-
Notifications
You must be signed in to change notification settings - Fork 7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adding gitlab repo health monitor #243
Conversation
@@ -102,7 +102,7 @@ def test_override_check_description(self): | |||
BranchProtectionStatusChecks.check(mock_github, OWNER, REPO, BRANCH, config), | |||
) | |||
|
|||
def test_no_required_status_checks(self): | |||
def test_single_required_status_checks(self): |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There's already another test with this name.
@@ -307,6 +307,10 @@ endef | |||
test-deps: get-shell-check get-detekt get-mock-swiftlint get-trivy install-plugin-dependencies | |||
.PHONY: test-deps | |||
|
|||
unit-test-no-deps: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I use this locally, its been pretty useful.
@@ -611,13 +611,13 @@ def get_plugin_command(scan, image, plugin, depth, include_dev, scan_images, plu | |||
"-e", | |||
f"APPLICATION={APPLICATION}", | |||
"-e", | |||
f"ARTEMIS_REV_PROXY_DOMAIN_SUBSTRING={REV_PROXY_DOMAIN_SUBSTRING}", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changing these to the correct env var names.
@@ -640,6 +640,10 @@ def get_plugin_command(scan, image, plugin, depth, include_dev, scan_images, plu | |||
"-e", | |||
f"ARTEMIS_GITHUB_APP_ID={GITHUB_APP_ID}", | |||
"-e", | |||
f"ARTEMIS_REVPROXY_DOMAIN_SUBSTRING={REV_PROXY_DOMAIN_SUBSTRING}", | |||
"-e", | |||
f"ARTEMIS_REVPROXY_SECRET={REV_PROXY_SECRET}", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is the location of the secret in secrets manager, not the actual secret.
…Media/artemis into adding-gitlab-repo-health
...plugins/gitlab_repo_health/rules/first_order_rules/branch_protection_prevent_secret_files.py
Show resolved
Hide resolved
backend/engine/plugins/gitlab_repo_health/rules/first_order_rules/__init__.py
Outdated
Show resolved
Hide resolved
...engine/plugins/gitlab_repo_health/rules/first_order_rules/branch_protection_pull_requests.py
Show resolved
Hide resolved
...engine/plugins/gitlab_repo_health/rules/first_order_rules/branch_protection_pull_requests.py
Show resolved
Hide resolved
branch_rules = [] | ||
for rule in approval_rules: | ||
for each_branch in rule.get("protected_branches"): | ||
if (each_branch.get("name")) == branch: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Does gitlab support any sort of pattern matching for rules? This sort of logic has led to bugs in GHRC due to not processing pattern matching locally
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
They do not, unfortunately.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I realized this is actually fortunately, not unfortunately.
...engine/plugins/gitlab_repo_health/rules/first_order_rules/branch_protection_pull_requests.py
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good from my end; I'll let @g-marconet evaluate on his end.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Description
Adding Gitlab repo health plugin
Motivation and Context
We want to be able to check the configuration status of Gitlab repos
How Has This Been Tested?
Tested in nonprod
Types of changes
Checklist