-
Notifications
You must be signed in to change notification settings - Fork 215
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add tests and address review comments
Signed-off-by: Tushar Goel <[email protected]>
- Loading branch information
Showing
4 changed files
with
271 additions
and
12 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,224 @@ | ||
import datetime | ||
import pytz | ||
from unittest import TestCase | ||
|
||
from packageurl import PackageURL | ||
from univers.version_range import VersionRange | ||
|
||
from vulnerabilities.importer import AdvisoryData, AffectedPackage, Reference, VulnerabilitySeverity | ||
from vulnerabilities.severity_systems import SCORING_SYSTEMS | ||
from vulnerabilities.utils import compute_content_id | ||
|
||
|
||
class TestComputeContentId(TestCase): | ||
def setUp(self): | ||
self.maxDiff = None | ||
self.base_advisory = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=[ | ||
AffectedPackage( | ||
package=PackageURL( | ||
type="npm", | ||
name="package1", | ||
qualifiers={}, | ||
), | ||
affected_version_range=VersionRange.from_string("vers:npm/>=1.0.0|<2.0.0"), | ||
) | ||
], | ||
references=[ | ||
Reference( | ||
url="https://example.com/vuln1", | ||
reference_id="GHSA-1234-5678-9012", | ||
severities=[ | ||
VulnerabilitySeverity( | ||
system=SCORING_SYSTEMS["cvssv3.1"], | ||
value="7.5", | ||
) | ||
], | ||
) | ||
], | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
def test_same_content_different_order_same_id(self): | ||
""" | ||
Test that advisories with same content but different ordering have same content ID | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
# Same content but different order of references and affected packages | ||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=list(reversed(self.base_advisory.affected_packages)), | ||
references=list(reversed(self.base_advisory.references)), | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
self.assertEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_different_metadata_same_content_same_id(self): | ||
""" | ||
Test that advisories with same content but different metadata have same content ID | ||
when include_metadata=False | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
created_by="different_importer", | ||
url="https://different.url", | ||
) | ||
|
||
self.assertEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_different_metadata_different_id_when_included(self): | ||
""" | ||
Test that advisories with same content but different metadata have different content IDs | ||
when include_metadata=True | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
created_by="different_importer", | ||
url="https://different.url", | ||
) | ||
|
||
self.assertNotEqual( | ||
compute_content_id(advisory1, include_metadata=True), | ||
compute_content_id(advisory2, include_metadata=True), | ||
) | ||
|
||
def test_different_summary_different_id(self): | ||
""" | ||
Test that advisories with different summaries have different content IDs | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Different summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
self.assertNotEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_different_affected_packages_different_id(self): | ||
""" | ||
Test that advisories with different affected packages have different content IDs | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=[ | ||
AffectedPackage( | ||
package=PackageURL( | ||
type="npm", | ||
name="different-package", | ||
qualifiers={}, | ||
), | ||
affected_version_range=VersionRange.from_string("vers:npm/>=1.0.0|<2.0.0"), | ||
) | ||
], | ||
references=self.base_advisory.references, | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
self.assertNotEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_different_references_different_id(self): | ||
""" | ||
Test that advisories with different references have different content IDs | ||
""" | ||
advisory1 = self.base_advisory | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=[ | ||
Reference( | ||
url="https://example.com/different-vuln", | ||
reference_id="GHSA-9999-9999-9999", | ||
severities=[ | ||
VulnerabilitySeverity( | ||
system=SCORING_SYSTEMS["cvssv3.1"], | ||
value="8.5", | ||
) | ||
], | ||
) | ||
], | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
self.assertNotEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_different_weaknesses_different_id(self): | ||
""" | ||
Test that advisories with different weaknesses have different content IDs | ||
""" | ||
advisory1 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
weaknesses=[1, 2, 3], | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
advisory2 = AdvisoryData( | ||
summary="Test summary", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
weaknesses=[4, 5, 6], | ||
date_published=datetime.datetime(2024, 1, 1, tzinfo=pytz.UTC), | ||
) | ||
|
||
self.assertNotEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) | ||
|
||
def test_empty_fields_same_id(self): | ||
""" | ||
Test that advisories with empty optional fields still generate same content ID | ||
""" | ||
advisory1 = AdvisoryData( | ||
summary="", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
date_published=None, | ||
) | ||
|
||
advisory2 = AdvisoryData( | ||
summary="", | ||
affected_packages=self.base_advisory.affected_packages, | ||
references=self.base_advisory.references, | ||
date_published=None, | ||
) | ||
|
||
self.assertEqual( | ||
compute_content_id(advisory1), | ||
compute_content_id(advisory2), | ||
) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters