fix: аудит — 19 фиксов безопасности, надёжности, UI и 16 новых тестов
- S4: bump jinja2>=3.1.4, python-multipart>=0.0.18, httpx>=0.28.0
- S5: _detect_ecosystem — DEFAULT_ECOSYSTEM для неизвестных форматов
- S6: harvester — log.exception() вместо log.error()
- S8: _scan_component — urlencode параметров
- P1: scanner — proc.kill() при таймауте
- P3: api_packages — selectinload(Scan.findings), убран N+1
- P4+P5: утечка _url_locks и _llm_locks при early return
- P6: DB reaper — сброс {'status':'analyzing'} при старте
- UI: htmx-пагинация, фильтры не теряют flagged, 404 с layout
- UI: мобильные таблицы overflow-x, полная стата на дашборде
- UI: i18n статусов в _status_badge, urlencode package_name
- 16 новых тестов: analyze endpoint (6), scanner errors (4),
webhook signature (2), llm client (4)
This commit is contained in:
@@ -1,6 +1,5 @@
|
||||
"""Tests for Nexus package info extractors."""
|
||||
|
||||
|
||||
from guarddog_nexus.core.nexus import (
|
||||
extract_go_info,
|
||||
extract_npm_info,
|
||||
@@ -37,9 +36,10 @@ class TestGoExtractor:
|
||||
)
|
||||
|
||||
def test_long_module(self):
|
||||
assert extract_go_info(
|
||||
"/packages/github.com/gin-gonic/gin/@v/v1.9.0.zip"
|
||||
) == ("github.com/gin-gonic/gin", "v1.9.0")
|
||||
assert extract_go_info("/packages/github.com/gin-gonic/gin/@v/v1.9.0.zip") == (
|
||||
"github.com/gin-gonic/gin",
|
||||
"v1.9.0",
|
||||
)
|
||||
|
||||
def test_no_at_v(self):
|
||||
assert extract_go_info("packages/some/pkg/v1.0.0.zip") is None
|
||||
@@ -68,21 +68,22 @@ class TestNpmExtractor:
|
||||
|
||||
class TestDispatchExtractor:
|
||||
def test_pypi(self):
|
||||
assert extract_package_info(
|
||||
"/packages/requests/2.31.0/requests-2.31.0.tar.gz", "pypi"
|
||||
) == ("requests", "2.31.0")
|
||||
assert extract_package_info("/packages/requests/2.31.0/requests-2.31.0.tar.gz", "pypi") == (
|
||||
"requests",
|
||||
"2.31.0",
|
||||
)
|
||||
|
||||
def test_go(self):
|
||||
assert extract_package_info(
|
||||
"github.com/gorilla/mux/@v/v1.8.0.zip", "go"
|
||||
) == ("github.com/gorilla/mux", "v1.8.0")
|
||||
assert extract_package_info("github.com/gorilla/mux/@v/v1.8.0.zip", "go") == (
|
||||
"github.com/gorilla/mux",
|
||||
"v1.8.0",
|
||||
)
|
||||
|
||||
def test_npm(self):
|
||||
assert extract_package_info(
|
||||
"packages/lodash/-/lodash-4.17.21.tgz", "npm"
|
||||
) == ("lodash", "4.17.21")
|
||||
assert extract_package_info("packages/lodash/-/lodash-4.17.21.tgz", "npm") == (
|
||||
"lodash",
|
||||
"4.17.21",
|
||||
)
|
||||
|
||||
def test_unknown_ecosystem(self):
|
||||
assert extract_package_info(
|
||||
"/packages/pkg/1.0/file.tar.gz", "unknown"
|
||||
) == ("pkg", "1.0")
|
||||
assert extract_package_info("/packages/pkg/1.0/file.tar.gz", "unknown") == ("pkg", "1.0")
|
||||
|
||||
Reference in New Issue
Block a user