Skip to content

Commit 836d7b4

Browse files
committed
Make lint exit non-zero on invalid rules and validate rules in CI
1 parent 82fabe2 commit 836d7b4

2 files changed

Lines changed: 47 additions & 0 deletions

File tree

‎.github/workflows/lint-rules.yml‎

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
name: lint-rules
3+
4+
on:
5+
pull_request:
6+
paths:
7+
- 'rules/**'
8+
- 'src/**'
9+
- 'Cargo.toml'
10+
- 'Cargo.lock'
11+
- '.github/workflows/lint-rules.yml'
12+
push:
13+
branches: [master]
14+
paths:
15+
- 'rules/**'
16+
- 'src/**'
17+
18+
jobs:
19+
lint-rules:
20+
name: Validate detection rules
21+
runs-on: ubuntu-latest
22+
steps:
23+
- name: Checkout
24+
uses: actions/checkout@v6
25+
with:
26+
submodules: recursive
27+
28+
- name: Install Rust
29+
uses: actions-rs/toolchain@v1
30+
with:
31+
toolchain: stable
32+
profile: minimal
33+
override: true
34+
35+
- name: Cache cargo build
36+
uses: Swatinem/rust-cache@v2
37+
38+
- name: Build chainsaw
39+
run: cargo build --release
40+
41+
# Lints against the binary built from this PR, so a rule relying on a
42+
# schema change in the same PR is validated against that change.
43+
- name: Lint detection rules
44+
run: ./target/release/chainsaw --no-banner lint --kind chainsaw rules/

‎src/main.rs‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -927,6 +927,9 @@ fn run() -> Result<()> {
927927
count,
928928
count + failed
929929
);
930+
if failed > 0 {
931+
anyhow::bail!("{} detection rule(s) failed to validate", failed);
932+
}
930933
}
931934
Command::Search {
932935
path,

0 commit comments

Comments
 (0)