diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..943a03a --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,13 @@ +# To get started with Dependabot version updates, you'll need to specify which +# package ecosystems to update and where the package manifests are located. +# Please see the documentation for all configuration options: +# https://docs.github.com/github/administering-a-repository/configuration-options-for-dependency-updates + +version: 2 +updates: + - package-ecosystem: 'npm' # See documentation for possible values + directory: '/' # Location of package manifests + schedule: + interval: 'weekly' + allow: + - dependency-type: 'production' diff --git a/.github/workflows/npm-publish.yml b/.github/workflows/npm-publish.yml new file mode 100644 index 0000000..643d4c4 --- /dev/null +++ b/.github/workflows/npm-publish.yml @@ -0,0 +1,38 @@ +# This workflow will run tests using node and then publish a package to the +# npm registry when a release is created. +# For more information see: https://docs.github.com/en/actions/publishing-packages/publishing-nodejs-packages + +name: NPM Package + +on: + release: + types: [created] + +permissions: + id-token: write + contents: read + actions: read + +jobs: + build: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + - uses: actions/setup-node@v6 + with: + node-version: 24.x + - run: npm ci + - run: npm test + + publish-npm: + needs: build + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + - uses: actions/setup-node@v6 + with: + node-version: 24.x + registry-url: https://registry.npmjs.org/ + - run: npm i -g npm@11 + - run: npm ci + - run: npm publish diff --git a/.github/workflows/run-tests.yml b/.github/workflows/run-tests.yml new file mode 100644 index 0000000..03ef504 --- /dev/null +++ b/.github/workflows/run-tests.yml @@ -0,0 +1,26 @@ +name: Run Tests +on: + pull_request: + branches: + - '**' + push: + branches: + - main +permissions: + contents: read + actions: read +jobs: + test: + runs-on: ubuntu-latest + + strategy: + matrix: + node-version: [22.x, 24.x] + + steps: + - uses: actions/checkout@v6 + - uses: actions/setup-node@v6 + with: + node-version: ${{ matrix.node-version }} + - run: npm ci + - run: npm test diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..3150af0 --- /dev/null +++ b/.gitignore @@ -0,0 +1,4 @@ +/node_modules/* +/dist/* +/build +/coverage diff --git a/.prettierignore b/.prettierignore new file mode 100644 index 0000000..a79a9e7 --- /dev/null +++ b/.prettierignore @@ -0,0 +1,4 @@ +/dist +/coverage +tests/fixtures/invalid.json +/css diff --git a/LICENSE b/LICENSE index 261eeb9..a6cb839 100644 --- a/LICENSE +++ b/LICENSE @@ -186,7 +186,7 @@ same "printed page" as the copyright notice for easier identification within third-party archives. - Copyright [yyyy] [name of copyright owner] + Copyright 2026 Bundesamt für Sicherheit in der Informationstechnik (BSI) Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. diff --git a/README.md b/README.md index ff0d162..5b957d0 100644 --- a/README.md +++ b/README.md @@ -1,2 +1,83 @@ -# cli -A cli to access features of secvisogram via command line. +# @secvisogram/cli + +A command-line interface for rendering [CSAF](https://oasis-open.github.io/csaf-documentation/) +(Common Security Advisory Framework) documents (versions 2.0 and 2.1) to +HTML, without needing the [Secvisogram](https://github.com/secvisogram/secvisogram) +web app - see [issue #606](https://github.com/secvisogram/secvisogram/issues/606). + +It uses [`@secvisogram/html-template`](https://github.com/secvisogram/html-template) +for the actual rendering, and is a thin wrapper around it. + +## Installation + +```sh +npm install -g @secvisogram/cli +``` + +## Usage + +```sh +secvisogram-render render [-o ] +secvisogram-render --help +secvisogram-render --version +``` + +- `` - path to a CSAF 2.0 or 2.1 JSON document. +- `--output, -o ` - path to write the rendered HTML to. + If omitted, the HTML is written to stdout instead. +- `--help, -h` - print usage information. Works both on its own + (`secvisogram-render --help`) and after a command + (`secvisogram-render render --help`). +- `--version, -v` - print the installed version of `@secvisogram/cli`. + +### Examples + +Render to stdout: + +```sh +secvisogram-render render advisory.json +``` + +Render to a file: + +```sh +secvisogram-render render advisory.json -o advisory.html +``` + +The CSAF version (`2.0` or `2.1`) is read from the document's +`document.csaf_version` field; there's no separate flag to select it. +Any other value (or a missing field) is rejected with an error. + +The output is a single, self-contained HTML file/string - all CSS is +inlined into `