Some checks failed
CICD / Build and Publish CICD Base Image (push) Successful in 36s
CICD / Build and Push CICD Image (push) Has been cancelled
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Backend Tests (push) Has been cancelled
CICD / Pre-commit Checks (push) Has been cancelled
CICD / Frontend Tests (push) Has been cancelled
CICD / Backend Doctests (push) Has been cancelled
CICD / Frontend Dependency Audit (push) Has been cancelled
CICD / Backend Dependency Audit (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Backend Base Image (push) Has been cancelled
CICD / Build Frontend Base Image (push) Has been cancelled
CICD / Build Integration Tester Image (push) Has been cancelled
CICD / Build E2E Tester Image (push) Has been cancelled
CICD / Build Frontend Main Image (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Build Backend Main Image (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
## Summary This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution. ## What changed - Added Bandit to pre-commit backend checks. - Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit. - Added dedicated audit tasks: - backend audit via pip-audit - frontend audit via yarn npm audit - Updated CI/CD workflow to include and gate on frontend/backend audit jobs. - Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI. - Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable. - Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently. ## Validation - Pre-commit hooks run and pass after formatting/autofixes. - Branch commit created successfully after hook-driven file updates. - Branch pushed to remote and tracking is configured. ## Notes - pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout. - Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable. ## Follow-ups (optional) - Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale. - Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: #74
115 lines
3.0 KiB
JavaScript
115 lines
3.0 KiB
JavaScript
import typescript from '@typescript-eslint/eslint-plugin';
|
|
import typescriptParser from '@typescript-eslint/parser';
|
|
import vue from 'eslint-plugin-vue';
|
|
import vueParser from 'vue-eslint-parser';
|
|
import jsdoc from 'eslint-plugin-jsdoc';
|
|
import tsdoc from 'eslint-plugin-tsdoc';
|
|
import security from 'eslint-plugin-security';
|
|
|
|
const securityRules = security.configs?.recommended?.rules ?? {};
|
|
|
|
export default [
|
|
// Ignore patterns (replaces .eslintignore)
|
|
{
|
|
ignores: [
|
|
'node_modules/',
|
|
'.yarn/',
|
|
'dist/',
|
|
'dist-ssr/',
|
|
'*.local',
|
|
'coverage/',
|
|
'.env*',
|
|
'.vscode/',
|
|
'.idea/',
|
|
'*.tmp',
|
|
'*.temp',
|
|
],
|
|
},
|
|
|
|
// JavaScript files
|
|
{
|
|
files: ['**/*.{js,mjs,cjs}'],
|
|
languageOptions: {
|
|
ecmaVersion: 'latest',
|
|
sourceType: 'module',
|
|
},
|
|
plugins: {
|
|
security,
|
|
},
|
|
rules: {
|
|
'no-console': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
'no-debugger': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
...securityRules,
|
|
},
|
|
},
|
|
|
|
// TypeScript files
|
|
{
|
|
files: ['**/*.{ts,tsx}'],
|
|
languageOptions: {
|
|
parser: typescriptParser,
|
|
ecmaVersion: 'latest',
|
|
sourceType: 'module',
|
|
},
|
|
plugins: {
|
|
'@typescript-eslint': typescript,
|
|
jsdoc,
|
|
tsdoc,
|
|
security,
|
|
},
|
|
rules: {
|
|
'no-console': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
'no-debugger': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
...securityRules,
|
|
// TSDoc rules for TypeScript files
|
|
'tsdoc/syntax': 'error',
|
|
'jsdoc/require-description': 'error',
|
|
'jsdoc/require-param': 'error',
|
|
'jsdoc/require-param-description': 'error',
|
|
'jsdoc/require-returns': 'error',
|
|
'jsdoc/require-returns-description': 'error',
|
|
'jsdoc/check-param-names': 'error',
|
|
'jsdoc/check-tag-names': 'error',
|
|
'jsdoc/check-types': 'error',
|
|
'jsdoc/valid-types': 'error',
|
|
},
|
|
},
|
|
|
|
// Vue files
|
|
{
|
|
files: ['**/*.vue'],
|
|
languageOptions: {
|
|
parser: vueParser,
|
|
parserOptions: {
|
|
parser: typescriptParser,
|
|
ecmaVersion: 'latest',
|
|
sourceType: 'module',
|
|
},
|
|
},
|
|
plugins: {
|
|
vue,
|
|
'@typescript-eslint': typescript,
|
|
jsdoc,
|
|
tsdoc,
|
|
security,
|
|
},
|
|
rules: {
|
|
...vue.configs['vue3-essential'].rules,
|
|
'no-console': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
'no-debugger': process.env.NODE_ENV === 'production' ? 'warn' : 'off',
|
|
...securityRules,
|
|
// TSDoc rules for Vue files
|
|
'tsdoc/syntax': 'error',
|
|
'jsdoc/require-description': 'error',
|
|
'jsdoc/require-param': 'error',
|
|
'jsdoc/require-param-description': 'error',
|
|
'jsdoc/require-returns': 'error',
|
|
'jsdoc/require-returns-description': 'error',
|
|
'jsdoc/check-param-names': 'error',
|
|
'jsdoc/check-tag-names': 'error',
|
|
'jsdoc/check-types': 'error',
|
|
'jsdoc/valid-types': 'error',
|
|
},
|
|
},
|
|
];
|