Skip to main content

Snyk APIを使って脆弱性を検出・修正する

著者
Headshot of Josh Emerson

Josh Emerson

2018年1月3日

0 分で読めます
模様の入ったピースと、白い動物のような顔が描かれた黒い中央のピースで構成された、手描きのジグソーパズル

イラスト:Lou Reade

この記事では、Snyk APIを使って、特定のプロジェクトに関連するすべての問題を取得する方法を説明します。問題をレポートやダッシュボードに取り込めるほか、管理者や開発者が、すでに利用しているポータルやワークフロー上で脆弱性の状況を把握できるなど、さまざまなメリットがあります。

以下の手順では、APIを使って次の操作を行います:

  • アクセス可能な組織の一覧を取得する

  • 組織に属するすべてのプロジェクトを取得する

  • プロジェクトの問題一覧を取得する

前提条件

Snyk APIは、有料プランをご利用のお客様にお使いいただけます。APIを使い始めるには、ログインするかアカウントに登録し、https://app.snyk.ioからAPIキーを取得してください。APIで利用できるすべてのエンドポイントについては、https://snyk.docs.apiary.ioをご覧ください。

まだプロジェクトを作成していない場合は、Snykコマンドラインツールからsnyk monitorを実行して作成できます。また、GitHub、GitLab、Herokuなどのさまざまなソースから、ウェブサイト経由でプロジェクトを追加することもできます。

また、https://snyk.io/accountからAPIキーをコピーして、以下の該当箇所で使用してください。

組織の取得

最初に、組織のエンドポイントhttps://snyk.io/api/v1/orgsを使います。

curl --include \
     --header "Content-Type: application/json; charset=utf-8" \
     --header "Authorization: token <API_KEY>" \
  'https://snyk.io/api/v1/orgs'

組織の一覧が返されます。

{
  "orgs": [
    {
      "name": "defaultOrg",
      "id": "689ce7f9-7943-4a71-b704-2ba575f01089"
    },
    {
      "name": "My Other Org",
      "id": "a04d9cbd-ae6e-44af-b573-0556b0ad4bd2"
    }
  ]
}

プロジェクトの取得

次に、プロジェクトの問題を確認したい組織のIDを取得し、プロジェクトAPIのエンドポイントhttps://snyk.io/api/v1/org//projectsで使用します(orgには組織のIDを指定してください)。

curl --include \
     --header "Content-Type: application/json" \
     --header "Authorization: token <API_KEY>" \
  'https://snyk.io/api/v1/org/<ORG_ID>/projects'

プロジェクトの一覧が返されます。

{
  "org": {
    "name": "defaultOrg",
    "id": "689ce7f9-7943-4a71-b704-2ba575f01089"
  },
  "projects": [
    {
      "name": "atokeneduser/goof",
      "id": "6d5813be-7e6d-4ab8-80c2-1e3e2a454545"
    },
    {
      "name": "atokeneduser/clojure",
      "id": "af127b96-6966-46c1-826b-2e79ac49bbd9"
    }
  ]
}

プロジェクトの問題を取得する

プロジェクトの一覧を取得したら、関心のあるプロジェクトのIDを指定して、以下のように問題のエンドポイントにリクエストを送信します。

curl --include \
     --request POST \
     --header "Content-Type: application/json" \
     --header "Authorization: token <API_KEY>" \
  'https://snyk.io/api/v1/org/orgId/project/<PROJECT_ID>/aggregated-issues'

脆弱性の配列を含むissuesオブジェクトを含んだJSONレスポンスが返されます。また、組織でライセンスが有効になっている場合は、最後のスナップショット取得時にプロジェクトで検出されたライセンスの問題の配列も含まれます。

プロジェクトの問題を取得するAPIエンドポイントでは、問題の種類(脆弱性またはライセンスの問題)、深刻度(高、中、低)、問題が無視または修正済みかどうかでフィルタリングできます。深刻度が高く、無視も修正もされていない脆弱性だけを確認したい場合は、次のリクエストを送信します。

'https://snyk.io/api/v1/org/orgId/project/<PROJECT_ID>/aggregated-issues'curl --include \
     --request POST \
     --header "Content-Type: application/json" \
     --header "Authorization: token <API_KEY>" \
     --data-binary '{
       "filters": {
        "severities": [ "high" ],
        "types": [ "vuln" ],
        "ignored": false,
        "patched": false
      }
    }' \
  'https://snyk.io/api/v1/org/orgId/project/<PROJECT_ID>/aggregated-issues'

