Skip to content

test: comprehensive test suite for obtain_cves tool (56 tests) - #201

Open
manus-pi wants to merge 1 commit into
manus-use:mainfrom
manus-pi:test/obtain-cves-suite
Open

manus-pi wants to merge 1 commit into
manus-use:mainfrom
manus-pi:test/obtain-cves-suite

Conversation

@manus-pi

Copy link
Copy Markdown
Collaborator

Summary

Adds tests/test_obtain_cves.py — a comprehensive test suite for the obtain_cves tool module (src/manus_agent/tools/obtain_cves.py). All HTTP calls are fully mocked — zero real network traffic.

What's Tested

_get_all_cves_from_nvd (6 tests)

  • Single-page and paginated responses
  • Empty response handling
  • URL construction: date range, severity filters, results-per-page

_get_all_cves_from_github (8 tests)

  • Single-page and paginated (Link header) responses
  • Advisory → CVE structure mapping
  • Filtering out advisories missing cve_id
  • Connection/HTTP error resilience (returns empty list, doesn't crash)
  • Date range truncation in URL

_filter_cves_by_epss (11 tests)

  • EPSS score threshold filtering (> 0.05)
  • Percentile threshold filtering (> 0.5)
  • Boundary value testing (exactly at threshold — excluded)
  • Mixed results, missing EPSS data, empty input
  • EPSS data attachment to results
  • Batch CVE ID URL construction

_enrich_with_cisa_kev (6 tests)

  • KEV/non-KEV marking
  • Mixed KEV membership
  • Empty KEV feed, empty CVE list
  • In-place mutation verification

_submit_in_batches (10 tests)

  • Per-CVE webhook posting
  • Formatted CVE field structure (CVSS, EPSS, KEV, CPE, descriptions)
  • Missing optional data handling (no EPSS, no configs, no metrics)
  • Description extraction with fallback
  • CPE/affected product extraction
  • Empty input, batch chunking at 100

obtain_cves tool handler (11 tests)

  • Success path with EPSS filtering
  • No-CVEs-found path
  • NVD + GitHub deduplication
  • GitHub-only CVEs added correctly
  • Error handling (exception → error status)
  • Tool use ID echoing
  • EPSS filtering in 100-item chunks
  • Content structure (text + JSON blocks)

TOOL_SPEC + Integration (6 tests)

  • Spec name, description, required fields, types
  • vd_agent module references obtain_cves

Results

56 passed in 1.33s
1214 total tests passing (56 new + 1158 baseline)

All checks pass: ruff check, ruff format, pytest.

Add tests/test_obtain_cves.py covering all functions in the obtain_cves
tool module with fully mocked HTTP calls:

- _get_all_cves_from_nvd: pagination, empty response, URL construction,
  severity filters, results-per-page
- _get_all_cves_from_github: pagination via Link headers, advisory-to-CVE
  mapping, missing cve_id filtering, connection/HTTP error handling
- _filter_cves_by_epss: score threshold, percentile threshold, boundary
  values, mixed results, missing EPSS data, batch URL construction
- _enrich_with_cisa_kev: KEV/non-KEV marking, mixed results, empty KEV
  feed, mutation behavior
- _submit_in_batches: per-CVE posting, field formatting, missing
  optional data, description extraction, CPE/product extraction,
  empty input, batch chunking
- obtain_cves tool handler: success path, no-CVEs-found, NVD+GitHub
  deduplication, error handling, EPSS chunking, content structure
- TOOL_SPEC validation: name, description, required fields, types
- vd_agent integration: module reference verification

All 56 tests pass. Zero network calls. 1214 total tests passing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant