc8f
Move getCCIsForNISTTags function into libs/hdf-converters/src/mapping…
jtquach1 518361d
Update GitHub Action and cciListXml2json script to create NIST->CCI J…
jtquach1 36311c3
Update files from cciListXml2json script and new formatting
jtquach1 1ea35ea
Remove step
jtquach1 12d0bbd
Fix env var
jtquach1 8c2d75a
Remove trailing slash
jtquach1 67ff7ac
Restructure CCI to NIST and NIST to CCI logic across mappers and dele…
jtquach1 6125752
Export variables representing magic strings to be used in NIST2CCI fu…
jtquach1 9788090
Update path for output directory and rename steps
jtquach1 5965480
WIP address latest PR review comments
jtquach1 d94270a
Revert NIST->CCI trie to Record<string, string[]>
jtquach1 7943cb2
Fix typo
jtquach1 cfad3f4
Update XCCDF mapper and expected XML->HDF test outputs to not include…
jtquach1 6b3f75b
Fix typo in commented generating-expected-output code
jtquach1 b42ff7d
Regenerate test expected output files
jtquach1 20341bd
Uncomment GitHub Action code
jtquach1 afdbc30
Fix lint issue
jtquach1 6e717aa
Update XCCDF mapper as per NIST to CCI, CCI to NIST, and proper defau…
jtquach1 e6597bd
Reduce code complexity in CCI List XML to JSON converter
jtquach1 a9843fa
Produce empty array of CCI tags in JSONIX->CKL mapper if the input JS…
jtquach1 08b5a21
Add change to convert-cci-yml based on code review comment
jtquach1 16e69d7
Keep Revision info when mapping from CCI to NIST
jtquach1 c1101dd
Remove creator key from NistReference
jtquach1 c7c5f81
Update style.css
jtquach1 7b1b0a4
Bump @aws-sdk/client-s3 from 3.701.0 to 3.703.0
dependabot[bot] 4ff4095
Bump eslint-plugin-vue from 9.31.0 to 9.32.0
dependabot[bot] bdf872e
Update to node22 (#6440)
Amndeep7 327d225
prep for 2.11.0
Amndeep7 71a9530
v2.11.0
Amndeep7 bbde3f9
internal math changed yet again so fixed the sample
Amndeep7 4b48294
pointless change to frontend repo
Amndeep7 de626de
2.11.1
Amndeep7 c111a25
v2.11.1
Amndeep7 c643559
Bump @nestjs/common from 10.4.12 to 10.4.13
dependabot[bot] 4e4fedc
Bump dotenv from 16.4.5 to 16.4.7
dependabot[bot] 05e869f
Bump @nestjs/core from 10.4.12 to 10.4.13
dependabot[bot] 845418a
Bump @nestjs/testing from 10.4.12 to 10.4.13
dependabot[bot] a9fa3cc
Bump @nestjs/platform-express from 10.4.12 to 10.4.13
dependabot[bot] c24d702
Bump prettier from 3.4.1 to 3.4.2
dependabot[bot] db260c6
Bump cypress from 13.16.0 to 13.16.1
dependabot[bot] 03292de
Bump @aws-sdk/client-s3 from 3.703.0 to 3.705.0
dependabot[bot] ae851a8
Bump express from 4.21.1 to 4.21.2
dependabot[bot] 32d11e4
Bump tailwindcss from 3.4.15 to 3.4.16
dependabot[bot] d6885da
Bump sass-loader from 16.0.3 to 16.0.4
dependabot[bot] ffe83c2
Bump axios from 1.7.8 to 1.7.9
dependabot[bot] 12b9c4e
Bump @nestjs/common from 10.4.13 to 10.4.15
dependabot[bot] bc37c22
Bump @nestjs/core from 10.4.13 to 10.4.15
dependabot[bot] 9738a60
Bump @nestjs/platform-express from 10.4.13 to 10.4.15
dependabot[bot] 426906c
Bump @smithy/node-http-handler from 3.3.1 to 3.3.2
dependabot[bot] 460fbbf
Bump @nestjs/testing from 10.4.13 to 10.4.15
dependabot[bot] 3931802
Bump @aws-sdk/client-sts from 3.699.0 to 3.709.0
dependabot[bot] c309989
Bump xml-parser-xo from 4.1.2 to 4.1.3
dependabot[bot] 35727c3
Bump @aws-sdk/client-s3 from 3.705.0 to 3.709.0
dependabot[bot] 96ef2be
Bump @aws-sdk/client-config-service from 3.702.0 to 3.709.0
dependabot[bot] febae2e
Bump @types/node from 22.10.1 to 22.10.2
dependabot[bot] 7e956a8
Bump @aws-sdk/client-s3 from 3.709.0 to 3.712.0
dependabot[bot] 465dbaf
Bump fast-xml-parser from 4.5.0 to 4.5.1
dependabot[bot] 134d118
Bump @aws-sdk/client-config-service from 3.709.0 to 3.713.0
dependabot[bot] 39c88ac
Bump @aws-sdk/client-s3 from 3.712.0 to 3.713.0
dependabot[bot] 0aab461
Bump express-rate-limit from 7.4.1 to 7.5.0
dependabot[bot] 700e045
