Skip to content

Commit 004cae4

Browse files
committed
fix(ci): use full scans outside pull requests
1 parent 90462b7 commit 004cae4

2 files changed

Lines changed: 31 additions & 5 deletions

File tree

‎socketsecurity/socketcli.py‎

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -139,6 +139,14 @@ def _select_pull_request_provider(integration_type: str, scm_type: str) -> str:
139139
return scm_type if scm_type in ("github", "gitlab") else integration_type
140140

141141

142+
def _should_create_scm_diff(
143+
event_type: str,
144+
enable_diff: bool = False,
145+
force_diff_mode: bool = False,
146+
) -> bool:
147+
return event_type == "diff" or enable_diff or force_diff_mode
148+
149+
142150
def build_socket_sdk(config: CliConfig) -> socketdev:
143151
cli_user_agent_string = f"SocketPythonCLI/{config.version}"
144152
return socketdev(
@@ -684,7 +692,8 @@ def _is_unprocessed(c):
684692
return False
685693
return True
686694

687-
if scm is not None and scm.check_event_type() == "comment":
695+
scm_event_type = scm.check_event_type() if scm is not None else None
696+
if scm_event_type == "comment":
688697
# FIXME: This entire flow should be a separate command called "filter_ignored_alerts_in_comments"
689698
# It's not related to scanning or diff generation - it just:
690699
# 1. Triggers on comments in GitHub/GitLab
@@ -738,9 +747,13 @@ def _is_unprocessed(c):
738747
else:
739748
log.info("Ignore commands disabled (--disable-ignore), skipping comment processing")
740749

741-
elif scm is not None and scm.check_event_type() != "comment" and not force_api_mode:
750+
elif scm is not None and not force_api_mode:
742751
log.info("Push initiated flow")
743-
if scm.check_event_type() == "diff":
752+
if _should_create_scm_diff(
753+
scm_event_type,
754+
enable_diff=config.enable_diff,
755+
force_diff_mode=force_diff_mode,
756+
):
744757
log.info("Starting comment logic for PR/MR event")
745758
diff = core.create_new_diff(
746759
scan_paths,
@@ -878,15 +891,14 @@ def _is_unprocessed(c):
878891
)
879892
else:
880893
log.info("Starting non-PR/MR flow")
881-
diff = core.create_new_diff(
894+
diff = core.create_full_scan_with_report_url(
882895
scan_paths,
883896
params,
884897
no_change=should_skip_scan,
885898
save_files_list_path=config.save_submitted_files_list,
886899
save_manifest_tar_path=config.save_manifest_tar,
887900
base_paths=base_paths,
888901
explicit_files=scan_explicit_files,
889-
external_href=pr_context.url,
890902
)
891903

892904
output_handler.handle_output(diff)

‎tests/unit/test_socketcli.py‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,20 @@ def test_pr_context_provider_uses_integration_without_comment_adapter():
7474
assert socketcli._select_pull_request_provider("azure", "api") == "azure"
7575

7676

77+
def test_scm_merge_request_event_creates_diff():
78+
assert socketcli._should_create_scm_diff("diff") is True
79+
80+
81+
def test_scm_branch_event_defaults_to_full_scan():
82+
assert socketcli._should_create_scm_diff("main") is False
83+
84+
85+
@pytest.mark.parametrize("override", ["enable_diff", "force_diff_mode"])
86+
def test_scm_branch_event_honors_diff_override(override):
87+
options = {override: True}
88+
assert socketcli._should_create_scm_diff("main", **options) is True
89+
90+
7791
# ---------------------------------------------------------------------------
7892
# Buildkite-aware infrastructure error formatting.
7993
# ---------------------------------------------------------------------------

0 commit comments

Comments
 (0)