Assess native rule eligibility with explicit evidence gates

This commit is contained in:
Shirofune-Security committed 2026-09-19 07:24:04 +09:00
1 parent 9d993a2a7e
commit 36ad97114c
17 files changed
+781 -27

No files matched your search

+4
View File
@@ -33,6 +33,10 @@ jobs:
- name: Run
run: cd wela-extractor && cargo run --release -- ../hayabusa-rules ../WELA/config/eid_subcategory_mapping.csv ../WELA/config/security_rules.json
- name: Record rule input revisions and hashes
shell: bash
run: python WELA/tools/update_rule_manifest.py --rules-commit "$(git -C hayabusa-rules rev-parse HEAD)" --generator-commit "$(git -C wela-extractor rev-parse HEAD)"
- name: Create Text
id: create-text
run: |
+32
View File
@@ -0,0 +1,32 @@
name: Native rule eligibility tests
on:
push:
branches: ['**']
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
eligibility:
runs-on: windows-latest
strategy:
matrix:
shell: [powershell, pwsh]
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Evidence gates and full-corpus bounds
shell: ${{ matrix.shell }}
run: ./tests/RuleEligibility.Tests.ps1
- name: Existing audit output remains conservative
shell: ${{ matrix.shell }}
run: |
./tests/NativeProviders.Tests.ps1
./tests/AuditProfileOutput.Tests.ps1
./tests/DomainNtlmAuditOutput.Tests.ps1
- name: Public CLI and real read-only Windows observations
shell: ${{ matrix.shell }}
run: |
./WELA.ps1 rule-eligibility -ResultsPath "$env:RUNNER_TEMP/eligibility.json" -HtmlPath "$env:RUNNER_TEMP/eligibility.html"
$report = Get-Content "$env:RUNNER_TEMP/eligibility.json" -Raw | ConvertFrom-Json
if ($report.Summary.Ready -ne 0 -or -not $report.Corpus.Pinned) { throw 'Metadata-only CLI must not grant readiness.' }
./tests/NativeProviders.Windows.Tests.ps1 -OutputDirectory "$env:RUNNER_TEMP/eligibility-native-observations"