Merge pull request #873 from crazy-max/bake-attest-check
buildx(bake): funcs to check attest set in bake definition
This commit is contained in:
@@ -485,3 +485,113 @@ describe('hasGitAuthTokenSecret', () => {
|
|||||||
expect(Bake.hasGitAuthTokenSecret(def)).toEqual(expected);
|
expect(Bake.hasGitAuthTokenSecret(def)).toEqual(expected);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe('hasProvenanceAttestation', () => {
|
||||||
|
// prettier-ignore
|
||||||
|
test.each([
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "provenance",
|
||||||
|
"mode": "max"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
true
|
||||||
|
],
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "sbom"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
false
|
||||||
|
],
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "sbom"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"type": "provenance",
|
||||||
|
"mode": "max"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
true
|
||||||
|
]
|
||||||
|
])('given %o returns %p', async (def: BakeDefinition, expected: boolean) => {
|
||||||
|
expect(Bake.hasProvenanceAttestation(def)).toEqual(expected);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('hasSBOMAttestation', () => {
|
||||||
|
// prettier-ignore
|
||||||
|
test.each([
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "provenance",
|
||||||
|
"mode": "max"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
false
|
||||||
|
],
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "sbom"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
true
|
||||||
|
],
|
||||||
|
[
|
||||||
|
{
|
||||||
|
"target": {
|
||||||
|
"build": {
|
||||||
|
"attest": [
|
||||||
|
{
|
||||||
|
"type": "sbom"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"type": "provenance",
|
||||||
|
"mode": "max"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
}
|
||||||
|
} as unknown as BakeDefinition,
|
||||||
|
true
|
||||||
|
]
|
||||||
|
])('given %o returns %p', async (def: BakeDefinition, expected: boolean) => {
|
||||||
|
expect(Bake.hasSBOMAttestation(def)).toEqual(expected);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|||||||
@@ -424,4 +424,34 @@ export class Bake {
|
|||||||
}
|
}
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public static hasProvenanceAttestation(def: BakeDefinition): boolean {
|
||||||
|
return Bake.hasAttestationType('provenance', Bake.attestations(def));
|
||||||
|
}
|
||||||
|
|
||||||
|
public static hasSBOMAttestation(def: BakeDefinition): boolean {
|
||||||
|
return Bake.hasAttestationType('sbom', Bake.attestations(def));
|
||||||
|
}
|
||||||
|
|
||||||
|
public static hasAttestationType(name: string, attestations: Array<AttestEntry>): boolean {
|
||||||
|
for (const attestation of attestations) {
|
||||||
|
if (attestation.type == name) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
private static attestations(def: BakeDefinition): Array<AttestEntry> {
|
||||||
|
const attestations = new Array<AttestEntry>();
|
||||||
|
for (const key in def.target) {
|
||||||
|
const target = def.target[key];
|
||||||
|
if (target.attest) {
|
||||||
|
for (const attest of target.attest) {
|
||||||
|
attestations.push(Bake.parseAttestEntry(attest));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return attestations;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user