-
-
Notifications
You must be signed in to change notification settings - Fork 3
ci and quality gates
github-actions[bot] edited this page Oct 3, 2026
·
7 revisions
Every change to main passes lint, complexity limits, security scans and a ruleset.
-
.github/workflows/lint.ymlruns rustfmt and clippy (pedantic,-D warnings), biome and tsc, taplo, shellcheck, lizard complexity, actionlint andreuse lint(SPDX headers, withREUSE.tomlfor files that cannot hold a comment). Thereusetool and its build backend are pinned by hash inscripts/requirements-reuse.txtandscripts/requirements-reuse-build.txt. -
.github/workflows/dco.ymlruns thedcojob on each PR. It checks that every commit has aSigned-off-byline that matches its author. Dependabot commits are skipped. It is not a required check yet. -
.github/workflows/ci.ymlbuilds and tests the app. -
.github/workflows/security.ymlruns cargo-deny, gitleaks and zizmor. zizmor runs with--persona=pedanticin CI and in lefthook, and every write permission and every non-default read permission has a comment that says why. CI pins the zizmor version (1.30.1). -
.github/workflows/codeql.ymlruns CodeQL (security-extended) for actions, javascript-typescript and rust. Each matrix entry has a fixed job name,codeql (<language>). -
.github/workflows/scorecard.ymlruns OpenSSF Scorecard, publishes the result and uploads the SARIF to code scanning. -
.github/workflows/fuzz.ymlruns ClusterFuzzLite on the cargo-fuzz targets: a short run on each PR that changes the code, and a daily batch run on main. It is not a required check. See Fuzzing. -
.github/workflows/dependency-review.ymlfails a PR that adds a dependency with a high severity advisory. - Complexity limits: cognitive and cyclomatic complexity 10 or less, 40 lines per function, 5 parameters, nesting 3.
- No lint exclusions exist. The code is fixed instead.
- Socket reviews every dependency change.
- The
docs-checkjob (scripts/docs-check.sh) fails afeatPR that changes no page underdocs/wiki/, and any PR that editsCHANGELOG.md. It also checks that every wiki page is indexed.scripts/docs-check.test.shtests the check. The job lives in.github/workflows/docs-check.ymland runs again when the PR title changes. - A repository ruleset blocks direct pushes to main. A pull request needs green required checks.
- Install the hooks once:
lefthook install. - Rust:
cargo fmt --manifest-path src-tauri/Cargo.toml --checkandcargo clippy --manifest-path src-tauri/Cargo.toml --all-targets --locked -- -D warnings. - Web:
npx biome ci .andnpm run typecheck. - Complexity:
./scripts/complexity.sh. - Licenses:
reuse lint. - Sign-off: use
git commit -s.
- The Scorecard badge shows "invalid repo path" until the first Scorecard run is published.
- The Rust job needs the WebKitGTK packages on Linux.
- 2026-10-03 — Repo bootstrap: skeleton, linters, security scans, CI — #1
- 2026-10-03 — Remove the warnings from the CI logs — #3
- 2026-10-03 — Remove every clippy lint exclusion — #5
- 2026-10-03 — Remove CodeQL and Scorecard until the repo is public — #9
- 2026-10-03 — Cut dependencies flagged by Socket — #10
- 2026-10-03 — Hash-pinned CI tools and typed vite config — #15
- 2026-10-03 — Add the docs-check job: code changes need a docs or changelog update — #16
- 2026-10-03 — Restore CodeQL and Scorecard, add dependency review and audit badges — #26
- 2026-10-03 — Add
reuse lintand the DCO check — #30 - 2026-10-03 — Run zizmor with the pedantic persona; document every workflow permission — #47
- 2026-10-03 — docs-check: a feat PR needs a wiki change, and CHANGELOG.md is generated, not edited — #50
Generated from docs/wiki in the repository. Edit there, not here.