audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
and --user-only (no system package managers, no sudo).
log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.
audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).
Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
59 lines
2.1 KiB
Python
59 lines
2.1 KiB
Python
import json
|
|
from datetime import datetime, timezone, UTC
|
|
|
|
from scripts.controls_schema import Control, ControlsFile
|
|
|
|
|
|
def test_controls_file_serializes_with_resource_type_index():
|
|
a = Control(
|
|
control_id="FSBP S3.5",
|
|
title="S3 buckets should require requests to use SSL",
|
|
severity="medium",
|
|
resource_types=["aws_s3_bucket"],
|
|
requirement="The bucket policy must include a deny statement for "
|
|
"non-TLS access (aws:SecureTransport = false).",
|
|
source_url="https://docs.aws.amazon.com/securityhub/.../S3.5",
|
|
)
|
|
b = Control(
|
|
control_id="FSBP IAM.5",
|
|
title="MFA should be enabled for IAM users",
|
|
severity="medium",
|
|
resource_types=["aws_iam_user"],
|
|
requirement="IAM users with console access must have MFA.",
|
|
source_url="https://docs.aws.amazon.com/securityhub/.../IAM.5",
|
|
)
|
|
cf = ControlsFile(
|
|
source="fsbp",
|
|
fetched_at=datetime(2026, 5, 12, 9, 0, 0, tzinfo=UTC),
|
|
controls=[a, b],
|
|
)
|
|
payload = json.loads(cf.to_json())
|
|
assert payload["source"] == "fsbp"
|
|
assert payload["fetched_at"].endswith("+00:00") or payload["fetched_at"].endswith("Z")
|
|
|
|
by_rtype = payload["by_resource_type"]
|
|
assert "aws_s3_bucket" in by_rtype
|
|
assert by_rtype["aws_s3_bucket"] == ["FSBP S3.5"]
|
|
assert "aws_iam_user" in by_rtype
|
|
assert by_rtype["aws_iam_user"] == ["FSBP IAM.5"]
|
|
|
|
ids = {c["control_id"] for c in payload["controls"]}
|
|
assert ids == {"FSBP S3.5", "FSBP IAM.5"}
|
|
|
|
|
|
def test_control_appears_under_every_resource_type():
|
|
c = Control(
|
|
control_id="FSBP X.1",
|
|
title="t", severity="low",
|
|
resource_types=["aws_s3_bucket", "aws_s3_bucket_policy"],
|
|
requirement="r", source_url="u",
|
|
)
|
|
cf = ControlsFile(
|
|
source="fsbp",
|
|
fetched_at=datetime(2026, 5, 12, tzinfo=UTC),
|
|
controls=[c],
|
|
)
|
|
payload = json.loads(cf.to_json())
|
|
assert payload["by_resource_type"]["aws_s3_bucket"] == ["FSBP X.1"]
|
|
assert payload["by_resource_type"]["aws_s3_bucket_policy"] == ["FSBP X.1"]
|