feat: deliver policy-driven Git Validator 2.0

This commit is contained in:
NuklearRabbit
2026-07-29 18:24:27 +02:00
parent 7b05c953b6
commit a0733875c4
18 changed files with 502 additions and 133 deletions
+106 -3
View File
@@ -4,6 +4,7 @@ const fs = require("node:fs/promises");
const path = require("node:path");
const { run } = require("./process-runner.cjs");
const { normalizeRemoteUrl } = require("../shared/repository-match.cjs");
const { applyPolicy, buildTrend, exportReport, normalizePolicy, validateSuppression } = require("./git-validator-policy.cjs");
const RECOMMENDED_GITIGNORE = `# Local configuration and secrets
.env
@@ -67,6 +68,7 @@ function result(id, category, title, status, detail, options = {}) {
fixAction: options.fixAction || null,
safe: options.safe === true,
confirmation: options.confirmation || null,
evidence: options.evidence || null,
};
}
@@ -84,10 +86,11 @@ function isSensitiveTrackedPath(filePath) {
}
class GitValidatorService {
constructor({ git, gitea, diagnostics }) {
constructor({ git, gitea, diagnostics, store }) {
this.git = git;
this.gitea = gitea;
this.diagnostics = diagnostics;
this.store = store;
}
async config(root, key, { local = true } = {}) {
@@ -176,7 +179,7 @@ class GitValidatorService {
{ weight: 35 },
),
);
return this.summarize(repository, checks);
return this.finalize(repository, checks, null);
}
const root = await this.git.ensureRepository(repository.localPath);
@@ -378,7 +381,107 @@ class GitValidatorService {
{ weight: 7 },
),
);
return this.summarize(repository, checks);
await this.addAssuranceChecks(root, tracked, lowerFiles, checks);
return this.finalize(repository, checks, status);
}
async addAssuranceChecks(root, tracked, lowerFiles, checks) {
const has = (...patterns) => lowerFiles.some((file) => patterns.some((pattern) => pattern.test(file)));
const fileCheck = (id, category, title, patterns, detail, weight = 5) => {
const present = has(...patterns);
checks.push(result(id, category, title, present ? "pass" : "warning", present ? `${title} is versioned.` : detail, { weight }));
};
fileCheck("security-policy", "Security", "Security policy", [/(^|\/)security\.md$/], "Add SECURITY.md with supported versions and private disclosure instructions.", 8);
fileCheck("codeowners", "Governance", "Code ownership", [/(^|\/)codeowners$/], "Add CODEOWNERS for security-sensitive and release paths.", 6);
fileCheck("license", "Governance", "Repository license", [/(^|\/)(license|copying)(\.[^/]+)?$/], "Document the repository license or private-use terms.", 5);
fileCheck("changelog", "Release readiness", "Changelog", [/(^|\/)changelog(\.[^/]+)?$/], "Add a changelog that maps releases to user-visible changes.", 7);
fileCheck("contributing", "Collaboration", "Contribution guide", [/(^|\/)contributing(\.[^/]+)?$/], "Add contribution, test and review instructions.", 4);
fileCheck("issue-templates", "Collaboration", "Issue templates", [/^\.gitea\/issue_template\//, /^\.github\/issue_template\//], "Add structured issue templates.", 3);
fileCheck("pull-request-template", "Collaboration", "Pull request template", [/(^|\/)pull_request_template\.md$/], "Add a pull request checklist for tests, risk and rollback.", 4);
fileCheck("runtime-pinning", "Reproducibility", "Runtime version pinning", [/(^|\/)(\.nvmrc|\.node-version|\.tool-versions|mise\.toml)$/], "Pin the runtime version used by developers and CI.", 7);
fileCheck("build-instructions", "Reproducibility", "Build instructions", [/(^|\/)(readme|building|build)(\.[^/]+)?$/], "Document a clean, reproducible build command.", 6);
const generated = tracked.filter((file) => /(^|\/)(dist|build|coverage|\.cache)\//i.test(file));
checks.push(result("generated-artifacts", "Performance and hygiene", "Generated output is not tracked", generated.length ? "warning" : "pass", generated.length ? `${generated.length} generated-path file(s) are tracked; review ${generated.slice(0, 5).join(", ")}.` : "No common generated output directories are tracked.", { weight: 8, evidence: generated.slice(0, 20) }));
