zero-check-pipeline/validate/deps.sh

67 lines
1.8 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[0;33m'
NC='\033[0m'
TARGET="${1:-.}"
errors=0
echo "=== Dependency Audit ==="
has_reqtxt=$(find "$TARGET" -maxdepth 2 -name "requirements*.txt" | head -1)
has_pyproject=$(find "$TARGET" -maxdepth 2 -name "pyproject.toml" | head -1)
has_python="${has_reqtxt}${has_pyproject}"
has_gomod=$(find "$TARGET" -maxdepth 2 -name "go.mod" | head -1)
if [ -z "$has_python" ] && [ -z "$has_gomod" ]; then
printf "${YELLOW}!${NC} No dependency files found — skipping\n"
exit 0
fi
if [ -n "$has_python" ]; then
if ! command -v pip-audit &>/dev/null; then
printf "${RED}${NC} pip-audit not installed\n"
exit 2
fi
echo "-- Python (pip-audit) --"
if [ -n "$has_reqtxt" ]; then
printf " source: %s (requirements file)\n" "$has_reqtxt"
audit_cmd="pip-audit -r $has_reqtxt"
else
printf " source: %s (environment mode)\n" "$has_pyproject"
audit_cmd="pip-audit"
fi
if $audit_cmd 2>/dev/null; then
printf "${GREEN}${NC} No known vulnerabilities in Python dependencies\n"
else
printf "${RED}${NC} Vulnerable Python dependencies found\n"
errors=$((errors + 1))
fi
fi
if [ -n "$has_gomod" ]; then
if ! command -v govulncheck &>/dev/null; then
printf "${YELLOW}!${NC} govulncheck not installed — skipping Go audit\n"
else
echo "-- Go (govulncheck) --"
printf " source: %s\n" "$has_gomod"
gomod_dir=$(dirname "$has_gomod")
if (cd "$gomod_dir" && govulncheck ./... 2>/dev/null); then
printf "${GREEN}${NC} No known vulnerabilities in Go dependencies\n"
else
printf "${RED}${NC} Vulnerable Go dependencies found\n"
errors=$((errors + 1))
fi
fi
fi
if [ "$errors" -gt 0 ]; then
exit 1
else
exit 0
fi