/** * A suppression that names no known check must be reported, not silently * ignored (M-BUG-28, prediction 8). * * This is what makes the ID-semantics change safe to ship: pins written against * the old positional numbering either still name a real check, or they now name * nothing — and "nothing" has to be visible. A silently-dead suppression is the * same failure the old scheme had, just in the other direction. */ import { describe, it } from 'node:test'; import assert from 'node:assert/strict'; import { parseIgnoreFile, unknownSuppressions } from '../../scanners/lib/suppression.mjs'; import { FINDING_CODES } from '../../scanners/lib/finding-codes.mjs'; /** * The next number no check in `scanner` occupies, DERIVED rather than written * down. An unoccupied number is a moving target — every added check claims one — * so a literal here expires the moment the registry grows, which is what C4 * (claiming CA-GAP-028) demonstrated. Derived, the input is unoccupied by * construction; the assertion it feeds is unchanged. */ function firstFreeId(scanner) { const n = Math.max(...Object.values(FINDING_CODES[scanner])) + 1; return `CA-${scanner}-${String(n).padStart(3, '0')}`; } describe('unknownSuppressions', () => { it('accepts an exact ID that names a declared check', () => { const s = parseIgnoreFile('CA-SKL-003\n'); assert.deepEqual(unknownSuppressions(s), []); }); it('reports an exact ID that names no declared check', () => { // CA-GAP-099 has never existed; the PLH one is past the end of PLH's range. const pastEnd = firstFreeId('PLH'); const s = parseIgnoreFile(`CA-GAP-099\n${pastEnd}\n`); assert.deepEqual(unknownSuppressions(s), ['CA-GAP-099', pastEnd]); }); it('reports an ID whose number no check occupies rather than pretending it matches', () => { // The registry never reissues a retired key's number, so an ID can name a // hole. Any unoccupied number exercises the same path. const free = firstFreeId('GAP'); const s = parseIgnoreFile(`${free}\n`); assert.deepEqual(unknownSuppressions(s), [free]); }); it('accepts a scanner-wide glob for a real scanner', () => { const s = parseIgnoreFile('CA-GAP-*\nCA-PLH-*\n'); assert.deepEqual(unknownSuppressions(s), []); }); it('reports a glob for a scanner that does not exist', () => { const s = parseIgnoreFile('CA-XYZ-*\n'); assert.deepEqual(unknownSuppressions(s), ['CA-XYZ-*']); }); it('stays quiet on an empty ignore file', () => { assert.deepEqual(unknownSuppressions(parseIgnoreFile('# just a comment\n')), []); assert.deepEqual(unknownSuppressions([]), []); }); });