@echo off setlocal enabledelayedexpansion echo ====================================================================== echo EDU-SPACE: AUTOMATED SECURITY AUDIT SUITE echo ====================================================================== echo. set ROOT_DIR=%~dp0 set VENV_PY=%ROOT_DIR%backend\venv\Scripts\python.exe set VENV_BANDIT=%ROOT_DIR%backend\venv\Scripts\bandit.exe set VENV_PIPAUDIT=%ROOT_DIR%backend\venv\Scripts\pip-audit.exe set VENV_ST=%ROOT_DIR%backend\venv\Scripts\st.exe set VENV_NJSSCAN=%ROOT_DIR%backend\venv\Scripts\njsscan.exe echo [1/5] Running Python SAST Analysis (bandit)... echo ---------------------------------------------------------------------- call "%VENV_BANDIT%" -r "%ROOT_DIR%backend\app" -ll -ii if %ERRORLEVEL% neq 0 ( echo [!] Warning: Bandit reported potential security concerns. ) else ( echo [OK] Bandit scan completed cleanly (0 Medium/High issues). ) echo. echo [2/5] Running Python SCA Dependency Audit (pip-audit)... echo ---------------------------------------------------------------------- call "%VENV_PIPAUDIT%" -s osv --progress-spinner off -r "%ROOT_DIR%backend\requirements.txt" if %ERRORLEVEL% neq 0 ( echo [!] Warning: pip-audit reported package vulnerabilities. ) else ( echo [OK] All Python dependencies are secure (0 known CVEs). ) echo. echo [3/5] Running Node.js SAST Analysis (njsscan)... echo ---------------------------------------------------------------------- call "%VENV_NJSSCAN%" "%ROOT_DIR%frontend\src" if %ERRORLEVEL% neq 0 ( echo [!] Warning: njsscan reported code smells or security concerns. ) else ( echo [OK] Node.js SAST analysis completed cleanly. ) echo. echo [4/5] Running Node.js SCA Dependency Audit (npm audit)... echo ---------------------------------------------------------------------- cd /d "%ROOT_DIR%frontend" call cmd.exe /c npm audit if %ERRORLEVEL% neq 0 ( echo [!] Warning: npm audit reported package vulnerabilities. ) else ( echo [OK] All Node.js dependencies are secure (0 vulnerabilities). ) cd /d "%ROOT_DIR%" echo. echo [5/5] Running Dynamic API Security Fuzzing (schemathesis)... echo ---------------------------------------------------------------------- echo Testing target: http://127.0.0.1:5000/api/v1/openapi.json set PYTHONUTF8=1 set PYTHONIOENCODING=utf-8 call "%VENV_ST%" run http://127.0.0.1:5000/api/v1/openapi.json --checks not_a_server_error --max-examples=10 if %ERRORLEVEL% neq 0 ( echo [!] Note: Schemathesis found potential unhandled edge cases or backend server is not running on port 5000. ) else ( echo [OK] API DAST fuzzing passed (0 unhandled 500 server errors). ) echo. echo ====================================================================== echo SECURITY AUDIT SUITE COMPLETED echo ====================================================================== pause