Skip to content

Commit 81593dc

Browse files
Merge branch 'main' into fix/empty-linter-pattern-never-matched
2 parents c1bf8a4 + ea5a76c commit 81593dc

11 files changed

Lines changed: 142 additions & 94 deletions

File tree

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 34 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ jobs:
2121
# ---------------------------------------------------------------------------
2222
a2ml-validate:
2323
name: Validate A2ML manifests
24-
runs-on: ubuntu-latest
24+
runs-on: ubuntu-24.04
2525

2626
steps:
2727
- name: Checkout repository
@@ -65,7 +65,7 @@ jobs:
6565
# ---------------------------------------------------------------------------
6666
k9-validate:
6767
name: Validate K9 contracts
68-
runs-on: ubuntu-latest
68+
runs-on: ubuntu-24.04
6969

7070
steps:
7171
- name: Checkout repository
@@ -114,7 +114,7 @@ jobs:
114114
# ---------------------------------------------------------------------------
115115
empty-lint:
116116
name: Empty-linter (invisible characters)
117-
runs-on: ubuntu-latest
117+
runs-on: ubuntu-24.04
118118

119119
steps:
120120
- name: Checkout repository
@@ -206,7 +206,7 @@ jobs:
206206
# ---------------------------------------------------------------------------
207207
groove-check:
208208
name: Groove manifest check
209-
runs-on: ubuntu-latest
209+
runs-on: ubuntu-24.04
210210

211211
steps:
212212
- name: Checkout repository
@@ -264,7 +264,7 @@ jobs:
264264
# ---------------------------------------------------------------------------
265265
eclexiaiser-validate:
266266
name: Validate eclexiaiser manifest
267-
runs-on: ubuntu-latest
267+
runs-on: ubuntu-24.04
268268

269269
steps:
270270
- name: Checkout repository
@@ -284,28 +284,34 @@ jobs:
284284
285285
echo "has_manifest=true" >> "$GITHUB_OUTPUT"
286286
287-
# Validate TOML structure using Python 3.11+ tomllib
288-
python3 -c "
289-
import tomllib, sys
290-
with open('eclexiaiser.toml', 'rb') as f:
291-
data = tomllib.load(f)
292-
project = data.get('project', {})
293-
if not project.get('name', '').strip():
294-
print('ERROR: project.name is required', file=sys.stderr)
295-
sys.exit(1)
296-
functions = data.get('functions', [])
297-
if not functions:
298-
print('ERROR: at least one [[functions]] entry is required', file=sys.stderr)
299-
sys.exit(1)
300-
for fn in functions:
301-
if not fn.get('name', '').strip():
302-
print('ERROR: function name cannot be empty', file=sys.stderr)
303-
sys.exit(1)
304-
if not fn.get('source', '').strip():
305-
print(f'ERROR: function {fn[\"name\"]} has no source path', file=sys.stderr)
306-
sys.exit(1)
307-
print(f'Valid: {project[\"name\"]} ({len(functions)} function(s))')
308-
" || {
287+
# Validate TOML structure using pre-installed yq
288+
(
289+
PROJECT_NAME=$(yq -e '.project.name // ""' eclexiaiser.toml)
290+
if [ -z "$PROJECT_NAME" ]; then
291+
echo "ERROR: project.name is required" >&2
292+
exit 1
293+
fi
294+
295+
FUNCTIONS_LEN=$(yq -e '.functions | length' eclexiaiser.toml)
296+
if [ -z "$FUNCTIONS_LEN" ] || [ "$FUNCTIONS_LEN" -eq 0 ]; then
297+
echo "ERROR: at least one [[functions]] entry is required" >&2
298+
exit 1
299+
fi
300+
301+
for i in $(seq 0 $((FUNCTIONS_LEN - 1))); do
302+
FN_NAME=$(yq -e ".functions[$i].name // \"\"" eclexiaiser.toml)
303+
if [ -z "$FN_NAME" ]; then
304+
echo "ERROR: function name cannot be empty" >&2
305+
exit 1
306+
fi
307+
FN_SRC=$(yq -e ".functions[$i].source // \"\"" eclexiaiser.toml)
308+
if [ -z "$FN_SRC" ]; then
309+
echo "ERROR: function $FN_NAME has no source path" >&2
310+
exit 1
311+
fi
312+
done
313+
echo "Valid: $PROJECT_NAME ($FUNCTIONS_LEN function(s))"
314+
) || {
309315
echo "::error file=eclexiaiser.toml::Invalid eclexiaiser.toml — see step output for details"
310316
exit 1
311317
}
@@ -327,7 +333,7 @@ jobs:
327333
# ---------------------------------------------------------------------------
328334
dogfood-summary:
329335
name: Dogfooding compliance summary
330-
runs-on: ubuntu-latest
336+
runs-on: ubuntu-24.04
331337
needs: [a2ml-validate, k9-validate, empty-lint, groove-check, eclexiaiser-validate]
332338
if: always()
333339

‎.github/workflows/governance.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,9 @@ concurrency:
2727
cancel-in-progress: true
2828

2929
permissions:
30+
actions: read
3031
contents: read
3132

3233
jobs:
3334
governance:
34-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
35+
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3

‎.github/workflows/mirror.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,5 +11,5 @@ permissions:
1111

1212
jobs:
1313
mirror:
14-
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
14+
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3
1515
secrets: inherit

‎.github/workflows/push-email-notify.yml‎

Lines changed: 26 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,19 +3,43 @@
33
# PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled;
44
# sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by
55
# new repos from the template; placed on existing repos by the farm sweep.
6+
#
7+
# Re-landed after the 2026-07-20 notification-storm freeze (removed in
8+
# 09f94c5), now on hyperpolymath/smtp-notify-action: Node-free, the SMTP
9+
# session is Idris2-specified and machine-checked, the binary is Zig-built,
10+
# byte-reproducible, and SHA-256-pinned inside the action itself.
611
name: Push email notification
712
on:
8-
push: {}
13+
push:
14+
# Branch pushes only: tag and deletion payloads mislabel Branch:/head_commit.
15+
branches: ['**']
16+
concurrency:
17+
# Deliberately per-RUN, so no run is ever queued behind another and none is
18+
# ever cancelled. Do NOT "tidy" this into a shared group such as
19+
# ${{ github.workflow }}-${{ github.ref }}. GitHub's workflow-syntax docs:
20+
# "By default, any existing pending job or workflow in the same concurrency
21+
# group will be canceled and the new queued job or workflow will take its
22+
# place." That happens regardless of cancel-in-progress, which governs only
23+
# the RUNNING job. On this workflow it silently loses a notification email,
24+
# with no error anywhere. Every run here reports a DISTINCT commit, so there
25+
# is no redundant work for a concurrency limit to remove.
26+
# The docs also offer `queue: max` (up to 100 pending); not used, because 100
27+
# is still a cap whereas a per-run group needs none.
28+
# Verified with zizmor 1.30.0: deleting this block raises concurrency-limits;
29+
# this form silences it exactly as a shared group would.
30+
group: push-email-${{ github.run_id }}
31+
cancel-in-progress: false
932
permissions:
1033
contents: read
1134
jobs:
1235
notify:
1336
name: Email on push
1437
if: ${{ vars.PUSH_EMAIL_ENABLED == 'true' }}
1538
runs-on: ubuntu-latest
39+
timeout-minutes: 5
1640
steps:
1741
- name: Send push notification email
18-
uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned
42+
uses: hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7 # v0.2.0
1943
with:
2044
server_address: ${{ secrets.SMTP_HOST }}
2145
server_port: ${{ secrets.SMTP_PORT }}

‎.github/workflows/rust-ci.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,4 +14,4 @@ permissions:
1414

1515
jobs:
1616
rust-ci:
17-
uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
17+
uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3

‎.github/workflows/scorecard.yml‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,11 +6,14 @@ on:
66
schedule:
77
- cron: '23 4 * * 1'
88

9-
permissions: read-all
9+
permissions:
10+
contents: read
11+
security-events: write
12+
id-token: write
1013

1114
jobs:
1215
analysis:
13-
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
16+
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3
1417
permissions:
1518
contents: read
1619
security-events: write

‎.github/workflows/secret-scanner.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,5 +17,5 @@ jobs:
1717
scan:
1818
permissions:
1919
contents: read
20-
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
20+
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@092dedada188f56c5915f74a5fd40aac093742c3
2121
secrets: inherit

‎.mise.toml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
[tools]
2+
rust = "stable"
3+
just = "1.46.0"

‎.tool-versions‎

Lines changed: 0 additions & 2 deletions
This file was deleted.

‎Lust.a2ml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
// Lust.a2ml for cloudguard-cli
2+
// SPDX-License-Identifier: MPL-2.0
3+
// Generated: 2026-04-08T19:51:51+01:00
4+
5+
Lust {
6+
name: "cloudguard-cli"
7+
version: "1.0.0"
8+
description: "Lust contractile for cloudguard-cli"
9+
10+
// Basic Lust configuration
11+
enabled: true
12+
13+
// Repository-specific settings will be added here
14+
}

0 commit comments

Comments
 (0)