Skip to content

patch: extended support for SI spec v2.1.0 - #69

Merged
jmeridth merged 6 commits into
ossf:mainfrom
eddie-knight:si-fetch-cli
Oct 8, 2026
Merged

jmeridth merged 6 commits into
ossf:mainfrom
eddie-knight:si-fetch-cli

Conversation

@eddie-knight

Copy link
Copy Markdown
Contributor

No description provided.

Discover lists the root and .github directories once each and returns the
first match from DiscoveryPaths, covering the filename and location variants
seen across OpenSSF repositories. Fetch exposes the raw-bytes read that Read
already did internally, so callers can inspect a file that Load rejects.
ErrNotFound distinguishes a missing file from a broken one.

The GitHub client now authenticates with GITHUB_TOKEN when set and talks to
GITHUB_API_URL when set, which also lets the tests run against a local server.

Signed-off-by: Eddie Knight <knight@linux.com>
Runs discovery and parsing over any number of targets (owner/repo,
owner/repo/path, github.com blob URLs, raw.githubusercontent.com URLs) and
prints a JSON array in input order. Outcomes are reported in-band as
ok / not-found / invalid so one broken file does not fail the whole batch;
schema-version is reported even for files Load rejects.

Signed-off-by: Eddie Knight <knight@linux.com>
A rate limit, 5xx or network failure says nothing about the file, so it
must not be reported as invalid: a consumer that hides invalid records
would turn a GitHub outage into a content change. Such failures now get
status "error" and the command exits 2 after printing the full array,
so a workflow can refuse to commit a degraded snapshot. invalid is now
strictly: fetched, but si.Load rejected it (or a malformed target).

Signed-off-by: Eddie Knight <knight@linux.com>
DiscoveryPaths spelled out every filename under every directory, and Discover
then recovered the directories from it with path.Dir plus a listing cache.
Two short lists and a nested loop do the same work with no cache; the spec
filename comes from the existing SecurityInsightsFilename constant. Behaviour
and call count are unchanged.

The CLI test no longer rebuilds a root listing to re-test discovery, which
the si package already covers; it keeps one empty-path case for the error
mapping. Changelog gets the v2.1.1 heading.

Signed-off-by: Eddie Knight <knight@linux.com>
Panel review of ossf#69 found no duplication of existing logic, but three
copies inside the PR and two bugs in what the PR itself set out to do.

Load now returns ErrParentUnavailable when the project-si-source parent
fails for a reason unrelated to its content (network error, or any status
other than 200 and 404), and si fetch maps it to status "error" rather
than "invalid", which is the case 884d93e was meant to prevent. The
CHANGELOG heading is v2.3.0: v2.2.0 is already tagged and the new
exported API is a feature release.

Fetch and Discover take a context.Context before the API ships; Read
keeps its signature. One http.Client with a 30s timeout serves GitHub and
parent fetches, built once per Discover/Fetch. A GITHUB_API_URL that is
not an absolute URL is an error instead of a silent fallback that would
send the token to github.com. Read wraps with %w so ErrNotFound survives
it. listDir matches files only.

The contents-API fake shared by both test packages lives in
internal/ghtest and records the Authorization header. parseTarget's two
URL branches are one table. The lenient schemaVersion struct stays, with
a comment: reusing si.Header loses the version when a sibling field is
malformed.

Tests cover the parent-unavailable path (sentinel and CLI mapping), the
directory branch of Fetch, the token header and the bad GITHUB_API_URL.
Coverage 83.1%.

Signed-off-by: Eddie Knight <knight@linux.com>
@eddie-knight
eddie-knight marked this pull request as ready for review October 8, 2026 14:16
@eddie-knight
eddie-knight requested a review from a team as a code owner October 8, 2026 14:16
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope
string lists). Keeps ErrParentUnavailable and the timed HTTP client from
this branch, takes SecurityInsightsFilenames from main, and folds the
.yaml name into Discover so the new spelling is found too.

Signed-off-by: Eddie Knight <knight@linux.com>
@jmeridth
jmeridth merged commit 8ae2326 into ossf:main Oct 8, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants