Skip to content

[PPSC-927] fix(supply-chain): survive armis-cli upgrades in init wrappers#216

Merged
yiftach-armis merged 4 commits into
mainfrom
fix/PPSC-927-stale-binary-path-after-upgrade
Jun 8, 2026
Merged

[PPSC-927] fix(supply-chain): survive armis-cli upgrades in init wrappers#216
yiftach-armis merged 4 commits into
mainfrom
fix/PPSC-927-stale-binary-path-after-upgrade

Conversation

@yiftach-armis

@yiftach-armis yiftach-armis commented Jun 8, 2026

Copy link
Copy Markdown
Collaborator

Related Issue

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Refactoring (no functional changes)
  • Performance improvement

Problem

supply-chain init injected shell wrappers that embedded a fully symlink-resolved binary path, which on Homebrew is the version-pinned Cellar dir (e.g. .../Cellar/armis-cli/1.11.0/...). After brew upgrade armis-cli deleted that dir, the wrappers command '<dead-path>' failed with exit 127 — and because each wrapper shadows the real command, every wrapped package manager (npm, pnpm, bun, pip, uv, poetry, npx) broke in new shells until init was re-run.

Solution

resolveCliPath now references armis-cli by bare name (re-resolved from PATH on every call) when it is on PATH, falling back to the stable symlink path via filepath.Abs(os.Executable()) without EvalSymlinks. The generated wrappers are also now fail-closed: if armis-cli cannot be found at invocation time, the wrapper prints a loud stderr warning that enforcement has lapsed and runs the real package manager un-wrapped, so installs never silently break. A cliBinaryName constant centralizes the literal.

Testing

Automated Tests

  • Unit tests added/updated
  • Integration tests added/updated
  • All tests passing locally

Manual Testing

Built the binary and inspected init --mode env output (bare 'armis-cli' reference + guard). In a real bash subshell, simulated the post-upgrade state (armis-cli absent from PATH): the wrapper warned on stderr and still ran the real npm (exit 0); with armis-cli present, it routed through supply-chain wrap. Full go test ./... green (2533 passed, 71.3% coverage), gofmt/go vet clean, AppSec scan_diff 0 findings.

Reviewer Notes

Forward-only: this cannot repair an RC file already on disk. Existing users must re-run armis-cli supply-chain init once after upgrading to a build with this fix (noted in CHANGELOG). HasCurrentInjection's exact-match means init correctly detects the old block and re-injects.

Checklist

  • Code follows project style guidelines
  • Pre-commit hooks pass
  • Self-review performed
  • Documentation updated (if needed)
  • Breaking changes documented (if applicable)
  • No new warnings generated

…cli upgrades

resolveCliPath embedded the fully symlink-resolved binary path, which on
Homebrew is the version-pinned Cellar dir (e.g. .../Cellar/armis-cli/1.11.0/...).
After `brew upgrade armis-cli` deleted that dir, every wrapped package manager
(npm, pnpm, bun, pip, uv, poetry, npx) failed to run in new shells.

- resolveCliPath now prefers the bare name `armis-cli` (re-resolved from PATH
  on every call) when on PATH, else the stable symlink path from
  filepath.Abs(os.Executable()) without EvalSymlinks.
- Generated wrappers are now fail-closed: if armis-cli cannot be found at
  invocation time, the wrapper warns loudly on stderr and runs the real
  package manager un-wrapped so installs never silently break.
- Add cliBinaryName const; add tests for the guard and resolveCliPath.

Forward-only: existing users must re-run `armis-cli supply-chain init` once
after upgrading to a build with this fix.
Copilot AI review requested due to automatic review settings June 8, 2026 14:16
@github-actions

github-actions Bot commented Jun 8, 2026

Copy link
Copy Markdown

Armis AppSecArmis AppSec Security Scan Results

🟠 HIGH issues found

Severity Count
🟠 HIGH 1

Total: 1

View all 1 findings

🟠 HIGH (1)

CWE-426 - Software and Data Integrity Failures (CWE-426

Location: internal/supplychain/shell.go:434

Untrusted Search Path): The program looks at the system's PATH variable and walks through every folder listed there. It collects the names of any executables it finds, such as "npm" or "pip". Later, when the tool creates shell wrapper functions, it uses those names directly in the commands it writes to your shell configuration files. Because the PATH contents are not checked or filtered, an attacker who can add a directory to your PATH (or place a malicious program in an existing PATH directory) can cause the wrapper to run their own program instead of the legitimate one. The wrapper will call the name it discovered, and the shell will resolve it using the same untrusted PATH, potentially executing the attacker‑controlled binary. In short, user‑controlled data (the PATH variable) flows into the part of the code that decides which program to run, without any validation, making it possible for an attacker to influence which executable is executed. No safeguards are present to stop this, so the vulnerability is real.

const maxScanPathResults = 128

// scanPathExecutables walks every directory on $PATH and returns the
// deduplicated, sorted set of entry names for which match(name) is true and
// (on Unix) the file carries at least one execute bit. It is the single place
// the PATH traversal, dedup, and execute-bit semantics live, shared by
// DetectPipVariants and DetectInstalledPMs so the two cannot drift apart.
// Returns nil when PATH is unset or nothing matches; callers decide their own
// fallback.
func scanPathExecutables(match func(name string) bool) []string {
	pathEnv := os.Getenv("PATH")
	if pathEnv == "" {
		return nil
	}

	seen := make(map[string]bool)
	const readDirChunk = 32 // entries per ReadDir call; small enough to avoid large allocs
	for _, dir := range filepath.SplitList(pathEnv) {
		if len(seen) >= maxScanPathResults {
			break
		}

CWEs: CWE-426: Untrusted Search Path

Comment thread internal/supplychain/shell.go Fixed
@github-actions

github-actions Bot commented Jun 8, 2026

Copy link
Copy Markdown

Test Coverage Report

total: (statements) 72.1%

Coverage by function
github.com/ArmisSecurity/armis-cli/cmd/armis-cli/main.go:19:			main					0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/agent.go:34:		Registry				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/agentdetect.go:29:	FlatResults				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/agentdetect.go:45:	NewScanner				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/agentdetect.go:53:	Scan					82.4%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:12:		resolvePath				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:23:		isUnderDir				81.8%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:46:		dirExists				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:56:		fileExists				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:67:		hasExtensionPrefix			80.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:88:		findExtensionVersion			64.3%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:111:	readVersionFromPackageJSON		71.4%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:127:	hasJetBrainsPlugin			100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:140:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:142:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:147:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:151:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:159:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:161:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:171:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:175:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:183:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:185:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:189:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:193:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:201:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:203:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:216:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:224:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:232:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:234:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:241:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:245:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:253:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:255:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:262:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:268:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:276:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:278:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:285:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:289:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:297:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:299:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:306:	CheckMCP				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:310:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:318:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:320:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:324:	CheckMCP				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:328:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:336:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:338:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:342:	CheckMCP				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:346:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:354:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:356:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:366:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:370:	DetectVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:378:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:380:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:395:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:399:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:407:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:409:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:417:	CheckMCP				75.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:425:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:433:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:435:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:439:	CheckMCP				83.3%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:460:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:468:	Name					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:470:	Detect					100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:474:	CheckMCP				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/detector.go:478:	DetectVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/format.go:13:		FormatPlain				81.8%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/format.go:50:		FormatJSON				100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/mcpconfig.go:19:	HasArmisMCP				83.3%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/mcpconfig.go:40:	HasArmisMCPInClaudeSettings		86.7%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/mcpconfig.go:68:	HasArmisMCPInZedSettings		66.7%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/mcpconfig.go:98:	HasArmisMCPInVSCodeFormat		75.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/mcpconfig.go:122:	hasArmisMCPInData			100.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:13:	NewPlatform				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:17:	UserHomeDirs				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:25:	VSCodeExtensionsDir			0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:30:	JetBrainsPluginDirs			0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:35:	VSCodeUserConfigDir			0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:39:	CursorAppExists				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:43:	JunieBinaryPaths			0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:51:	ZedConfigDir				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/platform_linux.go:55:	IsRoot					0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/userprofile.go:13:	enumerateUserDirs			0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/userprofile.go:41:	currentUserOnly				0.0%
github.com/ArmisSecurity/armis-cli/internal/agentdetect/userprofile.go:56:	globJetBrainsPluginDirs			0.0%
github.com/ArmisSecurity/armis-cli/internal/api/agents.go:30:			ReportAgentInventory			78.9%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:29:			Error					0.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:72:			copyWithContext				70.4%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:145:			WithHTTPClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:154:			WithUploadHTTPClient			100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:162:			WithAllowLocalURLs			100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:174:			NewClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:222:			IsDebug					100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:236:			setAuthHeader				77.8%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:271:			StartIngest				72.3%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:431:			GetIngestStatus				82.6%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:472:			WaitForIngest				84.6%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:523:			FetchNormalizedResults			74.2%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:578:			FetchAllNormalizedResults		91.7%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:604:			GetScanResult				68.4%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:639:			WaitForScan				90.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:660:			formatBytes				100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:682:			FetchArtifactScanResults		75.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:737:			ValidatePresignedURL			100.0%
github.com/ArmisSecurity/armis-cli/internal/api/client.go:774:			DownloadFromPresignedURL		84.2%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:58:			NewAuthProvider				95.2%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:104:			GetAuthorizationHeader			100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:124:			GetTenantID				85.7%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:141:			GetRegion				85.7%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:156:			IsLegacy				100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:169:			GetRawToken				85.7%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:197:			exchangeCredentials			87.9%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:268:			refreshIfNeeded				100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/auth.go:300:			parseJWTClaims				93.3%
github.com/ArmisSecurity/armis-cli/internal/auth/client.go:32:			Error					100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/client.go:44:			NewAuthClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/client.go:100:			Authenticate				77.4%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:34:		NewRegionCache				100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:40:		Load					82.4%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:75:		Save					76.9%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:105:		Clear					75.0%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:115:		getFilePath				83.3%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:132:		loadCachedRegion			100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:136:		saveCachedRegion			100.0%
github.com/ArmisSecurity/armis-cli/internal/auth/region_cache.go:140:		clearCachedRegion			100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:60:			InitColors				85.2%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:107:			ColorsEnabled				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:113:			ColorsForced				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:119:			SetOutputToFile				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:125:			GetOutputToFile				0.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:129:			enableColors				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:136:			disableColors				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:151:			parseErrorMessage			92.9%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:182:			PrintError				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:195:			PrintErrorf				0.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:202:			PrintWarning				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/color.go:208:			PrintWarningf				100.0%
github.com/ArmisSecurity/armis-cli/internal/cli/interactive.go:11:		IsInteractive				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/agent_detection.go:36:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/agent_detection.go:42:		runAgentDetection			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/agent_detection_collect.go:29:	init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/agent_detection_collect.go:33:	runAgentDetectionCollect		0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/agent_detection_collect.go:84:	buildInventoryPayload			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/auth.go:33:			init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/auth.go:39:			runAuth					92.9%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/failon.go:15:		ValidateFailOn				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/failon.go:37:		GetFailOn				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/output.go:32:		Cleanup					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/output.go:58:		ResolveOutput				96.4%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/theme.go:27:		armisTheme				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/cmdutil/theme.go:67:		GetInstallTheme				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/context.go:24:			NewSignalContext			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/context.go:33:			handleScanError				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/help.go:30:			SetupHelp				91.7%
github.com/ArmisSecurity/armis-cli/internal/cmd/help.go:59:			styledUsageTemplate			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/help.go:102:			defaultUsageTemplate			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/help.go:109:			initColorsForHelp			35.3%
github.com/ArmisSecurity/armis-cli/internal/cmd/help.go:150:			styleHelpOutput				83.3%
github.com/ArmisSecurity/armis-cli/internal/cmd/hook.go:24:			init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/hook_init.go:32:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/hook_init.go:38:		runHookInit				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:62:			init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:71:			runInstall				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:107:			showInstalledVersions			84.6%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:130:			installAll				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:223:			installTargets				29.1%
github.com/ArmisSecurity/armis-cli/internal/cmd/install.go:363:			printCredentialStatus			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install_interactive.go:17:	runInteractiveInstall			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install_interactive.go:234:	collectCredentials			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install_interactive.go:345:	validateAndReport			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install_interactive.go:376:	selectEditorsWithCodex			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/install_interactive.go:450:	offerHookSetup				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:167:			SetVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:175:			Execute					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:179:			init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:210:			PrintUpdateNotification			81.2%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:252:			printUpdateNotificationOnce		75.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:265:			getEnvOrDefault				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:272:			getEnvOrDefaultInt			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:284:			getAPIBaseURL				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:296:			getAuthProvider				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:308:			getPageLimit				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/root.go:315:			validatePageLimit			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/scan.go:92:			init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/scan_image.go:157:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/scan_repo.go:196:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain.go:17:		loadConfigUpward			80.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain.go:91:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:67:	init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:78:	runSupplyChainCheck			23.1%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:207:	countNoun				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:214:	buildSummary				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:231:	detectBaseLockfile			76.7%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_check.go:312:	resolvePolicy				63.2%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:65:	init					83.3%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:77:	runSupplyChainInit			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:113:	reportNothingInScope			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:154:	detectWrappablePMs			95.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:235:	summarizeDetectedPMs			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:283:	promptYesNo				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:303:	confirmInteractive			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:332:	readYesNo				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:352:	runInitEnv				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:366:	runInitNpmrc				75.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:416:	runInitRC				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:511:	runInitConfig				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:586:	detectOrgScopes				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:603:	collectScopesFromFile			89.5%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_init.go:634:	extractScope				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_status.go:28:	init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_status.go:33:	runSupplyChainStatus			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_status.go:116:	printEnvStatus				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_status.go:157:	runSupplyChainStatusJSON		0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_uninit.go:25:	init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_uninit.go:29:	runSupplyChainUninit			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:58:	init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:75:	runSupplyChainWrap			93.3%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:120:	canonicalPM				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:127:	runProxyWrap				72.4%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:188:	execPM					0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:255:	exitWithCode				60.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:280:	printBlockSummary			94.2%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:439:	ageToken				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:445:	rightPad				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:465:	printPkgFilterLine			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:503:	groupBlockedByPackage			84.6%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:536:	checkedAllPass				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:546:	formatPolicyShort			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:564:	shouldShowRationale			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:571:	rationaleAlreadyShown			80.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:583:	markRationaleShown			66.7%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:598:	filterRelevantBlocked			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:612:	isPrerelease				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:623:	allResultsPrerelease			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:635:	severityDot				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:639:	formatDurationShort			77.8%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:654:	registryEnvForPM			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:689:	parseSkipPackages			75.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:711:	resolveWrapPolicy			87.5%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:731:	wrapEcosystemEnforced			71.4%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:749:	requiresPreInstallBlock			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:757:	runPreInstallBlock			45.9%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:838:	printPreInstallBlockSummary		0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:886:	blockedViolationNames			0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:903:	pmToEcosystem				100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/supply_chain_wrap.go:944:	checkGradleStaleness			100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/uninstall.go:41:		init					100.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/uninstall.go:47:		runUninstall				0.0%
github.com/ArmisSecurity/armis-cli/internal/cmd/uninstall.go:66:		uninstallAll				32.9%
github.com/ArmisSecurity/armis-cli/internal/cmd/uninstall.go:193:		uninstallTargets			54.8%
github.com/ArmisSecurity/armis-cli/internal/cmd/uninstall.go:306:		confirm					100.0%
github.com/ArmisSecurity/armis-cli/internal/httpclient/client.go:31:		NewClient				92.3%
github.com/ArmisSecurity/armis-cli/internal/httpclient/client.go:61:		Do					86.1%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:23:		NewClaudeInstaller			75.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:35:		InstalledVersion			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:40:		Install					14.3%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:72:		pluginCacheDir				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:77:		PluginCacheDir				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:82:		EnvFilePath				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:87:		GetInstalledVersion			76.2%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:119:		HasExistingEnv				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:124:		registerMarketplace			83.3%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:141:		registerPlugin				75.0%
github.com/ArmisSecurity/armis-cli/internal/install/claude.go:170:		enablePlugin				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:18:		CodexConfigPath				66.7%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:26:		IsCodexDetected				80.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:37:		RegisterCodexMCP			78.6%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:71:		DeregisterCodexMCP			83.3%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:94:		buildCodexSection			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:107:		replaceTOMLSection			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:122:		removeTOMLSection			85.7%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:150:		findTOMLSectionBounds			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:204:		tomlQuote				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:210:		readFileOrEmpty				83.3%
github.com/ArmisSecurity/armis-cli/internal/install/codex.go:222:		writeFileAtomic				45.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:57:		EditorByID				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:70:		ConfigPath				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:81:		IsDetected				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:91:		Register				75.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:100:		DetectedEditors				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:117:		NewEditorInstaller			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:127:		InstalledVersion			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:130:		PluginDir				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:133:		EnvFilePath				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:136:		HasExistingEnv				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:147:		FetchPlugin				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:173:		GetInstalledVersion			80.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:183:		RegisterJetBrains			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:189:		defaultConfigPath			84.2%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:228:		homeDir					75.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:236:		appSupportPath				29.4%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:269:		registerEditor				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:283:		registerMCPServersFormat		100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:297:		registerVSCodeFormat			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:316:		registerZedFormat			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:335:		stdServerEntry				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/editors.go:342:		readJSONFileAsMap			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:19:		InstallHooks				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:30:		installHooksToFile			89.3%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:95:		RemoveHooks				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:106:		removeHooksFromFile			74.3%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:166:		isArmisHookEntry			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/hooks.go:178:		isArmisHookCommand			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:44:		ManifestPath				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:61:		ReadManifest				80.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:79:		WriteManifest				66.7%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:91:		NewManifest				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:102:		AddEditor				66.7%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:110:		RemoveEditor				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:115:		SetClaude				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:120:		SetCodex				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/manifest.go:125:		ConfigFormat				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:73:		HookClientByID				75.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:83:		ConfigPath				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:88:		IsDetected				80.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:98:		DetectHookClients			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:111:	hookConfigPath				75.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:122:	InstallNativeHook			73.3%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:153:	RemoveNativeHook			83.3%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:165:	installClientHook			85.7%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:182:	removeClientHook			66.7%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:193:	cursorHooksPath				50.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:199:	geminiHooksPath				50.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:205:	codexHooksPath				50.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:211:	copilotHooksPath			50.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:217:	clineHooksPath				16.7%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:241:	readJSONFileAsMapSafe			72.7%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:262:	installMergedHook			82.4%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:293:	removeMergedHook			0.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:327:	installCursorHook			94.7%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:362:	removeCursorHook			72.2%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:398:	buildCursorHooks			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:421:	buildGeminiHooks			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:442:	buildCodexHooks				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:473:	buildCopilotHooks			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:490:	buildClineHooks				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:508:	hasArmisHookEntries			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:517:	filterNonArmisEntries			80.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:527:	isArmisHookJSON				80.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:545:	cleanupLegacyCopilotHook		42.9%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:562:	removeLegacyFileIfArmisOnly		82.4%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:591:	posixQuote				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/native_hooks.go:595:	quotedCommand				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:53:		newPluginInstaller			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:61:		InstalledVersion			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:66:		LatestVersion				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:75:		FetchAndInstall				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:97:		fetchLatestRelease			69.6%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:137:		downloadAndExtract			73.6%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:253:		createVenv				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:286:		validateGitHubURL			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:300:		extractFile				57.1%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:312:		writeJSON				66.7%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:323:		findPython				76.9%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:350:		writeEnvFromEnvironment			85.7%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:381:		WriteEnvFromValues			51.3%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:449:		copyFile				63.6%
github.com/ArmisSecurity/armis-cli/internal/install/plugin.go:469:		venvPython				66.7%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:25:		InstallPreCommit			71.4%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:81:		RemovePreCommit				79.3%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:135:		PreCommitHookPath			0.0%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:144:		IsPreCommitInstalled			87.5%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:160:		resolveHooksDir				39.1%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:201:		DetectGitRoot				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/precommit.go:210:		buildPreCommitSection			83.3%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:19:		NewUninstaller				100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:28:		HasManifest				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:33:		PluginDir				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:38:		DeregisterEditor			0.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:59:		DeregisterAllEditors			80.6%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:110:		DeregisterClaude			64.7%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:144:		RemovePluginFiles			64.7%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:178:		editorConfigPath			0.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:189:		deregisterEditor			40.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:202:		deregisterFromFile			66.7%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:209:		deregisterMCPServersFormat		100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:225:		deregisterVSCodeFormat			77.8%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:241:		deregisterZedFormat			77.8%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:257:		removeContinueFile			75.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:271:		removeFromMarketplace			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:276:		removeFromInstalledPlugins		100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:281:		removeFromSettings			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:286:		removeJSONKey				55.6%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:301:		removeNestedJSONKey			61.5%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:321:		hasArmisEntry				83.3%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:343:		readAndParseJSON			100.0%
github.com/ArmisSecurity/armis-cli/internal/install/uninstall.go:355:		writeJSONAtomic				55.0%
github.com/ArmisSecurity/armis-cli/internal/install/validate.go:26:		ValidateCredentials			0.0%
github.com/ArmisSecurity/armis-cli/internal/install/validate.go:31:		resolveBaseURL				0.0%
github.com/ArmisSecurity/armis-cli/internal/install/validate.go:44:		validateCredentialsWithURL		100.0%
github.com/ArmisSecurity/armis-cli/internal/output/errno_unix.go:12:		isSyncNotSupported			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:55:			wrapText				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:78:			wrapLine				91.7%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:116:		formatRecommendations			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:186:		wrapTextWithFirstLinePrefix		90.9%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:225:		write					66.7%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:256:		Write					89.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:286:		Format					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:291:		FormatWithOptions			88.4%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:384:		SyncColors				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:388:		sortFindingsBySeverity			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:399:		loadSnippetFromFile			69.4%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:515:		formatCodeSnippetWithFrame		91.1%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:608:		truncatePlainLine			0.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:620:		highlightColumns			93.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:665:		scanDuration				89.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:698:		pluralize				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:707:		suppressionSummaryText			80.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:735:		renderBriefStatus			87.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:792:		renderSummaryDashboard			59.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:879:		renderFindings				88.9%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:908:		renderFinding				54.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1020:		renderGroupedFindings			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1044:		groupFindings				96.8%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1101:		severityRank				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1108:		isGitRepo				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1115:		getGitBlame				38.1%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1153:		parseGitBlame				95.2%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1189:		maskEmail				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1212:		getTopLevelDomain			75.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1224:		getHumanDisplayTitle			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1238:		wrapTitle				93.9%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1297:		maskFixForDisplay			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1332:		formatFixSection			0.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1397:		formatProposedSnippet			0.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1480:		limitHunkContext			64.7%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1556:		parseDiffHunk				91.7%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1578:		parseDiffLines				94.6%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1669:		findInlineChanges			73.5%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1740:		computeLCS				92.3%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1792:		buildTokenPositions			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1808:		tokenizeLine				92.9%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1836:		isWordChar				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1843:		formatDiffWithColorsStyled		77.1%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1917:		extractDiffFilename			80.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1939:		formatDiffHunkLine			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1959:		formatDiffContextLine			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:1970:		formatDiffRemoveLine			86.4%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2011:		formatDiffAddLine			86.4%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2053:		applyInlineHighlights			81.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2095:		truncateDiffLine			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2102:		truncateDiffLineWithFlag		66.7%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2116:		adjustHighlightSpans			83.3%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2138:		groupDiffHunks				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2169:		collectRenderOps			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2212:		renderChangeBlock			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2271:		formatDiffHunkSeparator			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2286:		formatValidationSection			0.0%
github.com/ArmisSecurity/armis-cli/internal/output/human.go:2343:		getExposureDescription			0.0%
github.com/ArmisSecurity/armis-cli/internal/output/icons.go:25:			GetConfidenceIcon			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/json.go:15:			Format					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/json.go:24:			FormatWithOptions			66.7%
github.com/ArmisSecurity/armis-cli/internal/output/json.go:32:			formatWithDebug				0.0%
github.com/ArmisSecurity/armis-cli/internal/output/json.go:58:			maskScanResultForOutput			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/json.go:78:			maskFindingSecrets			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:48:			Format					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:55:			FormatWithOptions			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:63:			formatWithSeverities			77.8%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:92:			isFailureSeverity			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:102:		convertToJUnitCasesWithSeverities	100.0%
