"""Adapter: zizmor --format sarif normalized to Finding[].""" from __future__ import annotations import json import re from scripts.manifest import Finding _LEVEL = {"error": "high", "warning": "medium", "note": "low"} _CWE_RE = re.compile(r"(CWE-\d+)") def parse_zizmor_output(stdout: str) -> list[Finding]: try: payload = json.loads(stdout) except json.JSONDecodeError: return [] out: list[Finding] = [] for run in payload.get("runs", []): cwe_by_rule: dict[str, str] = {} for rule in run.get("tool", {}).get("driver", {}).get("rules", []): for tag in rule.get("properties", {}).get("tags", []): m = _CWE_RE.match(tag) if m: cwe_by_rule[rule["id"]] = m.group(1) break for result in run.get("results", []): rule_id = result.get("ruleId", "unknown") locations = result.get("locations", []) if not locations: continue phys = locations[0].get("physicalLocation", {}) uri = phys.get("artifactLocation", {}).get("uri", "") region = phys.get("region", {}) start_line = region.get("startLine", 0) end_line = region.get("endLine", start_line) out.append(Finding( tool="zizmor", rule_id=rule_id, severity=_LEVEL.get(result.get("level", "warning"), "medium"), file=uri, line=start_line, end_line=end_line, message=result.get("message", {}).get("text", ""), cwe=cwe_by_rule.get(rule_id), )) return out