Supplier-scoped input

The input a supplier-scoped policy receives, with TypeScript types and a sample.

This page lists the JSON input a supplier-scoped policy receives, whether it is built in the Visual Builder or written in Rego or JavaScript. For how to write a policy, see Write and test policies.

Top-level fields

A supplier-scoped policy is called once per supplier, with supplier and the vulnerabilities of that supplier's components:

{
  supplier: { ... },
  vulnerabilities: [ ... ],
  namespace: { tenantId, space }
}
Policy input
NamespacetenantId, space
Suppliername, type, url, address, contact[]
Vulnerability[]severity, EPSS
SupplierAnnotationuser-edited: identifiers, notes, tags
VulnerabilityAnalysisstate, justification

TypeScript types

Below is the input as TypeScript types. Not every field is set on every input, so check for missing values in a policy.

// this is the top-level object that is passed to the policy
type PolicyInputType = {
  namespace?: Namespace;
  supplier?: Supplier;
  vulnerabilities?: Vulnerability[]; // across the supplier's components; each carries its component
};

type Namespace = {
  tenantId: OrganizationId;
  space: string;
};

type Supplier = {
  id?: SupplierId;
  name: string;
  type: SupplierType;
  address?: OrganizationalPostalAddress;
  url?: string[];
  contact?: OrganizationalContact[];
  createdAt?: string;
  updatedAt?: string;
  annotation?: SupplierAnnotation;
};

type SupplierAnnotation = {
  id?: SupplierId;
  displayName?: string;
  url?: string;
  contact?: OrganizationalContact;
  address?: OrganizationalPostalAddress;
  lei?: string;
  vat?: string;
  eori?: string;
  euid?: string;
  brn?: string;
  internalId?: string;
  cpeVendor?: string;
  duns?: string;
  uei?: string;
  cage?: string;
  gln?: string;
  iso6523?: string;
  notes: string;
  properties?: Record<string, string>;
  tags?: string[];
  createdAt?: string;
  updatedAt?: string;
};

type OrganizationalContact = {
  name?: string;
  email?: string;
  phone?: string;
};

type OrganizationalPostalAddress = {
  country?: string;
  region?: string;
  locality?: string;
  postOfficeBoxNumber?: string;
  postalCode?: string;
  streetAddress?: string;
};

type Vulnerability = {
  id: VulnerabilityId;
  component: ComponentRef;
  advisoryId: string;
  severity: number;
  vendorId: string;
  epss: number;
  vex?: VulnerabilityAnalysis;
};

type VulnerabilityAnalysis = {
  id: VulnerabilityAnalysisId;
  vulnerability: string; // vendor id CVE-2019-1234 etc
  affects?: ComponentRef[];
  state?: ImpactAnalysisState;
  justification?: ImpactAnalysisJustification;
  response?: ImpactAnalysisResponse[];
  details?: string;
  author?: UserId;
  issueOwner?: UserId;
  attestations?: string[]; // sha256
  externalReferences?: string[]; // links etc
  published: string;
  createdAt: string;
  updatedAt: string;
};

type OrganizationId = string;
type SupplierId = string;
type SupplierType = "ORGANIZATION" | "PERSON";

type ImpactAnalysisResponse =
  | "can_not_fix"
  | "will_not_fix"
  | "update"
  | "rollback"
  | "workaround_available";

type ImpactAnalysisState =
  | "resolved"
  | "resolved_with_pedigree"
  | "exploitable"
  | "in_triage"
  | "false_positive"
  | "not_affected";

type ImpactAnalysisJustification =
  | "code_not_present"
  | "code_not_reachable"
  | "requires_configuration"
  | "requires_dependency"
  | "requires_environment"
  | "protected_by_compiler"
  | "protected_at_runtime"
  | "protected_at_perimeter"
  | "protected_by_mitigating_control";

Example policy

/*
 * Evaluates once per supplier. Flags suppliers whose components have critical vulnerabilities (severity >= 9).
 */

const SEVERITY_THRESHOLD = 9;

function Policy({supplier, vulnerabilities}) {
  if (!vulnerabilities || vulnerabilities.length === 0) {
    return null;
  }

  const criticalVulns = vulnerabilities.filter(v => v.severity >= SEVERITY_THRESHOLD);

  if (criticalVulns.length === 0) {
    return null;
  }

  return [{
    severity: Math.max(...criticalVulns.map(v => v.severity)),
    message: `Supplier has ${criticalVulns.length} critical vulnerabilities (severity >= ${SEVERITY_THRESHOLD})`,
  }];
}