github.com/ArmisSecurity/armis-cli/internal/output/junit.go:135:		countFailuresWithSeverities		100.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:26:		Error					0.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:37:		Error					0.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:58:		GetFormatter				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:75:		ShouldFail				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:94:		FilterActiveFindings			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/output.go:107:		CheckExit				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:174:		normalizeCWE				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:183:		normalizeCVE				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:193:		stripMarkdown				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:205:		Format					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:232:		firstNonEmpty				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:251:		stableRuleID				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:269:		buildRules				96.3%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:340:		convertToSarifResults			90.3%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:441:		buildMessageText			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:448:		severityToSarifLevel			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:467:		severityToSecurityScore			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:486:		generateHelpURI				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:510:		convertFixToSarif			90.5%
github.com/ArmisSecurity/armis-cli/internal/output/sarif.go:627:		FormatWithOptions			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:140:		DefaultStyles				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:278:		NoColorStyles				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:355:		GetStyles				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:363:		SyncStylesWithColorMode			100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:388:		GetSeverityText				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:415:		RenderCodeBlock				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/styles.go:440:		TerminalWidth				33.3%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:21:		GetLexer				100.0%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:32:		GetChromaStyle				80.0%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:45:		HighlightCode				81.2%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:79:		HighlightLine				75.0%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:88:		getTerminalFormatter			60.0%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:103:		HighlightLineWithBackground		87.5%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:126:		getBackgroundANSI			58.3%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:158:		rgbToANSI256				0.0%
github.com/ArmisSecurity/armis-cli/internal/output/syntax.go:171:		parseHexColor				76.9%
github.com/ArmisSecurity/armis-cli/internal/output/writer.go:51:		validateOutputPath			92.3%
github.com/ArmisSecurity/armis-cli/internal/output/writer.go:88:		NewFileOutput				88.2%
github.com/ArmisSecurity/armis-cli/internal/output/writer.go:145:		Writer					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/writer.go:150:		Close					100.0%
github.com/ArmisSecurity/armis-cli/internal/output/writer.go:167:		FormatFromExtension			100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:32:		IsCI					100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:60:		isTerminalWriter			100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:68:		NewReader				100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:83:		NewWriter				50.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:117:		NewSpinner				100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:125:		NewSpinnerWithTimeout			100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:142:		NewSpinnerWithContext			100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:150:		SetWriter				100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:159:		Start					89.8%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:275:		Stop					100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:310:		Update					100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:317:		GetElapsed				100.0%
github.com/ArmisSecurity/armis-cli/internal/progress/progress.go:324:		formatDuration				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/finding_type.go:9:		DeriveFindingType			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:48:		NewScanner				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:63:		WithPollInterval			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:69:		WithFetchRetryInterval			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:75:		WithSBOMVEXOptions			0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:82:		WithPullPolicy				0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:88:		ScanImage				0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:119:		ScanTarball				77.8%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:231:		exportImage				0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:286:		isDockerAvailable			42.9%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:301:		getDockerCommand			75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:310:		validateDockerCommand			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:319:		imageExistsLocally			87.5%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:334:		determinePullBehavior			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:352:		isRetryableError			75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:360:		buildScanResult				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:387:		convertNormalizedFindings		85.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:510:		shouldFilterByExploitability		100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:529:		cleanDescription			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:548:		isEmptyFinding				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/image.go:563:		generateFindingTitle			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/image/validate.go:11:		validateImageName			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/mask.go:22:			MaskFixSecrets				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/files.go:26:		ParseFileList				87.5%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/files.go:41:		addFile					87.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/files.go:94:		Files					100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/files.go:99:		RepoRoot				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/files.go:104:		ValidateExistence			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:52:		GitChangedFiles				82.6%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:103:	gitRepoRoot				80.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:128:	changedUncommitted			41.7%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:157:	changedStaged				75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:170:	validateRef				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:183:	changedSinceRef				75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:206:	filterToScanPath			95.8%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:259:	runGit					91.7%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:286:	parseLines				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/gitchanges.go:306:	combineAndDedupe			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:28:		LoadIgnorePatterns			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:36:		LoadSuppressionConfig			0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:78:		LoadArmisIgnore				92.9%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:138:		parseArmisIgnoreFile			92.5%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:204:		Match					100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/ignore.go:216:		shouldSkipDir				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:85:		ApplyInlineSuppression			97.2%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:214:		parseInlineComment			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:241:		isCommentLine				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:255:		isFuncSignature				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:268:		containsAny				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:282:		findCommentStart			83.3%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:322:		parseDirectiveParams			93.9%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:380:		matchesInlineDirective			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:416:		buildInlineSuppressionInfo		100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/inline.go:444:		countSuppressed				0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/matcher.go:28:		MatchFinding				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/matcher.go:62:		cweMatches				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/matcher.go:78:		ApplySuppression			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/matcher.go:101:		recomputeSummary			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:46:		NewScanner				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:61:		WithPollInterval			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:67:		WithFetchRetryInterval			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:73:		WithIncludeFiles			0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:79:		WithSBOMVEXOptions			0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:85:		Scan					67.9%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:293:		tarGzDirectory				71.8%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:374:		isPathContained				75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:383:		tarGzFiles				78.6%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:474:		safeAddSize				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:481:		calculateFilesSize			78.6%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:507:		calculateDirSize			76.9%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:554:		shouldSkip				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:585:		isTestFile				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:631:		isRetryableError			75.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:640:		buildScanResult				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:667:		convertNormalizedFindings		73.3%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:790:		shouldFilterByExploitability		100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:809:		cleanDescription			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:830:		generateFindingTitle			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/repo.go:834:		isEmptyFinding				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:58:	NewSuppressionConfig			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:63:	IsEmpty					100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:77:	Add					100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:99:	CategoryMapping				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:112:	parseDirectiveLine			93.5%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:173:	hasDirectivePrefix			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/repo/suppression.go:187:	validateCWE				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/sbom_vex.go:38:		NewSBOMVEXDownloader			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/sbom_vex.go:50:		Download				85.2%
github.com/ArmisSecurity/armis-cli/internal/scan/sbom_vex.go:102:		downloadAndSave				77.8%
github.com/ArmisSecurity/armis-cli/internal/scan/status.go:16:			FormatScanStatus			100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/status.go:35:			FormatElapsed				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/status.go:48:			MapSeverity				100.0%
github.com/ArmisSecurity/armis-cli/internal/scan/testhelpers/findings.go:9:	CreateNormalizedFinding			0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/testhelpers/findings.go:14:	CreateNormalizedFindingWithLabels	0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/testhelpers/findings.go:19:	CreateNormalizedFindingFull		0.0%
