test.govlab/quality/core/parsers/tool.bandit.parser.test.ts

test.govlab/quality/core/parsers/tool.bandit.parser.test.ts is a file in Codebase Testing. 49 lines of code and 0 definitions.

import { describe, expect, it } from "vitest";
import { parseBanditOutput } from "@govlab/quality/core/parsers/tool.bandit.parser.ts";

const EXPECTED_COUNT = 2;

const RECORDED = JSON.stringify({
    errors: [],
    results: [
        {
            col_offset: 4,
            filename: "app.py",
            issue_severity: "HIGH",
            issue_text: "subprocess call with shell=True identified, security issue.",
            line_number: 7,
            test_id: "B602",
            test_name: "subprocess_popen_with_shell_equals_true",
        },
        {
            col_offset: 0,
            filename: "app.py",
            issue_severity: "LOW",
            issue_text: "Consider possible security implications associated with the subprocess module.",
            line_number: 1,
            test_id: "B404",
            test_name: "blacklist",
        },
    ],
});

describe("parseBanditOutput", () => {
    it("maps every result to an ADVISORY finding (advisory:true, never gates)", () => {
        const findings = parseBanditOutput(RECORDED, "python");
        expect(findings).toHaveLength(EXPECTED_COUNT);
        expect(findings.every((finding) => finding.advisory)).toBe(true);
        expect(findings[0]).toMatchObject({
            advisory: true,
            column: 5,
            ecosystem: "python",
            file: "app.py",
            line: 7,
            ruleId: "B602",
            severity: "error",
            tool: "bandit",
        });
        expect(findings[1]).toMatchObject({ advisory: true, column: 1, ruleId: "B404", severity: "error" });
    });

    it("returns [] on empty, no-results, or non-JSON output", () => {
        expect(parseBanditOutput("", "python")).toEqual([]);
        expect(parseBanditOutput("{}", "python")).toEqual([]);
        expect(parseBanditOutput("not json", "python")).toEqual([]);
    });
});