Files
AegisGitea-MCP/.pre-commit-config.yaml
Latte b8217dce8a
docker / test (pull_request) Successful in 24s
lint / lint (pull_request) Successful in 37s
lint / lint (push) Successful in 1m26s
test / test (push) Successful in 1m40s
test / test (pull_request) Successful in 34s
docker / lint (pull_request) Successful in 1m59s
docker / docker-test (pull_request) Successful in 14s
docker / docker-publish (pull_request) Has been skipped
feat: harden OAuth state secret validation, DCR file permissions, and policy defaults
- Enforce 32-char minimum on OAUTH_STATE_SECRET at startup (config.py)
- Write DCR client registry with owner-only (0o600) permissions before atomic replace
- Flip policy.yaml default write action from allow → deny
- Add CLAUDE.md with architecture, commands, and AGENTS.md contract summary
- Add .pre-commit-config.yaml mirroring `make lint` checks
- Update .gitignore: add .venv, .claude, .mypy_cache, .ruff_cache, .coverage.*
- Extend docs: audit log rotation guidance, OAUTH_STATE_SECRET and DCR_STORAGE_PATH notes
- Tests: short-secret rejection, 32-char acceptance, POSIX permission check for DCR store

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-14 14:13:22 +02:00

43 lines
1.3 KiB
YAML

# Pre-commit hooks mirror `make lint` so local commits enforce the same checks as CI.
# Installed via `make install-dev` (runs `pre-commit install`).
#
# Hooks use `language: system`, i.e. they invoke ruff/black/mypy from PATH rather than
# letting pre-commit manage isolated tool environments. This keeps versions identical to
# `make lint`/`make format` and lets mypy resolve the project's real dependencies.
# Requirement: commit with the dev virtualenv active (so requirements-dev.txt tools are on
# PATH). Outside an active venv the hooks will report the tools as "not found".
repos:
- repo: local
hooks:
- id: ruff-check
name: ruff check
entry: ruff check
language: system
types: [python]
args: [src/, tests/]
pass_filenames: false
- id: ruff-format
name: ruff format --check
entry: ruff format --check
language: system
types: [python]
args: [src/, tests/]
pass_filenames: false
- id: black
name: black --check
entry: black --check
language: system
types: [python]
args: [src/, tests/]
pass_filenames: false
- id: mypy
name: mypy
entry: mypy
language: system
types: [python]
args: [src/]
pass_filenames: false