Move the code and terraform audits into the reviews plugin
Copy the standalone code-review and terraform-review skills into
plugins/reviews as audit-code and audit-terraform. The rename separates the
automated, linter-driven audits from the guided review-pr walkthrough that
already lived here.
Resolve bundled script paths through ${SKILL_DIR}, exported in a new step 0.
CLAUDE_PLUGIN_ROOT is not set in the Bash tool environment, so the obvious
substitution would have expanded to nothing and broken every collection
script invocation.
Replace the PLAN and DESIGN docs with READMEs written from the current
SKILL.md and scripts. The old docs had drifted badly: they named semgrep
where the code calls opengrep, scoped five review agents where there are
now eight, and predated Lua, PowerShell, and GitHub Actions support.
Add CONSISTENCY_NORMS to the audit-terraform agent inputs. The collection
script writes consistency_norms.json and the agent prompt declares it, but
SKILL.md never listed it, leaving the variable unsubstituted.
Drop the --ingest-verdicts instruction from both skills. review_stats.py
parses no arguments, so the ref-mode verdict template it told users to feed
back could never be read.
Point audit-terraform's smoke test at README.md and resolve its fixture
paths relative to the test file rather than an absolute home directory.
Tests: 197 passing (audit-code), 106 passing (audit-terraform).
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
"""Adapter: actionlint -format '{{json .}}' normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_actionlint_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for item in payload:
|
||||
line = item.get("line", 0)
|
||||
out.append(Finding(
|
||||
tool="actionlint",
|
||||
rule_id=item.get("kind", "unknown"),
|
||||
severity="high",
|
||||
file=item.get("filepath", ""),
|
||||
line=line,
|
||||
end_line=line,
|
||||
message=item.get("message", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,29 @@
|
||||
"""Adapter: bandit -f json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_SEVERITY = {"HIGH": "high", "MEDIUM": "medium", "LOW": "low"}
|
||||
|
||||
|
||||
def parse_bandit_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for result in payload.get("results", []):
|
||||
line_range = result.get("line_range") or [result.get("line_number"), result.get("line_number")]
|
||||
out.append(Finding(
|
||||
tool="bandit",
|
||||
rule_id=result.get("test_id", ""),
|
||||
severity=_SEVERITY.get(result.get("issue_severity", ""), "medium"),
|
||||
file=result.get("filename", ""),
|
||||
line=line_range[0],
|
||||
end_line=line_range[-1],
|
||||
message=result.get("issue_text", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,51 @@
|
||||
"""Adapter: dotnet build text output normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_LINE_RE = re.compile(
|
||||
r"^(?P<file>[^(]+)\((?P<line>\d+),\d+\):\s*"
|
||||
r"(?P<severity>error|warning)\s+"
|
||||
r"(?P<code>[A-Z]+\d+):\s*"
|
||||
r"(?P<message>.+?)\s*"
|
||||
r"(?:\[[^\]]+\])?\s*$"
|
||||
)
|
||||
|
||||
|
||||
def _severity(code: str, severity_word: str) -> str:
|
||||
if code.startswith("SCS"):
|
||||
return "high"
|
||||
if severity_word == "error":
|
||||
return "medium"
|
||||
return "low"
|
||||
|
||||
|
||||
def parse_dotnet_build_output(stdout: str, repo_root: str) -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
seen: set[tuple[str, int, str]] = set()
|
||||
for raw in stdout.splitlines():
|
||||
m = _LINE_RE.match(raw)
|
||||
if not m:
|
||||
continue
|
||||
file_abs = m.group("file")
|
||||
rel = os.path.relpath(file_abs, repo_root) if file_abs.startswith(repo_root) else file_abs
|
||||
code = m.group("code")
|
||||
line = int(m.group("line"))
|
||||
key = (rel, line, code)
|
||||
if key in seen:
|
||||
continue
|
||||
seen.add(key)
|
||||
out.append(Finding(
|
||||
tool="dotnet",
|
||||
rule_id=code,
|
||||
severity=_severity(code, m.group("severity")),
|
||||
file=rel,
|
||||
line=line,
|
||||
end_line=line,
|
||||
message=m.group("message"),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,40 @@
|
||||
"""Adapter: eslint -f json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def _severity(rule_id: str, sev_num: int) -> str:
|
||||
if rule_id and "security" in rule_id:
|
||||
return "high"
|
||||
if sev_num == 2:
|
||||
return "medium"
|
||||
return "low"
|
||||
|
||||
|
||||
def parse_eslint_output(stdout: str, repo_root: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for entry in payload:
|
||||
file_path = entry.get("filePath", "")
|
||||
rel = os.path.relpath(file_path, repo_root) if file_path.startswith(repo_root) else file_path
|
||||
for msg in entry.get("messages", []):
|
||||
rule_id = msg.get("ruleId") or ""
|
||||
out.append(Finding(
|
||||
tool="eslint",
|
||||
rule_id=rule_id,
|
||||
severity=_severity(rule_id, msg.get("severity", 1)),
|
||||
file=rel,
|
||||
line=msg.get("line", 0),
|
||||
end_line=msg.get("endLine", msg.get("line", 0)),
|
||||
message=msg.get("message", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,27 @@
|
||||
"""Adapter: gitleaks --report-format json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_gitleaks_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for r in payload:
|
||||
out.append(Finding(
|
||||
tool="gitleaks",
|
||||
rule_id=r.get("RuleID", ""),
|
||||
severity="critical",
|
||||
file=r.get("File", ""),
|
||||
line=r.get("StartLine", 0),
|
||||
end_line=r.get("EndLine", r.get("StartLine", 0)),
|
||||
message=r.get("Description", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,41 @@
|
||||
"""Adapter: interrogate --quiet --output-format=json output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_interrogate_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, dict):
|
||||
return []
|
||||
files = payload.get("files")
|
||||
if not isinstance(files, dict):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for file_path, file_data in files.items():
|
||||
if not isinstance(file_data, dict):
|
||||
continue
|
||||
for entry in file_data.get("missing", []):
|
||||
if entry.get("private"):
|
||||
continue
|
||||
full_name = entry.get("name", "")
|
||||
symbol = full_name.split(":", 1)[-1] if ":" in full_name else full_name
|
||||
if symbol.startswith("_"):
|
||||
continue
|
||||
kind = entry.get("type", "symbol")
|
||||
line = entry.get("lineno", 0)
|
||||
out.append(Finding(
|
||||
tool="interrogate",
|
||||
rule_id="interrogate:missing-docstring",
|
||||
severity="low",
|
||||
file=file_path,
|
||||
line=line,
|
||||
end_line=line,
|
||||
message=f"missing docstring for public {kind} {symbol}",
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,34 @@
|
||||
"""Adapter: jscpd JSON output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_jscpd_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, dict):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for dup in payload.get("duplicates", []):
|
||||
first = dup.get("firstFile", {})
|
||||
second = dup.get("secondFile", {})
|
||||
lines = dup.get("lines", 0)
|
||||
severity = "medium" if lines >= 30 else "low"
|
||||
out.append(Finding(
|
||||
tool="jscpd",
|
||||
rule_id=f"jscpd:clone-{lines}lines",
|
||||
severity=severity,
|
||||
file=first.get("name", ""),
|
||||
line=first.get("start", 0),
|
||||
end_line=first.get("end", 0),
|
||||
message=(
|
||||
f"duplicate of {second.get('name', '')}:"
|
||||
f"{second.get('start', 0)}-{second.get('end', 0)} ({lines} lines)"
|
||||
),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,31 @@
|
||||
"""Adapter: knip --reporter json output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_knip_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, dict):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for issue in payload.get("issues", []):
