{"id":20318009,"url":"https://github.com/crowdsecurity/hub-tests","last_synced_at":"2026-05-11T14:34:00.666Z","repository":{"id":47032290,"uuid":"269733575","full_name":"crowdsecurity/hub-tests","owner":"crowdsecurity","description":"Testing hub parsers","archived":false,"fork":false,"pushed_at":"2023-02-25T09:10:59.000Z","size":311,"stargazers_count":0,"open_issues_count":5,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2026-04-27T04:34:03.129Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/crowdsecurity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-06-05T18:16:18.000Z","updated_at":"2021-09-16T13:44:25.000Z","dependencies_parsed_at":"2024-06-21T09:04:40.728Z","dependency_job_id":null,"html_url":"https://github.com/crowdsecurity/hub-tests","commit_stats":{"total_commits":80,"total_committers":10,"mean_commits":8.0,"dds":0.625,"last_synced_commit":"3a64d57fa79d70e2df0f4019ebcd2a3a8ed10647"},"previous_names":[],"tags_count":16,"template":false,"template_full_name":null,"purl":"pkg:github/crowdsecurity/hub-tests","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fhub-tests","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fhub-tests/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fhub-tests/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fhub-tests/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/crowdsecurity","download_url":"https://codeload.github.com/crowdsecurity/hub-tests/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fhub-tests/sbom","scorecard":{"id":309750,"data":{"date":"2025-08-11","repo":{"name":"github.com/crowdsecurity/hub-tests","commit":"3a64d57fa79d70e2df0f4019ebcd2a3a8ed10647"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.5,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":8,"reason":"Found 25/30 approved changesets -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/dispatch_create_tag.yaml:1","Warn: no topLevel permission defined: .github/workflows/dispatch_hub.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dispatch_create_tag.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/crowdsecurity/hub-tests/dispatch_create_tag.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dispatch_create_tag.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/crowdsecurity/hub-tests/dispatch_create_tag.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dispatch_hub.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/crowdsecurity/hub-tests/dispatch_hub.yaml/master?enable=pin","Info:   0 out of   1 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":0,"reason":"license file not detected","details":["Warn: project does not have a license file"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 27 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2022-0493 / GHSA-p782-xgp4-8hr8","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T22:56:44.398Z","repository_id":47032290,"created_at":"2025-08-17T22:56:44.398Z","updated_at":"2025-08-17T22:56:44.398Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32899120,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-10T13:40:02.631Z","status":"online","status_checked_at":"2026-05-11T02:00:05.975Z","response_time":120,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T18:37:47.841Z","updated_at":"2026-05-11T14:34:00.645Z","avatar_url":"https://github.com/crowdsecurity.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Hub and Hub-tests\n\nThis repository hosts the software tool used to test each\nconfiguration hosted in the [hub](https://hub.crowdsec.net) or in its\n[repository](https://github.com/crowdsecurity/hub/). More precisely,\neach configuration item consists of a yaml configuration file used to\ndescribe crowdsec behaviour. The format of the configuration item\ndepends the type of configuration item. There're two types of\nconfiguration item:\n\n* parsers (for parsers and postoverflows)\n* scenarios \n\n# Hub and continuous integration\n\nEach changes in the [hub](https://github.com/crowdsecurity/hub)\nrepository, in the\n[hub-tests](https://github.com/crowdsecurity/hub-tests) repository or\nin the [crowdsec](https://github.com/crowdsecurity/crowdsec)\nrepository fires a continuous integration test.\n\n__**The results of those tests on master branch are carelessly pushed on\nour [github pages](https://crowdsecurity.github.io/hub/)**__\n\n# Create a basic test\n\nTo create such a test you'll need the the configuration item and\nfollow the steps:\n1. Clone the [hub](https://github.com/crowdsecurity/hub) repository.\n2. Put the configuration in the right place `\u003ctype\u003e/\u003cstage\u003e/\u003cprovider name\u003e/\u003cconfiguration item\u003e.yaml`\n3. Run `./tests.sh -i` to init the tool and `./tests.sh -g\n   \u003ctype\u003e/\u003cstage\u003e/\u003cprovider name\u003e/\u003cconfiguration item\u003e.yaml` to create\n   a skeleton test.\n4. The precedent step created a `config.yaml` file in a directory\n`\u003citem type\u003e/\u003cstage name\u003e/\u003cprovider name\u003e/.tests/\u003cconfiguration\nname\u003e`. You have to store logs in this directory to trigger the tested\nconfiguration item. The easiest way to do so is to craft a\n`parser_input.yaml` marshaled file representing a list of events\n([types.Events](https://github.com/crowdsecurity/crowdsec/blob/eda9c03c82a2aa35d07053986c3d70fe15dd4b4e/pkg/types/event.go#L17)). (if\nyou are creating a test for a postoverflow, the file would be\npo_input.yaml, and if you are creating a scenario the file is\nbucket_input.yaml)) Have a look at existing tests to\nget inspiration.\n5. Check the `config.yaml` file (defaults should be ok)\n6. Run `./tests.sh --single \u003citem type\u003e/\u003cstage name\u003e/\u003cprovider\n   name\u003e/.tests/\u003cconfiguration name\u003e`. When run the first time, this\n   will create a result file that will be used as a reference for future runs. If you're happy with it, you can now create\n   a pull request to merge the configuration item alonside with all\n   the files needed to test it.\n\n# How the tests work\n\n## Directory tree\n\nEach `config.yaml` in the hub repository subdirectories triggers a\ntest. It's meant to be stored in under a directory: `\u003citem\ntype\u003e/\u003cstage name if applicable\u003e/\u003cprovider name\u003e/.tests/\u003cconfiguration name\u003e/config.yaml`\n\nExample:\nThe first written test was for `crowdsecurity/sshd-logs` : the configuration being tested is `./parsers/s01-parse/crowdsecurity/sshd-logs.yaml`, thus the test should takes place in the directory `./parsers/s01-parse/crowdsecurity/.tests/sshd-logs`, with the tests configuration file being ./parsers/s01-parse/crowdsecurity/.tests/sshd-logs/config.yaml`\n\n\n## configuration file format\n\n```yaml\nparser_input: parser_input.yaml\nparser_results: parser_results.yaml\nbucket_input: bucket_input.yaml                 \nbucket_results: bucket_result.json              \npostoverflow_input: postoverflow_input.yaml     \npostoverflow_results: postoverflow_results.yaml \nreprocess: true\n\n#configuration\nindex: \"./config/hub/.index.json\"\nconfigurations:      \n  parsers:\n  - crowdsecurity/sshd-logs\n  - crowdsecurity/syslog-logs\n```\n\n## File involved for the test\nThe paths of these of files are defined from the same directory as the config.yaml\n* `parser_input.yaml`: file holding serialized events fed to the parser engine. If this configuration field is empty or missing, hub-tests will look for an `acquis.yaml` in the test directory, and will follow its directive.\n* `parser_results.yaml`: file holding parser result. The test results will be compared to this file, and fail if it differs. If the file doesn't exist, it is automatically generated (this is useful to create a new test). \n* `bucket_input.yaml`: file holding serialized bucket input. It's automatically generated from parsing. This is a serialized list of events.\n* `bucket_results.jdon`: same as parser_result.json, this file holds the bucket output. \n* `postoverflow_input.yaml`: same as bucket input, this file holds the serialized output of the scenarios. This is a serialized list of events.\n* `postoverflow_results.json`: same as parser result, this file holds the postoverflow result.\n* `reprocess`: make it true if you expect some reprocess to\n  happen. Useful only for buckets test. If scenarios are enabled, it\n  enforces postoverflows to pass even if no postoverflow is\n  configured, to be able to repour it in the buckets.\n\n## Other part of the configuration\n* `index`: where to find the `.index.json` from the root directory of the hub repository\n* `configurations`: This is dict of lists of configurations we want to load. Valid keys for the dict are `parsers`, `scenarios` and `postoverflows`. \n\n## Caveats or known bugs\n\nFor now a config directory is still needed with:\n\n * `simulation.yaml` this file can be empty\n * patterns directory with all parsers/groks patterns\n * `config/hub/.index.json` I suspect a small bug in pkg/cwversion that makes this requirement happen.\n\n## Creation of a new configuration test\n\nIn the root of hub repository there's a `tests.sh` provided as a tool to help write some tests.\n```\n./tests.sh                                                                                                                          16:56\nUsage:\n    ./tests.sh -h|--help                        Display this help message.\n    ./tests.sh -i                               Init tests : prepare env tests\n    ./tests.sh -g \u003cCONFIG_PATH/name.yaml\u003e       Generate new test by specifying target config (parser|scenario|postoverflow)\n    ./tests.sh --all                            Run all tests\n    ./tests.sh --single \u003cMYPATH/config.yaml\u003e    Run single test\n```\n\nTo write a new test on a pristine repository:\n ```\n./tests.sh -i\n./tests.sh -g \u003cpath to the item configuration yaml\u003e\n```\nIt'll create the needed .tests directory.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fhub-tests","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcrowdsecurity%2Fhub-tests","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fhub-tests/lists"}