Skip to content

Add bats-core tests and SECURITY.md - #5

Merged
farazulhoda merged 1 commit into
feature/sudoers-allowlistfrom
feature/tests-and-security-docs
Sep 27, 2026
Merged

farazulhoda merged 1 commit into
feature/sudoers-allowlistfrom
feature/tests-and-security-docs

Conversation

@farazulhoda

Copy link
Copy Markdown
Owner

Summary

Stacked on #4 (sudoers allowlist), which is stacked on #3 (authorization gate) — merge those first, then this.

  • Adds tests/ with a bats-core suite for the scripts that have real logic: authorization.sh, audit_log.sh, nmap.sh, host.sh, scanPlus.sh, pidof.sh, and log-retention.sh's root check.
  • Tests deliberately stop at the authorization boundary — no live network calls, no real target required, safe in CI. nmap.sh's test uses a stub nmap on PATH.
  • Wires a tests job into CI alongside ShellCheck and gitleaks.
  • Adds SECURITY.md: the reference doc for the authorization/audit/retention/privileged-access model this repo now implements, and the data classification policy for script output.

Test plan

  • bats tests/ — 21/21 passing locally
  • shellcheck clean across the repo
  • gitleaks detect clean
  • CI tests job added and will run on this PR

🤖 Generated with Claude Code

Adds tests/ with a bats-core suite covering the scripts that have real
logic: authorization.sh (denies without a ticket, denies unlisted
targets, allows approved ones, glob matching), audit_log.sh (dir/file
permissions, structured fields, append behavior, never fails the
caller), nmap.sh, host.sh, and scanPlus.sh (authorization gate
enforcement), pidof.sh, and log-retention.sh's root check.

Tests deliberately stop at the authorization boundary and never make
live network calls (no real curl/nmap/port probes) — they're safe to
run in CI without a network or a real target. nmap.sh's test uses a
stub nmap on PATH instead.

Wired a `tests` job into CI (.github/workflows/ci.yml) alongside
ShellCheck and gitleaks.

Added SECURITY.md documenting the authorization/audit/retention/
privileged-access model these scripts now implement, and the data
classification policy for their output — the reference doc for anyone
extending this repo.

Verified locally: 21/21 bats tests pass, shellcheck and gitleaks clean.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@farazulhoda
farazulhoda added this pull request to stack #6 September 27, 2026 06:59
@farazulhoda
farazulhoda merged commit 6c370de into master Sep 27, 2026
3 of 5 checks passed
farazulhoda added a commit that referenced this pull request Sep 27, 2026
Merge pull request #5 from farazulhoda/feature/tests-and-security-docs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant