Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding gitlab repo health monitor #243

Merged
merged 41 commits into from
Sep 12, 2024
Merged

Conversation

mdfleury-wbd
Copy link
Contributor

@mdfleury-wbd mdfleury-wbd commented Aug 21, 2024

Description

Adding Gitlab repo health plugin

Motivation and Context

We want to be able to check the configuration status of Gitlab repos

How Has This Been Tested?

Tested in nonprod

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation change

Checklist

  • My code follows conforms to the coding standards.
  • My change requires a change to the documentation.
  • I have updated the documentation accordingly.
  • I have added tests to cover my changes.
  • All new and existing tests passed.

@mdfleury-wbd mdfleury-wbd changed the title APPSECENG-1122 - Adding gitlab repo health monitor Adding gitlab repo health monitor Aug 26, 2024
@@ -102,7 +102,7 @@ def test_override_check_description(self):
BranchProtectionStatusChecks.check(mock_github, OWNER, REPO, BRANCH, config),
)

def test_no_required_status_checks(self):
def test_single_required_status_checks(self):
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's already another test with this name.

@@ -307,6 +307,10 @@ endef
test-deps: get-shell-check get-detekt get-mock-swiftlint get-trivy install-plugin-dependencies
.PHONY: test-deps

unit-test-no-deps:
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I use this locally, its been pretty useful.

@mdfleury-wbd mdfleury-wbd marked this pull request as ready for review August 28, 2024 11:01
@mdfleury-wbd mdfleury-wbd requested a review from a team as a code owner August 28, 2024 11:01
@@ -611,13 +611,13 @@ def get_plugin_command(scan, image, plugin, depth, include_dev, scan_images, plu
"-e",
f"APPLICATION={APPLICATION}",
"-e",
f"ARTEMIS_REV_PROXY_DOMAIN_SUBSTRING={REV_PROXY_DOMAIN_SUBSTRING}",
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changing these to the correct env var names.

@@ -640,6 +640,10 @@ def get_plugin_command(scan, image, plugin, depth, include_dev, scan_images, plu
"-e",
f"ARTEMIS_GITHUB_APP_ID={GITHUB_APP_ID}",
"-e",
f"ARTEMIS_REVPROXY_DOMAIN_SUBSTRING={REV_PROXY_DOMAIN_SUBSTRING}",
"-e",
f"ARTEMIS_REVPROXY_SECRET={REV_PROXY_SECRET}",
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the location of the secret in secrets manager, not the actual secret.

branch_rules = []
for rule in approval_rules:
for each_branch in rule.get("protected_branches"):
if (each_branch.get("name")) == branch:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Does gitlab support any sort of pattern matching for rules? This sort of logic has led to bugs in GHRC due to not processing pattern matching locally

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

They do not, unfortunately.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I realized this is actually fortunately, not unfortunately.

ZoogieZork
ZoogieZork previously approved these changes Sep 11, 2024
Copy link
Contributor

@ZoogieZork ZoogieZork left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good from my end; I'll let @g-marconet evaluate on his end.

Copy link
Contributor

@g-marconet g-marconet left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mdfleury-wbd mdfleury-wbd added this pull request to the merge queue Sep 12, 2024
Merged via the queue into main with commit f6281ab Sep 12, 2024
6 checks passed
@mdfleury-wbd mdfleury-wbd deleted the adding-gitlab-repo-health branch September 12, 2024 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants