You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Bash脚本中THREAT_LEVEL的两个验证条件合并?

问题

我有一个包含多次出现"threatLevel" : (整数)字段的JSON文件,需要通过grep检查其中是否存在从$THREAT_LEVEL到10(含)的威胁等级。现有Bash脚本通过两个elif分别验证THREAT_LEVEL为正整数、取值在1-10之间,我希望将这两个验证条件合并,请问是否有可行方案?

以下是当前脚本代码:

#!/bin/bash

FILE="${CI_PROJECT_DIR}/iq.results.json"

if [ -z ${THREAT_LEVEL+x} ]; then # Checks if THREAT_LEVEL is unset. If unset, no checks will be made.
    echo "THREAT_LEVEL is unset. The job will ignore checking the results of $FILE.";
    exit 0
elif ! [[ $THREAT_LEVEL =~ ^[0-9]+$ ]]; then # Checks that the THREAT_LEVEL is only a positive integer.
    echo "Error - Invalid THREAT_LEVEL: THREAT_LEVEL must be a positive integer. It is currently set to $THREAT_LEVEL."
    exit 1
elif [ "$THREAT_LEVEL" -lt 1 ] || [ "$THREAT_LEVEL" -gt 10 ]; then # Checks that the THREAT_LEVEL is only between 1 and 10.
    echo "Error - Invalid THREAT_LEVEL: THREAT_LEVEL must be between 1 and 10. It is currently set to $THREAT_LEVEL."
    exit 1
else
    echo "THREAT_LEVEL is currently set to $THREAT_LEVEL"
    if [ "$THREAT_LEVEL" -lt 10 ]; then # If the THREAT_LEVEL is less than 10, grep for anything between THREAT_LEVEL and 10 inclusive.
        if grep -q -E '"threatLevel" : (['"$THREAT_LEVEL"'-9]|10)' "$FILE"; then
            echo "Detected dependencies with Threat Level of $THREAT_LEVEL or above in $FILE. Failing job.";
            exit 1
        else   
            echo "No dependencies with Threat Level of $THREAT_LEVEL or above detected in $FILE. Job allowed to pass";
            exit 0
        fi
    else
        if grep -q -E '"threatLevel" : 10' "$FILE"; then # Else THREAT_LEVEL must be 10. Grep for 10.
            echo "Detected dependencies with Threat Level of 10 in $FILE. Failing job.";
            exit 1
        else   
            echo "No dependencies with Threat Level of 10 or above detected in $FILE. Job allowed to pass.";
            exit 0
        fi
    fi
fi

解决方案

当然可以合并这两个验证条件,这里提供两种实用的实现方式:

方式一:用正则直接匹配1-10的合法整数

直接通过正则表达式同时完成「正整数」和「1-10范围」的验证,把原来的两个elif替换成一个:

elif ! [[ $THREAT_LEVEL =~ ^([1-9]|10)$ ]]; then
    echo "Error - Invalid THREAT_LEVEL: THREAT_LEVEL must be an integer between 1 and 10. It is currently set to $THREAT_LEVEL."
    exit 1

这个正则的逻辑很清晰:

  • ^ 和 $ 锁定字符串首尾,确保输入没有多余字符
  • ([1-9]|10) 匹配1-9的单个数字,或者直接匹配"10"

方式二:合并条件判断逻辑

如果想保留「正整数验证」的明确逻辑,可以把两个不合法条件用逻辑或连接,放到同一个elif里:

elif ! [[ $THREAT_LEVEL =~ ^[0-9]+$ ]] || [ "$THREAT_LEVEL" -lt 1 ] || [ "$THREAT_LEVEL" -gt 10 ]; then
    echo "Error - Invalid THREAT_LEVEL: THREAT_LEVEL must be an integer between 1 and 10. It is currently set to $THREAT_LEVEL."
    exit 1

只要输入不是正整数,或者超出1-10范围,就触发错误提示。

修改后的完整脚本

以下是采用方式一的完整脚本:

#!/bin/bash

FILE="${CI_PROJECT_DIR}/iq.results.json"

if [ -z ${THREAT_LEVEL+x} ]; then
    echo "THREAT_LEVEL is unset. The job will ignore checking the results of $FILE.";
    exit 0
elif ! [[ $THREAT_LEVEL =~ ^([1-9]|10)$ ]]; then
    echo "Error - Invalid THREAT_LEVEL: THREAT_LEVEL must be an integer between 1 and 10. It is currently set to $THREAT_LEVEL."
    exit 1
else
    echo "THREAT_LEVEL is currently set to $THREAT_LEVEL"
    if [ "$THREAT_LEVEL" -lt 10 ]; then
        if grep -q -E '"threatLevel" : (['"$THREAT_LEVEL"'-9]|10)' "$FILE"; then
            echo "Detected dependencies with Threat Level of $THREAT_LEVEL or above in $FILE. Failing job.";
            exit 1
        else   
            echo "No dependencies with Threat Level of $THREAT_LEVEL or above detected in $FILE. Job allowed to pass";
            exit 0
        fi
    else
        if grep -q -E '"threatLevel" : 10' "$FILE"; then
            echo "Detected dependencies with Threat Level of 10 in $FILE. Failing job.";
            exit 1
        else   
            echo "No dependencies with Threat Level of 10 or above detected in $FILE. Job allowed to pass.";
            exit 0
        fi
    fi
fi

内容的提问来源于stack exchange,提问作者cien

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 13:25:10