ci: add local pre-push gate (ruff + mypy + pytest)
Forgejo Actions is not enabled on the instance, so run the same checks locally before pushing: - scripts/check.sh runs ruff, mypy, and pytest (mirrors the CI workflow). - .githooks/pre-push invokes it; enable per clone with `git config core.hooksPath .githooks`. Bypass with `git push --no-verify`. - Fix the pytest invocation in the CI workflow (and document it): use `python -m pytest` so the repo root is on sys.path, otherwise the test modules fail to `import tests.*`. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
49a7756a01
commit
b6e99eed41
4 changed files with 69 additions and 2 deletions
|
|
@ -42,4 +42,6 @@ jobs:
|
|||
run: pip install -e ".[dev]"
|
||||
|
||||
- name: Run test suite
|
||||
run: pytest -q
|
||||
# `python -m pytest` puts the repo root on sys.path so the test modules
|
||||
# can `import tests.*` (the pytest console script would not).
|
||||
run: python -m pytest -q
|
||||
|
|
|
|||
11
.githooks/pre-push
Executable file
11
.githooks/pre-push
Executable file
|
|
@ -0,0 +1,11 @@
|
|||
#!/usr/bin/env bash
|
||||
#
|
||||
# Pre-push gate: run the local CI checks (ruff + mypy + pytest) before allowing
|
||||
# a push. Blocks the push on any failure.
|
||||
#
|
||||
# Enable in a fresh clone with:
|
||||
# git config core.hooksPath .githooks
|
||||
# Bypass a single push with:
|
||||
# git push --no-verify
|
||||
#
|
||||
exec "$(git rev-parse --show-toplevel)/scripts/check.sh"
|
||||
15
README.md
15
README.md
|
|
@ -157,9 +157,22 @@ Für Details siehe [`docs/SECURITY_AND_OPERATIONS.md`](docs/SECURITY_AND_OPERATI
|
|||
|
||||
```bash
|
||||
pip install -e ".[dev]"
|
||||
pytest -q
|
||||
python -m pytest -q
|
||||
```
|
||||
|
||||
`python -m pytest` (statt des `pytest`-Skripts) legt das Repo-Root auf
|
||||
`sys.path`, damit die Testmodule `import tests.*` auflösen.
|
||||
|
||||
**Lokales CI-Gate:** `scripts/check.sh` bündelt `ruff` + `mypy` + `pytest`
|
||||
(spiegelt `.forgejo/workflows/ci.yml`). Als Pre-Push-Hook aktivieren — er
|
||||
blockt einen Push bei Fehlern:
|
||||
|
||||
```bash
|
||||
git config core.hooksPath .githooks # einmalig pro Clone
|
||||
```
|
||||
|
||||
Einen einzelnen Push im Notfall umgehen: `git push --no-verify`.
|
||||
|
||||
Die Test-Suite deckt die Prompt-Eingabeschicht (Datei- und URL-Quellen inkl.
|
||||
SSRF-Abwehr mit gemockter DNS-Auflösung und DNS-Pinning), die
|
||||
Konfigurationsauflösung (inkl. `${ENV}`-Expansion), die CLI-Validierung, die
|
||||
|
|
|
|||
41
scripts/check.sh
Executable file
41
scripts/check.sh
Executable file
|
|
@ -0,0 +1,41 @@
|
|||
#!/usr/bin/env bash
|
||||
#
|
||||
# Local CI gate: lint + type-check + tests. Mirrors .forgejo/workflows/ci.yml
|
||||
# so the same checks run before a push even without a Forgejo Actions runner.
|
||||
#
|
||||
# Run manually: scripts/check.sh
|
||||
# Run automatically: git config core.hooksPath .githooks (see .githooks/pre-push)
|
||||
# Bypass once (emergency): git push --no-verify
|
||||
#
|
||||
set -uo pipefail
|
||||
|
||||
cd "$(git rev-parse --show-toplevel)" || exit 1
|
||||
|
||||
# Prefer the project venv's tools if present, else fall back to PATH.
|
||||
BIN=""
|
||||
if [ -x ".venv/bin/ruff" ]; then BIN=".venv/bin/"; fi
|
||||
|
||||
fail=0
|
||||
run() {
|
||||
local label=$1; shift
|
||||
echo "== ${label} =="
|
||||
if "$@"; then
|
||||
echo " OK"
|
||||
else
|
||||
echo " FAILED"
|
||||
fail=1
|
||||
fi
|
||||
}
|
||||
|
||||
run "ruff (lint)" "${BIN}ruff" check src/ tests/
|
||||
run "mypy (types)" "${BIN}mypy"
|
||||
# Use `python -m pytest` (not the pytest console script) so the repo root is on
|
||||
# sys.path — the test modules import `from tests.test_docker_ops import ...`.
|
||||
run "pytest (tests)" "${BIN}python" -m pytest -q
|
||||
|
||||
echo
|
||||
if [ "$fail" -ne 0 ]; then
|
||||
echo "CI gate FAILED — fix the above or push with --no-verify to bypass."
|
||||
exit 1
|
||||
fi
|
||||
echo "CI gate passed."
|
||||
Loading…
Add table
Add a link
Reference in a new issue