Repository navigation
feat(allowlist): add Bicep (.bicep) support - #525
Conversation
|
🔍 OpenCodeReview found 1 issue(s) in this PR.
|
lizhengfeng101
left a comment
There was a problem hiding this comment.
Review: feat(allowlist): add Bicep (.bicep) support
Critical Bug: Julia (.jl) support accidentally removed
The PR replaces .jl with .bicep in supported_file_types.json instead of appending .bicep:
- ".jl"
+ ".bicep"Additionally, all Julia-related test cases are removed:
allowed_ext_test.go:.jl/.JLassertions replaced by.bicep/.BICEPTestIsExcludedPath: Julia test-file exclusion patterns deleted entirelysystem_rules_test.go: Julia resolution tests replaced with Bicep tests
Meanwhile, system_rules.json still maps "**/*.jl": "julia.md" and the julia.md rule doc remains on disk — creating an inconsistency where the rule mapping exists but .jl files would be filtered out at the allowlist stage and never reach rule resolution.
Fix: append .bicep after .jl in supported_file_types.json, restore all Julia test cases, and add Bicep test cases alongside them (net addition, not replacement).
Minor
- The
bicep.mdrule doc itself is well-written and follows the existing precision-over-recall structure — no issues there. - Consider explicitly listing common database ports (3306, 5432, 1433, 27017) in the "sensitive port" clause for precision.
Summary
Request changes due to the unintentional Julia regression. The Bicep additions are good — they just need to be additive rather than replacing existing language support.
|
Thanks for catching this — confirmed the root cause: my local Fixed in 490fd3d:
Verified the diff against |
Same root cause as the sibling Bicep PR (alibaba#525): the local main used to build this branch's working changes predated the Julia support merge (alibaba#501), so restoring those changes onto a branch freshly cut from the current upstream/main silently replaced the newer .jl allowlist entry and its test cases with the stale pre-Julia state instead of adding HCL/Terraform alongside them. Restores .jl in supported_file_types.json, the TestIsAllowedExt and TestIsExcludedPath Julia cases in allowed_ext_test.go, and the Julia resolution cases in system_rules_test.go -- system_rules.json's .jl -> julia.md mapping was already restored in a prior commit on this branch. Now a pure addition of HCL/Terraform support, not a replacement of Julia support.
* feat(allowlist): add HCL/Terraform (.hcl, .tfvars) support Adds .hcl and .tfvars to the allowlist and maps them, along with the already-supported .tf, to a new dedicated terraform.md review rule doc covering hardcoded secrets/credentials, overly permissive network/IAM access, state file hygiene, and lifecycle protection on stateful resources. .tf previously fell through to the generic default rule set with no Terraform-specific guidance despite already being allowlisted; bringing all three extensions under one doc gives consistent coverage rather than leaving .tf behind. Part of #470, closes #522. * Update internal/config/rules/system_rules.json Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix: restore Julia (.jl) support accidentally removed Same root cause as the sibling Bicep PR (#525): the local main used to build this branch's working changes predated the Julia support merge (#501), so restoring those changes onto a branch freshly cut from the current upstream/main silently replaced the newer .jl allowlist entry and its test cases with the stale pre-Julia state instead of adding HCL/Terraform alongside them. Restores .jl in supported_file_types.json, the TestIsAllowedExt and TestIsExcludedPath Julia cases in allowed_ext_test.go, and the Julia resolution cases in system_rules_test.go -- system_rules.json's .jl -> julia.md mapping was already restored in a prior commit on this branch. Now a pure addition of HCL/Terraform support, not a replacement of Julia support. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
lizhengfeng101
left a comment
There was a problem hiding this comment.
rebase remote main
Adds .bicep to the allowlist and maps it to a new dedicated bicep.md review rule doc covering hardcoded secrets/connection strings, missing @secure() on sensitive parameters, overly permissive RBAC role assignments, and insecure resource defaults (public network access, missing TLS enforcement). Part of alibaba#470, closes alibaba#523.
…explicitly The previous commit on this branch was built from a local main that predated the Julia (.jl) support merge (alibaba#501), so restoring stashed changes onto a freshly-branched, up-to-date main silently replaced the newer .jl allowlist entry, its system_rules.json mapping, and its allowed_ext_test.go / system_rules_test.go cases with the stale pre-Julia state instead of adding Bicep alongside them. Restores every removed Julia entry (allowlist, TestIsExcludedPath cases, system_rules.json mapping, and both test files) so this is now a pure addition of Bicep support, not a replacement of Julia support. Also lists common database ports (MySQL/3306, PostgreSQL/5432, SQL Server/1433, MongoDB/27017) explicitly in bicep.md's sensitive-port clause per review feedback.
490fd3d to
63056a6
Compare
|
rebased |
* feat(allowlist): add HCL/Terraform (.hcl, .tfvars) support Adds .hcl and .tfvars to the allowlist and maps them, along with the already-supported .tf, to a new dedicated terraform.md review rule doc covering hardcoded secrets/credentials, overly permissive network/IAM access, state file hygiene, and lifecycle protection on stateful resources. .tf previously fell through to the generic default rule set with no Terraform-specific guidance despite already being allowlisted; bringing all three extensions under one doc gives consistent coverage rather than leaving .tf behind. Part of alibaba#470, closes alibaba#522. * Update internal/config/rules/system_rules.json Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix: restore Julia (.jl) support accidentally removed Same root cause as the sibling Bicep PR (alibaba#525): the local main used to build this branch's working changes predated the Julia support merge (alibaba#501), so restoring those changes onto a branch freshly cut from the current upstream/main silently replaced the newer .jl allowlist entry and its test cases with the stale pre-Julia state instead of adding HCL/Terraform alongside them. Restores .jl in supported_file_types.json, the TestIsAllowedExt and TestIsExcludedPath Julia cases in allowed_ext_test.go, and the Julia resolution cases in system_rules_test.go -- system_rules.json's .jl -> julia.md mapping was already restored in a prior commit on this branch. Now a pure addition of HCL/Terraform support, not a replacement of Julia support. --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Closes #523. Part of #470.
What
Adds
.bicepto the code-review allowlist and maps it to a new dedicatedbicep.mdreview-rule doc.Rule doc coverage
bicep.mdfollows the same structure as the existinggraphql.md/terraform.md(precision-over-recall framing, security findings blocking / style non-blocking):@secure()*/Interneton sensitive portsminimumTlsVersion, disabledsupportsHttpsTrafficOnlyapi-versionusage relative to sibling resourcesTests
allowed_ext_test.go:.bicep/.BICEPallowlist casessystem_rules_test.go: rule-resolution case for.bicepresolving tobicep.mdVerification
go vet,go build,go teston the two touched packages (internal/config/allowlist,internal/config/rules): clean, all passinggofmt -l: clean