github.com/ArmisSecurity/armis-cli/internal/scan/title.go:14:			GenerateFindingTitle			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/bun.go:18:	ParseBunLockfile			80.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/bun.go:62:	parseBunPackageKey			80.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/bun.go:76:	shouldSkipBunPackage			83.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:28:	RunCheck				0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:32:	runCheck				96.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:99:	parseLockfile				33.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:126:	queryRegistry				0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:144:	DetectEcosystemFromPath			0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:148:	detectEcosystemFromPath			92.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:184:	isRequirementsFile			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/check.go:196:	diffEntries				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/gradle.go:16:	ParseGradleLockfile			90.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/lockfile.go:24:	readLockfile				90.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/maven.go:38:	ParseMavenDeps				90.5%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/maven.go:79:	mavenDepToEntry				87.5%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/npm.go:27:	ParseNPMLockfile			87.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/npm.go:76:	extractPackageName			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/npm.go:84:	shouldSkipResolved			83.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pdm.go:26:	ParsePDMLockfile			85.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pdm.go:64:	shouldSkipPDMSource			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pip.go:29:	ParsePipRequirements			90.5%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pip.go:79:	parsePipRequirement			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pip.go:106:	shouldSkipPipLine			85.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pip.go:126:	normalizePipName			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pipfile.go:20:	ParsePipfileLock			94.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pipfile.go:55:	pipfileEntryToPackage			80.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pnpm.go:28:	ParsePNPMLockfile			82.4%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pnpm.go:65:	parsePnpmPackageKey			79.2%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pnpm.go:116:	stripPeerFromKey			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/pnpm.go:147:	shouldSkipPnpmPackage			87.5%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/poetry.go:26:	ParsePoetryLockfile			85.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/poetry.go:58:	shouldSkipPoetrySource			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/uv.go:26:		ParseUVLockfile				85.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/uv.go:64:		shouldSkipUVSource			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:15:	ParseYarnLockfile			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:28:	isBerryLockfile				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:37:	parseYarnBerry				81.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:79:	extractBerryPackageName			30.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:119:	shouldSkipYarnResolution		100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:138:	parseYarnClassic			96.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:191:	extractClassicPackageName		75.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/check/yarn.go:199:	shouldSkipClassicProtocol		100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:59:		KnownEcosystemsHint			0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:67:		LoadConfig				88.2%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:100:		ToPolicy				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:126:		UnknownEcosystems			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:149:		EnforcesEcosystem			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/config.go:180:		FindConfigDir				91.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/detect.go:64:		DetectEcosystems			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/detect.go:103:		FindEcosystemLockfile			92.9%
github.com/ArmisSecurity/armis-cli/internal/supplychain/detect.go:131:		ecosystemLockfileName			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:80:		NewProxy				94.1%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:130:		Start					91.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:156:		Addr					100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:163:		Blocked					100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:171:		Checked					100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:177:		Allowed					100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:187:		Close					66.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:194:		handleRequest				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:222:		handleMetadataFiltering			72.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:347:		copyCacheHeaders			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:369:		sanitizeHeaderValue			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:373:		filterMetadata				92.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:528:		filterPyPISimple			89.8%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:622:		pypiFileAge				88.9%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:640:		pypiVersionFromFilename			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:676:		jsonString				83.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:687:		reverseProxy				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:691:		extractPackageNameFromPath		91.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:725:		isMetadataRequest			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:732:		isPrerelease				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:741:		extractPyPIPackageNameFromPath		100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/proxy.go:766:		isPyPIMetadataRequest			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:47:	NewMavenClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:59:	NewMavenClientWithHTTP			66.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:69:	GetPublishDate				96.3%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:123:	escapeSolrQueryValue			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:129:	fetchPublishDate			76.9%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/maven.go:183:	GetPublishDates				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/npm.go:58:	NewClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/npm.go:72:	NewClientWithHTTP			66.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/npm.go:82:	GetPublishDate				91.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/npm.go:105:	GetPublishDates				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/npm.go:135:	fetchMetadata				85.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:47:	NewPyPIClient				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:59:	NewPyPIClientWithHTTP			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:75:	GetPublishDate				79.2%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:124:	GetPublishDates				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:154:	fetchReleases				82.1%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:216:	NormalizePyPIName			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:220:	normalizePyPIName			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:228:	lookupReleaseNormalized			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/registry/pypi.go:244:	normalizeVersion			84.6%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:55:		sanitizePMNames				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:73:		DetectShells				91.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:106:		GenerateWrapper				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:118:		generatePosixWrapper			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:152:		generateFishWrapper			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:185:		shellQuote				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:206:		resolveCliPath				77.8%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:222:		InjectFunctions				88.9%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:237:		injectIntoFile				78.9%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:273:		RemoveFunctions				87.5%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:287:		removeFromFile				86.7%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:315:		removeBlock				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:339:		EvalCommand				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:343:		HasInjection				75.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:356:		HasCurrentInjection			75.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:365:		fileExists				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:381:		IsPipVariant				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:395:		CanonicalPipVariant			0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:433:		scanPathExecutables			84.6%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:519:		DetectPipVariants			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:540:		DetectInstalledPMs			0.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/shell.go:575:		IsOnPath				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:21:	DefaultPolicy				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:36:	ClassifySeverity			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:46:	IsExcluded				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:66:	ParseDuration				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:110:	parseFiniteNonNegativeFloat		100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:132:	scaleToDuration				100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:140:	ViolationToFinding			100.0%
github.com/ArmisSecurity/armis-cli/internal/supplychain/supplychain.go:154:	formatAge				100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:63:		NewChecker				100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:79:		CheckCached				100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:97:		CheckInBackground			100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:117:		check					85.7%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:160:		fetchLatestVersion			89.5%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:194:		getCacheFilePath			66.7%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:209:		readCache				84.6%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:233:		writeCache				76.9%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:257:		IsNewer					100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:280:		parseVersion				100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:303:		FormatNotification			100.0%
github.com/ArmisSecurity/armis-cli/internal/update/update.go:322:		getUpdateCommand			40.0%
github.com/ArmisSecurity/armis-cli/internal/util/cache.go:21:			GetCacheDir				75.0%
github.com/ArmisSecurity/armis-cli/internal/util/cache.go:41:			GetCacheFilePath			80.0%
github.com/ArmisSecurity/armis-cli/internal/util/format.go:7:			FormatCategory				100.0%
github.com/ArmisSecurity/armis-cli/internal/util/mask.go:109:			MaskSecretInLine			86.4%
github.com/ArmisSecurity/armis-cli/internal/util/mask.go:164:			maskValue				83.3%
github.com/ArmisSecurity/armis-cli/internal/util/mask.go:190:			MaskSecretInLines			100.0%
github.com/ArmisSecurity/armis-cli/internal/util/mask.go:204:			MaskSecretInMultiLineString		100.0%
github.com/ArmisSecurity/armis-cli/internal/util/mask.go:218:			MaskSecretsInStringMap			100.0%
github.com/ArmisSecurity/armis-cli/internal/util/path.go:13:			SanitizePath				90.9%
github.com/ArmisSecurity/armis-cli/internal/util/path.go:53:			SafeJoinPath				87.5%
github.com/ArmisSecurity/armis-cli/test/sample-repo/src/main.go:6:		main					0.0%
total:										(statements)				72.1%

