Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -180,6 +180,12 @@ The project uses `just` as a command runner to encapsulate common workflows.
* `just fix`
* Runs `cargo fix` and `cargo machete` / `cargo machete --fix` to clean up unused dependencies and minor issues.

* `just update`
* Updates flake inputs, Cargo deps and pre-commit hooks, and runs `just update-cli-scanner`.

* `just update-cli-scanner`
* Bumps the pinned Sysdig CLI scanner version in `src/infra/scanner_binary_manager.rs` to the latest release. It rewrites the lines tagged with `newest-version-marker`; do not remove those markers.

Additional helpful commands:

* `cargo test -- --nocapture` – run tests with full output when debugging.
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "sysdig-lsp"
version = "0.9.0"
version = "0.9.1"
edition = "2024"
authors = [ "Sysdig Inc." ]
readme = "README.md"
Expand Down
12 changes: 12 additions & 0 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,15 @@ update:
nix flake update
nix develop --command cargo update
nix develop --command pre-commit autoupdate
nix develop --command just update-cli-scanner

# Bump the pinned sysdig-cli-scanner to the latest version (lines tagged with newest-version-marker)
update-cli-scanner:
#!/usr/bin/env bash
set -euo pipefail
latest=$(curl --silent --show-error --fail --location https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt | tr -d '[:space:]')
IFS=. read -r major minor patch <<< "$latest"
file=src/infra/scanner_binary_manager.rs
sd 'Version::new\(\d+, \d+, \d+\)(.*newest-version-marker)' "Version::new($major, $minor, $patch)\${1}" "$file"
sd '"\d+\.\d+\.\d+"(.*newest-version-marker)' "\"$latest\"\${1}" "$file"
echo "sysdig-cli-scanner -> $latest"
2 changes: 2 additions & 0 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -45,12 +45,14 @@
cargo-nextest
cargo-tarpaulin
clippy
curl
just
lldb
pre-commit
rust-analyzer
rustc
rustfmt
sd
];

inputsFrom = [ sysdig-lsp ];
Expand Down
4 changes: 4 additions & 0 deletions src/domain/scanresult/package_type.rs
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,8 @@ pub enum PackageType {
Ruby,
Php,
CSharp,
Oci,
SoftwareRuntime,
}

impl Display for PackageType {
Expand All @@ -30,6 +32,8 @@ impl Display for PackageType {
PackageType::Ruby => "ruby",
PackageType::Php => "php",
PackageType::CSharp => "csharp",
PackageType::Oci => "oci",
PackageType::SoftwareRuntime => "software runtime",
}
)
}
Expand Down
8 changes: 4 additions & 4 deletions src/infra/scanner_binary_manager.rs
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ pub(super) struct ScannerBinaryManager {}

impl ScannerBinaryManager {
const fn version(&self) -> Version {
Version::new(1, 23, 0)
Version::new(1, 30, 1) // newest-version-marker — DO NOT REMOVE; auto-updated by `just update-cli-scanner`
}

pub async fn install_expected_version_if_not_present(
Expand Down Expand Up @@ -197,7 +197,7 @@ mod tests {
async fn it_gets_the_wanted_version() {
let mgr = ScannerBinaryManager::default();

assert_eq!(mgr.version().to_string(), "1.23.0");
assert_eq!(mgr.version().to_string(), "1.30.1"); // newest-version-marker — DO NOT REMOVE; auto-updated by `just update-cli-scanner`
}

#[tokio::test]
Expand Down Expand Up @@ -237,7 +237,7 @@ mod tests {
.await
.unwrap()
.to_string(),
"1.23.0"
mgr.version().to_string()
);
}

Expand All @@ -260,7 +260,7 @@ mod tests {
.await
.unwrap()
.to_string(),
"1.23.0"
mgr.version().to_string()
);
}
}
23 changes: 21 additions & 2 deletions src/infra/sysdig_image_scanner_json_scan_result_v1.rs
Original file line number Diff line number Diff line change
Expand Up @@ -372,6 +372,10 @@ pub(super) enum JsonPackageType {
Ruby,
#[serde(rename = "rust")]
Rust,
#[serde(rename = "oci")]
Oci,
#[serde(rename = "Software Runtime")]
SoftwareRuntime,
#[default]
Unknown,
}
Expand All @@ -388,6 +392,8 @@ impl From<JsonPackageType> for PackageType {
JsonPackageType::Python => Self::Python,
JsonPackageType::Ruby => Self::Ruby,
JsonPackageType::Rust => Self::Rust,
JsonPackageType::Oci => Self::Oci,
JsonPackageType::SoftwareRuntime => Self::SoftwareRuntime,
JsonPackageType::Unknown => Self::Unknown,
}
}
Expand Down Expand Up @@ -571,8 +577,10 @@ pub(super) struct JsonVulnerability {
#[cfg(test)]
mod tests {
use crate::{
domain::scanresult::{scan_result::ScanResult, severity::Severity},
infra::sysdig_image_scanner_json_scan_result_v1::JsonScanResultV1,
domain::scanresult::{
package_type::PackageType, scan_result::ScanResult, severity::Severity,
},
infra::sysdig_image_scanner_json_scan_result_v1::{JsonPackageType, JsonScanResultV1},
};

#[test]
Expand Down Expand Up @@ -672,4 +680,15 @@ mod tests {
assert!(found_layer.is_some(), "Should find layer by valid digest");
assert_eq!(found_layer.unwrap().digest(), Some(digest));
}

#[rstest::rstest]
#[case(r#""oci""#, PackageType::Oci)]
#[case(r#""Software Runtime""#, PackageType::SoftwareRuntime)]
fn it_deserializes_package_types_added_in_newer_scanners(
#[case] json: &str,
#[case] expected: PackageType,
) {
let package_type: JsonPackageType = serde_json::from_str(json).unwrap();
assert_eq!(PackageType::from(package_type), expected);
}
}
Loading