Commit Graph

11 Commits

Author SHA1 Message Date
f627ef018a feat: integrate security audits into pre-commit and CI/CD with backend pip-audit migration (#74)
Some checks failed
CICD / Build and Publish CICD Base Image (push) Successful in 36s
CICD / Build and Push CICD Image (push) Has been cancelled
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Backend Tests (push) Has been cancelled
CICD / Pre-commit Checks (push) Has been cancelled
CICD / Frontend Tests (push) Has been cancelled
CICD / Backend Doctests (push) Has been cancelled
CICD / Frontend Dependency Audit (push) Has been cancelled
CICD / Backend Dependency Audit (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Backend Base Image (push) Has been cancelled
CICD / Build Frontend Base Image (push) Has been cancelled
CICD / Build Integration Tester Image (push) Has been cancelled
CICD / Build E2E Tester Image (push) Has been cancelled
CICD / Build Frontend Main Image (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Build Backend Main Image (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
## Summary

This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution.

## What changed

- Added Bandit to pre-commit backend checks.
- Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit.
- Added dedicated audit tasks:
  - backend audit via pip-audit
  - frontend audit via yarn npm audit
- Updated CI/CD workflow to include and gate on frontend/backend audit jobs.
- Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI.
- Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable.
- Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently.

## Validation

- Pre-commit hooks run and pass after formatting/autofixes.
- Branch commit created successfully after hook-driven file updates.
- Branch pushed to remote and tracking is configured.

## Notes

- pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout.
- Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable.

## Follow-ups (optional)

- Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale.
- Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable.

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #74
2026-07-13 22:19:57 -04:00
549469f105 CI: Establish source-first quality gate and simplify pipeline flow (#71)
All checks were successful
CICD Start / Sanity and Base Decision (push) Successful in 24s
This PR establishes a deterministic source-level quality gate before any build promotion and removes redundant post-build quality checks.

The new flow makes local developer workflow and CI behavior align:
- Developers run pre-commit locally (with auto-fix where appropriate)
- CI runs a check-only smoke gate to validate pre-commit cleanliness
- Build/test promotion only proceeds after source checks pass

## What Changed

### 1. Added a source-first quality gate

- Added a dedicated source gate workflow:
  - `.gitea/workflows/cicd-source-checks.yaml`
- Gate now:
  - Checks out target SHA
  - Bootstraps backend/frontend toolchains
  - Installs dependencies (`backend` via `uv`, `frontend` via `yarn`)
  - Runs `pre-commit --all-files` as the quality smoke test
- Downstream build dispatch only occurs if this gate passes.

### 2. Updated pipeline routing

- `cicd-start.yaml` now dispatches the source gate first.
- `cicd-start.yaml` push trigger now includes all branches so feature branches run the same gate.
- Added explicit routing logs in dispatch steps (route decision, SHA, trace id) for easier debugging.

### 3. Removed redundant checks workflow

- Removed:
  - `.gitea/workflows/cicd-checks.yaml`
- Updated:
  - `.gitea/workflows/docker-build-main.yaml` now dispatches `cicd-tests.yaml` directly after successful main build.

### 4. CI check-only behavior vs local auto-fix behavior

Updated `.pre-commit-config.yaml` so hooks that can auto-fix behave as:

- **Local developer pre-commit**: auto-fix enabled
- **CI source gate**: check-only (no auto-fix)

Applied to:
- `ruff` / `ruff-format`
- `eslint`
- `prettier`
- `tsdoc-lint`
- `markdownlint`
- `pretty-format-toml`

This keeps CI as a true smoke validation of local pre-commit compliance.

### 5. Renovate workflow hardening

- Improved auth/token handling and diagnostics in:
  - `.gitea/workflows/renovate.yml`
- Added support for internal/self-signed TLS endpoints used by this environment.

## Why

- Faster, earlier feedback on source quality failures
- Avoid expensive build/test progression when source hygiene fails
- Align CI with developer habits for predictable outcomes
- Remove duplicated quality checks and reduce pipeline complexity

## New Effective CI Flow

1. `cicd-start.yaml`
2. `cicd-source-checks.yaml` (pre-commit smoke gate)
3. `docker-build-base.yaml` / `docker-build-main.yaml`
4. `cicd-tests.yaml`

## Acceptance Criteria Mapping (Issue #60)

- Source-level lane runs independently and consistently: **Implemented**
- Source-lane failure blocks promotion: **Implemented**
- Outputs/logging are clear and actionable: **Implemented**

## Notes

- Source gate is intentionally check-only in CI.
- Developers should continue running local pre-commit before pushing.
- Any remaining failures in source gate indicate local pre-commit was not fully clean.

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #71
2026-07-02 07:21:18 -04:00
9b742a5a6d feature/pp-58-runtime-image-contract (#68)
Some checks failed
CICD Start / Sanity and Base Decision (push) Successful in 18s
Renovate Dependency Updates / Renovate Dependencies (push) Failing after 7m19s
## Summary

This PR tightens repository quality enforcement around markdown and documentation. It adds `markdownlint` to the `cicd-checks` workflow, expands pre-commit coverage so markdown files are checked repo-wide, and cleans up the PP-58 documentation set to keep it aligned with the new policy.

## What changed

- Added a `Markdownlint Check` entry to `.gitea/workflows/cicd-checks.yaml`
- Added `markdownlint` to pre-commit and widened prettier coverage to include markdown files across the repo
- Updated `README.md` to satisfy markdownlint line-length rules
- Normalized the PP-58 documentation set:
  - `docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
  - `docs/adr/ADR003-deployable_runtime_image_contract.md`
  - `docs/DEVELOPMENT.md`
  - `docs/CICD_MULTI_STAGE_BUILD.md`
  - `docs/CICD_TROUBLESHOOTING_GUIDE.md`
  - `docs/SECURE_DOCKER_CICD.md`

## Validation

- `pre-commit run markdownlint --files README.md docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
- `pre-commit run prettier --files README.md docs/DEPLOYABLE_RUNTIME_CONTRACT.md`
- Workflow YAML validation returned no errors

## Notes

This change does not alter application runtime behavior. It only strengthens CI and documentation quality enforcement.

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #68
2026-06-19 17:00:57 -04:00
d02039a22e Backend runtime upgraded to Python 3.14 with exact dependency pinning (#57)
Some checks failed
CICD Start / Sanity and Base Decision (push) Successful in 18s
Runner Canary / Canary Heavy (ubuntu-act-8gb) (push) Has been skipped
Runner Canary / Canary Heavy (ubuntu-act-4gb) (push) Has been skipped
Runner Canary / Canary Burst (ubuntu-act (push) Failing after 11m10s
Runner Canary / Canary (ubuntu-latest) (push) Failing after 12m39s
Runner Canary / Canary (ubuntu-act) (push) Failing after 12m42s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>

## Summary

Upgrades backend runtime baseline and dependency management for issue #10.

### Changes

1. **Python Baseline**: Updated from 3.13 to 3.14
   - Updated `backend/pyproject.toml` requires-python constraint
   - Updated `backend/pyrightconfig.json` pythonVersion
   - Updated all Dockerfile and CI references

2. **Dependency Pinning**: Switched to exact version pins in `backend/pyproject.toml`
   - All dev and runtime dependencies now use `==` instead of `>=`
   - `fastapi==0.120.2`, `uvicorn==0.38.0`
   - ruff, pyright, pytest suite pinned to current resolved versions
   - Regenerated `backend/uv.lock` under Python 3.14

3. **Startup Compatibility Guard** (TDD via RED→GREEN)
   - New `compatibility_status()` function evaluates runtime and pinned deps
   - Startup raises `RuntimeError` if policy fails
   - Implemented via FastAPI lifespan (non-deprecated) handler

4. **Compatibility Status Endpoint**
   - New `GET /compatibility` returns policy status, runtime version, and package checks
   - Shares single source of truth with startup validation

5. **Integration Tests**
   - Added failing-then-passing tests for startup guard and endpoint behavior
   - 100% coverage maintained

6. **Direnv Configuration**
   - Added `UV_PYTHON="3.14"` pin to repo `.envrc`
   - Ensures direnv creates/recreates venv with correct Python version

### Validation

-  ruff format/check
-  pyright strict (0 errors)
-  pytest: 8 passed, 100% coverage (>=95 gate)
-  pydoclint: pass
-  xdoctest: pass

### Notes

- SQLAlchemy/SQLModel introduction deferred to next pass per scope
- Compatibility logic currently validates fastapi/uvicorn pins (runtime deps)
- Ready for container build validation and Renovate bot testing

