Skip to content

Fix scan and CycloneDX correctness and modernize browser extensions - #622

Closed
PekSec wants to merge 5 commits into
RetireJS:masterfrom
PekSec:codex/extension-analyst-console
Closed

PekSec wants to merge 5 commits into
RetireJS:masterfrom
PekSec:codex/extension-analyst-console

Conversation

@PekSec

@PekSec PekSec commented Sep 18, 2026

Copy link
Copy Markdown

Summary

CLI scans could finish before asynchronous OSV results arrived, CycloneDX reports could alter detected versions or discard evidence from repeated components, and browser scans could lose or mix results across navigation and background restarts. This change fixes those paths and replaces the extension popup with a shared 600×600 analyst console for Chrome and a modern Firefox WebExtension.

The popup provides resource search, severity and advisory details, URL copying, JSON export, and persisted settings. Scan failures, pending resources, and unidentified libraries remain distinct from identified libraries with no known vulnerabilities.

Commit organization

  1. Make Node build and test scripts portable across platforms.
  2. Fix CLI scan completion, invalid input and JSON handling, license boundaries, and advisory deduplication. Distinct CVEs sharing an issue remain separate.
  3. Preserve exact CycloneDX versions and merge vulnerability, occurrence, and detection evidence for repeated components.
  4. Share the extension runtime and UI across Chrome, Chrome without function scanning, and Firefox. Persist tab state and request ownership, reject stale navigation results, refresh detectors with a cached fallback, and isolate Chrome function scanning in its sandbox.
  5. Run Node checks and extension tests/builds in CI on Linux and Windows.

Validation

  • Node build and 76 tests pass, including new CLI and CycloneDX regressions.
  • TypeScript checking and ESLint pass.
  • All 16 extension runtime/popup tests pass.
  • Repository node validate and the full node test-detection.js suite pass.
  • All three extension packages build: dist/chrome, dist/chrome-no-func, and dist/firefox.
  • Native browser smoke checks on Windows with Chrome 153 and Firefox 156 verify detection, popup layout, search/counts, persisted settings, and copy/fallback. Chrome checks also verify downloaded JSON export, restricted pages, and the difference between sandbox and no-function scanning.

Compatibility and review notes

Firefox uses static and AST detection; sandbox function execution remains specific to the full Chrome package. Minimum browser versions are Chrome 116 and Firefox 140. Browser smoke scripts currently use Windows installation paths and are manual checks; CI runs the platform-independent unit tests and builds. Generated packages are ignored, and this PR does not publish store releases or change the vulnerability database.

This is an AI-assisted implementation. The old Firefox SDK sources remain archived and excluded from the new package; loading instructions describe the new builds.

@eoftedal

Copy link
Copy Markdown
Member

Please split this into separate pull requests for the different features. The CLI fixes should be separate from the plugin rewrites.

working-directory: node
- run: node node_modules/eslint/bin/eslint.js . --ext .ts --ignore-path ../.gitignore
working-directory: node
- run: npm ci --no-audit --no-fund

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why do you keep adding no-audit?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added the flag to suppress installation-time audit output; it was unnecessary for this change. In the replacement extension PR (#624), I removed --no-audit and --no-fund from CI and the build scripts, so npm's default audit behavior remains.

Comment thread chrome/README.md
# Browser extension development

To use the development version:
Run `build_chrome.bat` on Windows or `./build_chrome.sh` on Unix from the repository root. Node.js 18 or newer and npm are required. The build compiles the scanner and creates all three packages without relying on symlinks:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

node 18 is EOL

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The development instructions in #624 now recommend Node 24 LTS. CI covers Node 24 and 26 on Linux and Windows. Users loading the committed prebuilt extensions do not need Node installed.

@eoftedal

Copy link
Copy Markdown
Member

Prebuilt versions of the plugins were included to allow people to use the plugins without having node locally.

@eoftedal

Copy link
Copy Markdown
Member

For the changes to the plugin, please explain screen shots to explain what you mean by replacing the popup with a 600x600 analyst console.

.map((r) =>
r.results
.map((dep) => {
dep.version = (dep.version.split('.').length >= 3 ? dep.version : dep.version + '.0').replace(/-/g, '.');

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why was this deleted?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are cyclonedx parsers that only support 1-3 numbers and nothing more

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I removed the transformation because it changed detected versions and mutated shared findings. Given the parser compatibility requirement, the revised fix in #625 preserves the exact existing output transformation but applies it to a report-local copy. PURLs, component references, and identity evidence use that same formatted copy. Tests cover unchanged inputs, legacy output strings, and reference consistency. This retains the existing behavior rather than introducing a new numeric-only sanitizer.

@PekSec

PekSec commented Sep 18, 2026

Copy link
Copy Markdown
Author

I split this into three independent PRs targeting master:

#624 restores complete prebuilt packages in dist/chrome, dist/chrome-no-func, and dist/firefox. Users can download/extract the repository and load them without Node. All three packages were tested from a clean checkout without dependency installation or rebuilding.

It also includes two Playwright screenshots of the actual 600×600 popup scanning Google's XSS training page with jQuery 2.1.1: the resource overview and the inspector scrolled to CVE-2020-11022. The description explains the search, settings, copying, and full-snapshot export behavior. Firefox shares the UI and was tested separately.

The focused PRs include their validation results. I am closing this combined PR as superseded so review can continue there; the original branch and discussion are preserved.

@PekSec PekSec closed this Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants