Skip to content

CBX-NEXT-052: Regal Rego linting through shared SARIF audit support - #706

Merged
AdamFrisby merged 1 commit into
mainfrom
codeybox/1bebb70e
Oct 6, 2026
Merged

AdamFrisby merged 1 commit into
mainfrom
codeybox/1bebb70e

Conversation

@AdamFrisby

Copy link
Copy Markdown
Owner

Automated via CodeyBox — work item 1bebb70e3d5240c39473b46606f57bb9

Initiated by CodeyBox operator


Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox

Implements codeybox.regal on ExternalToolAuditorBase with the shared
SarifToolOutputParser: regal lint --format sarif over explicit local
Rego targets, findings exits {0,2,3} per the official Regal CLI exit
convention, version pin 0.40.0 via regal version probe, deterministic
rejection of --format/-f and --fix, repo-relative target validation,
and severity mapping (error->Error, warning->Warning, note->Info).
Disabled by default, verify-only tool requirement, hot-reloadable
scoped config (ExpectedVersion, ConfigPath, Targets plus shared
knobs). Documents OPA strict-mode non-coverage and read-only posture.
Adds 31-test RegalAuditorTests suite using the real production
parser/adapter/host-registration path with mocked process transport.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
@AdamFrisby
AdamFrisby merged commit 8429e8c into main Oct 6, 2026
@AdamFrisby
AdamFrisby deleted the codeybox/1bebb70e branch October 6, 2026 10:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant