Inventory local runtime artifacts in SBOM
This commit is contained in:
@@ -9,6 +9,8 @@ from uuid import uuid4
|
||||
from scripts.generate_component_inventory import (
|
||||
canonical_name,
|
||||
component,
|
||||
file_component,
|
||||
ocr_runtime_components,
|
||||
parse_lockfile,
|
||||
requirement_names,
|
||||
)
|
||||
@@ -94,6 +96,53 @@ sdks:
|
||||
)
|
||||
self.assertEqual(json.loads(json.dumps(result)), result)
|
||||
|
||||
def test_runtime_file_component_records_sha256_and_review_status(self) -> None:
|
||||
artifact = self.fixture_root / "model.pth"
|
||||
artifact.write_bytes(b"model fixture")
|
||||
result = file_component(
|
||||
artifact,
|
||||
name="EasyOCR model model.pth",
|
||||
component_type="machine-learning-model",
|
||||
scope="local-runtime-artifact",
|
||||
license_status="human review required",
|
||||
)
|
||||
self.assertEqual(result["type"], "machine-learning-model")
|
||||
self.assertEqual(
|
||||
result["hashes"],
|
||||
[{"alg": "SHA-256", "content": "21249a290a4255a0f3ee6685ff7933bffa241c3e35bb13a52dc0c7a679bed3b2"}],
|
||||
)
|
||||
self.assertIn(
|
||||
{"name": "inventory.license_status", "value": "human review required"},
|
||||
result["properties"],
|
||||
)
|
||||
|
||||
def test_ocr_inventory_includes_present_weights_and_reports_missing_english(self) -> None:
|
||||
model_dir = self.fixture_root / "models"
|
||||
model_dir.mkdir()
|
||||
(model_dir / "arabic.pth").write_bytes(b"arabic weights")
|
||||
(model_dir / "craft_mlt_25k.pth").write_bytes(b"detection weights")
|
||||
(model_dir / "arabic.pth.backup").write_bytes(b"backup")
|
||||
(model_dir / "temp.zip").write_bytes(b"download fragment")
|
||||
|
||||
artifacts, missing = ocr_runtime_components(model_dir)
|
||||
|
||||
self.assertEqual(
|
||||
{artifact["name"] for artifact in artifacts},
|
||||
{"EasyOCR model arabic.pth", "EasyOCR model craft_mlt_25k.pth"},
|
||||
)
|
||||
self.assertEqual(missing, ["english_g2.pth"])
|
||||
for artifact in artifacts:
|
||||
properties = {item["name"]: item["value"] for item in artifact["properties"]}
|
||||
self.assertEqual(
|
||||
properties["inventory.license_status"],
|
||||
"model redistribution terms not established; human review required",
|
||||
)
|
||||
self.assertEqual(
|
||||
properties["inventory.evidence.upstream_manifest"],
|
||||
"easyocr==1.7.2 config.py",
|
||||
)
|
||||
self.assertEqual(properties["inventory.evidence.upstream_md5_match"], "false")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
|
||||
Reference in New Issue
Block a user