この場合、レスポンスにはライセンスの問題は含まれず、深刻度が高く、無視も修正もされていない脆弱性のみが表示されます。

レスポンスの活用

プロジェクトの問題を取得すると、次のようなJSONペイロードが得られます。

{
  "ok": false,
  "issues": {
    "vulnerabilities": [
      {
        "id": "npm:ms:20170412",
        "url": "https://snyk.io/vuln/npm:ms:20170412",
        "title": "Regular Expression Denial of Service (ReDoS)",
        "type": "vuln",
        "description": "## Overview\n[`ms`](https://www.npmjs.com/package/ms) is a tiny millisecond conversion utility.\n\nAffected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to an incomplete fix for previously reported vulnerability [npm:ms:20151024](https://snyk.io/vuln/npm:ms:20151024). The fix limited the length of accepted input string to 10,000 characters, and turned to be insufficient making it possible to block the event loop for 0.3 seconds (on a typical laptop) with a specially crafted string passed to `ms()` function.\n\n*Proof of concept*\n```js\nms = require('ms');\nms('1'.repeat(9998) + 'Q') // Takes about ~0.3s\n```\n\n**Note:** Snyk's patch for this vulnerability limits input length to 100 characters. This new limit was deemed to be a breaking change by the author.\nBased on user feedback, we believe the risk of breakage is _very_ low, while the value to your security is much greater, and therefore opted to still capture this change in a patch for earlier versions as well.  Whenever patching security issues, we always suggest to run tests on your code to validate that nothing has been broken.\n\nFor more information on `Regular Expression Denial of Service (ReDoS)` attacks, go to our [blog](https://snyk.io/blog/redos-and-catastrophic-backtracking/).\n\n## Disclosure Timeline\n- Feb 9th, 2017 - Reported the issue to package owner.\n- Feb 11th, 2017 - Issue acknowledged by package owner.\n- April 12th, 2017 - Fix PR opened by Snyk Security Team.\n- May 15th, 2017 - Vulnerability published.\n- May 16th, 2017 - Issue fixed and version `2.0.0` released.\n- May 21th, 2017 - Patches released for versions `>=0.7.1, <=1.0.0`.\n\n## Remediation\nUpgrade `ms` to version 2.0.0 or higher.\n\n## References\n- [GitHub PR](https://github.com/zeit/ms/pull/89)\n- [GitHub Commit](https://github.com/zeit/ms/pull/89/commits/305f2ddcd4eff7cc7c518aca6bb2b2d2daad8fef)\n",
        "from": [
          "mongoose@4.2.4",
          "mquery@1.6.3",
          "debug@2.2.0",
          "ms@0.7.1"
        ],
        "package": "ms",
        "version": "0.7.1",
        "severity": "low",
        "language": "js",
        "packageManager": "npm",
        "semver": {
          "unaffected": ">=2.0.0",
          "vulnerable": "<2.0.0"
        },
        "publicationTime": "2017-05-15T06:02:45.497Z",
        "disclosureTime": "2017-04-11T21:00:00.000Z",
        "isUpgradable": true,
        "isPatchable": true,
        "identifiers": {
          "CVE": [],
          "CWE": [
            "CWE-400"
          ],
          "ALTERNATIVE": [
            "SNYK-JS-MS-10509"
          ]
        },
        "credit": [
          "Snyk Security Research Team"
        ],
        "CVSSv3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
        "cvssScore": 3.7,
        "patches": [
          {
            "id": "patch:npm:ms:20170412:0",
            "urls": [
              "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_100.patch"
            ],
            "version": "=1.0.0",
            "comments": [],
            "modificationTime": "2017-05-16T10:12:18.990Z"
          },
          {
            "id": "patch:npm:ms:20170412:1",
            "urls": [
              "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_072-073.patch"
            ],
            "version": "=0.7.2 || =0.7.3",
            "comments": [],
            "modificationTime": "2017-05-16T10:12:18.990Z"
          },
          {
            "id": "patch:npm:ms:20170412:2",
            "urls": [
              "https://s3.amazonaws.com/snyk-rules-pre-repository/snapshots/develop/patches/npm/ms/20170412/ms_071.patch"
            ],
            "version": "=0.7.1",
            "comments": [],
            "modificationTime": "2017-05-16T10:12:18.990Z"
          }
        ],
        "isIgnored": true,
        "isPatched": false,
        "upgradePath": [
          "mongoose@4.10.2",
          "mquery@2.3.1",
          "debug@2.6.8",
          "ms@2.0.0"
        ]
      }
    ],
    "licenses": []
  },
  "dependencyCount": 250,
  "packageManager": "npm"
}

脆弱性の名前、脆弱性のあるパッケージ、各脆弱性の詳細を確認するためのURLを表示したいとします。例としてjqを使うと、次のようにできます。

curl --request POST \
   --header "Content-Type: application/json" \
   --header "Authorization: token <API_KEY>" \
  'https://snyk.io/api/v1/org/orgId/project/<PROJECT_ID>/issues' \
  | jq '"Vulnerability: \(.issues.vulnerabilities[].title) in \(.issues.vulnerabilities[].package)@\(.issues.vulnerabilities[].version) - \(.issues.vulnerabilities[].url)"'

次のような結果が得られます。

Regular Expression Denial of Service (ReDoS) in ms@0.7.1 - https://snyk.io/vuln/npm:ms:20170412

Reporting API

次回の記事では、エンタープライズ向けReporting APIを使って、プロジェクトの問題エンドポイントでは実現できない分析を行う方法を紹介します。問題の経時的な推移や解決までの時間をグラフ化したい場合、より高度なフィルタリング機能を利用したい場合は、enterprise@snyk.ioまでメールでお問い合わせいただき、Reporting APIをお試しください。