"""Diagnostics must not leak scanner evidence or report missing audits as clean.""" import contextlib import importlib.util import io import json from pathlib import Path import tempfile import unittest spec = importlib.util.spec_from_file_location( 'security_summary', Path(__file__).with_name('summarize-security.py')) summary = importlib.util.module_from_spec(spec) spec.loader.exec_module(summary) class SecuritySummary(unittest.TestCase): def test_real_findings_are_counted_without_printing_evidence(self): with tempfile.TemporaryDirectory() as temp: reports = Path(temp) for project in ('root', 'backend', 'frontend', 'log-exporter'): (reports / f'npm-audit-{project}.json').write_text(json.dumps({ 'metadata': {'vulnerabilities': {'high': 2, 'critical': 1}}})) (reports / 'source-security.json').write_text(json.dumps({'Results': [{ 'Secrets': [{'Match': 'DO-NOT-PRINT', 'Code': 'PRIVATE-CODE'}], 'Misconfigurations': [{'Description': 'PRIVATE-DESCRIPTION'}]}]})) output = io.StringIO() with contextlib.redirect_stdout(output): self.assertEqual(summary.summarize(reports), 0) text = output.getvalue() self.assertIn('2 high, 1 critical', text) self.assertIn('1 secret findings, 1 infrastructure findings', text) self.assertNotIn('DO-NOT-PRINT', text) self.assertNotIn('PRIVATE-', text) def test_missing_and_failed_audits_are_not_reported_as_clean(self): with tempfile.TemporaryDirectory() as temp: reports = Path(temp) (reports / 'npm-audit-root.json').write_text('{invalid') (reports / 'npm-audit-backend.json').write_text('{"error": {"code": "NETWORK"}}') output = io.StringIO() with contextlib.redirect_stdout(output): self.assertEqual(summary.summarize(reports), 1) self.assertIn('dependency audit unavailable', output.getvalue()) self.assertIn('Source audit unavailable', output.getvalue()) self.assertNotIn('0 high', output.getvalue())