feat(plc): ingest CODESYS projects from a git repo (SAST + SBOM)
CI / Check (pull_request) Successful in 5m47s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
CI / Check (pull_request) Successful in 5m47s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
Onboard a PLC/SPS target with a git repo (or source archive) of exported control logic and get the same results as an upload — the natural way CODESYS projects are version-controlled, so each scan is a git pull rather than a blob re-upload. - scan_matrix: the PLC control-logic requirement is satisfied by a PlcProject *or* a code artifact (git repo / source archive). - plan: resolve_artifact binds the PLC scan to the PlcProject if present, else the code artifact. - orchestrator: a PLC/SPS target routes to the control-logic scanner over the clone (not the SAST/semgrep pipeline), then still runs DAST for a reachable device. - plc::sbom::collect_sbom: the control-app SBOM now also comes from any `.projectarchive` committed inside the working tree (a git repo / extracted archive), in addition to an uploaded archive. Docs: new guide page "PLC / SPS (CODESYS)" documenting the best-case git repo layout (commit PLCopen XML exports for SAST + the .projectarchive for the SBOM; don't commit only the binary .project). UI: onboarding wizard shows the same guidance for PLC/SPS targets. Implements the git-ingest follow-up from #166 / #165. Tracker #167. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
7369e031c4
commit
1a8a6e5149
@@ -214,6 +214,36 @@ pub fn OnboardingPage() -> Element {
|
||||
// ---- Step 1: artifacts ----
|
||||
if step_now == 1 {
|
||||
div { class: "card-header", "Attach artifacts" }
|
||||
if target_type() == "plc_sps" {
|
||||
div {
|
||||
style: "margin: 12px 16px 0; padding: 12px 14px; border-left: 3px solid var(--accent, #3b82f6); background: var(--surface-2, rgba(59,130,246,0.08)); font-size: 0.88em; line-height: 1.55;",
|
||||
div { style: "font-weight: 600; margin-bottom: 4px;", "CODESYS / PLC projects" }
|
||||
"Attach a "
|
||||
b { "PLC project" }
|
||||
" (PLCopen XML / ST, or a .projectarchive), or a "
|
||||
b { "Git repository" }
|
||||
" of exported source — every scan is then just a pull."
|
||||
ul { style: "margin: 6px 0 0; padding-left: 18px;",
|
||||
li {
|
||||
b { "Control-logic SAST" }
|
||||
" — commit "
|
||||
b { "PLCopen XML exports" }
|
||||
" (Project → Export PLCopenXML) or raw .st; ST and graphical FBD/LD are both analyzed."
|
||||
}
|
||||
li {
|
||||
b { "Library + runtime SBOM" }
|
||||
" — include the "
|
||||
b { ".projectarchive" }
|
||||
"; PLCopen XML alone carries no libraries."
|
||||
}
|
||||
li {
|
||||
"Avoid committing only the binary "
|
||||
code { ".project" }
|
||||
" — it can't be parsed and doesn't diff."
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
div { style: "padding: 16px;",
|
||||
div { style: "display: flex; gap: 8px; flex-wrap: wrap; align-items: flex-end;",
|
||||
div { class: "form-group", style: "margin: 0;",
|
||||
|
||||
Reference in New Issue
Block a user