Add bats-core tests and SECURITY.md - #5
Merged
farazulhoda merged 1 commit intoSep 27, 2026
Merged
Conversation
Adds tests/ with a bats-core suite covering the scripts that have real logic: authorization.sh (denies without a ticket, denies unlisted targets, allows approved ones, glob matching), audit_log.sh (dir/file permissions, structured fields, append behavior, never fails the caller), nmap.sh, host.sh, and scanPlus.sh (authorization gate enforcement), pidof.sh, and log-retention.sh's root check. Tests deliberately stop at the authorization boundary and never make live network calls (no real curl/nmap/port probes) — they're safe to run in CI without a network or a real target. nmap.sh's test uses a stub nmap on PATH instead. Wired a `tests` job into CI (.github/workflows/ci.yml) alongside ShellCheck and gitleaks. Added SECURITY.md documenting the authorization/audit/retention/ privileged-access model these scripts now implement, and the data classification policy for their output — the reference doc for anyone extending this repo. Verified locally: 21/21 bats tests pass, shellcheck and gitleaks clean. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
farazulhoda
added this pull request to stack #6
September 27, 2026 06:59
farazulhoda
added a commit
that referenced
this pull request
Sep 27, 2026
Merge pull request #5 from farazulhoda/feature/tests-and-security-docs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on #4 (sudoers allowlist), which is stacked on #3 (authorization gate) — merge those first, then this.
tests/with a bats-core suite for the scripts that have real logic:authorization.sh,audit_log.sh,nmap.sh,host.sh,scanPlus.sh,pidof.sh, andlog-retention.sh's root check.nmap.sh's test uses a stubnmaponPATH.testsjob into CI alongside ShellCheck and gitleaks.SECURITY.md: the reference doc for the authorization/audit/retention/privileged-access model this repo now implements, and the data classification policy for script output.Test plan
bats tests/— 21/21 passing locallyshellcheckclean across the repogitleaks detectcleantestsjob added and will run on this PR🤖 Generated with Claude Code