diff --git a/README.md b/README.md index b202fa4..5b431c2 100644 --- a/README.md +++ b/README.md @@ -96,7 +96,7 @@ steps: verbose: true jsonOutput: true jsonOutputFile: 'sysdig-cli-scan-output.json' - sysdigCliScannerVersion: '1.6.0' + sysdigCliScannerVersion: '1.30.1' # newest-version-marker — DO NOT REMOVE; auto-updated by `just update-cli-scanner` policy: my_custom_policy,my-custom-policy-ab - task: PublishBuildArtifacts@1 @@ -141,7 +141,7 @@ steps: - **JSON Output File (`jsonOutputFile`)**: The file name to export the JSON result to. This will be ignored if `jsonOutput` is `false`. Default: `sysdig-cli-scan-output.json`, -- **Sysdig CLI Scanner Version (`sysdigCliScannerVersion`)**: The version of the Sysdig CLI Scanner to use. Will use the latest version if not specified. Default: `latest`, +- **Sysdig CLI Scanner Version (`sysdigCliScannerVersion`)**: The version of the Sysdig CLI Scanner to use. Will use the latest version if not specified. Versions are supported for 1 year after release; oldest version tested is 1.23.0. Default: `latest`, - **Policy (`policy`)**: Policy to evaluate in the pipeline execution. If not specified, only the Always Apply policy will be evaluated. Default: `null`, diff --git a/azure-pipelines.yml b/azure-pipelines.yml index 831c1e8..324a898 100644 --- a/azure-pipelines.yml +++ b/azure-pipelines.yml @@ -66,8 +66,10 @@ steps: export INPUT_IMAGE='$(imageName)' export INPUT_VERBOSE='true' export INPUT_FAILBUILD='false' - export INPUT_SYSDIGCLISCANNERVERSION='latest' - # Run the task directly - node sysdig-cli-scan-task/dist/index.js + # Run the task directly, with the default (latest) and the oldest supported scanner + for version in latest 1.23.0; do # oldest-version-marker — DO NOT REMOVE; auto-updated by `just update-oldest-cli-scanner` + echo "Running smoke test with sysdig-cli-scanner ${version}..." + INPUT_SYSDIGCLISCANNERVERSION="${version}" node sysdig-cli-scan-task/dist/index.js + done displayName: 'Local smoke-run of the task' \ No newline at end of file diff --git a/flake.nix b/flake.nix index 9a4b15f..fdd4713 100644 --- a/flake.nix +++ b/flake.nix @@ -26,8 +26,12 @@ mkShell { packages = [ azure-cli + # GNU tools the justfile `scanner` recipes rely on (BSD versions on macOS break them). + coreutils curl git + gnugrep + gnused jq just nodejs_22 diff --git a/justfile b/justfile index 00a457a..1f760b7 100644 --- a/justfile +++ b/justfile @@ -30,11 +30,100 @@ publish-release: pin-actions: pinact run -u -# Update everything: flake inputs, tfx-cli, and pinned actions +# Update everything: flake inputs, tfx-cli, pinned actions, and the sysdig-cli-scanner versions update: nix flake update nix develop --command just update-tfx nix develop --command just pin-actions + nix develop --command just update-cli-scanner + nix develop --command just update-oldest-cli-scanner + +# (internal) Print the latest published sysdig-cli-scanner version +[private] +_latest-version: + @curl --silent --fail --show-error --location https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt | tr -d '[:space:]' + +# Find the oldest sysdig-cli-scanner version still within the support window (default 365 days) +oldest-cli-scanner window_days="365": + #!/usr/bin/env bash + set -euo pipefail + base="https://download.sysdig.com/scanning/bin/sysdig-cli-scanner" + os="linux"; arch="amd64" + cutoff=$(( $(date -u +%s) - {{window_days}} * 86400 )) + latest=$(just _latest-version) + major=${latest%%.*} + minor=$(echo "$latest" | cut -d. -f2) + oldest_ver=""; oldest_epoch="" + for m in $(seq "$minor" -1 0); do + minor_hit=0; misses=0 + for p in $(seq 0 30); do + v="$major.$m.