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves supply-chain init’s injected shell wrappers so they remain functional across armis-cli upgrades (notably Homebrew Cellar path churn) and so wrappers don’t hard-fail package manager commands when armis-cli is missing.

Changes:

  • Updated wrapper generation to avoid embedding symlink-resolved, version-pinned armis-cli paths and instead prefer a PATH-resolved armis-cli reference when available.
  • Added a “fail-closed” runtime guard in generated wrappers: if armis-cli can’t be located, emit a stderr warning and run the real package manager unwrapped.
  • Added unit tests for the new wrapper guard behavior and resolveCliPath behavior; documented the fix in the changelog.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
internal/supplychain/shell.go Changes wrapper generation + resolveCliPath to be upgrade-proof and add runtime guard/fallback behavior.
internal/supplychain/shell_test.go Adds tests asserting guard/warning/fallback behavior and resolveCliPath selection logic.
docs/CHANGELOG.md Documents the behavioral change and the need to re-run supply-chain init once after upgrading.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread internal/supplychain/shell.go Outdated
Comment on lines +150 to +158
// The `command -v` guard makes the wrapper fail-closed: if armis-cli is
// not resolvable at invocation time (e.g. a stale absolute path left by a
// package-manager upgrade), the wrapper warns loudly on stderr and runs the
// real package manager un-wrapped rather than failing the command outright.
// armis:ignore cwe:78 reason:pm is constrained to ^[a-z][a-z0-9-]*(\.[0-9]+)?$ by sanitizePMNames, so any dot is followed only by digits (not a shell metacharacter); safeCli is shellQuote-escaped; command -v is used only for presence detection and its output is discarded
fmt.Fprintf(&b,
"function %s\n"+
" if command -v %s >/dev/null 2>&1\n"+
" command %s supply-chain wrap %s $argv\n"+

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch — fixed in 05acf31. You're right that fish's command builtin has no POSIX -v; command -v armis-cli would error and make the if always take the else branch, silently disabling enforcement for every fish user even when armis-cli is present. Switched the fish guard to command -q (fish 3.0+), and dropped the now-redundant >/dev/null 2>&1 since -q emits no output. bash/zsh keep command -v (correct POSIX).

Comment thread internal/supplychain/shell_test.go Outdated
Comment on lines +520 to +522
if !strings.Contains(wrapper, "if command -v") {
t.Errorf("fish wrapper missing `command -v` guard:\n%s", wrapper)
}

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 05acf31 — the fish wrapper now uses command -q and TestGenerateWrapper_FishContainsGuard asserts on if command -q accordingly (the posix test still asserts command -v, which stays correct for bash/zsh). Verified the generated fish output: if command -q 'armis-cli' with no redirect.

…lveCliPath

The code-scanning check flags resolveCliPath for untrusted search path
because it returns the bare name "armis-cli" (PATH-resolved by the shell).
This is a false positive: cliBinaryName is a hardcoded constant (not user
input), the generated wrapper already resolves the package manager itself
by bare name (`command npm`), and supply-chain init configures the current
user's own shell, whose $PATH is not a trust boundary for a local CLI. Add
an armis:ignore matching the existing cwe:426 cwe:427 annotations on
IsOnPath and DetectInstalledPMs in this file.
…apper guard

fish's `command` builtin does not accept POSIX `-v`; `command -v` would error
and make the guard always take the else branch, silently disabling enforcement
for every fish user even when armis-cli is present. Switch the fish guard to
`command -q` (fish 3.0+), which is the native presence check and emits no
output (so the `>/dev/null 2>&1` redirect is no longer needed). bash/zsh keep
`command -v`, which is correct POSIX. Update the fish test to assert `-q`.

Addresses PR #216 review comments from copilot-pull-request-reviewer.
Copilot AI review requested due to automatic review settings June 8, 2026 14:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.

Comment thread internal/supplychain/shell.go Outdated
Comment on lines +128 to +137
fmt.Fprintf(&b,
"%s() {\n"+
" if command -v %s >/dev/null 2>&1; then\n"+
" command %s supply-chain wrap %s \"$@\"\n"+
" else\n"+
" printf '[armis] armis-cli not found - running %s WITHOUT supply-chain enforcement\\n' >&2\n"+
" command %s \"$@\"\n"+
" fi\n"+
"}\n",
pm, safeCli, safeCli, pm, pm, pm)
Comment thread internal/supplychain/shell.go Outdated
Comment on lines +157 to +166
fmt.Fprintf(&b,
"function %s\n"+
" if command -q %s\n"+
" command %s supply-chain wrap %s $argv\n"+
" else\n"+
" printf '[armis] armis-cli not found - running %s WITHOUT supply-chain enforcement\\n' >&2\n"+
" command %s $argv\n"+
" end\n"+
"end\n",
pm, safeCli, safeCli, pm, pm, pm)
Comment thread internal/supplychain/shell_test.go Outdated
Comment on lines +522 to +524
if !strings.Contains(wrapper, "if command -q") {
t.Errorf("fish wrapper missing `command -q` guard:\n%s", wrapper)
}
When resolveCliPath() falls back to an absolute path (armis-cli not on
PATH at init time), the wrapper guard's bare `command -v`/`command -q`
check is given a slash-containing argument. That is unspecified across
shells and can report the binary missing even when it exists, making the
wrapper silently take the `else` branch and bypass enforcement.

Prepend an executable-path check that reliably handles the absolute-path
case while keeping the PATH lookup for the bare-name case:
  POSIX: `if [ -x <abs> ] || command -v <abs> ...`
  fish:  `if test -x <abs>; or command -q <abs>`

Tests assert the `command -v`/`command -q` substring rather than the
exact `if` prefix so the guard can be extended without breaking them, and
a new test locks in the executable-path check for the absolute-path case.

Addresses copilot-pull-request-reviewer feedback on PR #216.
@yiftach-armis yiftach-armis merged commit 97a36ac into main Jun 8, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants