xpeditis2.0/scripts/ci/test_security_summary.py
David 5c59ef044b
Some checks failed
Dev CI / Backend — Lint (push) Successful in 1m4s
Dev CI / Security gate (push) Failing after 1m36s
Dev CI / Backend — Unit Tests (push) Successful in 1m7s
Dev CI / Frontend — Lint & Type-check (push) Successful in 1m51s
Dev CI / Frontend — Unit Tests (push) Successful in 1m22s
Dev CI / Notify Failure (push) Has been skipped
fix
2026-09-23 22:56:46 +02:00

46 lines
2.1 KiB
Python

"""Diagnostics must not leak scanner evidence or report missing audits as clean."""
import contextlib
import importlib.util
import io
import json
from pathlib import Path
import tempfile
import unittest
spec = importlib.util.spec_from_file_location(
'security_summary', Path(__file__).with_name('summarize-security.py'))
summary = importlib.util.module_from_spec(spec)
spec.loader.exec_module(summary)
class SecuritySummary(unittest.TestCase):
def test_real_findings_are_counted_without_printing_evidence(self):
with tempfile.TemporaryDirectory() as temp:
reports = Path(temp)
for project in ('root', 'backend', 'frontend', 'log-exporter'):
(reports / f'npm-audit-{project}.json').write_text(json.dumps({
'metadata': {'vulnerabilities': {'high': 2, 'critical': 1}}}))
(reports / 'source-security.json').write_text(json.dumps({'Results': [{
'Secrets': [{'Match': 'DO-NOT-PRINT', 'Code': 'PRIVATE-CODE'}],
'Misconfigurations': [{'Description': 'PRIVATE-DESCRIPTION'}]}]}))
output = io.StringIO()
with contextlib.redirect_stdout(output):
self.assertEqual(summary.summarize(reports), 0)
text = output.getvalue()
self.assertIn('2 high, 1 critical', text)
self.assertIn('1 secret findings, 1 infrastructure findings', text)
self.assertNotIn('DO-NOT-PRINT', text)
self.assertNotIn('PRIVATE-', text)
def test_missing_and_failed_audits_are_not_reported_as_clean(self):
with tempfile.TemporaryDirectory() as temp:
reports = Path(temp)
(reports / 'npm-audit-root.json').write_text('{invalid')
(reports / 'npm-audit-backend.json').write_text('{"error": {"code": "NETWORK"}}')
output = io.StringIO()
with contextlib.redirect_stdout(output):
self.assertEqual(summary.summarize(reports), 1)
self.assertIn('dependency audit unavailable', output.getvalue())
self.assertIn('Source audit unavailable', output.getvalue())
self.assertNotIn('0 high', output.getvalue())