Files
WELA/.github/workflows/event-measurement.yml
田中ザック Isaac Mathis 2fd37d0318 Measure bounded native event delivery and verify exact EVTX samples (#430)
* Add bounded local delivery measurement and exact EVTX samples

* Link delivery measurement changelog to PR 430

* Reject evidence aliases before Windows path normalization

* Use PowerShell 5.1-compatible record IDs and bound fixture cleanup

* Revalidate the native EVTX artifact before recording final evidence

* Require exact observed local computer identities for sampled events

* Clarify provider scope within shared built-in event channels

* Preserve mixed XML payload ordering in EVTX sample verification

* Bound ordered event XML comparisons for nested UserData

* Dispose observer wait handle when bookmark creation fails
2026-09-21 09:14:48 +09:00

41 lines
1.3 KiB
YAML

name: Local event delivery measurement
on:
push:
branches: ['**']
paths:
- 'WELA.ps1'
- 'scripts/EventMeasurement*'
- 'scripts/EvtxRecovery.ps1'
- 'scripts/ControlApplicability.ps1'
- 'scripts/NativeValidation.ps1'
- 'config/event_measurement.json'
- 'tests/EventMeasurement*'
- '.github/workflows/event-measurement.yml'
pull_request:
workflow_dispatch:
permissions:
contents: read
jobs:
native-delivery:
strategy:
fail-fast: false
matrix:
os: [windows-2022, windows-2025]
engine: [powershell, pwsh]
runs-on: ${{ matrix.os }}
timeout-minutes: 12
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Fixtures and native callback/export proof (Windows PowerShell 5.1)
if: matrix.engine == 'powershell'
shell: powershell
run: |
./tests/EventMeasurement.Tests.ps1
./tests/EventMeasurement.Windows.Tests.ps1 -AllowDisposablePolicyWrite
- name: Fixtures and native callback/export proof (PowerShell 7)
if: matrix.engine == 'pwsh'
shell: pwsh
run: |
./tests/EventMeasurement.Tests.ps1
./tests/EventMeasurement.Windows.Tests.ps1 -AllowDisposablePolicyWrite