Demonstrate Rio with Juice Shop built from source - #111
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The runnable demo is not wired into binary verification, Python tests, or ShellCheck coverage.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds a source-built Juice Shop walkthrough demonstrating Rio enrichment, quality gating, and Dependency-Track delivery.
Changes:
- Adds pinned Docker build and disposable receiver automation.
- Documents the end-to-end walkthrough and provenance.
- Publishes backend-success and frontend-failure sample evidence.
| File | Description |
|---|---|
tools/README.md |
Links the new walkthrough. |
tools/demo-juice-shop/README.md |
Documents the demonstration workflow. |
tools/demo-juice-shop/demo.py |
Automates building, receiver setup, status, and cleanup. |
tools/demo-juice-shop/build.sh |
Builds Juice Shop and generates SBOMs. |
tools/demo-juice-shop/example/README.md |
Explains captured results and provenance. |
tools/demo-juice-shop/example/source.json |
Records source-build provenance. |
tools/demo-juice-shop/example/pipeline.json |
Captures Rio build context. |
tools/demo-juice-shop/example/build-overrides.patch |
Records Angular tool pins. |
tools/demo-juice-shop/example/backend-record.json |
Provides the successful receipt. |
tools/demo-juice-shop/example/backend-inspect.txt |
Provides backend inspection output. |
tools/demo-juice-shop/example/backend-report.html |
Provides the offline backend report. |
tools/demo-juice-shop/example/frontend-record.json |
Provides the failed-gate receipt. |
tools/demo-juice-shop/example/frontend-inspect.txt |
Provides frontend inspection output. |
tools/demo-juice-shop/example/frontend-report.html |
Provides the offline frontend report. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Build Juice Shop from pinned source, generate backend npm and frontend bundle CycloneDX SBOMs, then demonstrate Rio enrichment, quality checks and delivery to local Dependency-Track. The walkthrough leads with actual Rio 0.7.0 inspection output and inspectable JSON/HTML samples for backend success and frontend gate failure.
The setup helper retains source, generated lockfiles, build metadata and hashes. The Angular 22.0.1 build-tool adjustment is recorded in a patch and dirty workspace context. Published sample provenance identifies the source revision, builder image/architecture and generator versions; supplier and example CI URL are clearly labeled synthetic demo assertions. Cleanup checks resource ownership.
Validation:
Follow-up to #106. No release is requested.