ci-hygiene guard: lockfile-only installs, pinned images, no host-port services (warn-only)
All checks were successful
check / gate (push) Successful in 19s
All checks were successful
check / gate (push) Successful in 19s
House rule 6 (09-23). The bridge now also posts windy-git/ci-hygiene on every PR head (added lines) and default branch (whole files), scanning CI workflows and Dockerfiles for: floating pip / uv pip installs (not -r, not --no-deps, not exact pins), uv sync without --locked/--frozen, npm install instead of npm ci (unless every package is exact-pinned), yarn/pnpm without a frozen lockfile, :latest images and COPY lock* globs (Windy Mail #147), and CI services publishing a HOST port (every job shares one dind: Windy Mind runs 147/176 died on 5432). Warn-only; CI_HYGIENE_MODE=block later. Allow-list ci/ci-hygiene-allow.yml (empty). compute_guard's walker is now parameterised (line_fn / path_ok / prefilter) so both guards share one scanner, cache and allow loader; the bridge posts both through one _post_guard. Today: 95 issues in 21 repos; windy-git, calendar, traveler, traveler-site clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -382,3 +382,11 @@ def test_guard_that_cannot_run_posts_nothing(fake, monkeypatch):
|
||||
monkeypatch.setitem(sys.modules, "compute_guard", _Guard(None))
|
||||
bridge.post_compute_guard("windy-chat", SHA, "main", True)
|
||||
assert f.posted == []
|
||||
|
||||
|
||||
def test_ci_hygiene_posts_under_its_own_context(fake, monkeypatch):
|
||||
f = fake(statuses=[{"context": "windy-git/compute-guard", "state": "success", "description": "WARN 1"}])
|
||||
monkeypatch.setitem(sys.modules, "ci_hygiene", _Guard([_F()]))
|
||||
bridge.post_ci_hygiene("windy-chat", SHA, "main", True)
|
||||
# the compute-guard status with the same description must not suppress it
|
||||
assert [(p["context"], p["description"]) for p in f.posted] == [("windy-git/ci-hygiene", "WARN 1")]
|
||||
|
||||
Reference in New Issue
Block a user