#!/usr/bin/env bash
# Run under unshare --net; no actual application or external target is scanned.
set -euo pipefail
root="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
tmp="$(mktemp -d /tmp/my-devsecops-test.XXXXXXXX)"
trap 'echo "Test evidence: $tmp"' EXIT
bash "$root/scripts/smoke-test.sh"
mkdir -p "$tmp/source" "$tmp/empty"
printf 'requests==2.19.1\n' > "$tmp/source/requirements.txt"
rc=0
bash "$root/scripts/scan-supply-chain.sh" dir "$tmp/source" "$tmp/vulnerable" || rc=$?
[[ "$rc" == 2 ]] || { echo "Expected Grype findings exit 2, got $rc" >&2; exit 1; }
python3 - "$tmp/vulnerable" <<'PY'
import json,sys
from pathlib import Path
p=Path(sys.argv[1])
s=json.loads((p/'sbom.cdx.json').read_text())
assert s['bomFormat']=='CycloneDX'
assert any(c['name']=='requests' for c in s['components'])
r=json.loads((p/'grype.json').read_text())
assert any(m['vulnerability']['severity'] in ['High','Critical'] for m in r['matches'])
PY
bash "$root/scripts/scan-supply-chain.sh" dir "$tmp/empty" "$tmp/clean"
if GRYPE_DB_CACHE_DIR="$tmp/missing-db" bash "$root/scripts/scan-supply-chain.sh" dir "$tmp/source" "$tmp/missing"; then
  echo 'ERROR: missing database passed' >&2; exit 1
fi
echo 'PASS: offline secrets/Trivy/Syft/Grype; clean fixture passes; missing DB fails.'