|
||||
file_path = issue.get("file", "")
|
||||
for export in issue.get("exports", []):
|
||||
name = export.get("name", "")
|
||||
line = export.get("line", 0)
|
||||
out.append(Finding(
|
||||
tool="knip",
|
||||
rule_id="knip:dead-export",
|
||||
severity="medium",
|
||||
file=file_path,
|
||||
line=line,
|
||||
end_line=line,
|
||||
message=f"unused export '{name}'",
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,46 @@
|
||||
"""Adapter: lizard --csv output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def _severity_for_ccn(ccn: int) -> str | None:
|
||||
if ccn >= 20:
|
||||
return "high"
|
||||
if ccn >= 10:
|
||||
return "medium"
|
||||
return None
|
||||
|
||||
|
||||
def parse_lizard_output(stdout: str) -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
for raw in stdout.splitlines():
|
||||
parts = raw.strip().split(",")
|
||||
if len(parts) < 6:
|
||||
continue
|
||||
try:
|
||||
ccn = int(parts[1])
|
||||
except ValueError:
|
||||
continue
|
||||
severity = _severity_for_ccn(ccn)
|
||||
if severity is None:
|
||||
continue
|
||||
location = parts[5]
|
||||
loc_parts = location.split("@")
|
||||
if len(loc_parts) < 3:
|
||||
continue
|
||||
name, line_str, file_path = loc_parts[0], loc_parts[1], loc_parts[2]
|
||||
try:
|
||||
line = int(line_str)
|
||||
except ValueError:
|
||||
continue
|
||||
out.append(Finding(
|
||||
tool="lizard",
|
||||
rule_id=f"lizard:ccn={ccn}",
|
||||
severity=severity,
|
||||
file=file_path,
|
||||
line=line,
|
||||
end_line=line,
|
||||
message=f"function {name} has CCN {ccn}",
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,32 @@
|
||||
"""Adapter: luac -p stderr normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_PATTERN = re.compile(r"^luac:\s+(.+?):(\d+):\s+(.+)$")
|
||||
|
||||
|
||||
def parse_luac_output(stderr: str, repo_root: str = "") -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
prefix = repo_root.rstrip("/") + "/" if repo_root else ""
|
||||
for line in stderr.splitlines():
|
||||
m = _PATTERN.match(line.strip())
|
||||
if not m:
|
||||
continue
|
||||
filepath, lineno_str, message = m.group(1), m.group(2), m.group(3)
|
||||
if prefix and filepath.startswith(prefix):
|
||||
filepath = filepath[len(prefix):]
|
||||
lineno = int(lineno_str)
|
||||
out.append(Finding(
|
||||
tool="luac",
|
||||
rule_id="syntax-error",
|
||||
severity="critical",
|
||||
file=filepath,
|
||||
line=lineno,
|
||||
end_line=lineno,
|
||||
message=message,
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,37 @@
|
||||
"""Adapter: mypy text output normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_LINE_RE = re.compile(
|
||||
r"^(?P<file>[^:]+):(?P<line>\d+):\s*"
|
||||
r"(?P<severity>error|warning|note):\s*"
|
||||
r"(?P<message>.+?)"
|
||||
r"(?:\s+\[(?P<code>[a-z\-]+)\])?\s*$"
|
||||
)
|
||||
|
||||
_SEVERITY = {"error": "medium", "warning": "low", "note": None}
|
||||
|
||||
|
||||
def parse_mypy_output(stdout: str) -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
for raw in stdout.splitlines():
|
||||
m = _LINE_RE.match(raw)
|
||||
if not m:
|
||||
continue
|
||||
sev = _SEVERITY.get(m.group("severity"))
|
||||
if sev is None:
|
||||
continue
|
||||
out.append(Finding(
|
||||
tool="mypy",
|
||||
rule_id=m.group("code") or "",
|
||||
severity=sev,
|
||||
file=m.group("file"),
|
||||
line=int(m.group("line")),
|
||||
end_line=int(m.group("line")),
|
||||
message=m.group("message"),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,51 @@
|
||||
"""Adapter: opengrep --json normalized to Finding[]. Same JSON schema as semgrep (opengrep is a semgrep fork)."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_SEVERITY = {"ERROR": "high", "WARNING": "medium", "INFO": "low"}
|
||||
_CWE_RE = re.compile(r"(CWE-\d+)")
|
||||
_LOCAL_RULES_MARKER = "scripts.rules."
