|
7 | 7 | # See https://aboutcode.org for more information about nexB OSS projects. |
8 | 8 | # |
9 | 9 |
|
10 | | -import pytest |
| 10 | +from datetime import datetime |
| 11 | + |
| 12 | +from django.core.exceptions import ValidationError |
| 13 | +from django.test import TestCase |
11 | 14 | from django.utils import timezone |
12 | 15 | from packageurl import PackageURL |
13 | 16 | from univers.version_range import VersionRange |
|
18 | 21 | from vulnerabilities.importer import Reference |
19 | 22 | from vulnerabilities.pipes.advisory import get_or_create_aliases |
20 | 23 | from vulnerabilities.pipes.advisory import import_advisory |
| 24 | +from vulnerabilities.utils import compute_content_id |
21 | 25 |
|
22 | | -advisory_data1 = AdvisoryData( |
23 | | - summary="vulnerability description here", |
24 | | - affected_packages=[ |
25 | | - AffectedPackage( |
26 | | - package=PackageURL(type="pypi", name="dummy"), |
27 | | - affected_version_range=VersionRange.from_string("vers:pypi/>=1.0.0|<=2.0.0"), |
28 | | - ) |
29 | | - ], |
30 | | - references=[Reference(url="https://example.com/with/more/info/CVE-2020-13371337")], |
31 | | - date_published=timezone.now(), |
32 | | - url="https://test.com", |
33 | | -) |
34 | 26 |
|
| 27 | +class TestPipeAdvisory(TestCase): |
| 28 | + def setUp(self): |
| 29 | + self.advisory_data1 = AdvisoryData( |
| 30 | + summary="vulnerability description here", |
| 31 | + affected_packages=[ |
| 32 | + AffectedPackage( |
| 33 | + package=PackageURL(type="pypi", name="dummy"), |
| 34 | + affected_version_range=VersionRange.from_string("vers:pypi/>=1.0.0|<=2.0.0"), |
| 35 | + ) |
| 36 | + ], |
| 37 | + references=[Reference(url="https://example.com/with/more/info/CVE-2020-13371337")], |
| 38 | + date_published=timezone.now(), |
| 39 | + url="https://test.com", |
| 40 | + ) |
35 | 41 |
|
36 | | -def get_advisory1(created_by="test_pipeline"): |
37 | | - from vulnerabilities.pipes.advisory import insert_advisory |
| 42 | + def get_advisory1(self, created_by="test_pipeline"): |
| 43 | + from vulnerabilities.pipes.advisory import insert_advisory |
38 | 44 |
|
39 | | - return insert_advisory( |
40 | | - advisory=advisory_data1, |
41 | | - pipeline_id=created_by, |
42 | | - ) |
| 45 | + return insert_advisory( |
| 46 | + advisory=self.advisory_data1, |
| 47 | + pipeline_id=created_by, |
| 48 | + ) |
43 | 49 |
|
| 50 | + def get_all_vulnerability_relationships_objects(self): |
| 51 | + return { |
| 52 | + "vulnerabilities": list(models.Vulnerability.objects.all()), |
| 53 | + "aliases": list(models.Alias.objects.all()), |
| 54 | + "references": list(models.VulnerabilityReference.objects.all()), |
| 55 | + "advisories": list(models.Advisory.objects.all()), |
| 56 | + "packages": list(models.Package.objects.all()), |
| 57 | + "references": list(models.VulnerabilityReference.objects.all()), |
| 58 | + "severity": list(models.VulnerabilitySeverity.objects.all()), |
| 59 | + } |
44 | 60 |
|
45 | | -def get_all_vulnerability_relationships_objects(): |
46 | | - return { |
47 | | - "vulnerabilities": list(models.Vulnerability.objects.all()), |
48 | | - "aliases": list(models.Alias.objects.all()), |
49 | | - "references": list(models.VulnerabilityReference.objects.all()), |
50 | | - "advisories": list(models.Advisory.objects.all()), |
51 | | - "packages": list(models.Package.objects.all()), |
52 | | - "references": list(models.VulnerabilityReference.objects.all()), |
53 | | - "severity": list(models.VulnerabilitySeverity.objects.all()), |
54 | | - } |
| 61 | + def test_vulnerability_pipes_importer_import_advisory(self): |
| 62 | + advisory1 = self.get_advisory1(created_by="test_importer_pipeline") |
| 63 | + import_advisory(advisory=advisory1, pipeline_id="test_importer_pipeline") |
| 64 | + all_vulnerability_relation_objects = self.get_all_vulnerability_relationships_objects() |
| 65 | + import_advisory(advisory=advisory1, pipeline_id="test_importer_pipeline") |
| 66 | + assert ( |
| 67 | + all_vulnerability_relation_objects == self.get_all_vulnerability_relationships_objects() |
| 68 | + ) |
55 | 69 |
|
| 70 | + def test_vulnerability_pipes_importer_import_advisory_different_pipelines(self): |
| 71 | + advisory1 = self.get_advisory1(created_by="test_importer_pipeline") |
| 72 | + import_advisory(advisory=advisory1, pipeline_id="test_importer1_pipeline") |
| 73 | + all_vulnerability_relation_objects = self.get_all_vulnerability_relationships_objects() |
| 74 | + import_advisory(advisory=advisory1, pipeline_id="test_importer2_pipeline") |
| 75 | + assert ( |
| 76 | + all_vulnerability_relation_objects == self.get_all_vulnerability_relationships_objects() |
| 77 | + ) |
56 | 78 |
|
57 | | -@pytest.mark.django_db |
58 | | -def test_vulnerability_pipes_importer_import_advisory(): |
59 | | - advisory1 = get_advisory1(created_by="test_importer_pipeline") |
60 | | - import_advisory(advisory=advisory1, pipeline_id="test_importer_pipeline") |
61 | | - all_vulnerability_relation_objects = get_all_vulnerability_relationships_objects() |
62 | | - import_advisory(advisory=advisory1, pipeline_id="test_importer_pipeline") |
63 | | - assert all_vulnerability_relation_objects == get_all_vulnerability_relationships_objects() |
| 79 | + def test_vulnerability_pipes_get_or_create_aliases(self): |
| 80 | + aliases = ["CVE-TEST-123", "CVE-TEST-124"] |
| 81 | + result_aliases_qs = get_or_create_aliases(aliases=aliases) |
| 82 | + result_aliases = [i.alias for i in result_aliases_qs] |
| 83 | + assert 2 == result_aliases_qs.count() |
| 84 | + assert "CVE-TEST-123" in result_aliases |
| 85 | + assert "CVE-TEST-124" in result_aliases |
64 | 86 |
|
| 87 | + def test_advisory_insert_without_url(self): |
| 88 | + with self.assertRaises(ValidationError): |
| 89 | + date = datetime.now() |
| 90 | + models.Advisory.objects.create( |
| 91 | + unique_content_id=compute_content_id(advisory_data=self.advisory_data1), |
| 92 | + summary=self.advisory_data1.summary, |
| 93 | + affected_packages=[pkg.to_dict() for pkg in self.advisory_data1.affected_packages], |
| 94 | + references=[ref.to_dict() for ref in self.advisory_data1.references], |
| 95 | + date_imported=date, |
| 96 | + date_collected=date, |
| 97 | + created_by="test_pipeline", |
| 98 | + ) |
65 | 99 |
|
66 | | -@pytest.mark.django_db |
67 | | -def test_vulnerability_pipes_importer_import_advisory_different_pipelines(): |
68 | | - advisory1 = get_advisory1(created_by="test_importer_pipeline") |
69 | | - import_advisory(advisory=advisory1, pipeline_id="test_importer1_pipeline") |
70 | | - all_vulnerability_relation_objects = get_all_vulnerability_relationships_objects() |
71 | | - import_advisory(advisory=advisory1, pipeline_id="test_importer2_pipeline") |
72 | | - assert all_vulnerability_relation_objects == get_all_vulnerability_relationships_objects() |
| 100 | + def test_advisory_insert_without_content_id(self): |
| 101 | + with self.assertRaises(ValidationError): |
| 102 | + date = datetime.now() |
| 103 | + models.Advisory.objects.create( |
| 104 | + url=self.advisory_data1.url, |
| 105 | + summary=self.advisory_data1.summary, |
| 106 | + affected_packages=[pkg.to_dict() for pkg in self.advisory_data1.affected_packages], |
| 107 | + references=[ref.to_dict() for ref in self.advisory_data1.references], |
| 108 | + date_imported=date, |
| 109 | + date_collected=date, |
| 110 | + created_by="test_pipeline", |
| 111 | + ) |
73 | 112 |
|
| 113 | + def test_advisory_insert_no_duplicate_content_id(self): |
| 114 | + date = datetime.now() |
| 115 | + models.Advisory.objects.create( |
| 116 | + unique_content_id=compute_content_id(advisory_data=self.advisory_data1), |
| 117 | + url=self.advisory_data1.url, |
| 118 | + summary=self.advisory_data1.summary, |
| 119 | + affected_packages=[pkg.to_dict() for pkg in self.advisory_data1.affected_packages], |
| 120 | + references=[ref.to_dict() for ref in self.advisory_data1.references], |
| 121 | + date_imported=date, |
| 122 | + date_collected=date, |
| 123 | + created_by="test_pipeline", |
| 124 | + ) |
74 | 125 |
|
75 | | -@pytest.mark.django_db |
76 | | -def test_vulnerability_pipes_get_or_create_aliases(): |
77 | | - aliases = ["CVE-TEST-123", "CVE-TEST-124"] |
78 | | - result_aliases_qs = get_or_create_aliases(aliases=aliases) |
79 | | - result_aliases = [i.alias for i in result_aliases_qs] |
80 | | - assert 2 == result_aliases_qs.count() |
81 | | - assert "CVE-TEST-123" in result_aliases |
82 | | - assert "CVE-TEST-124" in result_aliases |
| 126 | + with self.assertRaises(ValidationError): |
| 127 | + models.Advisory.objects.create( |
| 128 | + unique_content_id=compute_content_id(advisory_data=self.advisory_data1), |
| 129 | + url=self.advisory_data1.url, |
| 130 | + summary=self.advisory_data1.summary, |
| 131 | + affected_packages=[pkg.to_dict() for pkg in self.advisory_data1.affected_packages], |
| 132 | + references=[ref.to_dict() for ref in self.advisory_data1.references], |
| 133 | + date_imported=date, |
| 134 | + date_collected=date, |
| 135 | + created_by="test_pipeline", |
| 136 | + ) |
0 commit comments