mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-11 22:14:17 +00:00
fix(sdk): handle registry URL in Image provider connection test
- Detect registry URLs (e.g. docker.io/namespace) vs image references - Use list_repositories for registry URLs, list_tags for images - Add test for registry URL connection test
This commit is contained in:
2 files changed
+45
-1
No files matched your search
@@ -906,11 +906,17 @@ class ImageProvider(Provider):
|
||||
"""
|
||||
Test connection to container registry by verifying image accessibility.
|
||||
|
||||
Handles two cases:
|
||||
- Image reference (e.g. ``alpine:3.18``, ``ghcr.io/user/repo:tag``):
|
||||
verifies the specific tag exists.
|
||||
- Registry URL (e.g. ``docker.io/namespace``, ``ghcr.io/org``):
|
||||
verifies we can list repositories in that namespace.
|
||||
|
||||
Uses registry HTTP APIs directly instead of Trivy to avoid false
|
||||
failures caused by Trivy DB download issues.
|
||||
|
||||
Args:
|
||||
image: Container image to test
|
||||
image: Container image or registry URL to test
|
||||
raise_on_exception: Whether to raise exceptions
|
||||
provider_id: Fallback for image name
|
||||
registry_username: Registry username for basic auth
|
||||
@@ -935,6 +941,26 @@ class ImageProvider(Provider):
|
||||
else:
|
||||
repo_and_tag = image
|
||||
|
||||
# Determine if this is a registry URL (namespace only) or a full
|
||||
# image reference. A registry URL like ``docker.io/andoniaf`` has
|
||||
# a registry host but the remaining part contains no ``/`` (no
|
||||
# repo) and no ``:`` (no tag).
|
||||
is_registry_url = (
|
||||
registry_host and "/" not in repo_and_tag and ":" not in repo_and_tag
|
||||
)
|
||||
|
||||
if is_registry_url:
|
||||
# Registry enumeration mode — test by listing repositories
|
||||
adapter = create_registry_adapter(
|
||||
registry_url=image,
|
||||
username=registry_username,
|
||||
password=registry_password,
|
||||
token=registry_token,
|
||||
)
|
||||
adapter.list_repositories()
|
||||
return Connection(is_connected=True)
|
||||
|
||||
# Image reference mode — verify the specific tag exists
|
||||
if ":" in repo_and_tag:
|
||||
repository, tag = repo_and_tag.rsplit(":", 1)
|
||||
else:
|
||||
|
||||
@@ -325,6 +325,24 @@ class TestImageProvider:
|
||||
assert result.is_connected is False
|
||||
assert "not found" in result.error
|
||||
|
||||
@patch("prowler.providers.image.image_provider.create_registry_adapter")
|
||||
def test_test_connection_registry_url(self, mock_factory):
|
||||
"""Test registry URL (namespace) uses list_repositories."""
|
||||
mock_adapter = MagicMock()
|
||||
mock_adapter.list_repositories.return_value = ["andoniaf/myapp"]
|
||||
mock_factory.return_value = mock_adapter
|
||||
|
||||
result = ImageProvider.test_connection(image="docker.io/andoniaf")
|
||||
|
||||
assert result.is_connected is True
|
||||
mock_factory.assert_called_once_with(
|
||||
registry_url="docker.io/andoniaf",
|
||||
username=None,
|
||||
password=None,
|
||||
token=None,
|
||||
)
|
||||
mock_adapter.list_repositories.assert_called_once()
|
||||
|
||||
def test_build_status_extended(self):
|
||||
"""Test status message content for different finding types."""
|
||||
provider = _make_provider()
|
||||
|
||||
Reference in new issue
Block a user