feat: harden server pull deployments and git hygiene
This commit is contained in:
@@ -24,6 +24,32 @@ coverage/
|
||||
Thumbs.db
|
||||
`;
|
||||
|
||||
const RECOMMENDED_GITATTRIBUTES = `* text=auto eol=lf
|
||||
*.bat text eol=crlf
|
||||
*.cmd text eol=crlf
|
||||
*.ps1 text eol=crlf
|
||||
*.png binary
|
||||
*.jpg binary
|
||||
*.jpeg binary
|
||||
*.gif binary
|
||||
*.ico binary
|
||||
*.zip binary
|
||||
`;
|
||||
|
||||
const RECOMMENDED_EDITORCONFIG = `root = true
|
||||
|
||||
[*]
|
||||
charset = utf-8
|
||||
end_of_line = lf
|
||||
insert_final_newline = true
|
||||
trim_trailing_whitespace = true
|
||||
indent_style = space
|
||||
indent_size = 2
|
||||
|
||||
[*.{bat,cmd,ps1}]
|
||||
end_of_line = crlf
|
||||
`;
|
||||
|
||||
function sameRemote(left, right) {
|
||||
const a = normalizeRemoteUrl(left);
|
||||
const b = normalizeRemoteUrl(right);
|
||||
@@ -275,6 +301,36 @@ class GitValidatorService {
|
||||
},
|
||||
),
|
||||
);
|
||||
for (const [id, title, filename, action] of [
|
||||
["gitattributes", ".gitattributes normalizes text and binary files", ".gitattributes", "add-gitattributes"],
|
||||
["editorconfig", ".editorconfig keeps editors consistent", ".editorconfig", "add-editorconfig"],
|
||||
]) {
|
||||
const present = lowerFiles.includes(filename);
|
||||
checks.push(result(id, "Repository hygiene", title, present ? "pass" : "warning",
|
||||
present ? `${filename} is versioned.` : `No tracked ${filename} was found.`, {
|
||||
weight: 5,
|
||||
fixAction: present ? null : action,
|
||||
safe: false,
|
||||
confirmation: `Create a recommended ${filename} in the working tree for review?`,
|
||||
}));
|
||||
}
|
||||
|
||||
const packageManagers = [
|
||||
{ manifests: ["package.json"], locks: ["package-lock.json", "pnpm-lock.yaml", "yarn.lock", "bun.lock", "bun.lockb"] },
|
||||
{ manifests: ["pyproject.toml", "requirements.in", "pipfile"], locks: ["uv.lock", "poetry.lock", "requirements.txt", "pipfile.lock"] },
|
||||
{ manifests: ["composer.json"], locks: ["composer.lock"] },
|
||||
{ manifests: ["gemfile"], locks: ["gemfile.lock"] },
|
||||
];
|
||||
const lockCheck = packageManagers.find((entry) => entry.manifests.some((name) => lowerFiles.includes(name)));
|
||||
if (lockCheck) {
|
||||
const lockfile = lockCheck.locks.find((name) => lowerFiles.includes(name));
|
||||
checks.push(result("dependency-lock", "Supply chain", "Dependencies are reproducibly locked", lockfile ? "pass" : "warning",
|
||||
lockfile ? `${lockfile} is versioned.` : "A dependency manifest exists without a recognized lockfile.", { weight: 9 }));
|
||||
}
|
||||
|
||||
const hasCi = lowerFiles.some((file) => /^\.gitea\/workflows\/[^/]+\.ya?ml$/.test(file));
|
||||
checks.push(result("continuous-integration", "Gitea governance", "Automated checks run on Gitea", hasCi ? "pass" : "warning",
|
||||
hasCi ? "At least one Gitea Actions workflow is versioned." : "No .gitea/workflows YAML file was found.", { weight: 8 }));
|
||||
|
||||
const sensitive = tracked.filter(isSensitiveTrackedPath);
|
||||
checks.push(
|
||||
@@ -397,6 +453,16 @@ class GitValidatorService {
|
||||
});
|
||||
return { created: ".gitignore" };
|
||||
}
|
||||
if (["add-gitattributes", "add-editorconfig"].includes(check.fixAction)) {
|
||||
const definition = check.fixAction === "add-gitattributes"
|
||||
? { name: ".gitattributes", content: RECOMMENDED_GITATTRIBUTES }
|
||||
: { name: ".editorconfig", content: RECOMMENDED_EDITORCONFIG };
|
||||
const target = path.join(root, definition.name);
|
||||
if (await fs.stat(target).catch(() => null))
|
||||
throw new Error(`${definition.name} already exists; rescan before repairing.`);
|
||||
await fs.writeFile(target, definition.content, { encoding: "utf8", flag: "wx" });
|
||||
return { created: definition.name };
|
||||
}
|
||||
if (check.fixAction === "protect-default-branch") {
|
||||
return this.gitea.createBranchProtection(
|
||||
repository.owner.login,
|
||||
@@ -411,6 +477,8 @@ class GitValidatorService {
|
||||
module.exports = {
|
||||
GitValidatorService,
|
||||
RECOMMENDED_GITIGNORE,
|
||||
RECOMMENDED_GITATTRIBUTES,
|
||||
RECOMMENDED_EDITORCONFIG,
|
||||
sameRemote,
|
||||
isSensitiveTrackedPath,
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user