Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ steps:
verbose: true
jsonOutput: true
jsonOutputFile: 'sysdig-cli-scan-output.json'
sysdigCliScannerVersion: '1.6.0'
sysdigCliScannerVersion: '1.30.1' # newest-version-marker — DO NOT REMOVE; auto-updated by `just update-cli-scanner`
policy: my_custom_policy,my-custom-policy-ab

- task: PublishBuildArtifacts@1
Expand Down Expand Up @@ -141,7 +141,7 @@ steps:

- **JSON Output File (`jsonOutputFile`)**: The file name to export the JSON result to. This will be ignored if `jsonOutput` is `false`. Default: `sysdig-cli-scan-output.json`,

- **Sysdig CLI Scanner Version (`sysdigCliScannerVersion`)**: The version of the Sysdig CLI Scanner to use. Will use the latest version if not specified. Default: `latest`,
- **Sysdig CLI Scanner Version (`sysdigCliScannerVersion`)**: The version of the Sysdig CLI Scanner to use. Will use the latest version if not specified. Versions are supported for 1 year after release; oldest version tested is <!-- oldest-version-marker: DO NOT REMOVE; auto-updated by `just update-oldest-cli-scanner` -->1.23.0<!-- /oldest-version-marker -->. Default: `latest`,

- **Policy (`policy`)**: Policy to evaluate in the pipeline execution. If not specified, only the Always Apply policy will be evaluated. Default: `null`,

Expand Down
8 changes: 5 additions & 3 deletions azure-pipelines.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,8 +66,10 @@ steps:
export INPUT_IMAGE='$(imageName)'
export INPUT_VERBOSE='true'
export INPUT_FAILBUILD='false'
export INPUT_SYSDIGCLISCANNERVERSION='latest'

# Run the task directly
node sysdig-cli-scan-task/dist/index.js
# Run the task directly, with the default (latest) and the oldest supported scanner
for version in latest 1.23.0; do # oldest-version-marker — DO NOT REMOVE; auto-updated by `just update-oldest-cli-scanner`
echo "Running smoke test with sysdig-cli-scanner ${version}..."
INPUT_SYSDIGCLISCANNERVERSION="${version}" node sysdig-cli-scan-task/dist/index.js
done
displayName: 'Local smoke-run of the task'
4 changes: 4 additions & 0 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,12 @@
mkShell {
packages = [
azure-cli
# GNU tools the justfile `scanner` recipes rely on (BSD versions on macOS break them).
coreutils
curl
git
gnugrep
gnused
jq
just
nodejs_22
Expand Down
91 changes: 90 additions & 1 deletion justfile
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,100 @@ publish-release:
pin-actions:
pinact run -u

# Update everything: flake inputs, tfx-cli, and pinned actions
# Update everything: flake inputs, tfx-cli, pinned actions, and the sysdig-cli-scanner versions
update:
nix flake update
nix develop --command just update-tfx
nix develop --command just pin-actions
nix develop --command just update-cli-scanner
nix develop --command just update-oldest-cli-scanner

# (internal) Print the latest published sysdig-cli-scanner version
[private]
_latest-version:
@curl --silent --fail --show-error --location https://download.sysdig.com/scanning/sysdig-cli-scanner/latest_version.txt | tr -d '[:space:]'

# Find the oldest sysdig-cli-scanner version still within the support window (default 365 days)
oldest-cli-scanner window_days="365":
#!/usr/bin/env bash
set -euo pipefail
base="https://download.sysdig.com/scanning/bin/sysdig-cli-scanner"
os="linux"; arch="amd64"
cutoff=$(( $(date -u +%s) - {{window_days}} * 86400 ))
latest=$(just _latest-version)
major=${latest%%.*}
minor=$(echo "$latest" | cut -d. -f2)
oldest_ver=""; oldest_epoch=""
for m in $(seq "$minor" -1 0); do
minor_hit=0; misses=0
for p in $(seq 0 30); do
v="$major.$m.$p"
lm=$(curl -sfI "$base/$v/$os/$arch/sysdig-cli-scanner" \
| grep -i '^last-modified:' | sed 's/^[Ll]ast-[Mm]odified: //' | tr -d '\r' || true)
if [ -z "$lm" ]; then
misses=$((misses + 1)); [ "$misses" -ge 2 ] && break; continue
fi
misses=0
epoch=$(date -u -d "$lm" +%s)
if [ "$epoch" -ge "$cutoff" ]; then
minor_hit=1
if [ -z "$oldest_epoch" ] || [ "$epoch" -lt "$oldest_epoch" ]; then
oldest_epoch=$epoch; oldest_ver=$v
fi
fi
done
# Versions are chronological: once a whole minor is out of window, stop.
[ "$minor_hit" -eq 0 ] && [ -n "$oldest_ver" ] && break
done
if [ -z "$oldest_ver" ]; then
echo "No version found within the last {{window_days}} days" >&2
exit 1
fi
echo >&2 "Oldest supported: $oldest_ver (released $(date -u -d "@$oldest_epoch" '+%Y-%m-%d'))"
echo "$oldest_ver"

