feat: add cds report compliance/evidence report command - #766
Open
RonaldHensbergen wants to merge 5 commits into
Open
RonaldHensbergen wants to merge 5 commits into
RonaldHensbergen wants to merge 5 commits into
Conversation
Adds `cds report <profile>` which exports a single, exportable
readiness-evidence snapshot for a rendered stack: resolved module list
(id/source/version/dependsOn), linked signature/SBOM/provenance
evidence per image (looked up from the signed-images fixture, with
graceful degradation and a W101 warning for locally-built or
unlinkable images instead of a hard failure), the contract/topology
graph, and a secret-leak check (E119) confirming no profile-declared
secret value renders literally into Compose output instead of a
${CDS_*} placeholder.
Supports human-readable text (default) or --json, and --output/-o to
save to a file. Diagnostics are always printed to stderr so --json
output stays parseable.
Fixes #734.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Adds in-process tests for cli.main's report command (json/text output, diagnostics-to-stderr, exit codes, --output) and for build_compliance_report's validate/plan/render failure branches and cli.report's edge cases, bringing new-code coverage to 100% on cli/report.py and cli/image_verification.py's lookup_image_evidence. Fixes a Sonar/Bandit false positive (S105/S107) by renaming a test helper's 'secret_status' parameter to 'leak_status'. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- File #767 (GitOps), #768 (DB operator), #769 (cds maturity) for the three haven-parity-plan workstreams that had no issue yet. - Create milestone 'Dutch Public-Sector Data & Security Alignment' and file #771 (Cyberbeveiligingswet/NIS2 scope), #772 (Common Ground/Haven reference profile), #773 (FDS data-provider alignment), #774 (NIS2-aligned cds security reporting). - Cross-link the new issues from docs/roadmap.md and update docs/haven-parity-plan.md's status table and next steps accordingly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
markdownlint's MD033/no-inline-html rule rejected the <span style=...> color spans used to visually mark resolved/CRA-tagged rows. Convert those rows to plain Markdown (strikethrough for resolved items) with no styling loss to the table's information content. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Adds
cds report <profile>which exports a single, exportable readiness-evidence snapshot for a rendered stack, resolving issue #734.The report aggregates:
tests/fixtures/signed-images.json(no new verification pipeline is duplicated — reusescli/image_verification.py's existing fixture lookup via a new publiclookup_image_evidence()wrapper).dependsOnedges.spec.secrets.values) render literally into the Compose output instead of a${CDS_*}placeholder.Missing evidence degrades gracefully instead of failing the report:
not-available, no diagnostic (expected dev state).not-available+W101warning.not-available+W101warning, distinct reason.E119error,secretLeakCheck.status: fail, exit code1.Supports human-readable text (default) or
--json, and--output/-oto save to a file. Diagnostics are always printed to stderr so--jsonstdout output stays parseable.New docs:
docs/compliance-report.md, including the required disclaimer that this is readiness evidence, not a legal compliance/conformity certification — cross-linked fromdocs/image-signing.md/docs/image-scanning.md.Testing
tests/test_report.py(13 tests): module/topology summary assembly, image evidence for available/local-build/no-match/no-fixture-configured cases, secret-leak pass/fail, and a regression test confirming non-declaredCDS_*env vars (e.g. a database name) are excluded from the leak scan so they don't false-positive. Plus CLI-level smoke tests for text/--json/--output.ruff checkclean,markdownlintclean on the new doc.python scripts/run_tests_with_deprecation_gate.py→ 977 tests, only the 3 pre-existing, unrelatedProductionPlaintextExposureWorkflowTestfailures (reproduced identically on a cleanmaincheckout — not caused by this change).Fixes #734.