diff --git a/.devcontainer/init-setup.sh b/.devcontainer/init-setup.sh index 9a96131ee5..f84c58ecb9 100644 --- a/.devcontainer/init-setup.sh +++ b/.devcontainer/init-setup.sh @@ -20,8 +20,8 @@ set -e # - To build the project, use: # ./gradlew build # -# - For running pre-commit hooks (if configured), use: -# pre-commit run --all-files +# - To run the lint/format/secret checks, use: +# task pre-commit # # Make sure you are in the project root directory after this script executes. # ============================================================================= @@ -70,6 +70,6 @@ echo "" echo " To build the project: " echo -e "\e[34m gradle build\e[0m" echo "" -echo " To run pre-commit hooks (if configured):" -echo -e "\e[34m pre-commit run --all-files -c .pre-commit-config.yaml\e[0m" +echo " To run the lint/format/secret checks:" +echo -e "\e[34m task pre-commit\e[0m" echo "==================================================================" diff --git a/.github/scripts/requirements_pre_commit.in b/.github/scripts/requirements_pre_commit.in deleted file mode 100644 index 416634f528..0000000000 --- a/.github/scripts/requirements_pre_commit.in +++ /dev/null @@ -1 +0,0 @@ -pre-commit diff --git a/.github/scripts/requirements_pre_commit.txt b/.github/scripts/requirements_pre_commit.txt deleted file mode 100644 index a476a5268b..0000000000 --- a/.github/scripts/requirements_pre_commit.txt +++ /dev/null @@ -1,121 +0,0 @@ -# -# This file is autogenerated by pip-compile with Python 3.12 -# by the following command: -# -# pip-compile --generate-hashes --output-file='.github\scripts\requirements_pre_commit.txt' --strip-extras '.github\scripts\requirements_pre_commit.in' -# -cfgv==3.5.0 \ - --hash=sha256:a8dc6b26ad22ff227d2634a65cb388215ce6cc96bbcc5cfde7641ae87e8dacc0 \ - --hash=sha256:d5b1034354820651caa73ede66a6294d6e95c1b00acc5e9b098e917404669132 - # via pre-commit -distlib==0.4.0 \ - --hash=sha256:9659f7d87e46584a30b5780e43ac7a2143098441670ff0a49d5f9034c54a6c16 \ - --hash=sha256:feec40075be03a04501a973d81f633735b4b69f98b05450592310c0f401a4e0d - # via virtualenv -filelock==3.29.0 \ - --hash=sha256:69974355e960702e789734cb4871f884ea6fe50bd8404051a3530bc07809cf90 \ - --hash=sha256:96f5f6344709aa1572bbf631c640e4ebeeb519e08da902c39a001882f30ac258 - # via - # python-discovery - # virtualenv -identify==2.6.19 \ - --hash=sha256:20e6a87f786f768c092a721ad107fc9df0eb89347be9396cadf3f4abbd1fb78a \ - --hash=sha256:6be5020c38fcb07da56c53733538a3081ea5aa70d36a156f83044bfbf9173842 - # via pre-commit -nodeenv==1.10.0 \ - --hash=sha256:5bb13e3eed2923615535339b3c620e76779af4cb4c6a90deccc9e36b274d3827 \ - --hash=sha256:996c191ad80897d076bdfba80a41994c2b47c68e224c542b48feba42ba00f8bb - # via pre-commit -platformdirs==4.9.6 \ - --hash=sha256:3bfa75b0ad0db84096ae777218481852c0ebc6c727b3168c1b9e0118e458cf0a \ - --hash=sha256:e61adb1d5e5cb3441b4b7710bea7e4c12250ca49439228cc1021c00dcfac0917 - # via - # python-discovery - # virtualenv -pre-commit==4.6.0 \ - --hash=sha256:718d2208cef53fdc38206e40524a6d4d9576d103eb16f0fec11c875e7716e9d9 \ - --hash=sha256:e2cf246f7299edcabcf15f9b0571fdce06058527f0a06535068a86d38089f29b - # via -r .github/scripts/requirements_pre_commit.in -python-discovery==1.2.2 \ - --hash=sha256:876e9c57139eb757cb5878cbdd9ae5379e5d96266c99ef731119e04fffe533bb \ - --hash=sha256:e1ae95d9af875e78f15e19aed0c6137ab1bb49c200f21f5061786490c9585c7a - # via virtualenv -pyyaml==6.0.3 \ - --hash=sha256:00c4bdeba853cc34e7dd471f16b4114f4162dc03e6b7afcc2128711f0eca823c \ - --hash=sha256:0150219816b6a1fa26fb4699fb7daa9caf09eb1999f3b70fb6e786805e80375a \ - --hash=sha256:02893d100e99e03eda1c8fd5c441d8c60103fd175728e23e431db1b589cf5ab3 \ - --hash=sha256:02ea2dfa234451bbb8772601d7b8e426c2bfa197136796224e50e35a78777956 \ - --hash=sha256:0f29edc409a6392443abf94b9cf89ce99889a1dd5376d94316ae5145dfedd5d6 \ - --hash=sha256:10892704fc220243f5305762e276552a0395f7beb4dbf9b14ec8fd43b57f126c \ - --hash=sha256:16249ee61e95f858e83976573de0f5b2893b3677ba71c9dd36b9cf8be9ac6d65 \ - --hash=sha256:1d37d57ad971609cf3c53ba6a7e365e40660e3be0e5175fa9f2365a379d6095a \ - --hash=sha256:1ebe39cb5fc479422b83de611d14e2c0d3bb2a18bbcb01f229ab3cfbd8fee7a0 \ - --hash=sha256:214ed4befebe12df36bcc8bc2b64b396ca31be9304b8f59e25c11cf94a4c033b \ - --hash=sha256:2283a07e2c21a2aa78d9c4442724ec1eb15f5e42a723b99cb3d822d48f5f7ad1 \ - --hash=sha256:22ba7cfcad58ef3ecddc7ed1db3409af68d023b7f940da23c6c2a1890976eda6 \ - --hash=sha256:27c0abcb4a5dac13684a37f76e701e054692a9b2d3064b70f5e4eb54810553d7 \ - --hash=sha256:28c8d926f98f432f88adc23edf2e6d4921ac26fb084b028c733d01868d19007e \ - --hash=sha256:2e71d11abed7344e42a8849600193d15b6def118602c4c176f748e4583246007 \ - --hash=sha256:34d5fcd24b8445fadc33f9cf348c1047101756fd760b4dacb5c3e99755703310 \ - --hash=sha256:37503bfbfc9d2c40b344d06b2199cf0e96e97957ab1c1b546fd4f87e53e5d3e4 \ - --hash=sha256:3c5677e12444c15717b902a5798264fa7909e41153cdf9ef7ad571b704a63dd9 \ - --hash=sha256:3ff07ec89bae51176c0549bc4c63aa6202991da2d9a6129d7aef7f1407d3f295 \ - --hash=sha256:41715c910c881bc081f1e8872880d3c650acf13dfa8214bad49ed4cede7c34ea \ - --hash=sha256:418cf3f2111bc80e0933b2cd8cd04f286338bb88bdc7bc8e6dd775ebde60b5e0 \ - --hash=sha256:44edc647873928551a01e7a563d7452ccdebee747728c1080d881d68af7b997e \ - --hash=sha256:4a2e8cebe2ff6ab7d1050ecd59c25d4c8bd7e6f400f5f82b96557ac0abafd0ac \ - --hash=sha256:4ad1906908f2f5ae4e5a8ddfce73c320c2a1429ec52eafd27138b7f1cbe341c9 \ - --hash=sha256:501a031947e3a9025ed4405a168e6ef5ae3126c59f90ce0cd6f2bfc477be31b7 \ - --hash=sha256:5190d403f121660ce8d1d2c1bb2ef1bd05b5f68533fc5c2ea899bd15f4399b35 \ - --hash=sha256:5498cd1645aa724a7c71c8f378eb29ebe23da2fc0d7a08071d89469bf1d2defb \ - --hash=sha256:5cf4e27da7e3fbed4d6c3d8e797387aaad68102272f8f9752883bc32d61cb87b \ - --hash=sha256:5e0b74767e5f8c593e8c9b5912019159ed0533c70051e9cce3e8b6aa699fcd69 \ - --hash=sha256:5ed875a24292240029e4483f9d4a4b8a1ae08843b9c54f43fcc11e404532a8a5 \ - --hash=sha256:5fcd34e47f6e0b794d17de1b4ff496c00986e1c83f7ab2fb8fcfe9616ff7477b \ - --hash=sha256:5fdec68f91a0c6739b380c83b951e2c72ac0197ace422360e6d5a959d8d97b2c \ - --hash=sha256:6344df0d5755a2c9a276d4473ae6b90647e216ab4757f8426893b5dd2ac3f369 \ - --hash=sha256:64386e5e707d03a7e172c0701abfb7e10f0fb753ee1d773128192742712a98fd \ - --hash=sha256:652cb6edd41e718550aad172851962662ff2681490a8a711af6a4d288dd96824 \ - --hash=sha256:66291b10affd76d76f54fad28e22e51719ef9ba22b29e1d7d03d6777a9174198 \ - --hash=sha256:66e1674c3ef6f541c35191caae2d429b967b99e02040f5ba928632d9a7f0f065 \ - --hash=sha256:6adc77889b628398debc7b65c073bcb99c4a0237b248cacaf3fe8a557563ef6c \ - --hash=sha256:79005a0d97d5ddabfeeea4cf676af11e647e41d81c9a7722a193022accdb6b7c \ - --hash=sha256:7c6610def4f163542a622a73fb39f534f8c101d690126992300bf3207eab9764 \ - --hash=sha256:7f047e29dcae44602496db43be01ad42fc6f1cc0d8cd6c83d342306c32270196 \ - --hash=sha256:8098f252adfa6c80ab48096053f512f2321f0b998f98150cea9bd23d83e1467b \ - --hash=sha256:850774a7879607d3a6f50d36d04f00ee69e7fc816450e5f7e58d7f17f1ae5c00 \ - --hash=sha256:8d1fab6bb153a416f9aeb4b8763bc0f22a5586065f86f7664fc23339fc1c1fac \ - --hash=sha256:8da9669d359f02c0b91ccc01cac4a67f16afec0dac22c2ad09f46bee0697eba8 \ - --hash=sha256:8dc52c23056b9ddd46818a57b78404882310fb473d63f17b07d5c40421e47f8e \ - --hash=sha256:9149cad251584d5fb4981be1ecde53a1ca46c891a79788c0df828d2f166bda28 \ - --hash=sha256:93dda82c9c22deb0a405ea4dc5f2d0cda384168e466364dec6255b293923b2f3 \ - --hash=sha256:96b533f0e99f6579b3d4d4995707cf36df9100d67e0c8303a0c55b27b5f99bc5 \ - --hash=sha256:9c57bb8c96f6d1808c030b1687b9b5fb476abaa47f0db9c0101f5e9f394e97f4 \ - --hash=sha256:9c7708761fccb9397fe64bbc0395abcae8c4bf7b0eac081e12b809bf47700d0b \ - --hash=sha256:9f3bfb4965eb874431221a3ff3fdcddc7e74e3b07799e0e84ca4a0f867d449bf \ - --hash=sha256:a33284e20b78bd4a18c8c2282d549d10bc8408a2a7ff57653c0cf0b9be0afce5 \ - --hash=sha256:a80cb027f6b349846a3bf6d73b5e95e782175e52f22108cfa17876aaeff93702 \ - --hash=sha256:b30236e45cf30d2b8e7b3e85881719e98507abed1011bf463a8fa23e9c3e98a8 \ - --hash=sha256:b3bc83488de33889877a0f2543ade9f70c67d66d9ebb4ac959502e12de895788 \ - --hash=sha256:b865addae83924361678b652338317d1bd7e79b1f4596f96b96c77a5a34b34da \ - --hash=sha256:b8bb0864c5a28024fac8a632c443c87c5aa6f215c0b126c449ae1a150412f31d \ - --hash=sha256:ba1cc08a7ccde2d2ec775841541641e4548226580ab850948cbfda66a1befcdc \ - --hash=sha256:bdb2c67c6c1390b63c6ff89f210c8fd09d9a1217a465701eac7316313c915e4c \ - --hash=sha256:c1ff362665ae507275af2853520967820d9124984e0f7466736aea23d8611fba \ - --hash=sha256:c2514fceb77bc5e7a2f7adfaa1feb2fb311607c9cb518dbc378688ec73d8292f \ - --hash=sha256:c3355370a2c156cffb25e876646f149d5d68f5e0a3ce86a5084dd0b64a994917 \ - --hash=sha256:c458b6d084f9b935061bc36216e8a69a7e293a2f1e68bf956dcd9e6cbcd143f5 \ - --hash=sha256:d0eae10f8159e8fdad514efdc92d74fd8d682c933a6dd088030f3834bc8e6b26 \ - --hash=sha256:d76623373421df22fb4cf8817020cbb7ef15c725b9d5e45f17e189bfc384190f \ - --hash=sha256:ebc55a14a21cb14062aa4162f906cd962b28e2e9ea38f9b4391244cd8de4ae0b \ - --hash=sha256:eda16858a3cab07b80edaf74336ece1f986ba330fdb8ee0d6c0d68fe82bc96be \ - --hash=sha256:ee2922902c45ae8ccada2c5b501ab86c36525b883eff4255313a253a3160861c \ - --hash=sha256:efd7b85f94a6f21e4932043973a7ba2613b059c4a000551892ac9f1d11f5baf3 \ - --hash=sha256:f7057c9a337546edc7973c0d3ba84ddcdf0daa14533c2065749c9075001090e6 \ - --hash=sha256:fa160448684b4e94d80416c0fa4aac48967a969efe22931448d853ada8baf926 \ - --hash=sha256:fc09d0aa354569bc501d4e787133afc08552722d3ab34836a80547331bb5d4a0 - # via pre-commit -virtualenv==21.2.4 \ - --hash=sha256:29d21e941795206138d0f22f4e45ff7050e5da6c6472299fb7103318763861ac \ - --hash=sha256:b294ef68192638004d72524ce7ef303e9d0cf5a44c95ce2e54a7500a6381cada - # via pre-commit diff --git a/.github/workflows/pre_commit.yml b/.github/workflows/pre_commit.yml index fe2d1b6877..85d2efa996 100644 --- a/.github/workflows/pre_commit.yml +++ b/.github/workflows/pre_commit.yml @@ -1,8 +1,7 @@ name: Pre-commit -# Runs `pre-commit run` for ruff / codespell / gitleaks / EOF / trailing-ws. -# Called from build.yml on PRs and merge_group; also runnable on demand via -# workflow_dispatch for manual local-equivalent linting. +# Runs the repo-wide lint/format/secret checks via `task pre-commit`. +# Called from build.yml on PRs and merge_group; also runnable on demand via workflow_dispatch. on: workflow_call: workflow_dispatch: @@ -13,10 +12,6 @@ permissions: jobs: pre-commit: runs-on: ubuntu-latest - env: - # Prevents sdist builds → no tar extraction - PIP_ONLY_BINARY: ":all:" - PIP_DISABLE_PIP_VERSION_CHECK: "1" steps: - name: Harden Runner uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3 @@ -29,23 +24,13 @@ jobs: fetch-depth: 0 persist-credentials: false - - name: Set up Python - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 + - name: Install uv + uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 with: - python-version: 3.12 - cache: "pip" # caching pip dependencies - cache-dependency-path: ./.github/scripts/requirements_pre_commit.txt + enable-cache: true - - name: Run Pre-Commit Hooks - run: | - pip install --require-hashes --only-binary=:all: -r ./.github/scripts/requirements_pre_commit.txt + - name: Install Task + uses: go-task/setup-task@3be4020d41929789a01026e0e427a4321ce0ad44 # v2.0.0 - - name: Run Pre-Commit - run: | - pre-commit run ruff --all-files -c .pre-commit-config.yaml - pre-commit run ruff-format --all-files -c .pre-commit-config.yaml - pre-commit run codespell --all-files -c .pre-commit-config.yaml - pre-commit run gitleaks --all-files -c .pre-commit-config.yaml - pre-commit run end-of-file-fixer --all-files -c .pre-commit-config.yaml - pre-commit run trailing-whitespace --all-files -c .pre-commit-config.yaml - git diff --exit-code + - name: Run pre-commit checks + run: task pre-commit diff --git a/.github/workflows/sync_files_v2.yml b/.github/workflows/sync_files_v2.yml index b91884c82e..4647442d4f 100644 --- a/.github/workflows/sync_files_v2.yml +++ b/.github/workflows/sync_files_v2.yml @@ -58,15 +58,23 @@ jobs: - name: Install Python dependencies run: | - pip install --require-hashes --only-binary=:all: -r ./.github/scripts/requirements_sync_readme.txt -r ./.github/scripts/requirements_pre_commit.txt + pip install --require-hashes --only-binary=:all: -r ./.github/scripts/requirements_sync_readme.txt + + - name: Install uv + uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 + with: + enable-cache: true + + - name: Install Task + uses: go-task/setup-task@3be4020d41929789a01026e0e427a4321ce0ad44 # v2.0.0 - name: Sync translation TOML files run: | python .github/scripts/check_language_toml.py --reference-file "frontend/editor/public/locales/en-US/translation.toml" --branch main - - name: pre-commit run + - name: Sort translation TOML files run: | - pre-commit run toml-sort-fix --all-files + task pre-commit:toml-sort FIX=1 - name: Commit translation files run: | diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 2490b4ae6e..83753a9263 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,52 +1,14 @@ +# The actual checks live in .taskfiles/pre-commit.yml (with helper scripts under +# scripts/pre-commit/) and are driven by Task. This hook just delegates to `task +# pre-commit` so the git pre-commit hook, CI and a manual `task pre-commit` all +# run the exact same thing. Requires `task` and `uv` on PATH. To auto-fix instead +# of only checking, run `task pre-commit:fix`. repos: - - repo: https://github.com/astral-sh/ruff-pre-commit - rev: v0.15.14 + - repo: local hooks: - - id: ruff - args: - - --fix - - --line-length=127 - files: ^((\.github/scripts|scripts|app/core/src/main/resources/static/python)/.+)?[^/]+\.py$ - exclude: (split_photos.py) - - id: ruff-format - files: ^((\.github/scripts|scripts|app/core/src/main/resources/static/python)/.+)?[^/]+\.py$ - exclude: (split_photos.py) - - repo: https://github.com/codespell-project/codespell - rev: v2.4.2 - hooks: - - id: codespell - args: - - --ignore-words-list=thirdParty,tabEl,tabEls,Sie,ist,fulfilment - - --skip="./.*,*.csv,*.json,*.ambr" - - --quiet-level=2 - files: \.(html|css|js|py|md)$ - exclude: (.vscode|.devcontainer|app/core/src/main/resources|app/proprietary/src/main/resources|frontend/editor/public/vendor|Dockerfile|.*/pdfjs.*|.*/thirdParty.*|bootstrap.*|.*\.min\..*|.*diff\.js) - - repo: https://github.com/gitleaks/gitleaks - rev: v8.30.0 - hooks: - - id: gitleaks - - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v6.0.0 - hooks: - - id: end-of-file-fixer - files: ^.*(\.js|\.java|\.py|\.yml)$ - exclude: ^(.*/pdfjs.*|.*/thirdParty.*|bootstrap.*|.*\.min\..*|.*diff\.js|\.github/workflows/.*$) - - id: trailing-whitespace - files: ^.*(\.js|\.java|\.py|\.yml)$ - exclude: ^(.*/pdfjs.*|.*/thirdParty.*|bootstrap.*|.*\.min\..*|.*diff\.js|\.github/workflows/.*$) - - repo: https://github.com/pappasam/toml-sort - rev: v0.24.4 - hooks: - - id: toml-sort-fix - files: frontend/editor/public/locales/.*\.toml$ - args: ['--in-place', '--all', '--ignore-case'] - # - repo: https://github.com/thibaudcolas/pre-commit-stylelint - # rev: v16.21.1 - # hooks: - # - id: stylelint - # additional_dependencies: - # - stylelint@16.21.1 - # - stylelint-config-standard@38.0.0 - # - "@stylistic/stylelint-plugin@3.1.3" - # files: \.(css)$ - # args: [--fix] + - id: task-pre-commit + name: task pre-commit + entry: task pre-commit + language: system + pass_filenames: false + always_run: true diff --git a/.taskfiles/pre-commit.yml b/.taskfiles/pre-commit.yml new file mode 100644 index 0000000000..63fdd9ea01 --- /dev/null +++ b/.taskfiles/pre-commit.yml @@ -0,0 +1,159 @@ +version: '3' + +# Repo-wide lint/format/secret checks - the single source of truth that the git +# pre-commit hook (.pre-commit-config.yaml) and CI (pre_commit.yml) both call. + +vars: + GITLEAKS: '8.30.0' + + # File selections as git pathspecs: git does the include/exclude matching, so + # there is no grep/xargs and it behaves identically on every platform. + PY_FILES: >- + 'scripts/*.py' + '.github/scripts/*.py' + 'app/core/src/main/resources/static/python/*.py' + ':(exclude)*split_photos.py' + SPELL_FILES: >- + '*.html' + '*.css' + '*.js' + '*.py' + '*.md' + ':(exclude).vscode/*' + ':(exclude).devcontainer/*' + ':(exclude)app/core/src/main/resources/*' + ':(exclude)app/proprietary/src/main/resources/*' + ':(exclude)frontend/editor/public/vendor/*' + ':(exclude)*Dockerfile*' + ':(exclude)*pdfjs*' + ':(exclude)*thirdParty*' + ':(exclude)*bootstrap*' + ':(exclude)*.min.*' + ':(exclude)*diff.js' + WS_FILES: >- + '*.js' + '*.java' + '*.py' + '*.yml' + ':(exclude)*pdfjs*' + ':(exclude)*thirdParty*' + ':(exclude)*bootstrap*' + ':(exclude)*.min.*' + ':(exclude)*diff.js' + ':(exclude).github/workflows/*' + LOCALE_TOML: 'frontend/editor/public/locales/*/translation.toml' + + GITLEAKS_BIN: '.task/bin/gitleaks-{{.GITLEAKS}}{{if eq OS "windows"}}.exe{{end}}' + +tasks: + default: + desc: "Check formatting, spelling, and secrets across the repo" + cmds: + - task: ruff + - task: ruff-format + - task: codespell + - task: gitleaks + - task: whitespace + - task: toml-sort + + fix: + desc: "Auto-fix formatting, spelling, and secrets issues across the repo" + cmds: + # Auto-fixers first, then the report-only tools (codespell, gitleaks) so a + # finding there does not stop the fixers from running. + - task: ruff + vars: { FIX: '1' } + - task: ruff-format + vars: { FIX: '1' } + - task: whitespace + vars: { FIX: '1' } + - task: toml-sort + vars: { FIX: '1' } + - task: codespell + - task: gitleaks + + install: + desc: "Install the pinned pre-commit Python tools (ruff, codespell, toml-sort)" + run: once + cmds: + - uv sync --project scripts/pre-commit --locked + sources: + - scripts/pre-commit/uv.lock + - scripts/pre-commit/pyproject.toml + status: + - test -d scripts/pre-commit/.venv + + clean: + desc: "Remove the cache/build artifacts" + cmds: + - task: '{{if eq OS "windows"}}clean-windows{{else}}clean-unix{{end}}' + + clean-unix: + internal: true + cmds: + - rm -rf scripts/pre-commit/.venv .task/bin/gitleaks-* + + # On Windows, use PowerShell so it matches the same paths and tolerates absent + # files without erroring. + clean-windows: + internal: true + ignore_error: true + cmds: + - powershell -NoProfile -Command "Remove-Item -Recurse -Force -ErrorAction SilentlyContinue scripts/pre-commit/.venv, .task/bin/gitleaks-*" + + # Individual checks (hidden from `task --list`, but callable, e.g. + # `task pre-commit:toml-sort FIX=1`). Pass FIX=1 to auto-fix where supported. + ruff: + deps: [install] + cmds: + - uv run --project scripts/pre-commit --no-sync ruff check --line-length=127 {{if .FIX}}--fix {{end}}$(git ls-files {{.PY_FILES}}) + + ruff-format: + deps: [install] + cmds: + - uv run --project scripts/pre-commit --no-sync ruff format {{if .FIX}}{{else}}--check {{end}}$(git ls-files {{.PY_FILES}}) + + codespell: + deps: [install] + cmds: + - uv run --project scripts/pre-commit --no-sync codespell --ignore-words-list=thirdParty,tabEl,tabEls,Sie,ist,fulfilment --quiet-level=2 $(git ls-files {{.SPELL_FILES}}) + + toml-sort: + deps: [install] + cmds: + - uv run --project scripts/pre-commit --no-sync toml-sort --all --ignore-case {{if .FIX}}--in-place{{else}}--check{{end}} {{.LOCALE_TOML}} + + whitespace: + cmds: + - uv run --no-project python scripts/pre-commit/whitespace.py {{if .FIX}}--fix {{end}}$(git ls-files {{.WS_FILES}}) + + gitleaks: + deps: [gitleaks-bin] + # Scan staged changes only, matching the old hook: the git-mode fingerprints + # in .gitleaksignore (file:rule:line) still apply, and with nothing staged + # this is a no-op. Secrets are never auto-fixed, so FIX has no effect. + cmds: + - "{{.GITLEAKS_BIN}} git --pre-commit --redact --staged --verbose" + + gitleaks-bin: + internal: true + desc: "Ensure the pinned gitleaks binary is cached in .task/bin" + status: + - test -f {{.GITLEAKS_BIN}} + vars: + GL_ARCH: '{{if eq ARCH "amd64"}}x64{{else if eq ARCH "arm64"}}arm64{{else if eq ARCH "386"}}x32{{else}}{{ARCH}}{{end}}' + GL_PLATFORM: '{{OS}}_{{.GL_ARCH}}' + GL_URL: 'https://github.com/gitleaks/gitleaks/releases/download/v{{.GITLEAKS}}/gitleaks_{{.GITLEAKS}}_{{.GL_PLATFORM}}' + # SHA-256 of each release asset, from gitleaks_{{.GITLEAKS}}_checksums.txt. + GL_SHA: >- + {{if eq .GL_PLATFORM "linux_x64"}}79a3ab579b53f71efd634f3aaf7e04a0fa0cf206b7ed434638d1547a2470a66e + {{- else if eq .GL_PLATFORM "linux_arm64"}}b4cbbb6ddf7d1b2a603088cd03a4e3f7ce48ee7fd449b51f7de6ee2906f5fa2f + {{- else if eq .GL_PLATFORM "darwin_x64"}}ca221d012d247080c2f6f61f4b7a83bffa2453806b0c195c795bbe9a8c775ed5 + {{- else if eq .GL_PLATFORM "darwin_arm64"}}b251ab2bcd4cd8ba9e56ff37698c033ebf38582b477d21ebd86586d927cf87e7 + {{- else if eq .GL_PLATFORM "windows_x64"}}54fe94f644b832dd08e8c3a5915efb3bfa862386d59fb27ca0792cb687a83573 + {{- end}} + cmds: + - cmd: bash scripts/pre-commit/install-gitleaks.sh "{{.GL_URL}}.tar.gz" "{{.GL_SHA}}" "{{.GITLEAKS_BIN}}" + platforms: [linux, darwin] + - cmd: powershell -NoProfile -File scripts/pre-commit/install-gitleaks.ps1 -Url "{{.GL_URL}}.zip" -Sha "{{.GL_SHA}}" -Dest "{{.GITLEAKS_BIN}}" + platforms: [windows] diff --git a/Taskfile.yml b/Taskfile.yml index a12d455352..0b25cf7aa6 100644 --- a/Taskfile.yml +++ b/Taskfile.yml @@ -25,6 +25,9 @@ includes: e2e: taskfile: .taskfiles/e2e.yml dir: . + pre-commit: + taskfile: .taskfiles/pre-commit.yml + dir: . tasks: # ============================================================ @@ -174,3 +177,4 @@ tasks: - task: backend:clean - task: frontend:clean - task: engine:clean + - task: pre-commit:clean diff --git a/scripts/generate_requirements.bat b/scripts/generate_requirements.bat index eeed0ba2c6..94cea30b3f 100644 --- a/scripts/generate_requirements.bat +++ b/scripts/generate_requirements.bat @@ -34,11 +34,6 @@ pip-compile --allow-unsafe --generate-hashes --upgrade --strip-extras ^ --output-file=".github\scripts\requirements_dev.txt" ^ ".github\scripts\requirements_dev.in" -echo Generating .github\scripts\requirements_pre_commit.txt -pip-compile --generate-hashes --upgrade --strip-extras ^ - --output-file=".github\scripts\requirements_pre_commit.txt" ^ - ".github\scripts\requirements_pre_commit.in" - echo Generating .github\scripts\requirements_sync_readme.txt pip-compile --generate-hashes --upgrade --strip-extras ^ --output-file=".github\scripts\requirements_sync_readme.txt" ^ diff --git a/scripts/pre-commit/install-gitleaks.ps1 