Skip to content

Demonstrate Rio with Juice Shop built from source - #111

Merged
tonit merged 3 commits into
mainfrom
106-juice-shop-demo
Oct 1, 2026
Merged

tonit merged 3 commits into
mainfrom
106-juice-shop-demo

Conversation

@tonit

@tonit tonit commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Build Juice Shop from pinned source, generate backend npm and frontend bundle CycloneDX SBOMs, then demonstrate Rio enrichment, quality checks and delivery to local Dependency-Track. The walkthrough leads with actual Rio 0.7.0 inspection output and inspectable JSON/HTML samples for backend success and frontend gate failure.

The setup helper retains source, generated lockfiles, build metadata and hashes. The Angular 22.0.1 build-tool adjustment is recorded in a patch and dirty workspace context. Published sample provenance identifies the source revision, builder image/architecture and generator versions; supplier and example CI URL are clearly labeled synthetic demo assertions. Cleanup checks resource ownership.

Validation:

  • Fresh pinned-source Docker build and disposable Dependency-Track 5.1.1 receiver.
  • Installed Rio 0.7.0 and local binary both delivered the backend (689 component entries, HTTP 200/event token) and blocked the frontend (672 entries, 559 findings).
  • Separate inventory check observed 654 stored backend components and no frontend project.
  • Verified input/output digests, unchanged dependency inventories, exact metadata, credential absence and owned-resource cleanup.
  • Exact offline inspection/HTML regeneration from receipt-only copies after receiver shutdown; reports visually reviewed.
  • Full Go tests/vet, ShellCheck, Python 3.9 syntax, preview consistency and documentation links passed.
  • CI detects Juice Shop demo changes, lints its build script, tests helper preflight/cleanup and stale-sample rejection, and verifies the saved receipts/reports offline with each native built binary (Linux, macOS, Windows).

Follow-up to #106. No release is requested.

@tonit
tonit marked this pull request as ready for review October 1, 2026 18:36
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The runnable demo is not wired into binary verification, Python tests, or ShellCheck coverage.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a source-built Juice Shop walkthrough demonstrating Rio enrichment, quality gating, and Dependency-Track delivery.

Changes:

  • Adds pinned Docker build and disposable receiver automation.
  • Documents the end-to-end walkthrough and provenance.
  • Publishes backend-success and frontend-failure sample evidence.
File Description
tools/​README.md Links the new walkthrough.
tools/​demo-juice-shop/​README.md Documents the demonstration workflow.
tools/​demo-juice-shop/​demo.py Automates building, receiver setup, status, and cleanup.
tools/​demo-juice-shop/​build.sh Builds Juice Shop and generates SBOMs.
tools/​demo-juice-shop/​example/​README.md Explains captured results and provenance.
tools/​demo-juice-shop/​example/​source.json Records source-build provenance.
tools/​demo-juice-shop/​example/​pipeline.json Captures Rio build context.
tools/​demo-juice-shop/​example/​build-overrides.patch Records Angular tool pins.
tools/​demo-juice-shop/​example/​backend-record.json Provides the successful receipt.
tools/​demo-juice-shop/​example/​backend-inspect.txt Provides backend inspection output.
tools/​demo-juice-shop/​example/​backend-report.html Provides the offline backend report.
tools/​demo-juice-shop/​example/​frontend-record.json Provides the failed-gate receipt.
tools/​demo-juice-shop/​example/​frontend-inspect.txt Provides frontend inspection output.
tools/​demo-juice-shop/​example/​frontend-report.html Provides the offline frontend report.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tools/demo-juice-shop/demo.py
@tonit
tonit merged commit e728dc8 into main Oct 1, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants