[GOLANG] Enable IAST features in net-http-orchestrion variant - #7342
[GOLANG] Enable IAST features in net-http-orchestrion variant#7342RomainMuller wants to merge 12 commits into
net-http-orchestrion variant#7342Conversation
JJ-Change-Id: nlvymv
Add the documented insecure hashing routes to the `net-http-orchestrion` weblog so the IAST proof of concept can exercise MD5, SHA-1, and SHA-256 operations. Enable only the functional weak-hash checks supported by the proof of concept for that weblog variant. Keep deduplication, telemetry, extended location, and stack trace coverage disabled. JJ-Change-Id: kvkmov
Enable weak-hash coverage for the orchestrion-instrumented Go weblog with the tracer development version. Align evidence and location expectations with the Go tracer output, and update the weblog image to Go 1.26. JJ-Change-Id: npnyrt
Exercise RC4 and AES from the `net-http-orchestrion` weblog so the Go IAST integration can distinguish weak and secure cipher usage. Enable the weak-cipher, stack-trace, and extended-location tests for Go 2.11 and document the endpoint contract. JJ-Change-Id: txwxmx
Keep `TestWeakCipher_StackTrace` marked as `missing_feature` for all Go weblog variants while retaining the core and extended-location test activation for `net-http-orchestrion`. JJ-Change-Id: rvxlpn
JJ-Change-Id: txlxtp
|
|
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68bfcbeb49
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
JJ-Change-Id: nnknpn
JJ-Change-Id: mnsymx
JJ-Change-Id: pruzmq
Consume the existing optional `github_token` BuildKit secret when building the Orchestrion weblog. Configure Git only in the build process environment so the initial module download can access private DataDog repositories without persisting or logging the credential. JJ-Change-Id: tlokyq
Exchange the PR workflow OIDC identity for a read-only token scoped to the internal `dd-iast-go` repository. Limit the exchange to the Go Orchestrion build in PR 7342 while the repository awaits open-sourcing. Create the BuildKit token file with restrictive permissions immediately before the build and remove it through shell exit traps. JJ-Change-Id: kxwrvp
JJ-Change-Id: tookvu
Changes
Adds
dd-iast-goto thenet-http-orchestrioncompile-time integrations set, and enable select IAST tests that are supposed to be passing now.Workflow
🚀 Once your PR is reviewed and the CI green, you can merge it!
🛟 #apm-shared-testing 🛟
Reviewer checklist
tests/ormanifests/is modified ? I have the approval from R&P teambuild-XXX-imagelabel is present