|
||||
|
||||
|
||||
def _clean_rule_id(check_id: str) -> str:
|
||||
if _LOCAL_RULES_MARKER in check_id:
|
||||
return check_id.rsplit(_LOCAL_RULES_MARKER, 1)[-1]
|
||||
return check_id
|
||||
|
||||
|
||||
def _cwe(meta: dict) -> str | None:
|
||||
raw = meta.get("cwe")
|
||||
if isinstance(raw, list) and raw:
|
||||
m = _CWE_RE.search(str(raw[0]))
|
||||
return m.group(1) if m else None
|
||||
if isinstance(raw, str):
|
||||
m = _CWE_RE.search(raw)
|
||||
return m.group(1) if m else None
|
||||
return None
|
||||
|
||||
|
||||
def parse_opengrep_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for r in payload.get("results", []):
|
||||
extra = r.get("extra", {})
|
||||
metadata = extra.get("metadata", {})
|
||||
out.append(Finding(
|
||||
tool="opengrep",
|
||||
rule_id=_clean_rule_id(r.get("check_id", "")),
|
||||
severity=_SEVERITY.get(extra.get("severity", ""), "medium"),
|
||||
file=r.get("path", ""),
|
||||
line=r.get("start", {}).get("line", 0),
|
||||
end_line=r.get("end", {}).get("line", r.get("start", {}).get("line", 0)),
|
||||
message=extra.get("message", ""),
|
||||
cwe=_cwe(metadata),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,31 @@
|
||||
"""Adapter: osv-scanner --format json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_osv_scanner_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for r in payload.get("results", []):
|
||||
manifest_path = r.get("source", {}).get("path", "")
|
||||
for pkg in r.get("packages", []):
|
||||
p = pkg.get("package", {})
|
||||
name = p.get("name", "")
|
||||
version = p.get("version", "")
|
||||
for v in pkg.get("vulnerabilities", []):
|
||||
out.append(Finding(
|
||||
tool="osv-scanner",
|
||||
rule_id=v.get("id", ""),
|
||||
severity="high",
|
||||
file=manifest_path,
|
||||
line=1,
|
||||
end_line=1,
|
||||
message=f"{name} {version}: {v.get('summary', '')}",
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,35 @@
|
||||
"""Adapter: pip-audit -f json normalized to Finding[].
|
||||
|
||||
Findings are attached to the dependency manifest file rather than a source
|
||||
file, since the vulnerability is in a pinned dep, not in code.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def parse_pip_audit_output(stdout: str, manifest_path: str = "requirements.txt") -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for dep in payload.get("dependencies", []):
|
||||
name = dep.get("name", "")
|
||||
version = dep.get("version", "")
|
||||
for v in dep.get("vulns", []):
|
||||
fix = v.get("fix_versions") or []
|
||||
fix_str = ", ".join(fix) if fix else None
|
||||
out.append(Finding(
|
||||
tool="pip-audit",
|
||||
rule_id=v.get("id", ""),
|
||||
severity="high",
|
||||
file=manifest_path,
|
||||
line=1,
|
||||
end_line=1,
|
||||
message=f"{name} {version}: {v.get('description', '')}",
|
||||
fix_suggestion=f"upgrade to {fix_str}" if fix_str else None,
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,56 @@
|
||||
"""Adapter: Invoke-ScriptAnalyzer JSON normalized to Finding[].
|
||||
|
||||
Shared by both PowerShell tools — PSScriptAnalyzer's built-in rules and the
|
||||
InjectionHunter custom rule pack — because both are Invoke-ScriptAnalyzer runs
|
||||
and emit the same DiagnosticRecord shape.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_SEVERITY = {
|
||||
"ParseError": "critical",
|
||||
"Error": "high",
|
||||
"Warning": "medium",
|
||||
"Information": "low",
|
||||
}
|
||||
|
||||
_INJECTION_FLOOR = "high"
|
||||
|
||||
|
||||
def parse_psscriptanalyzer_output(
|
||||
stdout: str, repo_root: str, tool: str = "psscriptanalyzer",
|
||||
) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if isinstance(payload, dict):
|
||||
payload = [payload]
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
|
||||
out: list[Finding] = []
|
||||
for item in payload:
|
||||
if not isinstance(item, dict):
|
||||
continue
|
||||
path = item.get("ScriptPath") or item.get("ScriptName") or ""
|
||||
rel = os.path.relpath(path, repo_root) if path.startswith(repo_root) else path
|
||||
line = item.get("Line") or 0
|
||||
severity = _SEVERITY.get(item.get("Severity", ""), "medium")
|
||||
if tool == "injectionhunter":
|
||||
severity = _INJECTION_FLOOR
|
||||
out.append(Finding(
|
||||
tool=tool,
|
||||
rule_id=item.get("RuleName", "unknown"),
|
||||
severity=severity,
|
||||
file=rel,
|
||||
line=line,
|
||||
end_line=item.get("EndLine") or line,
|
||||
message=item.get("Message", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,46 @@
|
||||
"""Adapter: radon cc -j JSON output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def _severity_for_complexity(cc: int) -> str | None:
|
||||
if cc >= 20:
|
||||
return "high"
|
||||
if cc >= 10:
|
||||
return "medium"
|
||||
return None
|
||||
|
||||
|
||||
def parse_radon_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, dict):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for file_path, items in payload.items():
|
||||
if not isinstance(items, list):
|
||||
continue
|
||||
for item in items:
|
||||
cc = item.get("complexity", 0)
|
||||
severity = _severity_for_complexity(cc)
|
||||
if severity is None:
|
||||
continue
|
||||
line = item.get("lineno", 0)
|
||||
end_line = item.get("endline", line)
|
||||
name = item.get("name", "?")
|
||||
kind = item.get("type", "function")
|
||||
out.append(Finding(
|
||||
tool="radon",
|
||||
rule_id=f"radon:cc={cc}",
|
||||
severity=severity,
|
||||
file=file_path,
|
||||
line=line,
|
||||
end_line=end_line,
|
||||
message=f"high cyclomatic complexity (CCN={cc}) in {kind} {name}",
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,40 @@
|
||||
"""Adapter: ruff check --output-format=json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def _severity_for_rule(code: str) -> str:
|
||||
if not code:
|
||||
return "low"
|
||||
if code.startswith("S"):
|
||||
return "high"
|
||||
if code.startswith("B"):
|
||||
return "medium"
|
||||
return "low"
|
||||
|
||||
|
||||
def parse_ruff_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for item in payload:
|
||||
loc = item.get("location") or {}
|
||||
end = item.get("end_location") or loc
|
||||
code = item.get("code", "")
|
||||
out.append(Finding(
|
||||
tool="ruff",
|
||||
rule_id=code,
|
||||
severity=_severity_for_rule(code),
|
||||
file=item.get("filename", ""),
|
||||
line=loc.get("row", 0),
|
||||
end_line=end.get("row", loc.get("row", 0)),
|
||||
message=item.get("message", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,38 @@
|
||||
"""Adapter: ruff check with idiom/simplification selectors → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
def _severity_for_idiom_rule(code: str) -> str:
|
||||
if not code:
|
||||
return "low"
|
||||
if code.startswith(("PLR", "C90", "B")):
|
||||
return "medium"
|
||||
return "low"
|
||||
|
||||
|
||||
def parse_ruff_idiom_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for item in payload:
|
||||
loc = item.get("location") or {}
|
||||
end = item.get("end_location") or loc
|
||||
code = item.get("code", "")
|
||||
out.append(Finding(
|
||||
tool="ruff-idiom",
|
||||
rule_id=code,
|
||||
severity=_severity_for_idiom_rule(code),
|
||||
file=item.get("filename", ""),
|
||||
line=loc.get("row", 0),
|
||||
end_line=end.get("row", loc.get("row", 0)),
|
||||
message=item.get("message", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,34 @@
|
||||
"""Adapter: selene --display-style=json normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_SEVERITY = {"Error": "high", "Warning": "medium", "Note": "low"}
|
||||
|
||||
|
||||
def parse_selene_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
if not isinstance(payload, list):
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for item in payload:
|
||||
code = item.get("code", {})
|
||||
span = item.get("span", {})
|
||||
start = span.get("start", {})
|
||||
end_span = span.get("end", {})
|
||||
out.append(Finding(
|
||||
tool="selene",
|
||||
rule_id=code.get("name", "unknown"),
|
||||
severity=_SEVERITY.get(code.get("severity", ""), "medium"),
|
||||
file=item.get("filename", ""),
|
||||
line=start.get("line", 0),
|
||||
end_line=end_span.get("line", start.get("line", 0)),
|
||||
message=item.get("primary_label", ""),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,33 @@
|
||||
"""Adapter: tsc --noEmit text output normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_LINE_RE = re.compile(
|
||||
r"^(?P<file>[^(]+)\((?P<line>\d+),\d+\):\s*"
