-
-
Notifications
You must be signed in to change notification settings - Fork 2.8k
80 lines (73 loc) · 2.18 KB
/
Copy pathsigma-test.yml
File metadata and controls
80 lines (73 loc) · 2.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
# This workflow will install Python dependencies, run tests and lint with a single version of Python
# For more information see: https://help.github.com/actions/language-and-framework-guides/using-python-with-github-actions
name: Sigma Rule Tests
on: [push, pull_request, merge_group, workflow_dispatch]
jobs:
yamllint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: yaml-lint
uses: ibiqlik/action-yamllint@v3
with:
strict: true # fail on warnings as well
test-sigma-logsource:
runs-on: ubuntu-latest
needs: yamllint
steps:
- uses: actions/checkout@v5
with:
submodules: true
- name: Set up Python 3.11
uses: actions/setup-python@v6
with:
python-version: 3.11
- name: Test Sigma logsource
run: |
pip install PyYAML colorama
python tests/test_logsource.py
test-sigma-legacy:
runs-on: ubuntu-latest
needs: yamllint
steps:
- uses: actions/checkout@v5
with:
submodules: true
- name: Set up Python 3.11
uses: actions/setup-python@v6
with:
python-version: 3.11
- name: Test Sigma Rules
run: |
pip install PyYAML colorama
python tests/test_rules.py
sigma-check:
runs-on: ubuntu-latest
needs: yamllint
steps:
- uses: actions/checkout@v5
with:
submodules: true
- name: Set up Python 3.11
uses: actions/setup-python@v6
with:
python-version: 3.11
- name: Install dependencies
run: |
pip install pysigma
pip install sigma-cli
pip install pySigma-validators-sigmahq==0.21.*
- name: Test Sigma Rule Syntax
run: |
sigma check --fail-on-error --fail-on-issues --validation-config tests/sigma_cli_conf.yml rules*
duplicate-id-check:
runs-on: ubuntu-latest
needs: yamllint
steps:
- uses: actions/checkout@v5
with:
submodules: true
- name: Check for duplicate IDs
shell: /usr/bin/bash {0} # Use bash without -e to enable exit code manipulation
run: |
grep -rh "^id: " rules* deprecated unsupported | sort | uniq -c | grep -vE "^\s+1 id: "; exit $(( $? ^ 1 ))