You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Node.js应用中集成Secvisogram CSAF验证器服务库实现JSON验证?

在Node.js中集成Secvisogram CSAF验证器实现JSON验证功能

安装依赖

首先安装官方提供的CSA验证器服务包:

npm install @secvisogram/csaf-validator-service

实现核心验证函数

下面是直接可用的验证函数,接收CSAF格式的JSON对象,返回包含验证状态和错误列表的结果,完全对齐官网JSON Editor的输出逻辑:

const { validateCsaf } = require('@secvisogram/csaf-validator-service');

async function validateCsafJson(csafJson) {
  try {
    const validationResult = await validateCsaf(csafJson);
    
    return {
      "Validate Status": validationResult.valid ? "PASS" : "FAIL",
      "Validation Errors": validationResult.errors.map(error => ({
        message: error.message,
        fieldPath: error.path,
        schemaRulePath: error.schemaPath
      }))
    };
  } catch (exception) {
    // 捕获JSON格式非法、验证服务内部错误等异常情况
    return {
      "Validate Status": "ERROR",
      "Validation Errors": [{ message: exception.message }]
    };
  }
}

使用示例

调用验证函数并处理结果:

// 替换为你的CSAF格式JSON数据
const sampleCsafData = {
  "document": {
    "title": "Sample CSAF Advisory",
    "csaf_version": "2.0",
    "category": "csaf_security_advisory",
    "publisher": {
      "name": "Example Org",
      "namespace": "https://example.org"
    },
    "tracking": {
      "id": "EXAMPLE-2024-001",
      "status": "final",
      "version": "1.0"
    }
  }
};

// 执行验证
validateCsafJson(sampleCsafData)
  .then(result => {
    console.log("验证状态:", result["Validate Status"]);
    if (result["Validation Errors"].length > 0) {
      console.log("验证错误详情:", result["Validation Errors"]);
    }
  });

功能说明

  • Validate Status 会返回三种状态:PASS(完全符合CSAF规范)、FAIL(不符合规范但格式合法)、ERROR(JSON格式非法或验证服务异常)
  • Validation Errors 中的每条错误包含错误描述、违规字段路径、对应的CSAF schema规则路径,和官网JSON Editor右下角展示的错误信息结构一致

内容的提问来源于stack exchange,提问作者santosh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 20:20:21