b8217dce8a
docker / test (pull_request) Successful in 24s
lint / lint (pull_request) Successful in 37s
lint / lint (push) Successful in 1m26s
test / test (push) Successful in 1m40s
test / test (pull_request) Successful in 34s
docker / lint (pull_request) Successful in 1m59s
docker / docker-test (pull_request) Successful in 14s
docker / docker-publish (pull_request) Has been skipped
- Enforce 32-char minimum on OAUTH_STATE_SECRET at startup (config.py) - Write DCR client registry with owner-only (0o600) permissions before atomic replace - Flip policy.yaml default write action from allow → deny - Add CLAUDE.md with architecture, commands, and AGENTS.md contract summary - Add .pre-commit-config.yaml mirroring `make lint` checks - Update .gitignore: add .venv, .claude, .mypy_cache, .ruff_cache, .coverage.* - Extend docs: audit log rotation guidance, OAUTH_STATE_SECRET and DCR_STORAGE_PATH notes - Tests: short-secret rejection, 32-char acceptance, POSIX permission check for DCR store Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
43 lines
1.3 KiB
YAML
43 lines
1.3 KiB
YAML
# Pre-commit hooks mirror `make lint` so local commits enforce the same checks as CI.
|
|
# Installed via `make install-dev` (runs `pre-commit install`).
|
|
#
|
|
# Hooks use `language: system`, i.e. they invoke ruff/black/mypy from PATH rather than
|
|
# letting pre-commit manage isolated tool environments. This keeps versions identical to
|
|
# `make lint`/`make format` and lets mypy resolve the project's real dependencies.
|
|
# Requirement: commit with the dev virtualenv active (so requirements-dev.txt tools are on
|
|
# PATH). Outside an active venv the hooks will report the tools as "not found".
|
|
repos:
|
|
- repo: local
|
|
hooks:
|
|
- id: ruff-check
|
|
name: ruff check
|
|
entry: ruff check
|
|
language: system
|
|
types: [python]
|
|
args: [src/, tests/]
|
|
pass_filenames: false
|
|
|
|
- id: ruff-format
|
|
name: ruff format --check
|
|
entry: ruff format --check
|
|
language: system
|
|
types: [python]
|
|
args: [src/, tests/]
|
|
pass_filenames: false
|
|
|
|
- id: black
|
|
name: black --check
|
|
entry: black --check
|
|
language: system
|
|
types: [python]
|
|
args: [src/, tests/]
|
|
pass_filenames: false
|
|
|
|
- id: mypy
|
|
name: mypy
|
|
entry: mypy
|
|
language: system
|
|
types: [python]
|
|
args: [src/]
|
|
pass_filenames: false
|