b/scripts/pre-commit/install-gitleaks.ps1 new file mode 100644 index 0000000000..ec554bb6cb --- /dev/null +++ b/scripts/pre-commit/install-gitleaks.ps1 @@ -0,0 +1,31 @@ +# Download, checksum-verify and extract the gitleaks binary. +# +# Usage: install-gitleaks.ps1 -Url -Sha -Dest +# +# Called by the pre-commit:gitleaks-bin Task target, which owns the pinned +# version and per-platform checksums and passes the resolved values in. +param( + [Parameter(Mandatory)] [string]$Url, + [Parameter(Mandatory)] [string]$Sha, + [Parameter(Mandatory)] [string]$Dest +) +$ErrorActionPreference = 'Stop' + +if (-not $Sha) { + throw 'No pinned gitleaks checksum for this platform' +} + +New-Item -ItemType Directory -Force -Path (Split-Path -Parent $Dest) | Out-Null + +$archive = New-TemporaryFile +$extract = Join-Path $env:TEMP 'gitleaks-extract' +try { + Invoke-WebRequest -Uri $Url -OutFile $archive + if ((Get-FileHash $archive -Algorithm SHA256).Hash -ne $Sha) { + throw 'gitleaks checksum mismatch' + } + Expand-Archive -Force -Path $archive -DestinationPath $extract + Move-Item -Force -Path (Join-Path $extract 'gitleaks.exe') -Destination $Dest +} finally { + Remove-Item -Force -ErrorAction SilentlyContinue $archive, $extract -Recurse +} diff --git a/scripts/pre-commit/install-gitleaks.sh b/scripts/pre-commit/install-gitleaks.sh new file mode 100644 index 0000000000..efafc88f56 --- /dev/null +++ b/scripts/pre-commit/install-gitleaks.sh @@ -0,0 +1,30 @@ +#!/usr/bin/env bash +# Download, checksum-verify and extract the gitleaks binary. +# +# Usage: install-gitleaks.sh +# +# Called by the pre-commit:gitleaks-bin Task target, which owns the pinned +# version and per-platform checksums and passes the resolved values in. +set -euo pipefail + +url=$1 +sha=$2 +dest=$3 + +if [ -z "$sha" ]; then + echo "No pinned gitleaks checksum for this platform" >&2 + exit 1 +fi + +mkdir -p "$(dirname "$dest")" +archive=$(mktemp) +trap 'rm -f "$archive"' EXIT + +curl -fsSL "$url" -o "$archive" +actual=$(shasum -a 256 "$archive" | awk '{print $1}') +if [ "$actual" != "$sha" ]; then + echo "gitleaks checksum mismatch: expected $sha, got $actual" >&2 + exit 1 +fi +tar -xzO -f "$archive" gitleaks > "$dest" +chmod +x "$dest" diff --git a/scripts/pre-commit/pyproject.toml b/scripts/pre-commit/pyproject.toml new file mode 100644 index 0000000000..cd13b56f5e --- /dev/null +++ b/scripts/pre-commit/pyproject.toml @@ -0,0 +1,16 @@ +# Pinned Python lint/format tools for `task pre-commit`. uv.lock locks these +# plus their transitive dependencies by hash, so `uv run --project +# scripts/pre-commit --locked ` is reproducible and integrity-checked. +# This is not a packaged project - it only exists to lock the tooling. +[project] +name = "stirling-precommit-tools" +version = "0" +requires-python = ">=3.11" +dependencies = [ + "ruff==0.15.14", + "codespell==2.4.2", + "toml-sort==0.24.4", +] + +[tool.uv] +package = false diff --git a/scripts/pre-commit/uv.lock b/scripts/pre-commit/uv.lock new file mode 100644 index 0000000000..b90593a6e8 --- /dev/null +++ b/scripts/pre-commit/uv.lock @@ -0,0 +1,75 @@ +version = 1 +revision = 3 +requires-python = ">=3.11" + +[[package]] +name = "codespell" +version = "2.4.2" +source = { registry = "https://pypi.org/simple" } +sdist = { url = "https://files.pythonhosted.org/packages/2d/9d/1d0903dff693160f893ca6abcabad545088e7a2ee0a6deae7c24e958be69/codespell-2.4.2.tar.gz", hash = "sha256:3c33be9ae34543807f088aeb4832dfad8cb2dae38da61cac0a7045dd376cfdf3", size = 352058, upload-time = "2026-03-05T18:10:42.936Z" } +wheels = [ + { url = "https://files.pythonhosted.org/packages/42/a1/52fa05533e95fe45bcc09bcf8a503874b1c08f221a4e35608017e0938f55/codespell-2.4.2-py3-none-any.whl", hash = "sha256:97e0c1060cf46bd1d5db89a936c98db8c2b804e1fdd4b5c645e82a1ec6b1f886", size = 353715, upload-time = "2026-03-05T18:10:41.398Z" }, +] + +[[package]] +name = "ruff" +version = "0.15.14" +source = { registry = "https://pypi.org/simple" } +sdist = { url = "https://files.pythonhosted.org/packages/dc/8a/8bce2894573e9dae6ff4d77fe34ad727d79b9e6238ad288c5638990d90f6/ruff-0.15.14.tar.gz", hash = "sha256:48e866b165be4a9bdbf310f7d3c9a07edef2fe8cd63ffeb4e00bb590506ebf9f", size = 4700910, upload-time = "2026-05-21T14:34:55.177Z" } +wheels = [ + { url = "https://files.pythonhosted.org/packages/b9/c8/74a92c6ff9fcfb4f1f947126d3ebee8389276e161ecc85de5bda7cda51bd/ruff-0.15.14-py3-none-linux_armv6l.whl", hash = "sha256:8dd2db9416e487c8d4b01fa7056bb02c4d05969d4f8d17a08c229c2f4ff3c108", size = 10739177, upload-time = "2026-05-21T14:34:37.332Z" }, + { url = "https://files.pythonhosted.org/packages/45/91/254a35c20acc38a7223c9d2d594af12e794432464f2cdeb52af1dc4a892d/ruff-0.15.14-py3-none-macosx_10_12_x86_64.whl", hash = "sha256:be4ff55af755bd71a00ab3dc6bd7ffc467bd76e0df6881e286c2e3d23e8fb43b", size = 11144969, upload-time = "2026-05-21T14:34:43.978Z" }, + { url = "https://files.pythonhosted.org/packages/56/9e/d13e40f83b8d0a94430e6778ce1d94a43b38cf2efe63278bdd2b4c65abbf/ruff-0.15.14-py3-none-macosx_11_0_arm64.whl", hash = "sha256:48d5909d7d06276ce7dde6d32bfa4b0d4cb2651145cd8ee4b440722cbc77832f", size = 10478207, upload-time = "2026-05-21T14:34:48.378Z" }, + { url = "https://files.pythonhosted.org/packages/8d/f1/b15a7839fa4f332f8acec78e20564f26bb2d866e3d21710b877fd0263000/ruff-0.15.14-py3-none-manylinux_2_17_aarch64.manylinux2014_aarch64.whl", hash = "sha256:ca8cbfa94c4f90984a67561978602746d4cd27103568f745fa90eee3f0d4107d", size = 10818459, upload-time = "2026-05-21T14:34:22.318Z" }, + { url = "https://files.pythonhosted.org/packages/45/33/53d651177f84f94b400a0e27f8824eeada3dddc9d5ee8aeb048f4352a520/ruff-0.15.14-py3-none-manylinux_2_17_armv7l.manylinux2014_armv7l.whl", hash = "sha256:9a6bbc0333f1ab053423bcbf6226477d266ca7cec7738c4c8e3f55647803f3c4", size = 10541800, upload-time = "2026-05-21T14:34:20.209Z" }, + { url = "https://files.pythonhosted.org/packages/b8/a6/868f87e0bf9786ed24b5d0d0ad8676b8a94fd1912f42cddf9cfc7857818a/ruff-0.15.14-py3-none-manylinux_2_17_i686.manylinux2014_i686.whl", hash = "sha256:8a24a4f7605d7003a6674d4387651effd939dead3fddd0f36561eb77a9a2e542", size = 11342149, upload-time = "2026-05-21T14:34:46.365Z" }, + { url = "https://files.pythonhosted.org/packages/a7/8b/38cd5c19faffdcc05a408d2b78edccc69492ab9720eadb49ea15ef80d768/ruff-0.15.14-py3-none-manylinux_2_17_ppc64le.manylinux2014_ppc64le.whl", hash = "sha256:049b5326e53ed80978f2fc041a280603f69dd6b0c95464342a2bb4572d9d9e2f", size = 12212563, upload-time = "2026-05-21T14:34:28.579Z" }, + { url = "https://files.pythonhosted.org/packages/3e/4d/a3c5b874a556d5731e3e657aaf04311bb76f0a5c3ec220ed43051be6b64b/ruff-0.15.14-py3-none-manylinux_2_17_s390x.manylinux2014_s390x.whl", hash = "sha256:d4ed42e6696c8dfa5f06728e6441993901f548eb92d73bc472cb5a38d1395fbf", size = 11493299, upload-time = "2026-05-21T14:34:41.836Z" }, + { url = "https://files.pythonhosted.org/packages/1e/c0/56472c251d09858a53e51efbd485b09e1995d8731668b76d52e5dd6ee0f1/ruff-0.15.14-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl", hash = "sha256:715c543cf450c4888251f91c52f1942a800541d9bddd7ac060aa4e6b77ae7cba", size = 11455931, upload-time = "2026-05-21T14:34:57.276Z" }, + { url = "https://files.pythonhosted.org/packages/2c/4a/e2e7b4d8dbf233d4eace59c75bc3435fa6d8bd3bae82d351d4e4300c0fd1/ruff-0.15.14-py3-none-manylinux_2_31_riscv64.whl", hash = "sha256:72ebab6013ec887d439d8b7593737a0a4ffb06d45d209d4e4bf2e92813082d3f", size = 11400794, upload-time = "2026-05-21T14:34:39.773Z" }, + { url = "https://files.pythonhosted.org/packages/97/c7/83c0539fe34c3e09136204d1e75d6052492364e0b3cb05e9465423f567d7/ruff-0.15.14-py3-none-musllinux_1_2_aarch64.whl", hash = "sha256:49072d36abdbe97a8dd7f480afe9c675699c0c495d4c84076e2c1203c4550581", size = 10804759, upload-time = "2026-05-21T14:34:31.045Z" }, + { url = "https://files.pythonhosted.org/packages/86/a6/18f2bfc095a2ab4a78745644e428205532ce6653a5d0fa8501572891534d/ruff-0.15.14-py3-none-musllinux_1_2_armv7l.whl", hash = "sha256:958522aee105068640c2c2ceae08f413ae44d922f52a1374ac13d6a96032fc93", size = 10539517, upload-time = "2026-05-21T14:34:53.064Z" }, + { url = "https://files.pythonhosted.org/packages/54/3a/5a8b3b69c654d4e4bf1d246ac5b49cbcdac6eaab6905925f8915f31e3b80/ruff-0.15.14-py3-none-musllinux_1_2_i686.whl", hash = "sha256:f3707da619a143a2e8830e2abab8224478d69ace2d28cb6c20543ae97c36bf61", size = 11065169, upload-time = "2026-05-21T14:34:24.484Z" }, + { url = "https://files.pythonhosted.org/packages/ed/c5/8864e4e7925b836ea354b31d57641ec03830564e281a8b6f061f8c3e0ec1/ruff-0.15.14-py3-none-musllinux_1_2_x86_64.whl", hash = "sha256:bb01d645694e3ec0102105d07ef2d53703970407d59c04e59d3ba0b7a1d53553", size = 11560214, upload-time = "2026-05-21T14:34:50.975Z" }, + { url = "https://files.pythonhosted.org/packages/36/38/012bf76752e1f89ed50b77b99532d90f3a3e287bc7918e1fc0948ac866ac/ruff-0.15.14-py3-none-win32.whl", hash = "sha256:6d0c1ad2a0ab718d39b6d8fd2217981ce4d625cd96a720095f798fb47d8b13e6", size = 10805548, upload-time = "2026-05-21T14:34:33.453Z" }, + { url = "https://files.pythonhosted.org/packages/d1/b7/4ea2c170f10ad760fff2a5250beb18897719dc8b52b53a24cddbb9dd3f19/ruff-0.15.14-py3-none-win_amd64.whl", hash = "sha256:802342981e056db3851a7836e5b070f8f15f67d4a685ae2a6160939d364b2902", size = 11939523, upload-time = "2026-05-21T14:34:18.077Z" }, + { url = "https://files.pythonhosted.org/packages/62/d5/bc97ff895ec35cf3925d4bd60f3b39d822f377a446906ec9bcc87405e59b/ruff-0.15.14-py3-none-win_arm64.whl", hash = "sha256:ff47b90a9ef6a40c9e2f3b479c1fb78531adf055b94c1eba0a7ba04b31951826", size = 11208607, upload-time = "2026-05-21T14:34:26.525Z" }, +] + +[[package]] +name = "stirling-precommit-tools" +version = "0" +source = { virtual = "." } +dependencies = [ + { name = "codespell" }, + { name = "ruff" }, + { name = "toml-sort" }, +] + +[package.metadata] +requires-dist = [ + { name = "codespell", specifier = "==2.4.2" }, + { name = "ruff", specifier = "==0.15.14" }, + { name = "toml-sort", specifier = "==0.24.4" }, +] + +[[package]] +name = "toml-sort" +version = "0.24.4" +source = { registry = "https://pypi.org/simple" } +dependencies = [ + { name = "tomlkit" }, +] +sdist = { url = "https://files.pythonhosted.org/packages/47/c5/d6f650fdcf8e1f83096815fa67fb13a9a345b99da6015c60c4b7e4a8ea2b/toml_sort-0.24.4.tar.gz", hash = "sha256:429b69f5b98b7047a11380c80ecf0838556bdea1a8902d0be564961c48841423", size = 17793, upload-time = "2026-03-24T14:05:53.637Z" } +wheels = [ + { url = "https://files.pythonhosted.org/packages/0f/5a/1f0e54df4eacf0f4d8f94ba50cf72be33d2a3f04babdfb1931bead48a0ab/toml_sort-0.24.4-py3-none-any.whl", hash = "sha256:125aa5fb94f33c542c6901040456145dd38f79bbb310b56b436a93057d30a739", size = 16577, upload-time = "2026-03-24T14:05:54.757Z" }, +] + +[[package]] +name = "tomlkit" +version = "0.15.0" +source = { registry = "https://pypi.org/simple" } +sdist = { url = "https://files.pythonhosted.org/packages/51/db/03eaf4331631ef6b27d6e3c9b68c54dc6f0d63d87201fed600cc409307fd/tomlkit-0.15.0.tar.gz", hash = "sha256:7d1a9ecba3086638211b13814ea79c90dd54dd11993564376f3aa92271f5c7a3", size = 161875, upload-time = "2026-05-10T07:38:22.245Z" } +wheels = [ + { url = "https://files.pythonhosted.org/packages/6a/43/8bd850ee71a191bf072e31302c73a66be413fecdd98fdcd111ecbcce13ca/tomlkit-0.15.0-py3-none-any.whl", hash = "sha256:4dbc8f0fc024412b57ced8757ac7461305126a648ff8c2c807fcb8e133a78738", size = 41328, upload-time = "2026-05-10T07:38:23.517Z" }, +] diff --git a/scripts/pre-commit/whitespace.py b/scripts/pre-commit/whitespace.py new file mode 100644 index 0000000000..df77d3728d --- /dev/null +++ b/scripts/pre-commit/whitespace.py @@ -0,0 +1,60 @@ +#!/usr/bin/env python3 +"""Trailing-whitespace and end-of-file normalisation, driven by Task. + +Replaces the end-of-file-fixer / trailing-whitespace pre-commit hooks, which +have no read-only mode. Run via `task pre-commit` (check) and `task +pre-commit:fix`; Task selects the files (with `git ls-files`) and passes them +as arguments. + + python scripts/whitespace.py ... # check: report, exit 1 if any need fixing + python scripts/whitespace.py --fix ... # fix: rewrite in place + +Operates on bytes and only ever touches trailing spaces/tabs and the final +newline, so it never mangles content or line endings. Binary files (those with +a NUL byte) are skipped. +""" + +from __future__ import annotations + +import sys +from pathlib import Path + + +def normalise(data: bytes) -> bytes: + # Strip trailing spaces/tabs from each line (leave \r so CRLF survives). + lines = [line.rstrip(b" \t") for line in data.split(b"\n")] + body = b"\n".join(lines) + # Ensure a non-empty file ends with exactly one newline. + stripped = body.rstrip(b"\r\n") + return stripped + b"\n" if stripped else body + + +def main() -> int: + args = sys.argv[1:] + fix = "--fix" in args + paths = [a for a in args if a != "--fix"] + + offenders: list[str] = [] + for path in paths: + data = Path(path).read_bytes() + if b"\0" in data: + continue + fixed = normalise(data) + if fixed == data: + continue + offenders.append(path) + if fix: + Path(path).write_bytes(fixed) + + if offenders and not fix: + print(f"{len(offenders)} file(s) need whitespace fixing:") + for path in offenders: + print(f" {path}") + return 1 + if offenders and fix: + print(f"Fixed whitespace in {len(offenders)} file(s).") + return 0 + + +if __name__ == "__main__": + sys.exit(main())