ci: add local pre-push gate (ruff + mypy + pytest)

Forgejo Actions is not enabled on the instance, so run the same checks
locally before pushing:

- scripts/check.sh runs ruff, mypy, and pytest (mirrors the CI workflow).
- .githooks/pre-push invokes it; enable per clone with
  `git config core.hooksPath .githooks`. Bypass with `git push --no-verify`.
- Fix the pytest invocation in the CI workflow (and document it): use
  `python -m pytest` so the repo root is on sys.path, otherwise the test
  modules fail to `import tests.*`.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Dieter Schlüter 2026-07-07 10:48:57 +02:00
commit b6e99eed41
4 changed files with 69 additions and 2 deletions

View file

@ -42,4 +42,6 @@ jobs:
run: pip install -e ".[dev]" run: pip install -e ".[dev]"
- name: Run test suite - name: Run test suite
run: pytest -q # `python -m pytest` puts the repo root on sys.path so the test modules
# can `import tests.*` (the pytest console script would not).
run: python -m pytest -q

11
.githooks/pre-push Executable file
View file

@ -0,0 +1,11 @@
#!/usr/bin/env bash
#
# Pre-push gate: run the local CI checks (ruff + mypy + pytest) before allowing
# a push. Blocks the push on any failure.
#
# Enable in a fresh clone with:
# git config core.hooksPath .githooks
# Bypass a single push with:
# git push --no-verify
#
exec "$(git rev-parse --show-toplevel)/scripts/check.sh"

View file

@ -157,9 +157,22 @@ Für Details siehe [`docs/SECURITY_AND_OPERATIONS.md`](docs/SECURITY_AND_OPERATI
```bash ```bash
pip install -e ".[dev]" pip install -e ".[dev]"
pytest -q python -m pytest -q
``` ```
`python -m pytest` (statt des `pytest`-Skripts) legt das Repo-Root auf
`sys.path`, damit die Testmodule `import tests.*` auflösen.
**Lokales CI-Gate:** `scripts/check.sh` bündelt `ruff` + `mypy` + `pytest`
(spiegelt `.forgejo/workflows/ci.yml`). Als Pre-Push-Hook aktivieren — er
blockt einen Push bei Fehlern:
```bash
git config core.hooksPath .githooks # einmalig pro Clone
```
Einen einzelnen Push im Notfall umgehen: `git push --no-verify`.
Die Test-Suite deckt die Prompt-Eingabeschicht (Datei- und URL-Quellen inkl. Die Test-Suite deckt die Prompt-Eingabeschicht (Datei- und URL-Quellen inkl.
SSRF-Abwehr mit gemockter DNS-Auflösung und DNS-Pinning), die SSRF-Abwehr mit gemockter DNS-Auflösung und DNS-Pinning), die
Konfigurationsauflösung (inkl. `${ENV}`-Expansion), die CLI-Validierung, die Konfigurationsauflösung (inkl. `${ENV}`-Expansion), die CLI-Validierung, die

41
scripts/check.sh Executable file
View file

@ -0,0 +1,41 @@
#!/usr/bin/env bash
#
# Local CI gate: lint + type-check + tests. Mirrors .forgejo/workflows/ci.yml
# so the same checks run before a push even without a Forgejo Actions runner.
#
# Run manually: scripts/check.sh
# Run automatically: git config core.hooksPath .githooks (see .githooks/pre-push)
# Bypass once (emergency): git push --no-verify
#
set -uo pipefail
cd "$(git rev-parse --show-toplevel)" || exit 1
# Prefer the project venv's tools if present, else fall back to PATH.
BIN=""
if [ -x ".venv/bin/ruff" ]; then BIN=".venv/bin/"; fi
fail=0
run() {
local label=$1; shift
echo "== ${label} =="
if "$@"; then
echo " OK"
else
echo " FAILED"
fail=1
fi
}
run "ruff (lint)" "${BIN}ruff" check src/ tests/
run "mypy (types)" "${BIN}mypy"
# Use `python -m pytest` (not the pytest console script) so the repo root is on
# sys.path — the test modules import `from tests.test_docker_ops import ...`.
run "pytest (tests)" "${BIN}python" -m pytest -q
echo
if [ "$fail" -ne 0 ]; then
echo "CI gate FAILED — fix the above or push with --no-verify to bypass."
exit 1
fi
echo "CI gate passed."