-
Notifications
You must be signed in to change notification settings - Fork 15
63 lines (53 loc) · 2.35 KB
/
Copy pathscanner-selftest.yml
File metadata and controls
63 lines (53 loc) · 2.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
name: scanner-selftest
# The gate that makes external rule PRs safely mergeable: installs ripgrep,
# runs the pytest suite, and validates the ruleset + a fixture scan against
# their schemas. Path-filtered to the scanner subproject.
on:
push:
branches: [main]
paths:
- 'dsgai_scanner_tool/**'
- '.github/workflows/scanner-selftest.yml'
pull_request:
paths:
- 'dsgai_scanner_tool/**'
- '.github/workflows/scanner-selftest.yml'
permissions:
contents: read
jobs:
selftest:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: '3.11'
- name: Install ripgrep (with PCRE2)
run: sudo apt-get update -qq && sudo apt-get install -y ripgrep
- name: Install dev dependencies
run: python -m pip install --quiet -r dsgai_scanner_tool/requirements-dev.txt
- name: Validate ruleset against its schema
run: |
python -c "import yaml, json, jsonschema; \
jsonschema.validate(yaml.safe_load(open('dsgai_scanner_tool/rules/dsgai-rules.yaml')), \
json.load(open('dsgai_scanner_tool/rules/rules.schema.json'))); \
print('ruleset schema OK')"
- name: Assert compiled JSON is in sync with YAML
run: python dsgai_scanner_tool/build/build_rules_json.py --check
- name: Run the self-test suite
working-directory: dsgai_scanner_tool
run: python -m pytest tests/test_runner.py -q
- name: Validate a fixture scan against the checkpoint + SARIF schemas
working-directory: dsgai_scanner_tool
run: |
python cli/dsgai_scan.py scan tests/fixtures/vulnerable-app \
--json-out /tmp/DSGAI-scan.json --sarif /tmp/scan.sarif --format none || true
python -c "import json, jsonschema; \
jsonschema.validate(json.load(open('/tmp/DSGAI-scan.json')), \
json.load(open('schemas/dsgai-scan.schema.json'))); \
print('checkpoint schema OK')"
python -c "import json; s=json.load(open('/tmp/scan.sarif')); \
assert s['version']=='2.1.0' and s['runs'][0]['tool']['driver']['name']=='dsgai-scan'; \
print('SARIF OK')"