Add unit tests for AST parsing and security sink detection
- Created `StellaOps.AuditPack.Tests.csproj` for unit testing the AuditPack library. - Implemented comprehensive unit tests in `index.test.js` for AST parsing, covering various JavaScript and TypeScript constructs including functions, classes, decorators, and JSX. - Added `sink-detect.test.js` to test security sink detection patterns, validating command injection, SQL injection, file write, deserialization, SSRF, NoSQL injection, and more. - Included tests for taint source detection in various contexts such as Express, Koa, and AWS Lambda.
This commit is contained in:
@@ -80,9 +80,9 @@ public sealed class TrustPolicyLoader : ITrustPolicyLoader
|
||||
continue;
|
||||
}
|
||||
|
||||
value ??= new TrustPolicyAttestation();
|
||||
value.Signers ??= new List<TrustPolicySigner>();
|
||||
normalizedAttestations[key.Trim()] = value;
|
||||
var attestation = value ?? new TrustPolicyAttestation();
|
||||
attestation.Signers ??= new List<TrustPolicySigner>();
|
||||
normalizedAttestations[key.Trim()] = attestation;
|
||||
}
|
||||
|
||||
policy.Attestations = normalizedAttestations;
|
||||
|
||||
Reference in New Issue
Block a user