Some checks are pending
CD Preprod / Deploy to Preprod (push) Blocked by required conditions
CD Preprod / Notify Success (push) Blocked by required conditions
CD Preprod / Notify Failure (push) Blocked by required conditions
CD Preprod / Security gate (push) Successful in 29s
CD Preprod / Backend — Lint (push) Successful in 1m3s
CD Preprod / Frontend — Lint & Type-check (push) Successful in 1m9s
CD Preprod / Backend — Unit Tests (push) Successful in 1m5s
CD Preprod / Frontend — Unit Tests (push) Successful in 43s
CD Preprod / Backend — Integration Tests (push) Successful in 46s
CD Preprod / Build Frontend (push) Successful in 35s
CD Preprod / Build Backend (push) Successful in 1m3s
CD Preprod / Build Log Exporter (push) Successful in 34s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, backend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, frontend) (push) Successful in 25s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (amd64, log-exporter) (push) Successful in 21s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, backend) (push) Successful in 24s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, frontend) (push) Successful in 23s
CD Preprod / Image security (${{ matrix.service }}, ${{ matrix.arch }}) (arm64, log-exporter) (push) Successful in 22s
41 lines
1.8 KiB
Python
41 lines
1.8 KiB
Python
import contextlib
|
|
import importlib.util
|
|
import io
|
|
import json
|
|
from pathlib import Path
|
|
import tempfile
|
|
import unittest
|
|
|
|
spec = importlib.util.spec_from_file_location(
|
|
'image_summary', Path(__file__).with_name('summarize-image-security.py'))
|
|
summary = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(summary)
|
|
|
|
|
|
class ImageSummary(unittest.TestCase):
|
|
def test_reports_global_npm_path_and_preserves_failure(self):
|
|
with tempfile.TemporaryDirectory() as directory:
|
|
path = Path(directory) / 'image-security.json'
|
|
path.write_text(json.dumps({'Results': [{'Vulnerabilities': [{
|
|
'Severity': 'HIGH', 'VulnerabilityID': 'CVE-example',
|
|
'PkgName': 'pacote', 'InstalledVersion': '19.0.2',
|
|
'FixedVersion': '21.5.1',
|
|
'PkgPath': 'usr/local/lib/node_modules/npm/node_modules/pacote/package.json',
|
|
}]}]}))
|
|
output = io.StringIO()
|
|
with contextlib.redirect_stdout(output):
|
|
self.assertEqual(summary.summarize(path), 1)
|
|
self.assertIn('19.0.2 -> 21.5.1', output.getvalue())
|
|
self.assertIn('usr/local/lib/node_modules/npm/', output.getvalue())
|
|
|
|
def test_missing_invalid_and_clean_reports(self):
|
|
with tempfile.TemporaryDirectory() as directory:
|
|
path = Path(directory) / 'image-security.json'
|
|
with contextlib.redirect_stdout(io.StringIO()):
|
|
self.assertEqual(summary.summarize(path), 1)
|
|
for content in ('broken', '{}', '{"Results": null}'):
|
|
path.write_text(content)
|
|
self.assertEqual(summary.summarize(path), 1)
|
|
path.write_text('{"Results": []}')
|
|
self.assertEqual(summary.summarize(path), 0)
|