in src/main/java/com/amazon/inspector/jenkins/amazoninspectorbuildstep/sbomparsing/SbomOutputParser.java [27:46]
public void parseVulnCounts() {
List<Vulnerability> vulnerabilities = sbom.getSbom().getVulnerabilities();
if (vulnerabilities == null) {
return;
}
for (Vulnerability vulnerability : vulnerabilities) {
List<Rating> ratings = vulnerability.getRatings();
Severity severity = getHighestRatingFromList(ratings);
if (vulnerability.getId().contains("IN-DOCKER")) {
dockerCounts.increment(severity);
} else {
vulnCounts.increment(severity);
}
aggregateCounts.increment(severity);
}
}