diff --git a/scanner_tool/owasp_checker.py b/scanner_tool/owasp_checker.py index e11de4a..0ea770e 100644 --- a/scanner_tool/owasp_checker.py +++ b/scanner_tool/owasp_checker.py @@ -45,6 +45,10 @@ # A06: Vulnerable and Outdated Components (Simulated Check) # Key: package name, Value: First SAFE version (anything < this version is vulnerable) + + +##TODO: IMPLEMENT THE SAFE PACKAGES LIST FROM Google's safe package list through a GRPC CALL with API KEY +## SOURCE : https://cloud.google.com/assured-open-source-software/docs/supported-packages#python VULNERABLE_PACKAGES = { "requests": "2.29.0", "jinja2": "3.1.2", diff --git a/tests/test_owasp_checker.py b/tests/test_owasp_checker.py index 55d283d..96c4b02 100644 --- a/tests/test_owasp_checker.py +++ b/tests/test_owasp_checker.py @@ -1,3 +1,5 @@ + +#TODO: Update tests to match the updates on owasp file once ready. import unittest import os import tempfile