Skip to content

fix(report): preserve archive member provenance in JSON - #816

Open
mohgupta-ship-it wants to merge 1 commit into
mainfrom
codex/fix-archive-component-paths
Open

mohgupta-ship-it wants to merge 1 commit into
mainfrom
codex/fix-archive-component-paths

Conversation

@mohgupta-ship-it

Copy link
Copy Markdown
Member

JSON component rows omitted archive provenance already present in the scanner inventory. A consumer therefore received paths such as bundle.whl!/package/module.py without the structured container and member fields needed to interpret them.

Preserve outer_path, nested_path, and container metadata for archive members while keeping the existing virtual path, executable flags, source identity, findings, risk scoring, and completeness behavior. Ordinary filenames containing !/ remain ordinary files. Document how consumers should interpret the additive fields; existing consumer validators still need to adopt them.

Validation:

  • 408 focused report and archive tests passed, including eight new regression cases.
  • Repository lint and formatting checks passed.
  • A freshly built and installed wheel preserved provenance for synthetic wheels, retained SC9 findings, and rejected an incomplete nested archive with exit 2.
  • The complete Python suite was not completed locally. Local Docker smoke testing was unavailable because the container service could not be reached; both remain CI checks.

Prepared by Codex on Mohit's behalf.

Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant