Skip to content

Make ruleset verifiable by including manifest file

Julian Thome requested to merge julianthome/rule-verification into main

What does this MR do?

This MR adds the logic to compare the manifest.json that is now added to every sast-rules release. It compares the entries of the manifest file against the rule files that are active during the scan and reports differences. Add a test or review step that explicitly check... (gitlab-org/gitlab#463607 - closed) • Julian Thome • 17.3 • On track provides a more detailed documentation of the general approach.

What are the relevant issue numbers?

Add a test or review step that explicitly check... (gitlab-org/gitlab#463607 - closed) • Julian Thome • 17.3 • On track

Does this MR meet the acceptance criteria?

Edited by Julian Thome

Merge request reports

Loading