Some checks failed
CICD / Build and Publish CICD Base Image (push) Successful in 36s
CICD / Build and Push CICD Image (push) Has been cancelled
CICD / Build CICD Image Failure Postmortem (push) Has been cancelled
CICD / Backend Tests (push) Has been cancelled
CICD / Pre-commit Checks (push) Has been cancelled
CICD / Frontend Tests (push) Has been cancelled
CICD / Backend Doctests (push) Has been cancelled
CICD / Frontend Dependency Audit (push) Has been cancelled
CICD / Backend Dependency Audit (push) Has been cancelled
CICD / CICD Tests Complete (push) Has been cancelled
CICD / Build Backend Base Image (push) Has been cancelled
CICD / Build Frontend Base Image (push) Has been cancelled
CICD / Build Integration Tester Image (push) Has been cancelled
CICD / Build E2E Tester Image (push) Has been cancelled
CICD / Build Frontend Main Image (push) Has been cancelled
CICD / Production Images Complete (push) Has been cancelled
CICD / End-to-End Tests (push) Has been cancelled
CICD / E2E Tests Failure Postmortem (push) Has been cancelled
CICD / Build Backend Main Image (push) Has been cancelled
CICD / Production Image Failures Postmortem (push) Has been cancelled
CICD / Source Lanes Failure Postmortem (push) Has been cancelled
CICD / Runtime Black-Box Integration Tests (push) Has been cancelled
CICD / Integration Tests Failure Postmortem (push) Has been cancelled
## Summary This PR integrates security-focused checks into the existing quality gates and aligns local workflows with CI/CD execution. ## What changed - Added Bandit to pre-commit backend checks. - Integrated eslint-plugin-security into the existing frontend ESLint setup used by pre-commit. - Added dedicated audit tasks: - backend audit via pip-audit - frontend audit via yarn npm audit - Updated CI/CD workflow to include and gate on frontend/backend audit jobs. - Switched backend vulnerability scanning from Safety to pip-audit to avoid interactive/auth requirements in CI. - Updated backend dependency set and lockfile to resolve test dependency conflicts and keep the environment solvable. - Marked backend integration API tests with the integration marker so marker-based unit/integration separation works consistently. ## Validation - Pre-commit hooks run and pass after formatting/autofixes. - Branch commit created successfully after hook-driven file updates. - Branch pushed to remote and tracking is configured. ## Notes - pip-audit now executes from backend context (for example via uv --directory backend run ...), matching project layout. - Remaining reported vulnerabilities depend on upstream package fix availability/constraints and may require follow-up once publishable fix versions are consumable. ## Follow-ups (optional) - Add a curated pip-audit ignore policy for non-actionable/transient advisories with rationale. - Open a focused follow-up PR for remaining dependency advisories once upstream fixes are practically installable. Co-authored-by: copilotcoder <copilotcoder@darkhelm.org> Reviewed-on: #74
125 lines
4.7 KiB
YAML
125 lines
4.7 KiB
YAML
---
|
|
repos:
|
|
# General hooks for all files
|
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
|
rev: v4.6.0
|
|
hooks:
|
|
- id: trailing-whitespace
|
|
- id: end-of-file-fixer
|
|
- id: check-merge-conflict
|
|
- id: check-added-large-files
|
|
- id: check-yaml
|
|
- id: check-json
|
|
- id: check-toml
|
|
- id: mixed-line-ending
|
|
|
|
# Markdown linting
|
|
- repo: https://github.com/igorshubovych/markdownlint-cli
|
|
rev: v0.45.0
|
|
hooks:
|
|
- id: markdownlint
|
|
entry: bash -c 'if [ "${CI:-}" = "true" ]; then markdownlint "$@"; else markdownlint --fix "$@"; fi' --
|
|
files: \.(md|markdown)$
|
|
|
|
# TOML linting
|
|
- repo: https://github.com/macisamuele/language-formatters-pre-commit-hooks
|
|
rev: v2.14.0
|
|
hooks:
|
|
- id: pretty-format-toml
|
|
entry: bash -c 'if [ "${CI:-}" = "true" ]; then pretty-format-toml "$@"; else pretty-format-toml --autofix "$@"; fi' --
|
|
|
|
# Python backend linting and formatting with ruff
|
|
- repo: local
|
|
hooks:
|
|
# Linter
|
|
- id: ruff
|
|
name: ruff-lint
|
|
entry: bash -c 'cd backend && if [ "${CI:-}" = "true" ]; then uv run ruff check . --config=pyproject.toml; else uv run ruff check --fix . --config=pyproject.toml; fi'
|
|
language: system
|
|
files: ^backend/
|
|
types: [python]
|
|
pass_filenames: false
|
|
# Formatter
|
|
- id: ruff-format
|
|
name: ruff-format
|
|
entry: bash -c 'cd backend && if [ "${CI:-}" = "true" ]; then uv run ruff format --check . --config=pyproject.toml; else uv run ruff format . --config=pyproject.toml; fi'
|
|
language: system
|
|
files: ^backend/
|
|
types: [python]
|
|
pass_filenames: false
|
|
|
|
# Python type checking with pyright
|
|
- repo: local
|
|
hooks:
|
|
- id: pyright
|
|
name: pyright
|
|
entry: bash -c 'cd backend && uv run pyright . --project=.'