$p" + lm=$(curl -sfI "$base/$v/$os/$arch/sysdig-cli-scanner" \ + | grep -i '^last-modified:' | sed 's/^[Ll]ast-[Mm]odified: //' | tr -d '\r' || true) + if [ -z "$lm" ]; then + misses=$((misses + 1)); [ "$misses" -ge 2 ] && break; continue + fi + misses=0 + epoch=$(date -u -d "$lm" +%s) + if [ "$epoch" -ge "$cutoff" ]; then + minor_hit=1 + if [ -z "$oldest_epoch" ] || [ "$epoch" -lt "$oldest_epoch" ]; then + oldest_epoch=$epoch; oldest_ver=$v + fi + fi + done + # Versions are chronological: once a whole minor is out of window, stop. + [ "$minor_hit" -eq 0 ] && [ -n "$oldest_ver" ] && break + done + if [ -z "$oldest_ver" ]; then + echo "No version found within the last {{window_days}} days" >&2 + exit 1 + fi + echo >&2 "Oldest supported: $oldest_ver (released $(date -u -d "@$oldest_epoch" '+%Y-%m-%d'))" + echo "$oldest_ver" + +# (internal) Replace the version tagged with -version-marker wherever it +# appears. Markers are HTML-comment spans in Markdown and trailing `#`/`//` +# comments in YAML/TS. Target files are discovered, not hardcoded, so a new +# marker anywhere is picked up automatically. DO NOT delete those markers. +[private] +_set-version marker version: + #!/usr/bin/env bash + set -euo pipefail + # Discover files carrying this marker. Skip deps, build output, and the + # tooling/docs that only name the marker in prose. + mapfile -t files < <(grep -rl \ + --exclude-dir=.git --exclude-dir=node_modules --exclude-dir=dist \ + --exclude=justfile --exclude=AGENTS.md \ + "{{marker}}-version-marker" . | sort) + if [ "${#files[@]}" -eq 0 ]; then + echo "No files found carrying {{marker}}-version-marker" >&2 + exit 1 + fi + for f in "${files[@]}"; do + echo "Updating $f" >&2 + # Markdown: X + sed -i -E "s#()(\`?)[0-9][0-9.]*(\`?)()#\1\2{{version}}\3\4#g" "$f" + # YAML/TS: line carrying a `#`/`//` {{marker}}-version-marker comment + sed -i -E "/(#|\/\/)[[:space:]]*{{marker}}-version-marker/ s/[0-9]+\.[0-9]+\.[0-9]+/{{version}}/" "$f" + done + +# Substitute the oldest supported version wherever the oldest-version-marker is placed +update-oldest-cli-scanner window_days="365": + #!/usr/bin/env bash + set -euo pipefail + oldest=$(just oldest-cli-scanner {{window_days}}) + just _set-version oldest "$oldest" + echo "Oldest supported version set to $oldest (via oldest-version-marker)" + +# Update the pinned sysdig-cli-scanner version (README example) to the latest available. +# The task itself defaults to `latest` at runtime. +update-cli-scanner: + #!/usr/bin/env bash + set -euo pipefail + latest=$(just _latest-version) + just _set-version newest "$latest" + echo "Newest version set to $latest (via newest-version-marker)" # Bump tfx-cli to the latest upstream commit and recompute its hashes update-tfx: diff --git a/sysdig-cli-scan-task/package-lock.json b/sysdig-cli-scan-task/package-lock.json index e209dcf..359d7c9 100644 --- a/sysdig-cli-scan-task/package-lock.json +++ b/sysdig-cli-scan-task/package-lock.json @@ -1,12 +1,12 @@ { "name": "sysdig-cli-scan-task", - "version": "1.0.3", + "version": "1.0.4", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "sysdig-cli-scan-task", - "version": "1.0.3", + "version": "1.0.4", "license": "ISC", "dependencies": { "@types/http-proxy-agent": "^4.0.1", diff --git a/sysdig-cli-scan-task/package.json b/sysdig-cli-scan-task/package.json index a02c194..0d3daea 100644 --- a/sysdig-cli-scan-task/package.json +++ b/sysdig-cli-scan-task/package.json @@ -1,6 +1,6 @@ { "name": "sysdig-cli-scan-task", - "version": "1.0.3", + "version": "1.0.4", "description": "Sysdig Secure Scan Task", "main": "index.js", "scripts": { diff --git a/sysdig-cli-scan-task/task.json b/sysdig-cli-scan-task/task.json index f15b123..10c10ee 100644 --- a/sysdig-cli-scan-task/task.json +++ b/sysdig-cli-scan-task/task.json @@ -10,7 +10,7 @@ "version": { "Major": 1, "Minor": 0, - "Patch": 3 + "Patch": 4 }, "minimumAgentVersion": "3.232.1", "groups": [ diff --git a/vss-extension.json b/vss-extension.json index daf0e76..7f6f2fa 100644 --- a/vss-extension.json +++ b/vss-extension.json @@ -2,7 +2,7 @@ "manifestVersion": 1, "id": "sysdig-cli-scan-task", "name": "Sysdig CLI scanner", - "version": "1.0.3", + "version": "1.0.4", "publisher": "SysdigDevOps", "description": "Scan images with Sysdig Secure as part of your development pipeline.", "public": true,