diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_common/helper/Tool.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_common/helper/Tool.java index 135fd8676e8..b6f7aa99961 100644 --- a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_common/helper/Tool.java +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_common/helper/Tool.java @@ -30,7 +30,8 @@ public enum Tool { BUGTRACKER_UTILITY(new ToolHelperBugTrackerUtility(), "bugtracker-utility", "fbtu"), VULN_EXPORTER(new ToolHelperVulnExporter(), "vuln-exporter", "fve"), DEBRICKED_CLI(new ToolHelperDebrickedCli(), "debricked-cli", "dcli"), - SOURCE_ANALYZER(new ToolHelperSourceAnalyzer(), "sourceanalyzer"); + SOURCE_ANALYZER(new ToolHelperSourceAnalyzer(), "sourceanalyzer"), + FORTIFY_AGENTIC_ANALYZER(new ToolHelperFortifyAgenticAnalyzer(), "fortifyaa", "faa"); private static final Map TOOL_NAME_MAP = new HashMap<>(); private static final Map TOOL_ALIAS_MAP = new HashMap<>(); @@ -271,4 +272,31 @@ public boolean requiresToolDefinitions() { return false; } } + + /** + * Helper implementation for fortify agentic analyzer (faa) tool. + */ + private static final class ToolHelperFortifyAgenticAnalyzer implements IToolHelper { + private static final String TOOL_NAME = "fortify-agentic-analyzer"; + + @Override + public String getToolName() { + return TOOL_NAME; + } + + @Override + public String getDefaultBinaryName() { + return PlatformHelper.isWindows() ? "fortifyaa.exe" : "fortifyaa"; + } + + @Override + public String getDefaultEnvPrefix() { + return "FORTIFY_AGENTIC_ANALYZER"; + } + + @Override + public boolean requiresToolDefinitions() { + return false; + } + } } diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_main/cli/cmd/ToolCommands.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_main/cli/cmd/ToolCommands.java index 7e09030e55d..2a4e4ce46dc 100644 --- a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_main/cli/cmd/ToolCommands.java +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/_main/cli/cmd/ToolCommands.java @@ -20,6 +20,7 @@ import com.fortify.cli.tool.debricked_cli.cli.cmd.ToolDebrickedCliCommands; import com.fortify.cli.tool.definitions.cli.cmd.ToolDefinitionsCommands; import com.fortify.cli.tool.env.cli.cmd.ToolEnvCommands; +import com.fortify.cli.tool.faa.cli.cmd.ToolFortifyAgenticAnalyzer; import com.fortify.cli.tool.fcli.cli.cmd.ToolFcliCommands; import com.fortify.cli.tool.fod_uploader.cli.cmd.ToolFoDUploaderCommands; import com.fortify.cli.tool.sc_client.cli.cmd.ToolSCClientCommands; @@ -38,9 +39,10 @@ ToolDebrickedCliCommands.class, ToolFcliCommands.class, ToolFoDUploaderCommands.class, + ToolFortifyAgenticAnalyzer.class, ToolSCClientCommands.class, ToolSourceAnalyzerCommands.class, - ToolVulnExporterCommands.class, + ToolVulnExporterCommands.class, ToolDefinitionsCommands.class } ) diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzer.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzer.java new file mode 100644 index 00000000000..8812aca72b8 --- /dev/null +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzer.java @@ -0,0 +1,38 @@ +/* + * Copyright 2021-2026 Open Text. + * + * The only warranties for products and services of Open Text + * and its affiliates and licensors ("Open Text") are as may + * be set forth in the express warranty statements accompanying + * such products and services. Nothing herein should be construed + * as constituting an additional warranty. Open Text shall not be + * liable for technical or editorial errors or omissions contained + * herein. The information contained herein is subject to change + * without notice. + */ +package com.fortify.cli.tool.faa.cli.cmd; + +import com.fortify.cli.common.cli.cmd.AbstractContainerCommand; + +import picocli.CommandLine.Command; + +/** + * Container command for all 'fcli tool fortify-agentic-analyzer' subcommands. + * + * @author Sangamesh Vijaykumar +*/ +@Command( + name = ToolFortifyAgenticAnalyzer.TOOL_NAME, + aliases = {"faa"}, + subcommands = { + ToolFortifyAgenticAnalyzerListCommand.class, + ToolFortifyAgenticAnalyzerGetCommand.class, + ToolFortifyAgenticAnalyzerRegisterCommand.class, + ToolFortifyAgenticAnalyzerRunCommand.class + } +) +public class ToolFortifyAgenticAnalyzer extends AbstractContainerCommand { + static final String TOOL_NAME = "fortifyaa"; + static final String[] TOOL_ENV_VAR_PREFIXES = {"FORTIFYAA"}; + +} diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerGetCommand.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerGetCommand.java new file mode 100644 index 00000000000..55d6e22242e --- /dev/null +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerGetCommand.java @@ -0,0 +1,35 @@ +/* + * Copyright 2021-2026 Open Text. + * + * The only warranties for products and services of Open Text + * and its affiliates and licensors ("Open Text") are as may + * be set forth in the express warranty statements accompanying + * such products and services. Nothing herein should be construed + * as constituting an additional warranty. Open Text shall not be + * liable for technical or editorial errors or omissions contained + * herein. The information contained herein is subject to change + * without notice. + */ +package com.fortify.cli.tool.faa.cli.cmd; + +import com.fortify.cli.common.output.cli.mixin.OutputHelperMixins; +import com.fortify.cli.tool._common.cli.cmd.AbstractToolGetCommand; +import com.fortify.cli.tool._common.helper.Tool; + +import lombok.Getter; +import picocli.CommandLine.Command; +import picocli.CommandLine.Mixin; + +/** + * Get command for the Fortify Agentic Analyzer tool. + * @author Sangamesh Vijaykumar + */ +@Command(name = OutputHelperMixins.Get.CMD_NAME) +public class ToolFortifyAgenticAnalyzerGetCommand extends AbstractToolGetCommand{ + @Getter @Mixin private OutputHelperMixins.Get outputHelper; + + @Override + protected final Tool getTool() { + return Tool.FORTIFY_AGENTIC_ANALYZER; + } +} diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerListCommand.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerListCommand.java new file mode 100644 index 00000000000..4b352ca1163 --- /dev/null +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerListCommand.java @@ -0,0 +1,37 @@ +/* + * Copyright 2021-2026 Open Text. + * + * The only warranties for products and services of Open Text + * and its affiliates and licensors ("Open Text") are as may + * be set forth in the express warranty statements accompanying + * such products and services. Nothing herein should be construed + * as constituting an additional warranty. Open Text shall not be + * liable for technical or editorial errors or omissions contained + * herein. The information contained herein is subject to change + * without notice. + */ +package com.fortify.cli.tool.faa.cli.cmd; + +import com.fortify.cli.common.output.cli.mixin.OutputHelperMixins; +import com.fortify.cli.tool._common.cli.cmd.AbstractToolListCommand; +import com.fortify.cli.tool._common.helper.Tool; + +import lombok.Getter; +import picocli.CommandLine.Command; +import picocli.CommandLine.Mixin; + +/** + * List command for the Fortify Agentic Analyzer tool. + * + * @author Sangamesh Vijaykumar + */ +@Command(name = OutputHelperMixins.List.CMD_NAME) +public class ToolFortifyAgenticAnalyzerListCommand extends AbstractToolListCommand{ + @Getter @Mixin private OutputHelperMixins.List outputHelper; + + @Override + protected Tool getTool() { + return Tool.FORTIFY_AGENTIC_ANALYZER; + } + +} diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRegisterCommand.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRegisterCommand.java new file mode 100644 index 00000000000..ae19c875f70 --- /dev/null +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRegisterCommand.java @@ -0,0 +1,50 @@ +/* + * Copyright 2021-2026 Open Text. + * + * The only warranties for products and services of Open Text + * and its affiliates and licensors ("Open Text") are as may + * be set forth in the express warranty statements accompanying + * such products and services. Nothing herein should be construed + * as constituting an additional warranty. Open Text shall not be + * liable for technical or editorial errors or omissions contained + * herein. The information contained herein is subject to change + * without notice. + */ +package com.fortify.cli.tool.faa.cli.cmd; + +import java.io.File; + +import com.fortify.cli.tool._common.cli.cmd.AbstractToolRegisterCommand; +import com.fortify.cli.tool._common.helper.Tool; +import com.fortify.cli.tool._common.helper.ToolVersionDetector; + +import picocli.CommandLine.Command; + +/** + * Register command for the Fortify Agentic Analyzer tool. + * + * @author Sangamesh Vijaykumar + */ +@Command(name = "register") +public class ToolFortifyAgenticAnalyzerRegisterCommand extends AbstractToolRegisterCommand{ + + @Override + protected Tool getTool() { + return Tool.FORTIFY_AGENTIC_ANALYZER; + } + + @Override + protected String detectVersion(File toolBinary, File installDir) { + // Execute fortifyaa to detect its version + String output = ToolVersionDetector.tryExecute(toolBinary, ""); + if (output != null) { + String version = ToolVersionDetector.extractVersionFromOutput(output); + if (version != null) { + return version; + } + } + + return "unknown"; + } + +} diff --git a/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRunCommand.java b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRunCommand.java new file mode 100644 index 00000000000..e76dee1bff7 --- /dev/null +++ b/fcli-core/fcli-tool/src/main/java/com/fortify/cli/tool/faa/cli/cmd/ToolFortifyAgenticAnalyzerRunCommand.java @@ -0,0 +1,32 @@ +/* + * Copyright 2021-2026 Open Text. + * + * The only warranties for products and services of Open Text + * and its affiliates and licensors ("Open Text") are as may + * be set forth in the express warranty statements accompanying + * such products and services. Nothing herein should be construed + * as constituting an additional warranty. Open Text shall not be + * liable for technical or editorial errors or omissions contained + * herein. The information contained herein is subject to change + * without notice. + */ +package com.fortify.cli.tool.faa.cli.cmd; +import com.fortify.cli.tool._common.cli.cmd.AbstractToolRunCommand; +import com.fortify.cli.tool._common.helper.Tool; + +import picocli.CommandLine.Command; + +/** + * Run command for the Fortify Agentic Analyzer tool. + * + * @author Sangamesh Vijaykumar + */ +@Command(name = "run") +public class ToolFortifyAgenticAnalyzerRunCommand extends AbstractToolRunCommand { + + @Override + protected Tool getTool() { + return Tool.FORTIFY_AGENTIC_ANALYZER; + } + +} diff --git a/fcli-core/fcli-tool/src/main/resources/com/fortify/cli/tool/i18n/ToolMessages.properties b/fcli-core/fcli-tool/src/main/resources/com/fortify/cli/tool/i18n/ToolMessages.properties index b85b07462f3..229f5968908 100644 --- a/fcli-core/fcli-tool/src/main/resources/com/fortify/cli/tool/i18n/ToolMessages.properties +++ b/fcli-core/fcli-tool/src/main/resources/com/fortify/cli/tool/i18n/ToolMessages.properties @@ -481,6 +481,27 @@ fcli.tool.sourceanalyzer.run.usage.description = This command allows for running fcli.tool.sourceanalyzer.update-rules.usage.header = Update OpenText SAST rulepacks. fcli.tool.sourceanalyzer.update-rules.usage.description = This command runs the fortifyupdate utility from the registered OpenText SAST installation to update local rulepacks. \ Ensure that the installation has network access to your OpenText update server or that it is otherwise configured for offline updates. + +# fcli tool fortify-agentic-analyzer (faa) +fcli.tool.fortify-agentic-analyzer.usage.header = Manage Fortify Agentic Analyzer registrations. +fcli.tool.fortify-agentic-analyzer.usage.description = This command allows for performing various operations related to Fortify Agentic Analyzer, such as listing available versions, registering installations, and running the tool. +fcli.tool.fortify-agentic-analyzer.list.usage.header = List available and installed Fortify Agentic Analyzer versions. +fcli.tool.fortify-agentic-analyzer.list.usage.description = List available and installed Fortify Agentic Analyzer versions. +fcli.tool.fortify-agentic-analyzer.get.usage.header = Get information about a specific Fortify Agentic Analyzer version. +fcli.tool.fortify-agentic-analyzer.get.usage.description = This command retrieves detailed information about a specific Fortify Agentic Analyzer version, \ + including available platforms and installation status. +fcli.tool.fortify-agentic-analyzer.register.usage.header = Register an external Fortify Agentic Analyzer installation. +fcli.tool.fortify-agentic-analyzer.register.usage.description.0 = ${fcli.tool.register.generic-description} +fcli.tool.fortify-agentic-analyzer.register.usage.description.1 = Examples:\n\ + \ --path /opt/fortify/tools/fortifyaa\n\ + \ --path $FORTIFY_AGENTIC_ANALYZER_HOME\n\ + \ --path $PATH\n\ + \ --path $FORTIFY_AGENTIC_ANALYZER_HOME:$PATH\n + +fcli.tool.fortify-agentic-analyzer.run.usage.header = Run Fortify Agentic Analyzer. +fcli.tool.fortify-agentic-analyzer.run.usage.description = This command allows for running Fortify Agentic Analyzer as already installed in the user's machine. It is recommended to use double dashes to separate \ + fcli options from Fortify Agentic Analyzer options, i.e., 'fcli tool fortify-agentic-analyzer run -- ' \ + to explicitly differentiate between fcli options and Fortify Agentic Analyzer options. ################################################################################################################# # The following are technical properties that shouldn't be internationalized #################################### #################################################################################################################