Repository navigation
patch: extended support for SI spec v2.1.0 - #69
Merged
Merged
Conversation
Discover lists the root and .github directories once each and returns the first match from DiscoveryPaths, covering the filename and location variants seen across OpenSSF repositories. Fetch exposes the raw-bytes read that Read already did internally, so callers can inspect a file that Load rejects. ErrNotFound distinguishes a missing file from a broken one. The GitHub client now authenticates with GITHUB_TOKEN when set and talks to GITHUB_API_URL when set, which also lets the tests run against a local server. Signed-off-by: Eddie Knight <knight@linux.com>
Runs discovery and parsing over any number of targets (owner/repo, owner/repo/path, github.com blob URLs, raw.githubusercontent.com URLs) and prints a JSON array in input order. Outcomes are reported in-band as ok / not-found / invalid so one broken file does not fail the whole batch; schema-version is reported even for files Load rejects. Signed-off-by: Eddie Knight <knight@linux.com>
A rate limit, 5xx or network failure says nothing about the file, so it must not be reported as invalid: a consumer that hides invalid records would turn a GitHub outage into a content change. Such failures now get status "error" and the command exits 2 after printing the full array, so a workflow can refuse to commit a degraded snapshot. invalid is now strictly: fetched, but si.Load rejected it (or a malformed target). Signed-off-by: Eddie Knight <knight@linux.com>
DiscoveryPaths spelled out every filename under every directory, and Discover then recovered the directories from it with path.Dir plus a listing cache. Two short lists and a nested loop do the same work with no cache; the spec filename comes from the existing SecurityInsightsFilename constant. Behaviour and call count are unchanged. The CLI test no longer rebuilds a root listing to re-test discovery, which the si package already covers; it keeps one empty-path case for the error mapping. Changelog gets the v2.1.1 heading. Signed-off-by: Eddie Knight <knight@linux.com>
Panel review of ossf#69 found no duplication of existing logic, but three copies inside the PR and two bugs in what the PR itself set out to do. Load now returns ErrParentUnavailable when the project-si-source parent fails for a reason unrelated to its content (network error, or any status other than 200 and 404), and si fetch maps it to status "error" rather than "invalid", which is the case 884d93e was meant to prevent. The CHANGELOG heading is v2.3.0: v2.2.0 is already tagged and the new exported API is a feature release. Fetch and Discover take a context.Context before the API ships; Read keeps its signature. One http.Client with a 30s timeout serves GitHub and parent fetches, built once per Discover/Fetch. A GITHUB_API_URL that is not an absolute URL is an error instead of a silent fallback that would send the token to github.com. Read wraps with %w so ErrNotFound survives it. listDir matches files only. The contents-API fake shared by both test packages lives in internal/ghtest and records the Authorization header. parseTarget's two URL branches are one table. The lenient schemaVersion struct stays, with a comment: reusing si.Header loses the version when a sibling field is malformed. Tests cover the parent-unavailable path (sentinel and CLI mapping), the directory branch of Fetch, the token header and the bad GITHUB_API_URL. Coverage 83.1%. Signed-off-by: Eddie Knight <knight@linux.com>
eddie-knight
marked this pull request as ready for review
October 8, 2026 14:16
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope string lists). Keeps ErrParentUnavailable and the timed HTTP client from this branch, takes SecurityInsightsFilenames from main, and folds the .yaml name into Discover so the new spelling is found too. Signed-off-by: Eddie Knight <knight@linux.com>
jmeridth
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.