Co-authored-by: copilotcoder <copilotcoder@darkhelm.org>
Reviewed-on: #57
Co-authored-by: Cliff Hill <xlorep@darkhelm.org>
Co-committed-by: Cliff Hill <xlorep@darkhelm.org>
2026-06-18 11:19:24 -04:00
5d74dd8d8f Adding some stuff for the new structure to work with my system.
Some checks failed
Tests / Build and Push CICD Base Image (push) Failing after 37m18s
Tests / Build and Push CICD Complete Image (push) Has been cancelled
Tests / Trailing Whitespace Check (push) Has been cancelled
Tests / End of File Check (push) Has been cancelled
Tests / YAML Syntax Check (push) Has been cancelled
Tests / TOML Syntax Check (push) Has been cancelled
Tests / Mixed Line Ending Check (push) Has been cancelled
Tests / TOML Formatting Check (push) Has been cancelled
Tests / Ruff Linting (push) Has been cancelled
Tests / Ruff Format Check (push) Has been cancelled
Tests / Pyright Type Check (push) Has been cancelled
Tests / Darglint Docstring Check (push) Has been cancelled
Tests / No Docstring Types Check (push) Has been cancelled
Tests / ESLint Check (push) Has been cancelled
Tests / Prettier Format Check (push) Has been cancelled
Tests / TypeScript Type Check (push) Has been cancelled
Tests / TSDoc Lint Check (push) Has been cancelled
Tests / Backend Tests (push) Has been cancelled
Tests / Frontend Tests (push) Has been cancelled
Tests / Backend Doctests (push) Has been cancelled
Tests / Integration Tests (push) Has been cancelled
Tests / End-to-End Tests (push) Has been cancelled
Renovate Dependency Updates / Renovate Dependencies (push) Failing after 16m22s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2026-04-08 09:45:49 -04:00
fdbce98be6 CICD now is aligned with pre-commit.
Some checks failed
Tests / Build and Push CICD Image (push) Successful in 49m20s
Tests / TOML Syntax Check (push) Successful in 30s
Tests / Mixed Line Ending Check (push) Successful in 26s
Tests / TOML Formatting Check (push) Successful in 41s
Tests / Ruff Linting (push) Successful in 25s
Tests / Ruff Format Check (push) Successful in 29s
Tests / Pyright Type Check (push) Failing after 37s
Tests / Darglint Docstring Check (push) Successful in 38s
Tests / No Docstring Types Check (push) Successful in 25s
Tests / ESLint Check (push) Successful in 59s
Tests / YAML Syntax Check (push) Successful in 7m5s
Tests / Prettier Format Check (push) Successful in 52s
Tests / Backend Tests (push) Failing after 31s
Tests / TypeScript Type Check (push) Successful in 2m12s
Tests / Backend Doctests (push) Successful in 1m29s
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Tests / Frontend Tests (push) Failing after 1m36s
Tests / End of File Check (push) Successful in 9m45s
Tests / TSDoc Lint Check (push) Failing after 13m8s
Tests / Trailing Whitespace Check (push) Failing after 13m13s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-30 10:02:17 -04:00
68e1499532 Little fixes for hopefully more successes.
Some checks failed
Tests / Build and Push CICD Image (push) Successful in 46m47s
Tests / End of File Check (push) Successful in 27s
Tests / Mixed Line Ending Check (push) Successful in 28s
Tests / TOML Formatting Check (push) Failing after 26s
Tests / Ruff Linting (push) Failing after 23s
Tests / Ruff Format Check (push) Successful in 25s
Tests / Pyright Type Check (push) Failing after 1m0s
Tests / Darglint Docstring Check (push) Successful in 27s
Tests / No Docstring Types Check (push) Successful in 22s
Tests / ESLint Check (push) Successful in 54s
Tests / Prettier Format Check (push) Successful in 30s
Tests / TypeScript Type Check (push) Successful in 1m5s
Tests / Trailing Whitespace Check (push) Failing after 7m54s
Tests / Backend Tests (push) Failing after 1m6s
Tests / TSDoc Lint Check (push) Successful in 56s
Tests / Backend Doctests (push) Successful in 28s
Tests / Frontend Tests (push) Failing after 2m12s
Tests / Integration Tests (push) Has been skipped
Tests / End-to-End Tests (push) Has been skipped
Tests / TOML Syntax Check (push) Successful in 11m16s
Tests / YAML Syntax Check (push) Failing after 13m32s
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-29 21:16:09 -04:00
8aa8d41e8a Did some things, made more improvements.
Some checks failed
CI/CD Pipeline / Backend Tests (Python) (push) Has been cancelled
CI/CD Pipeline / Frontend Tests (TypeScript/Vue) (push) Has been cancelled
CI/CD Pipeline / Integration Tests (push) Has been cancelled
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-19 21:35:02 -04:00
4502c92f9b Making pre-commit powerful again.
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-18 21:31:34 -04:00
8ab2e1dd28 Did some things.
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-18 21:29:28 -04:00
9c4a8d96bc Initial commit.
Signed-off-by: Cliff Hill <xlorep@darkhelm.org>
2025-10-18 09:14:10 -04:00