const executables = tracked.filter((file) => /\.(exe|dll|msi|scr|com|bat|cmd|ps1)$/i.test(file));
checks.push(result("executable-artifacts", "Security", "Executable artifacts are intentional", executables.length ? "warning" : "pass", executables.length ? `Review executable content: ${executables.slice(0, 8).join(", ")}.` : "No executable-shaped artifacts are tracked.", { weight: 8, evidence: executables.slice(0, 20) }));
const workflowFiles = tracked.filter((file) => /^\.(gitea|github)\/workflows\/[^/]+\.ya?ml$/i.test(file));
const workflowText = (await Promise.all(workflowFiles.slice(0, 40).map((file) => fs.readFile(path.join(root, file), "utf8").catch(() => "")))).join("\n");
const unpinned = [...workflowText.matchAll(/uses:\s*[^\s@]+@([^\s#]+)/g)].map((match) => match[1]).filter((ref) => !/^[0-9a-f]{40}$/i.test(ref));
checks.push(result("pinned-actions", "Security", "External CI actions are commit-pinned", unpinned.length ? "warning" : "pass", unpinned.length ? `${unpinned.length} action reference(s) use mutable tags or branches.` : "External actions are commit-pinned or no external actions are used.", { weight: 9, evidence: unpinned.slice(0, 20) }));
const broadPermissions = /permissions:\s*(write-all|write)/i.test(workflowText) || /contents:\s*write/i.test(workflowText);
checks.push(result("workflow-permissions", "Security", "Workflow permissions use least privilege", broadPermissions ? "error" : "pass", broadPermissions ? "A workflow requests broad write permissions; scope permissions per job and capability." : "No broad workflow write permission was detected.", { weight: 12 }));
const [commitSignature, tagSignature, recentSubjects] = await Promise.all([
run("git", ["log", "-1", "--format=%G?"], { cwd: root, timeout: 10_000, allowExitCodes: [128] }).then((value) => value.stdout.trim()).catch(() => "N"),
run("git", ["tag", "--points-at", "HEAD", "--format=%(contents:signature)"], { cwd: root, timeout: 10_000, allowExitCodes: [128] }).then((value) => value.stdout.trim()).catch(() => ""),
run("git", ["log", "-20", "--format=%s"], { cwd: root, timeout: 10_000, allowExitCodes: [128] }).then((value) => value.stdout.trim().split(/\r?\n/).filter(Boolean)).catch(() => []),
]);
checks.push(result("signed-commits", "Governance", "Latest commit is signed", /[GUYX]/.test(commitSignature) ? "pass" : "warning", /[GUYX]/.test(commitSignature) ? "Git reports a cryptographic signature on HEAD." : "HEAD has no verifiable Git signature.", { weight: 6 }));
checks.push(result("signed-tags", "Governance", "Release tags are signed", tagSignature ? "pass" : "warning", tagSignature ? "HEAD has a signed tag." : "HEAD has no signed release tag.", { weight: 5 }));
const conventional = recentSubjects.length > 0 && recentSubjects.every((subject) => /^(feat|fix|docs|style|refactor|perf|test|build|ci|chore|revert)(\(.+\))?!?:\s.+/i.test(subject));
checks.push(result("conventional-commits", "Governance", "Recent commits follow a convention", conventional ? "pass" : "warning", conventional ? `${recentSubjects.length} recent commit subject(s) follow Conventional Commits.` : "Some recent commit subjects do not follow Conventional Commits.", { weight: 4 }));
const releaseFiles = {
"release-checksums": /(^|\/)(sha256sums|checksums?)(\.[^/]+)?$/,
"release-provenance": /(^|\/)(provenance|attestation)(\.[^/]+)?$/,
"release-sbom": /(^|\/)(sbom)(\.[^/]+)?$/,
};
for (const [id, pattern] of Object.entries(releaseFiles)) fileCheck(id, "Release readiness", id.replace(/^release-/, "Release "), [pattern], `No ${id.replace(/^release-/, "")} artifact is versioned or generated in the repository.`, 4);