# (internal) Replace the version tagged with <marker>-version-marker wherever it
# appears. Markers are HTML-comment spans in Markdown and trailing `#`/`//`
# comments in YAML/TS. Target files are discovered, not hardcoded, so a new
# marker anywhere is picked up automatically. DO NOT delete those markers.
[private]
_set-version marker version:
#!/usr/bin/env bash
set -euo pipefail
# Discover files carrying this marker. Skip deps, build output, and the
# tooling/docs that only name the marker in prose.
mapfile -t files < <(grep -rl \
--exclude-dir=.git --exclude-dir=node_modules --exclude-dir=dist \
--exclude=justfile --exclude=AGENTS.md \
"{{marker}}-version-marker" . | sort)
if [ "${#files[@]}" -eq 0 ]; then
echo "No files found carrying {{marker}}-version-marker" >&2
exit 1
fi
for f in "${files[@]}"; do
echo "Updating $f" >&2
# Markdown: <!-- {{marker}}-version-marker ... -->X<!-- /{{marker}}-version-marker -->
sed -i -E "s#(<!-- {{marker}}-version-marker[^>]*-->)(\`?)[0-9][0-9.]*(\`?)(<!-- /{{marker}}-version-marker -->)#\1\2{{version}}\3\4#g" "$f"
# YAML/TS: line carrying a `#`/`//` {{marker}}-version-marker comment
sed -i -E "/(#|\/\/)[[:space:]]*{{marker}}-version-marker/ s/[0-9]+\.[0-9]+\.[0-9]+/{{version}}/" "$f"
done

# Substitute the oldest supported version wherever the oldest-version-marker is placed
update-oldest-cli-scanner window_days="365":
#!/usr/bin/env bash
set -euo pipefail
oldest=$(just oldest-cli-scanner {{window_days}})
just _set-version oldest "$oldest"
echo "Oldest supported version set to $oldest (via oldest-version-marker)"

# Update the pinned sysdig-cli-scanner version (README example) to the latest available.
# The task itself defaults to `latest` at runtime.
update-cli-scanner:
#!/usr/bin/env bash
set -euo pipefail
latest=$(just _latest-version)
just _set-version newest "$latest"
echo "Newest version set to $latest (via newest-version-marker)"

# Bump tfx-cli to the latest upstream commit and recompute its hashes
update-tfx:
Expand Down
4 changes: 2 additions & 2 deletions sysdig-cli-scan-task/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion sysdig-cli-scan-task/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "sysdig-cli-scan-task",
"version": "1.0.3",
"version": "1.0.4",
"description": "Sysdig Secure Scan Task",
"main": "index.js",
"scripts": {
Expand Down
2 changes: 1 addition & 1 deletion sysdig-cli-scan-task/task.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"version": {
"Major": 1,
"Minor": 0,
"Patch": 3
"Patch": 4
},
"minimumAgentVersion": "3.232.1",
"groups": [
Expand Down
2 changes: 1 addition & 1 deletion vss-extension.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"manifestVersion": 1,
"id": "sysdig-cli-scan-task",
"name": "Sysdig CLI scanner",
"version": "1.0.3",
"version": "1.0.4",
"publisher": "SysdigDevOps",
"description": "Scan images with Sysdig Secure as part of your development pipeline.",
"public": true,
Expand Down
Loading