2022-05-12 16:56:04 +00:00
|
|
|
package cli
|
|
|
|
|
|
|
|
import (
|
|
|
|
"os"
|
|
|
|
"strings"
|
|
|
|
"testing"
|
|
|
|
|
2023-10-25 13:43:06 +00:00
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
|
2022-05-12 16:56:04 +00:00
|
|
|
"github.com/anchore/stereoscope/pkg/imagetest"
|
2023-10-25 13:43:06 +00:00
|
|
|
"github.com/anchore/syft/syft/format/cyclonedxjson"
|
2022-05-12 16:56:04 +00:00
|
|
|
)
|
|
|
|
|
2024-08-12 16:08:04 +00:00
|
|
|
// We have schema validation mechanisms in schema/cyclonedx/
|
2022-05-12 16:56:04 +00:00
|
|
|
// This test allows us to double check that validation against the cyclonedx-cli tool
|
|
|
|
func TestValidCycloneDX(t *testing.T) {
|
|
|
|
imageFixture := func(t *testing.T) string {
|
|
|
|
fixtureImageName := "image-pkg-coverage"
|
|
|
|
imagetest.GetFixtureImage(t, "docker-archive", fixtureImageName)
|
|
|
|
tarPath := imagetest.GetFixtureImageTarPath(t, fixtureImageName)
|
|
|
|
return "docker-archive:" + tarPath
|
|
|
|
}
|
|
|
|
|
|
|
|
// TODO update image to exercise entire cyclonedx schema
|
|
|
|
tests := []struct {
|
|
|
|
name string
|
|
|
|
subcommand string
|
|
|
|
args []string
|
|
|
|
fixture func(*testing.T) string
|
|
|
|
assertions []traitAssertion
|
|
|
|
}{
|
|
|
|
{
|
|
|
|
name: "validate cyclonedx output",
|
2024-01-04 16:56:57 +00:00
|
|
|
subcommand: "scan",
|
2024-09-09 15:15:13 +00:00
|
|
|
args: []string{"-o", "cyclonedx-json", "-o", "cyclonedx-json=results/sbom.cdx.json"},
|
2022-05-12 16:56:04 +00:00
|
|
|
fixture: imageFixture,
|
|
|
|
assertions: []traitAssertion{
|
|
|
|
assertSuccessfulReturnCode,
|
|
|
|
assertValidCycloneDX,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, test := range tests {
|
|
|
|
t.Run(test.name, func(t *testing.T) {
|
|
|
|
fixtureRef := test.fixture(t)
|
|
|
|
args := []string{
|
|
|
|
test.subcommand, fixtureRef, "-q",
|
|
|
|
}
|
2023-06-05 17:01:00 +00:00
|
|
|
args = append(args, test.args...)
|
2022-05-12 16:56:04 +00:00
|
|
|
|
|
|
|
cmd, stdout, stderr := runSyft(t, nil, args...)
|
|
|
|
for _, traitFn := range test.assertions {
|
|
|
|
traitFn(t, stdout, stderr, cmd.ProcessState.ExitCode())
|
|
|
|
}
|
2023-04-14 18:33:36 +00:00
|
|
|
logOutputOnFailure(t, cmd, stdout, stderr)
|
2022-05-12 16:56:04 +00:00
|
|
|
|
|
|
|
validateCycloneDXJSON(t, stdout)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func assertValidCycloneDX(tb testing.TB, stdout, stderr string, rc int) {
|
|
|
|
tb.Helper()
|
|
|
|
f, err := os.CreateTemp("", "tmpfile-")
|
|
|
|
if err != nil {
|
|
|
|
tb.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// close and remove the temporary file at the end of the program
|
|
|
|
defer f.Close()
|
|
|
|
defer os.Remove(f.Name())
|
|
|
|
|
|
|
|
data := []byte(stdout)
|
|
|
|
|
|
|
|
if _, err := f.Write(data); err != nil {
|
|
|
|
tb.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
args := []string{
|
|
|
|
"validate",
|
|
|
|
"--input-format",
|
|
|
|
"json",
|
|
|
|
"--input-version",
|
|
|
|
"v1_4",
|
|
|
|
"--input-file",
|
|
|
|
"/sbom",
|
|
|
|
}
|
|
|
|
|
|
|
|
cmd, stdout, stderr := runCycloneDXInDocker(tb, nil, "cyclonedx/cyclonedx-cli", f, args...)
|
|
|
|
if cmd.ProcessState.ExitCode() != 0 {
|
|
|
|
tb.Errorf("expected no validation failures for cyclonedx-cli but got rc=%d", rc)
|
|
|
|
}
|
|
|
|
|
2023-04-14 18:33:36 +00:00
|
|
|
logOutputOnFailure(tb, cmd, stdout, stderr)
|
2022-05-12 16:56:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// validate --input-format json --input-version v1_4 --input-file bom.json
|
|
|
|
func validateCycloneDXJSON(t *testing.T, stdout string) {
|
|
|
|
f, err := os.CreateTemp("", "tmpfile-")
|
2023-10-25 13:43:06 +00:00
|
|
|
require.NoError(t, err)
|
2022-05-12 16:56:04 +00:00
|
|
|
|
|
|
|
// close and remove the temporary file at the end of the program
|
2023-10-25 13:43:06 +00:00
|
|
|
t.Cleanup(func() {
|
|
|
|
assert.NoError(t, f.Close())
|
|
|
|
assert.NoError(t, os.Remove(f.Name()))
|
|
|
|
})
|
2022-05-12 16:56:04 +00:00
|
|
|
|
|
|
|
data := []byte(stdout)
|
|
|
|
|
|
|
|
if _, err := f.Write(data); err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
2023-10-25 13:43:06 +00:00
|
|
|
// get the latest supported version of CycloneDX by syft and convert the expression to the format used by cyclonedx-cli
|
|
|
|
// e.g. "1.5" -> "v1_5"
|
|
|
|
versions := cyclonedxjson.SupportedVersions()
|
|
|
|
version := versions[len(versions)-1]
|
|
|
|
versionInput := "v" + strings.Replace(version, ".", "_", -1)
|
|
|
|
|
2022-05-12 16:56:04 +00:00
|
|
|
args := []string{
|
|
|
|
"validate",
|
|
|
|
"--input-format",
|
|
|
|
"json",
|
|
|
|
"--input-version",
|
2023-10-25 13:43:06 +00:00
|
|
|
versionInput,
|
2022-05-12 16:56:04 +00:00
|
|
|
"--input-file",
|
|
|
|
"/sbom",
|
|
|
|
}
|
|
|
|
|
|
|
|
cmd, stdout, stderr := runCycloneDXInDocker(t, nil, "cyclonedx/cyclonedx-cli", f, args...)
|
|
|
|
if strings.Contains(stdout, "BOM is not valid") {
|
2023-10-25 13:43:06 +00:00
|
|
|
t.Log("STDOUT:\n", stdout)
|
2022-05-12 16:56:04 +00:00
|
|
|
t.Errorf("expected no validation failures for cyclonedx-cli but found invalid BOM")
|
|
|
|
}
|
|
|
|
|
2023-04-14 18:33:36 +00:00
|
|
|
logOutputOnFailure(t, cmd, stdout, stderr)
|
2022-05-12 16:56:04 +00:00
|
|
|
}
|