checks.push(result("signing-readiness", "Release readiness", "Signing policy is documented", has(/(^|\/)(security|release|signing)(\.[^/]+)?$/) ? "pass" : "warning", has(/(^|\/)(security|release|signing)(\.[^/]+)?$/) ? "Signing guidance is present." : "Document signing identity, verification and timestamp requirements.", { weight: 6 }));
}
async finalize(repository, checks, status) {
const repositoryState = this.store?.getGitValidatorState?.(repository.fullName) || { policy: { id: "standard" }, suppressions: [], trends: [] };
const { policy, checks: governedChecks } = applyPolicy(checks, repositoryState.policy, repositoryState.suppressions);
const report = this.summarize(repository, governedChecks);
report.policy = policy;
report.commitSha = status?.head || status?.branch?.oid || null;
report.categories = Object.fromEntries([...new Set(governedChecks.map((check) => check.category))].map((category) => {
const categoryChecks = governedChecks.filter((check) => check.category === category);
return [category, Math.round(categoryChecks.filter((check) => check.status === "pass" || check.suppressed).length / categoryChecks.length * 100)];
}));
report.ready = report.score >= policy.requiredScore && !governedChecks.some((check) => check.blocking);
report.expiredSuppressions = governedChecks.filter((check) => check.expiredSuppression).map((check) => check.id);
report.trend = buildTrend(repositoryState.trends.at(-1), report);
if (this.store?.appendGitValidatorTrend) await this.store.appendGitValidatorTrend(repository.fullName, report.trend);
return report;
}
async setPolicy(repository, policyInput) {
const policy = normalizePolicy(policyInput);
if (!this.store?.setGitValidatorPolicy) throw new Error("Git Validator policy persistence is unavailable.");
await this.store.setGitValidatorPolicy(repository.fullName, policy);
return policy;
}
async suppress(repository, input) {
const state = this.store?.getGitValidatorState?.(repository.fullName) || { policy: { id: "standard" } };
const suppression = validateSuppression(input, normalizePolicy(state.policy));
await this.store.addGitValidatorSuppression(repository.fullName, suppression);
return suppression;
}
export(report, format) { return exportReport(report, format); }
async previewRepair(repository, check) {
if (!check?.fixAction) throw new Error("This validator check has no repair action.");
const root = repository.localPath ? await this.git.ensureRepository(repository.localPath) : null;
const fileDefinitions = {
"add-gitignore": [".gitignore", RECOMMENDED_GITIGNORE],
"add-gitattributes": [".gitattributes", RECOMMENDED_GITATTRIBUTES],
"add-editorconfig": [".editorconfig", RECOMMENDED_EDITORCONFIG],
};
if (fileDefinitions[check.fixAction]) {
const [name, content] = fileDefinitions[check.fixAction];
if (await fs.stat(path.join(root, name)).catch(() => null)) throw new Error(`${name} already exists; rescan before repairing.`);
return { checkId: check.id, action: check.fixAction, files: [name], diff: `diff --git a/${name} b/${name}\nnew file mode 100644\n--- /dev/null\n+++ b/${name}\n${content.split("\n").filter((line, index, lines) => index < lines.length - 1).map((line) => `+${line}`).join("\n")}\n`, remoteMutation: false };
}
if (check.fixAction === "configure-local-safety") return { checkId: check.id, action: check.fixAction, files: [".git/config"], diff: "+ fetch.prune = true\n+ pull.ff = only\n+ rebase.autoStash = true\n", remoteMutation: false };
if (check.fixAction === "align-origin") return { checkId: check.id, action: check.fixAction, files: [".git/config"], diff: `- origin = current\n+ origin = ${repository.preferredCloneUrl || repository.cloneUrl || repository.sshUrl}\n`, remoteMutation: false };
if (check.fixAction === "protect-default-branch") return { checkId: check.id, action: check.fixAction, files: [], diff: `Gitea policy change:\n+ protect ${repository.defaultBranch || "main"}\n+ block force pushes\n+ require pull request review\n`, remoteMutation: true };
throw new Error("Unsupported Git Validator repair action.");
}
summarize(repository, checks) {