Add a check for local filesystem paths in report output - #145
Merged
Conversation
Reads artifact source and fails when a staged path reaches a data row or the "located at" line of an artifact decorated with artifact_processor. Runs in the lint job on any Python change. The seeker stages evidence under <report folder>/data, so every files_found entry is an absolute path on the machine running the tool. artifact_processor normalizes only the third element of the return tuple; anything else is published as-is. Nothing else catches this: the column is never empty and the row count is always right. Context.get_relative_path also fails open, and the committed test harness never sets Context._data_folder, so in that harness a leaking artifact and a correct one record identical output. That is why the check reads source rather than a recorded baseline. No artifact in this repo is affected; the check passes here as it stands. It is added for parity with the iLEAPP and ALEAPP copies, which are byte-identical, and to keep the idiom from arriving later. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The seeker stages evidence under the report folder, so a path taken from files_found is absolute on the machine that ran the tool. artifact_processor normalizes only the third element of the return tuple; a path placed in a data row or handed to the report writer is published as-is.
Nothing else catches it: the column is never empty and the row count is always right. The check reads artifact source and runs in the lint job.
No artifact here is affected. Added for parity with the iLEAPP and ALEAPP copies, which are byte-identical.