fix: harden connector manifest validation

This commit is contained in:
Codex
2026-06-16 23:40:33 +02:00
parent 4a4b86ae10
commit 8d6d9bf9c2
5 changed files with 289 additions and 28 deletions
+54
View File
@@ -58,3 +58,57 @@ func TestValidateV2ManifestRequiresRuntimeMetadata(t *testing.T) {
t.Fatalf("missing runtime finding: %+v", result.Findings)
}
}
func TestValidateV2ManifestRejectsEmptyCanaryRef(t *testing.T) {
raw, err := os.ReadFile(filepath.Clean("../../../connectors/github/attesto.connector.json"))
if err != nil {
t.Fatal(err)
}
var manifest Manifest
if err := json.Unmarshal(raw, &manifest); err != nil {
t.Fatal(err)
}
manifest.Runtime["canary"].(map[string]any)["ref"] = ""
result := ValidateManifest(manifest)
if result.OK {
t.Fatalf("expected invalid manifest without canary evidence ref")
}
var found bool
for _, finding := range result.Findings {
if finding.Code == "runtime.canary_ref" {
found = true
}
}
if !found {
t.Fatalf("missing canary ref finding: %+v", result.Findings)
}
}
func TestValidateV2ManifestRejectsPlaceholderMetadata(t *testing.T) {
raw, err := os.ReadFile(filepath.Clean("../../../connectors/github/attesto.connector.json"))
if err != nil {
t.Fatal(err)
}
var manifest Manifest
if err := json.Unmarshal(raw, &manifest); err != nil {
t.Fatal(err)
}
manifest.Repository["url"] = "https://example.com/change-me/github"
result := ValidateManifest(manifest)
if result.OK {
t.Fatalf("expected invalid manifest with placeholder metadata")
}
var found bool
for _, finding := range result.Findings {
if finding.Code == "manifest.placeholder" {
found = true
}
}
if !found {
t.Fatalf("missing placeholder finding: %+v", result.Findings)
}
}