|
|
language: system
|
|
files: ^backend/
|
|
types: [python]
|
|
pass_filenames: false
|
|
|
|
# Python docstring linting with pydoclint
|
|
- repo: local
|
|
hooks:
|
|
- id: pydoclint
|
|
name: pydoclint
|
|
entry: bash -c 'cd backend && uv run pydoclint --config=pyproject.toml src/'
|
|
language: system
|
|
files: ^backend/.*\.py$
|
|
types: [python]
|
|
pass_filenames: false
|
|
|
|
- id: bandit
|
|
name: bandit
|
|
entry: bash -c 'cd backend && uv run bandit -q -r src/backend'
|
|
language: system
|
|
files: ^backend/src/backend/.*\.py$
|
|
types: [python]
|
|
pass_filenames: false
|
|
|
|
# Custom hook to enforce no types in docstrings
|
|
- repo: local
|
|
hooks:
|
|
- id: no-docstring-types
|
|
name: Prohibit types in docstrings
|
|
entry: python scripts/check_no_docstring_types.py
|
|
language: system
|
|
files: ^backend/.*\.py$
|
|
pass_filenames: true
|
|
|
|
# Frontend linting and formatting
|
|
- repo: local
|
|
hooks:
|
|
# ESLint with auto-fix for pre-commit (CI uses --no-fix)
|
|
- id: eslint
|
|
name: eslint
|
|
entry: bash -c 'export PATH="$HOME/.local/share/mise/shims:$HOME/.local/bin:$PATH" && cd frontend && if [ "${CI:-}" = "true" ]; then corepack yarn eslint . --max-warnings=0; else corepack yarn eslint . --fix; fi'
|
|
language: system
|
|
files: ^frontend/.*\.(js|ts|vue)$
|
|
pass_filenames: false
|
|
|
|
# Prettier with auto-format for pre-commit (CI uses --check)
|
|
- id: prettier
|
|
name: prettier
|
|
entry: bash -c 'export PATH="$HOME/.local/share/mise/shims:$HOME/.local/bin:$PATH" && FILES=(); for file in "$@"; do FILES+=("$(realpath "$file")"); done && if [ "${CI:-}" = "true" ]; then corepack yarn --cwd frontend prettier --check "${FILES[@]}"; else corepack yarn --cwd frontend prettier --write "${FILES[@]}"; fi' --
|
|
language: system
|
|
files: \.(js|ts|vue|json|css|scss|md|markdown)$
|
|
pass_filenames: true
|
|
|
|
# TypeScript type checking (same as CI)
|
|
- id: typescript-check
|
|
name: typescript-check
|
|
entry: bash -c 'export PATH="$HOME/.local/share/mise/shims:$HOME/.local/bin:$PATH" && cd frontend && corepack yarn vue-tsc --noEmit'
|
|
language: system
|
|
files: ^frontend/.*\.(ts|vue)$
|
|
pass_filenames: false
|
|
|
|
# TSDoc linting with auto-fix for pre-commit (CI uses --no-fix)
|
|
- id: tsdoc-lint
|
|
name: tsdoc-lint
|
|
entry: bash -c 'export PATH="$HOME/.local/share/mise/shims:$HOME/.local/bin:$PATH" && cd frontend && if command -v yarn >/dev/null 2>&1; then if [ "${CI:-}" = "true" ]; then yarn eslint . --ext .ts,.vue --max-warnings=0; else yarn eslint . --ext .ts,.vue --fix; fi; else if [ "${CI:-}" = "true" ]; then corepack yarn eslint . --ext .ts,.vue --max-warnings=0; else corepack yarn eslint . --ext .ts,.vue --fix; fi; fi'
|
|
language: system
|
|
files: ^frontend/.*\.(ts|vue)$
|
|
pass_filenames: false
|