mirror of
https://github.com/ossf/scorecard.git
synced 2024-11-05 05:17:00 +03:00
9d2976592f
With this patch applied projects like dracut pass the check: ``` "checks": [ { "details": [ "Debug: GitHub release found: 055", "Info: signed release artifact: dracut-055.tar.sign: https://api.github.com/repos/dracutdevs/dracut/releases/assets/37635937", "Debug: GitHub release found: 054", "Info: signed release artifact: dracut-054.tar.sign: https://api.github.com/repos/dracutdevs/dracut/releases/assets/36958052", "Debug: GitHub release found: 053", "Info: signed release artifact: dracut-053.tar.sign: https://api.github.com/repos/dracutdevs/dracut/releases/assets/32484038", "Debug: GitHub release found: 052", "Info: signed release artifact: dracut-052.tar.sign: https://api.github.com/repos/dracutdevs/dracut/releases/assets/32130796", "Debug: GitHub release found: 051", "Info: signed release artifact: dracut-051.tar.sign: https://api.github.com/repos/dracutdevs/dracut/releases/assets/31933850" ], "score": 10, "reason": "5 out of 5 artifacts are signed -- score normalized to 10", "name": "Signed-Releases", ```
97 lines
2.6 KiB
Go
97 lines
2.6 KiB
Go
// Copyright 2020 Security Scorecard Authors
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package checks
|
|
|
|
import (
|
|
"fmt"
|
|
"strings"
|
|
|
|
"github.com/ossf/scorecard/v3/checker"
|
|
sce "github.com/ossf/scorecard/v3/errors"
|
|
)
|
|
|
|
const (
|
|
// CheckSignedReleases is the registered name for SignedReleases.
|
|
CheckSignedReleases = "Signed-Releases"
|
|
releaseLookBack = 5
|
|
)
|
|
|
|
var artifactExtensions = []string{".asc", ".minisig", ".sig", ".sign"}
|
|
|
|
//nolint:gochecknoinits
|
|
func init() {
|
|
registerCheck(CheckSignedReleases, SignedReleases)
|
|
}
|
|
|
|
// SignedReleases runs Signed-Releases check.
|
|
func SignedReleases(c *checker.CheckRequest) checker.CheckResult {
|
|
releases, err := c.RepoClient.ListReleases()
|
|
if err != nil {
|
|
e := sce.WithMessage(sce.ErrScorecardInternal, fmt.Sprintf("Client.Repositories.ListReleases: %v", err))
|
|
return checker.CreateRuntimeErrorResult(CheckSignedReleases, e)
|
|
}
|
|
|
|
totalReleases := 0
|
|
totalSigned := 0
|
|
for _, r := range releases {
|
|
if len(r.Assets) == 0 {
|
|
continue
|
|
}
|
|
c.Dlogger.Debug3(&checker.LogMessage{
|
|
Text: fmt.Sprintf("GitHub release found: %s", r.TagName),
|
|
})
|
|
totalReleases++
|
|
signed := false
|
|
for _, asset := range r.Assets {
|
|
for _, suffix := range artifactExtensions {
|
|
if strings.HasSuffix(asset.Name, suffix) {
|
|
c.Dlogger.Info3(&checker.LogMessage{
|
|
Path: asset.URL,
|
|
Type: checker.FileTypeURL,
|
|
Text: fmt.Sprintf("signed release artifact: %s", asset.Name),
|
|
})
|
|
signed = true
|
|
break
|
|
}
|
|
}
|
|
if signed {
|
|
totalSigned++
|
|
break
|
|
}
|
|
}
|
|
if !signed {
|
|
c.Dlogger.Warn3(&checker.LogMessage{
|
|
Path: r.URL,
|
|
Type: checker.FileTypeURL,
|
|
Text: fmt.Sprintf("release artifact %s not signed", r.TagName),
|
|
})
|
|
}
|
|
if totalReleases >= releaseLookBack {
|
|
break
|
|
}
|
|
}
|
|
|
|
if totalReleases == 0 {
|
|
c.Dlogger.Warn3(&checker.LogMessage{
|
|
Text: "no GitHub releases found",
|
|
})
|
|
// Generic summary.
|
|
return checker.CreateInconclusiveResult(CheckSignedReleases, "no releases found")
|
|
}
|
|
|
|
reason := fmt.Sprintf("%d out of %d artifacts are signed", totalSigned, totalReleases)
|
|
return checker.CreateProportionalScoreResult(CheckSignedReleases, reason, totalSigned, totalReleases)
|
|
}
|