diff --git a/src/sp_repo_review/checks/security.py b/src/sp_repo_review/checks/security.py index b11de41c..c973b744 100644 --- a/src/sp_repo_review/checks/security.py +++ b/src/sp_repo_review/checks/security.py @@ -19,7 +19,7 @@ class SEC001(Security): url = mk_url("security") @staticmethod - def check(precommit: dict[str, Any], workflows: dict[str, Any]) -> bool: + def check(precommit: dict[str, Any], workflows: dict[str, Any]) -> bool | str: """ Projects with GitHub Actions should statically analyze their workflows with [zizmor](https://docs.zizmor.sh), which catches common security @@ -36,11 +36,14 @@ def check(precommit: dict[str, Any], workflows: dict[str, Any]) -> bool: You can also run it as the `zizmorcore/zizmor-action` GitHub Action. """ for repo_item in precommit.get("repos", []): - if ( - repo_item.get("repo", "").lower() - == "https://github.com/zizmorcore/zizmor-pre-commit" - ): - return True + match repo_item.get("repo", "").lower(): + case "https://github.com/zizmorcore/zizmor-pre-commit": + return True + case "https://github.com/woodruffw/zizmor-pre-commit" as repo: + return ( + "Use `https://github.com/zizmorcore/zizmor-pre-commit` " + f"instead of `{repo}` in `.pre-commit-config.yaml`" + ) for workflow in workflows.values(): for job in workflow.get("jobs", {}).values(): if not isinstance(job, dict): diff --git a/tests/test_security.py b/tests/test_security.py index 63f5bc98..c0b23966 100644 --- a/tests/test_security.py +++ b/tests/test_security.py @@ -39,3 +39,18 @@ def test_sec001_missing() -> None: """ ) assert not compute_check("SEC001", precommit=precommit, workflows={"ci": {}}).result + + +def test_sec001_rename() -> None: + precommit = yaml.safe_load( + """ + repos: + - repo: https://github.com/woodruffw/zizmor-pre-commit + rev: v1.5.0 + hooks: + - id: zizmor + """ + ) + res = compute_check("SEC001", precommit=precommit, workflows={"ci": {}}) + assert not res.result + assert "instead of `https://github.com/woodruffw/zizmor-pre-commit`" in res.err_msg