Skip to content

Commit

Permalink
feat(helper-cli): Add a command to show insights into scan issues
Browse files Browse the repository at this point in the history
Assign scan issues to categories and output for each category the amount
of dependency affected by a scan issue of the respective category. Also
show a secondary count which disregards the version.

These statistics can be useful as a basis to make a rough estimate of
the effort needed to fix the scan issues.

Signed-off-by: Frank Viernau <[email protected]>
  • Loading branch information
fviernau committed Jul 11, 2024
1 parent 799acd1 commit a094033
Show file tree
Hide file tree
Showing 2 changed files with 114 additions and 0 deletions.
1 change: 1 addition & 0 deletions helper-cli/src/main/kotlin/HelperMain.kt
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,7 @@ internal class HelperMain : CliktCommand(
ExtractRepositoryConfigurationCommand(),
GenerateTimeoutErrorResolutionsCommand(),
GetPackageLicensesCommand(),
GroupScanIssuesCommand(),
DownloadResultsFromPostgresCommand(),
ImportCopyrightGarbageCommand(),
ImportScanResultsCommand(),
Expand Down
113 changes: 113 additions & 0 deletions helper-cli/src/main/kotlin/commands/GroupScanIssuesCommand.kt
Original file line number Diff line number Diff line change
@@ -0,0 +1,113 @@
/*
* Copyright (C) 2019 The ORT Project Authors (see <https://github.com/oss-review-toolkit/ort/blob/main/NOTICE>)
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*
* SPDX-License-Identifier: Apache-2.0
* License-Filename: LICENSE
*/

package org.ossreviewtoolkit.helper.commands

import com.github.ajalt.clikt.core.CliktCommand
import com.github.ajalt.clikt.parameters.options.convert
import com.github.ajalt.clikt.parameters.options.option
import com.github.ajalt.clikt.parameters.options.required
import com.github.ajalt.clikt.parameters.types.file

import org.ossreviewtoolkit.model.Issue
import org.ossreviewtoolkit.model.OrtResult
import org.ossreviewtoolkit.model.Severity
import org.ossreviewtoolkit.model.readValue
import org.ossreviewtoolkit.utils.common.expandTilde

class GroupScanIssuesCommand : CliktCommand(
help = "Shows the amount of affected dependencies for each scan issue category."
) {
private val ortFile by option(
"--ort-file", "-i",
help = "The ORT result file to read as input."
).convert { it.expandTilde() }
.file(mustExist = true, canBeFile = true, canBeDir = false, mustBeWritable = false, mustBeReadable = true)
.convert { it.absoluteFile.normalize() }
.required()

override fun run() {
val ortResult = ortFile.readValue<OrtResult>()

val issues = ortResult.getScannerIssues(
omitExcluded = true,
omitResolved = true,
minSeverity = Severity.ERROR
).filter { (id, _) -> ortResult.isPackage(id) }

val issueCategoriesForId = issues.mapValues { issue ->
issue.value.mapTo(mutableSetOf()) { it.category }
}

val issueCategoriesForIdWithoutVersion = issueCategoriesForId.entries.groupBy(
{ it.key.copy(version = "") },
{ it.value }
).mapValues { it.value.flatten().toSet() }

val pkgCountsForIssueCategory = ScanIssueCategory.entries.associateWith { category ->
val numPackages = issueCategoriesForId.count { (_, categories) ->
category in categories
}

val numPackagesWithoutVersion = issueCategoriesForIdWithoutVersion.count { (_, categories) ->
category in categories
}

numPackages to numPackagesWithoutVersion
}

val stats = buildString {
pkgCountsForIssueCategory.entries.sortedByDescending { it.value.first }.forEach { (category, counts) ->
appendLine("$category: ${counts.first} / ${counts.second}")
}
}

print(stats)
}
}

private enum class ScanIssueCategory(
val regex: Regex
) {
PROVENANCE_INFO_MISSING(
"IOException: Could not resolve provenance for package '.*' for source code origins \\[.*\\]\\."
),
SCAN_TIMED_OUT(
"ERROR: Timeout after .* seconds while scanning file '.*'\\."
),
VCS_REVISION_NOT_FOUND(
".*Could not resolve revision.*Could not find any revision candidates.*"
),
VCS_PATH_NOT_EXISTENT(
".*Could not resolve provenance.*because the requested VCS path.*does not exist."
),
VCS_TYPE_UNKNOWN(
".*Could not determine VCS for type.*"
),
OTHER("");

constructor(regex: String) : this(regex.toRegex(setOf(RegexOption.DOT_MATCHES_ALL, RegexOption.MULTILINE)))

companion object {
fun forIssue(issue: Issue) = values().find { it.regex.matches(issue.message) } ?: OTHER

Check warning on line 108 in helper-cli/src/main/kotlin/commands/GroupScanIssuesCommand.kt

View workflow job for this annotation

GitHub Actions / qodana-scan

'Enum.values()' is recommended to be replaced by 'Enum.entries' since 1.9

'Enum.values()' is recommended to be replaced by 'Enum.entries' since 1.9
}
}

private val Issue.category: ScanIssueCategory
get() = ScanIssueCategory.forIssue(this)

0 comments on commit a094033

Please sign in to comment.