Skip to content

fix: load in-scope and out-of-scope as string lists and test the spec examples - #71

Merged
jmeridth merged 2 commits into
mainfrom
fix/in-scope-string-lists
Oct 8, 2026
Merged

jmeridth merged 2 commits into
mainfrom
fix/in-scope-string-lists

Conversation

@jmeridth

@jmeridth jmeridth commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Fixes #68
Closes #72

What/Why

The schema declares in-scope and out-of-scope as string lists, but the generated types made them *URL, so the strict loader rejected any file that set either field. Both are now []string.

The tests only used "minimal" fixtures, which is how the spec's own example-full.yml stopped loading without anyone noticing. The four Security Insights v2.2.0 examples now live unmodified in v2/si/test_data/spec-v2.2.0/, and TestLoadSpecExamples loads each one.

Proof it works

  • TestLoadSpecExamples passes. With the old *URL types, the full example fails with the in-scope and out-of-scope generate as *URL, so any file that uses them fails to load #68 error, cannot unmarshal []interface {} into ... si.URL.
  • The reuse example's parent file is served by httptest, so the tests stay offline.
  • make check-spec-examples confirms the fixtures match the spec's v2.2.0 tag byte for byte.
  • go test, golangci-lint, and make covcheck (76.2%) pass.

Risk

Low. The field type change is an API break on paper, but no file using these fields could load before, and no known consumer (including the OSPS Baseline scanner) reads them.

AI role

Drafted by Claude Opus 5.5 and reviewed by the maintainer.

Review focus

  • generated_types.go is hand-edited for these two fields only. Regenerating from the current spec also turns Project and Repository from pointers into values, which would break consumers and needs its own change. The schema fix that keeps future generation correct is fix(schema): generate in-scope and out-of-scope as string lists security-insights#213.
  • Whether check-spec-examples should also run in CI. It hits the network, so it's opt-in for now.

Fixes #68

What/Why
The schema declares in-scope and out-of-scope as string lists, but the
generated types made them *URL. The strict loader then rejected every
file that set either field. Both are now []string.

Proof it works
TestLoadV220Fields now loads a fixture with both fields. Without the
type change it fails with "cannot unmarshal []interface {} into ...
si.URL", the error in the issue. go test, golangci-lint, and make
covcheck (76.2%) pass.

Risk
Low. The field type change is an API break on paper, but no file that
set these fields could load before, and no known consumer reads them.

AI role
Drafted by Claude Opus 5.5 and reviewed by the maintainer.

Review focus
generated_types.go is hand-edited for these two fields only. A full
regeneration from the current spec also changes Project and Repository
from pointers to values, which needs its own change.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth self-assigned this Oct 8, 2026
jmeridth added a commit that referenced this pull request Oct 8, 2026
What/Why
Names the release v2.2.1, matching spec v2.2.0, and records the
in-scope and out-of-scope loading fix from #71.

Proof it works
Docs only.

Risk
Low. The bug fix entry describes #71, which must merge before the tag.

AI role
Drafted by Claude Opus 5.5. The maintainer chose the version.

Review focus
The version number.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth
jmeridth marked this pull request as ready for review October 8, 2026 07:31
@jmeridth
jmeridth requested a review from a team as a code owner October 8, 2026 07:31
Closes #72

What/Why
The tests only loaded "minimal" fixtures, so the spec's own
example-full.yml failed to load (#68) without any test noticing. The
four v2.2.0 spec examples now live unmodified in
test_data/spec-v2.2.0, and TestLoadSpecExamples loads each one. The
in-scope fields added to minimal-v2.2.0.yml earlier in this branch are
reverted, since that fixture is meant to stay minimal.

Proof it works
TestLoadSpecExamples passes. With the old *URL types, the full example
fails with the #68 unmarshal error. The reuse example's parent is
served by httptest, so no test touches the network.
make check-spec-examples confirms the fixtures match the v2.2.0 tag.
go test, golangci-lint, and make covcheck (76.2%) pass.

Risk
Low. Tests and a Makefile target only.

AI role
Drafted by Claude Opus 5.5 and reviewed by the maintainer.

Review focus
Whether check-spec-examples should also run in CI.

Signed-off-by: jmeridth <jmeridth@gmail.com>
@jmeridth jmeridth changed the title fix: load in-scope and out-of-scope as string lists fix: load in-scope and out-of-scope as string lists and test the spec examples Oct 8, 2026
@jmeridth
jmeridth requested a review from eddie-knight October 8, 2026 14:37

@eddie-knight eddie-knight left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These are not required values, but I just noticed that our test data only contains files marked "minimal."

@jmeridth
jmeridth merged commit f711ca7 into main Oct 8, 2026
3 checks passed
eddie-knight added a commit to eddie-knight/si-tooling that referenced this pull request Oct 8, 2026
Resolves conflicts with ossf#70 (.yml and .yaml filenames) and ossf#71 (scope
string lists). Keeps ErrParentUnavailable and the timed HTTP client from
this branch, takes SecurityInsightsFilenames from main, and folds the
.yaml name into Discover so the new spelling is found too.

Signed-off-by: Eddie Knight <knight@linux.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Test data should match spec example files in-scope and out-of-scope generate as *URL, so any file that uses them fails to load

2 participants