-
Notifications
You must be signed in to change notification settings - Fork 10
Expand file tree
/
Copy pathtest_fossa_parity.py
More file actions
106 lines (85 loc) · 4.39 KB
/
Copy pathtest_fossa_parity.py
File metadata and controls
106 lines (85 loc) · 4.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
"""Structural parity tests: assert our FOSSA-shaped output matches real FOSSA artifact shapes.
These tests load real FOSSA artifacts captured from a customer pipeline and compare them
against our --legal-format fossa output by shape (key sets + value types), not by value.
A value-level golden test would be too brittle; the goal is to catch structural drift.
"""
from __future__ import annotations
import json
from pathlib import Path
FIXTURE_DIR = Path(__file__).parent.parent / "fixtures" / "fossa"
def _load(name: str) -> dict:
return json.loads((FIXTURE_DIR / name).read_text())
def test_fixtures_present_and_parseable():
"""Sanity: all four FOSSA reference fixtures load as JSON objects."""
for name in (
"fossa-analyze-populated.json",
"fossa-analyze-empty.json",
"fossa-sbom-populated.json",
"fossa-sbom-empty-deep.json",
):
data = _load(name)
assert isinstance(data, dict), f"{name} should be a JSON object at the top level"
def test_analyze_fixture_top_level_shape():
"""The real FOSSA analyze artifact has exactly these top-level keys."""
data = _load("fossa-analyze-populated.json")
assert set(data.keys()) == {"project", "vulnerability", "licensing", "quality"}
assert "risk" not in data # FOSSA API 400s on risk category; key never appears
def test_sbom_fixture_top_level_shape():
"""The real FOSSA attribution artifact has exactly these 5 top-level keys."""
data = _load("fossa-sbom-populated.json")
assert set(data.keys()) == {
"copyrightsByLicense",
"deepDependencies",
"directDependencies",
"licenses",
"project",
}
def test_our_analyze_matches_fossa_analyze_top_level_keys():
"""Our build_fossa_report_payload top-level keyset matches the real fixture."""
from socketsecurity.config import CliConfig
from socketsecurity.core.classes import Diff
from socketsecurity.fossa_compat import build_fossa_report_payload
config = CliConfig.from_args(["--api-token", "test", "--legal-format", "fossa"])
ours = build_fossa_report_payload(Diff(), config)
theirs = _load("fossa-analyze-empty.json")
assert set(ours.keys()) == set(theirs.keys())
def test_our_analyze_project_keys_match():
from socketsecurity.config import CliConfig
from socketsecurity.core.classes import Diff
from socketsecurity.fossa_compat import build_fossa_report_payload
config = CliConfig.from_args(["--api-token", "test", "--legal-format", "fossa"])
ours = build_fossa_report_payload(Diff(), config)
theirs = _load("fossa-analyze-empty.json")
assert set(ours["project"].keys()) == set(theirs["project"].keys())
def test_our_sbom_matches_fossa_sbom_top_level_keys():
from socketsecurity.config import CliConfig
from socketsecurity.core.classes import Diff
from socketsecurity.fossa_compat import build_fossa_attribution_payload
config = CliConfig.from_args(["--api-token", "test", "--legal-format", "fossa"])
ours = build_fossa_attribution_payload(Diff(), config)
theirs = _load("fossa-sbom-populated.json")
assert set(ours.keys()) == set(theirs.keys())
def test_our_sbom_project_keys_match():
from socketsecurity.config import CliConfig
from socketsecurity.core.classes import Diff
from socketsecurity.fossa_compat import build_fossa_attribution_payload
config = CliConfig.from_args(["--api-token", "test", "--legal-format", "fossa"])
ours = build_fossa_attribution_payload(Diff(), config)
theirs = _load("fossa-sbom-populated.json")
assert set(ours["project"].keys()) == set(theirs["project"].keys())
def test_our_sbom_dependency_keys_match_when_populated():
"""When we have at least one dependency, its keyset matches a real FOSSA dependency entry."""
from socketsecurity.config import CliConfig
from socketsecurity.core.classes import Diff, Package
from socketsecurity.fossa_compat import build_fossa_attribution_payload
pkg = Package(
type="pypi", name="x", version="1.0", id="pid",
score={}, alerts=[], direct=True,
)
diff = Diff(packages={"pid": pkg})
config = CliConfig.from_args(["--api-token", "test", "--legal-format", "fossa"])
ours = build_fossa_attribution_payload(diff, config)
theirs = _load("fossa-sbom-populated.json")
our_dep = ours["directDependencies"][0]
their_dep = theirs["directDependencies"][0]
assert set(our_dep.keys()) == set(their_dep.keys())