test.govlab/quality/core/parsers/tool.checkov.parser.test.ts

test.govlab/quality/core/parsers/tool.checkov.parser.test.ts is a file in Codebase Testing. 52 lines of code and 0 definitions.

import { describe, expect, it } from "vitest";
import { parseCheckovOutput } from "@govlab/quality/core/parsers/tool.checkov.parser.ts";

const EXPECTED_COUNT = 2;
const RANGE_END = 10;

const RECORDED = JSON.stringify([
    {
        check_type: "terraform",
        results: {
            failed_checks: [
                {
                    check_id: "CKV_AWS_24",
                    check_name: "Ensure no security groups allow ingress from 0.0.0.0:0 to port 22",
                    file_line_range: [1, RANGE_END],
                    file_path: "\\main.tf",
                    severity: null,
                },
                {
                    check_id: "CKV_AWS_260",
                    check_name: "Ensure no security groups allow ingress from 0.0.0.0:0 to port 80",
                    file_line_range: [1, RANGE_END],
                    file_path: "\\main.tf",
                    severity: "HIGH",
                },
            ],
        },
    },
]);

describe("parseCheckovOutput", () => {
    it("aggregates failed_checks across blocks into ADVISORY findings (advisory:true), stripping the leading separator", () => {
        const findings = parseCheckovOutput(RECORDED, "iac");
        expect(findings).toHaveLength(EXPECTED_COUNT);
        expect(findings.every((finding) => finding.advisory)).toBe(true);
        expect(findings[0]).toMatchObject({
            advisory: true,
            column: 1,
            ecosystem: "iac",
            file: "main.tf",
            line: 1,
            ruleId: "CKV_AWS_24",
            severity: "error",
            tool: "checkov",
        });
        expect(findings[1]).toMatchObject({ advisory: true, ruleId: "CKV_AWS_260", severity: "error" });
    });

    it("returns [] on empty, no-failed-checks, or non-JSON output", () => {
        expect(parseCheckovOutput("", "iac")).toEqual([]);
        expect(
            parseCheckovOutput(JSON.stringify([{ check_type: "terraform", results: { failed_checks: [] } }]), "iac"),
        ).toEqual([]);
        expect(parseCheckovOutput("not json", "iac")).toEqual([]);
    });
});