|
||||
r"(?P<severity>error|warning)\s+"
|
||||
r"(?P<code>TS\d+):\s*"
|
||||
r"(?P<message>.+?)\s*$"
|
||||
)
|
||||
|
||||
|
||||
def parse_tsc_output(stdout: str) -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
for raw in stdout.splitlines():
|
||||
m = _LINE_RE.match(raw)
|
||||
if not m:
|
||||
continue
|
||||
sev = "medium" if m.group("severity") == "error" else "low"
|
||||
out.append(Finding(
|
||||
tool="tsc",
|
||||
rule_id=m.group("code"),
|
||||
severity=sev,
|
||||
file=m.group("file"),
|
||||
line=int(m.group("line")),
|
||||
end_line=int(m.group("line")),
|
||||
message=m.group("message"),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,31 @@
|
||||
"""Adapter: vulture text output → Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_LINE_RE = re.compile(
|
||||
r"^(?P<file>[^:]+):(?P<line>\d+):\s*(?P<msg>.+?)\s*\((?P<conf>\d+)%\s*confidence\)$"
|
||||
)
|
||||
|
||||
|
||||
def parse_vulture_output(stdout: str) -> list[Finding]:
|
||||
out: list[Finding] = []
|
||||
for raw in stdout.splitlines():
|
||||
m = _LINE_RE.match(raw.strip())
|
||||
if not m:
|
||||
continue
|
||||
conf = int(m.group("conf"))
|
||||
severity = "medium" if conf >= 80 else "low"
|
||||
out.append(Finding(
|
||||
tool="vulture",
|
||||
rule_id=f"vulture:{conf}pct",
|
||||
severity=severity,
|
||||
file=m.group("file"),
|
||||
line=int(m.group("line")),
|
||||
end_line=int(m.group("line")),
|
||||
message=m.group("msg"),
|
||||
))
|
||||
return out
|
||||
@@ -0,0 +1,48 @@
|
||||
"""Adapter: zizmor --format sarif normalized to Finding[]."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import re
|
||||
|
||||
from scripts.manifest import Finding
|
||||
|
||||
|
||||
_LEVEL = {"error": "high", "warning": "medium", "note": "low"}
|
||||
_CWE_RE = re.compile(r"(CWE-\d+)")
|
||||
|
||||
|
||||
def parse_zizmor_output(stdout: str) -> list[Finding]:
|
||||
try:
|
||||
payload = json.loads(stdout)
|
||||
except json.JSONDecodeError:
|
||||
return []
|
||||
out: list[Finding] = []
|
||||
for run in payload.get("runs", []):
|
||||
cwe_by_rule: dict[str, str] = {}
|
||||
for rule in run.get("tool", {}).get("driver", {}).get("rules", []):
|
||||
for tag in rule.get("properties", {}).get("tags", []):
|
||||
m = _CWE_RE.match(tag)
|
||||
if m:
|
||||
cwe_by_rule[rule["id"]] = m.group(1)
|
||||
break
|
||||
for result in run.get("results", []):
|
||||
rule_id = result.get("ruleId", "unknown")
|
||||
locations = result.get("locations", [])
|
||||
if not locations:
|
||||
continue
|
||||
phys = locations[0].get("physicalLocation", {})
|
||||
uri = phys.get("artifactLocation", {}).get("uri", "")
|
||||
region = phys.get("region", {})
|
||||
start_line = region.get("startLine", 0)
|
||||
end_line = region.get("endLine", start_line)
|
||||
out.append(Finding(
|
||||
tool="zizmor",
|
||||
rule_id=rule_id,
|
||||
severity=_LEVEL.get(result.get("level", "warning"), "medium"),
|
||||
file=uri,
|
||||
line=start_line,
|
||||
end_line=end_line,
|
||||
message=result.get("message", {}).get("text", ""),
|
||||
cwe=cwe_by_rule.get(rule_id),
|
||||
))
|
||||
return out
|
||||
Reference in New Issue
Block a user