Bump highlight.js from 11.10.0 to 11.11.0
dependabot[bot] c2bf1e1
Bump tailwindcss from 3.4.16 to 3.4.17
dependabot[bot] ae3ba5a
Bump @aws-sdk/client-config-service from 3.713.0 to 3.714.0
dependabot[bot] c143383
Bump vue-cookies from 1.8.4 to 1.8.5
dependabot[bot] 0e32f28
Bump @aws-sdk/client-s3 from 3.713.0 to 3.714.0
dependabot[bot] 6342895
Bump sanitize-html from 2.13.1 to 2.14.0
dependabot[bot] e838f96
Bump @aws-sdk/client-s3 from 3.714.0 to 3.715.0
dependabot[bot] f20fb6e
Bump cypress from 13.16.1 to 13.17.0
dependabot[bot] 1ebaa61
Bump @aws-sdk/client-config-service from 3.714.0 to 3.716.0
dependabot[bot] 15be6ad
Bump @aws-sdk/client-s3 from 3.715.0 to 3.716.0
dependabot[bot] ec4e294
Bump dotenv-cli from 7.4.4 to 8.0.0
dependabot[bot] 840f59e
Bump @aws-sdk/client-s3 from 3.716.0 to 3.717.0
dependabot[bot] 3af8639
Bump @smithy/node-http-handler from 3.3.2 to 3.3.3
dependabot[bot] 6866a4c
Bump diff2html from 3.4.48 to 3.4.51
dependabot[bot] 6cc1e97
Bump htmlparser2 from 9.1.0 to 10.0.0
dependabot[bot] c002380
Bump highlight.js from 11.11.0 to 11.11.1
dependabot[bot] 5e0a22b
Fix code smell
jtquach1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,60 @@ | ||
| name: Convert CCI List XML to JSON | ||
|
|
||
| on: | ||
| push: | ||
| branches: ['master'] | ||
|
|
||
| # Run this workflow on the 1st day at 00:00 every month | ||
| schedule: | ||
| - cron: '0 0 1 * *' | ||
|
|
||
| env: | ||
| # This URL is super brittle with how links constantly get changed. | ||
| CCI_LIST_ZIP_URL: https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CCI_List.zip | ||
|
|
||
| jobs: | ||
| convert-cci-list: | ||
| runs-on: ubuntu-22.04 | ||
| steps: | ||
| - name: Checkout the code | ||
| uses: actions/checkout@v4 | ||
| - run: git fetch --prune --unshallow | ||
| - name: Setup Node.js | ||
| uses: actions/setup-node@v4 | ||
| with: | ||
| node-version: '18' | ||
| check-latest: true | ||
| cache: 'yarn' | ||
|
|
||
| - name: Install project dependencies | ||
| run: yarn install --frozen-lockfile | ||
|
|
||
| - name: Download CCI List | ||
| run: | | ||
| curl -o U_CCI_List.zip $CCI_LIST_ZIP_URL && unzip U_CCI_List.zip | ||
|
|
||
| - name: Get publish date of CCI List | ||
| id: publish-date | ||
| uses: mavrosxristoforos/get-xml-info@2.0 | ||
| with: | ||
| xml-file: 'U_CCI_List.xml' | ||
| xpath: '/*[local-name()="cci_list"]/*[local-name()="metadata"]/*[local-name()="publishdate"]' | ||
| namespaces: '{"ns": "http://iase.disa.mil/cci"}' | ||
|
|
||
| - name: Set directory environment variables for next step | ||
| run: | | ||
| echo "ROOT_DIRECTORY=$(pwd)" >> $GITHUB_ENV | ||
| echo "OUTPUT_DIRECTORY=$(pwd)/libs/hdf-converters/src/mappings" >> $GITHUB_ENV | ||
|
|
||
| - name: Convert CCI List XML to CCI->NIST, CCI->Definitions, and NIST->CCI JSON files | ||
| run: yarn workspace @mitre/hdf-converters cciListXml2json -i $ROOT_DIRECTORY/U_CCI_List.xml -n $OUTPUT_DIRECTORY/U_CCI_List.nist.json -d $OUTPUT_DIRECTORY/U_CCI_List.defs.json -c $OUTPUT_DIRECTORY/U_CCI_List.cci.json | ||
|
|
||
| - name: Commit changes to produced JSON files | ||
| run: | | ||
| git config --local user.email "saf@groups.mitre.org" | ||
| git config --local user.name "MITRE SAF Automation" | ||
| git add $OUTPUT_DIRECTORY/U_CCI_List.nist.json $OUTPUT_DIRECTORY/U_CCI_List.defs.json $OUTPUT_DIRECTORY/U_CCI_List.cci.json | ||
| git commit -sm "Update CCI List to the current NIST and definition mappings as of $DATETIME" | ||
| git push | ||
| env: | ||
| DATETIME: ${{steps.publish-date.outputs.info}} | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1 @@ | ||
| 18 | ||
| 22 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1 @@ | ||
| v2.10.20 | ||
| v2.11.1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.