Add integration tests for security analyzer #8774
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
End-user friendly description of the problem this fixes or functionality this introduces.
N/A - This is a test improvement only.
Summarize what the PR does, explaining any non-trivial design decisions.
This PR adds integration tests for the security analyzer component to ensure it properly integrates with the event stream and correctly handles actions with different security risk levels. The tests verify:
Additionally, this PR adds three new security analyzers:
These new analyzers provide different security evaluation strategies:
These tests help ensure that no action gets passed to the runtime until the security analyzer has evaluated it and determined it is safe to run.
Link of any specific issues this addresses:
N/A
To run this PR locally, use the following command: