diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index febd5bc..8161ec2 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,32 +1,16 @@ -# // Copyright (c) Jonathan D.A. Jewell -# SPDX-License-Identifier: MPL-2.0 -# governance.yml — single wrapper calling the shared estate governance bundle -# in hyperpolymath/standards instead of carrying per-repo copies. -# -# Replaces the per-repo governance scaffolding removed in the same commit: -# quality.yml, guix-nix-policy.yml, npm-bun-blocker.yml, ts-blocker.yml, -# security-policy.yml, rsr-antipattern.yml, wellknown-enforcement.yml, -# workflow-linter.yml -# -# Load-bearing build/security workflows stay standalone in the repo -# (rust-ci, codeql, dependabot, release, scan/mirror/pages plumbing). - +# SPDX-License-Identifier: PMPL-1.0-or-later name: Governance + on: push: branches: [main, master] pull_request: + branches: [main, master] workflow_dispatch: -# Estate guardrail: cancel superseded runs so re-pushes / rebased PR -# updates do not pile up queued runs against the shared account-wide -# Actions concurrency pool. Applied only to read-only check workflows -# (no publish/mutation), so cancelling a superseded run is always safe. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true + permissions: contents: read + jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613 - timeout-minutes: 10 + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@5a93d9d57cc04de4002d6d0ecd336fc7a8698910 diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index f3a1bd9..e715848 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,317 +1,19 @@ -# // Copyright (c) Jonathan D.A. Jewell -# SPDX-License-Identifier: MPL-2.0 -# Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. -# See standards#191 for the reusable's purpose and design. - +# SPDX-License-Identifier: PMPL-1.0-or-later name: Hypatia Security Scan + on: push: branches: [main, master, develop] pull_request: branches: [main, master] schedule: - - cron: '0 0 * * 0' # Weekly on Sunday + - cron: '0 0 * * 0' workflow_dispatch: -# Estate guardrail: cancel superseded runs so re-pushes don't pile up. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true permissions: contents: read - security-events: write - pull-requests: write + security-events: read + jobs: scan: - name: Hypatia Neurosymbolic Analysis - runs-on: ubuntu-latest - timeout-minutes: 15 - steps: - - name: Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - with: - fetch-depth: 0 # Full history for better pattern analysis - - name: Setup Elixir for Hypatia scanner - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.18.2 - with: - elixir-version: '1.18' - otp-version: '27' - - name: Clone Hypatia - run: | - if [ ! -d "$HOME/hypatia" ]; then - git clone https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia" - fi - - name: Build Hypatia scanner (if needed) - run: | - cd "$HOME/hypatia" - if [ ! -f hypatia ]; then - echo "Building hypatia scanner..." - mix deps.get - mix escript.build - fi - - name: Run Hypatia scan - id: scan - env: - # Pass the built-in Actions token through to Hypatia so the - # DependabotAlerts rule can query this repo's own alerts. - # For cross-repo scanning (fleet-coordinator scan-supervised), - # a PAT with `security_events` scope is required instead. - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - echo "Scanning repository: ${{ github.repository }}" - - # Run scanner (exits non-zero when findings exist — suppress to continue) - HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json || true - - # Count findings - FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0) - echo "findings_count=$FINDING_COUNT" >> $GITHUB_OUTPUT - - # Extract severity counts - CRITICAL=$(jq '[.[] | select(.severity == "critical")] | length' hypatia-findings.json) - HIGH=$(jq '[.[] | select(.severity == "high")] | length' hypatia-findings.json) - MEDIUM=$(jq '[.[] | select(.severity == "medium")] | length' hypatia-findings.json) - - echo "critical=$CRITICAL" >> $GITHUB_OUTPUT - echo "high=$HIGH" >> $GITHUB_OUTPUT - echo "medium=$MEDIUM" >> $GITHUB_OUTPUT - - echo "## Hypatia Scan Results" >> $GITHUB_STEP_SUMMARY - echo "- Total findings: $FINDING_COUNT" >> $GITHUB_STEP_SUMMARY - echo "- Critical: $CRITICAL" >> $GITHUB_STEP_SUMMARY - echo "- High: $HIGH" >> $GITHUB_STEP_SUMMARY - echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY - - name: Upload findings artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: hypatia-findings - path: hypatia-findings.json - retention-days: 90 - - name: Convert Hypatia findings to SARIF - # Always runs (no findings_count guard): an EMPTY SARIF run is - # valid and intentional — uploading it clears stale Hypatia - # alerts from the code-scanning page when a repo goes clean. - # The converter is dependency-free Node (Node ships on - # ubuntu-latest; no npm install — estate npm ban respected) and - # is hardened against the heterogeneous Hypatia JSON schema: - # most findings are {rule_module,severity,type,file,reason, - # action}; only some carry an integer `line`; `file` may be - # empty or absolute. See lib/hypatia/cli.ex (collect_findings). - run: | - cat > "$RUNNER_TEMP/hypatia-sarif.cjs" <<'CJS' - const fs = require('fs'); - const path = require('path'); - const crypto = require('crypto'); - - const ws = process.env.GITHUB_WORKSPACE || process.cwd(); - - let findings = []; - try { - const parsed = JSON.parse(fs.readFileSync('hypatia-findings.json', 'utf8')); - if (Array.isArray(parsed)) findings = parsed; - } catch (_) { - // Scanner unavailable / empty / malformed -> empty SARIF. - // Intentionally clears stale alerts rather than erroring. - findings = []; - } - - // Mirrors Hypatia's own "github" annotation mapping - // (lib/hypatia/cli.ex output/2): critical|high -> error, - // medium -> warning, everything else -> note. - const levelFor = (sev) => { - switch (String(sev || '').toLowerCase()) { - case 'critical': - case 'high': return 'error'; - case 'medium': return 'warning'; - default: return 'note'; - } - }; - - // SARIF artifactLocation.uri must be a repo-relative POSIX - // path. Hypatia may emit absolute paths (scanned under - // $GITHUB_WORKSPACE) or "" / "." for repo-level findings. - const relUri = (file) => { - if (!file) return '.'; - let f = String(file); - if (path.isAbsolute(f)) { - const rel = path.relative(ws, f); - f = (rel && !rel.startsWith('..')) ? rel : path.basename(f); - } - f = f.replace(/\\/g, '/').replace(/^\.\//, ''); - return f || '.'; - }; - - const rules = new Map(); - const results = findings.map((f) => { - const mod = String(f.rule_module || 'hypatia'); - const type = String(f.type || 'finding'); - const ruleId = `hypatia/${mod}/${type}`; - const level = levelFor(f.severity); - if (!rules.has(ruleId)) { - rules.set(ruleId, { - id: ruleId, - name: `${mod}.${type}`, - shortDescription: { text: `Hypatia ${mod}: ${type}` }, - defaultConfiguration: { level } - }); - } - const uri = relUri(f.file); - const msg = String(f.reason || f.type || 'Hypatia finding'); - const startLine = - Number.isInteger(f.line) && f.line > 0 ? f.line : 1; - // Stable cross-run fingerprint for dedupe (no line, so a - // moved finding in the same file/rule stays one alert). - const fp = crypto - .createHash('sha256') - .update([ruleId, uri, type, msg].join('|')) - .digest('hex'); - return { - ruleId, - level, - message: { text: msg }, - locations: [ - { - physicalLocation: { - artifactLocation: { uri }, - region: { startLine } - } - } - ], - partialFingerprints: { 'hypatiaFindingHash/v1': fp } - }; - }); - - const sarif = { - $schema: 'https://json.schemastore.org/sarif-2.1.0.json', - version: '2.1.0', - runs: [ - { - tool: { - driver: { - name: 'Hypatia', - informationUri: 'https://github.com/hyperpolymath/hypatia', - rules: Array.from(rules.values()) - } - }, - results - } - ] - }; - - fs.writeFileSync('hypatia.sarif', JSON.stringify(sarif, null, 2)); - console.log(`hypatia.sarif written: ${results.length} result(s).`); - CJS - node "$RUNNER_TEMP/hypatia-sarif.cjs" - - name: Upload SARIF to GitHub code scanning - # Fork PRs get a read-only GITHUB_TOKEN, so security-events:write - # is unavailable and upload-sarif cannot publish — skip there - # rather than hard-fail (the push/schedule run on the default - # branch is the authoritative upload). Same-repo PRs and pushes - # do upload. This step is deliberately NOT continue-on-error: - # if the security-surface integration breaks we want a loud red, - # not a silently-ungated scanner (the exact failure mode #35 - # exists to end). The empty-SARIF "clear stale alerts" path is - # handled in the converter above and does not error here. - if: >- - always() && (github.event_name != 'pull_request' || - - - - - - github.event.pull_request.head.repo.fork != true) - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v3.28.1 - with: - sarif_file: hypatia.sarif - # Distinct category so Hypatia results coexist with CodeQL's - # (codeql.yml) instead of overwriting them on the same surface. - category: hypatia - - name: Submit findings to gitbot-fleet (Phase 2) - if: steps.scan.outputs.findings_count > 0 - # Phase 2 is the collaborative LEARNING side-channel ("bots share - # findings via gitbot-fleet"), not the security gate. The gate is - # the baseline-aware "Check for critical or high-severity issues" - # step below. A fleet-side regression (e.g. the submit script being - # moved/removed) must NEVER hard-fail every consuming repo's scan. - # Same reasoning as the "Comment on PR with findings" step. - # See hyperpolymath/hypatia#213 (gate decoupling) and the exit-127 - # estate-wide breakage when gitbot-fleet/scripts/submit-finding.sh - # no longer existed on the default branch. - continue-on-error: true - env: - # All GitHub context values surface as env vars so the run - # block never interpolates `${{ … }}` inline (closes the - # workflow_audit/unsafe_curl_payload + actions_expression_injection - # findings). - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - FLEET_PUSH_TOKEN: ${{ secrets.HYPATIA_DISPATCH_PAT }} - FLEET_DISPATCH_TOKEN: ${{ secrets.HYPATIA_DISPATCH_PAT }} - GITHUB_REPOSITORY: ${{ github.repository }} - GITHUB_SHA: ${{ github.sha }} - FINDINGS_COUNT: ${{ steps.scan.outputs.findings_count }} - run: "echo \"\U0001F4E4 Submitting $FINDINGS_COUNT findings to gitbot-fleet...\"\n\n# Clone gitbot-fleet to temp directory. A clone failure (network,\n# repo gone) is non-fatal: learning submission is best-effort.\nFLEET_DIR=\"/tmp/gitbot-fleet-$$\"\nif ! git clone --depth 1 https://github.com/hyperpolymath/gitbot-fleet.git \"$FLEET_DIR\"; then\n echo \"::warning::Could not clone gitbot-fleet — skipping Phase 2 learning submission (non-fatal).\"\n exit 0\nfi\n\n# The submission script's location in gitbot-fleet has drifted\n# before (it was absent from the default branch, which exit-127'd\n# every consuming repo's scan). Probe known locations rather than\n# hard-coding one path, and skip gracefully if none is present.\nSUBMIT_SCRIPT=\"\"\nfor cand in \\\n \"$FLEET_DIR/scripts/submit-finding.sh\" \\\n \"$FLEET_DIR/scripts/submit_finding.sh\" \\\n \"$FLEET_DIR/bin/submit-finding.sh\" \\\n \"$FLEET_DIR/submit-finding.sh\"; do\n if [ -f \"$cand\" ]; then\n SUBMIT_SCRIPT=\"$cand\"\n break\n fi\ndone\n\nif [ -z \"$SUBMIT_SCRIPT\" ]; then\n echo \"::warning::gitbot-fleet submit-finding script not found at any known path — skipping Phase 2 learning submission (non-fatal). Findings are still uploaded as an artifact and gated below.\"\n rm -rf \"$FLEET_DIR\"\n exit 0\nfi\n\n# Run submission script. Pass the findings path as ABSOLUTE —\n# the script cd's into its own working dir before reading the\n# file, so a relative path would resolve to the wrong place.\n# A submission-script failure is logged but non-fatal.\nif bash \"$SUBMIT_SCRIPT\" \"$GITHUB_WORKSPACE/hypatia-findings.json\"; then\n echo \"✅ Finding submission complete\"\nelse\n echo \"::warning::gitbot-fleet submission script exited non-zero — Phase 2 learning submission skipped (non-fatal).\"\nfi\n\n# Cleanup\nrm -rf \"$FLEET_DIR\"\n" - - name: Check for critical issues - if: steps.scan.outputs.critical > 0 - # GATING POLICY (explicit, by design — not an oversight): - # Hypatia is ADVISORY here. Critical findings are surfaced - # (step annotation + SARIF alert on the code-scanning page + - # PR comment) but do NOT fail this check. Enforcement is - # delegated to the code-scanning surface: tighten by adding a - # branch-protection "required" status on the `hypatia` SARIF - # category, not by reintroducing an `exit 1` here. This keeps - # the gate decision in one auditable place (hypatia#213 gate - # decoupling) and lets a repo opt into fail-on-critical without - # editing this canonical workflow. To change the policy, change - # branch protection — deliberately no commented-out `exit 1`. - run: | - echo "::warning::Hypatia found critical security issue(s) — advisory." - echo "See the Security → Code scanning page (category: hypatia)" - echo "and the hypatia-findings.json artifact for details." - - name: Generate scan report - run: | - cat << EOF > hypatia-report.md - # Hypatia Security Scan Report - - **Repository:** ${{ github.repository }} - **Scan Date:** $(date -u +"%Y-%m-%d %H:%M:%S UTC") - **Commit:** ${{ github.sha }} - - ## Summary - - | Severity | Count | - |----------|-------| - | Critical | ${{ steps.scan.outputs.critical }} | - | High | ${{ steps.scan.outputs.high }} | - | Medium | ${{ steps.scan.outputs.medium }} | - | **Total**| ${{ steps.scan.outputs.findings_count }} | - - ## Next Steps - - 1. Triage findings on the **Security → Code scanning** page - (SARIF category \`hypatia\`) — dismiss/track them there like - CodeQL alerts. - 2. The full finding set is also attached as the - \`hypatia-findings.json\` build artifact for offline review. - 3. Findings are **advisory** today (surfaced, not gated); the - gating policy is documented in the workflow's "Check for - critical issues" step. - - ## Learning - - These findings feed Hypatia's learning engine to improve future rules. - - --- - *Powered by [Hypatia](https://github.com/hyperpolymath/hypatia) - Neurosymbolic CI/CD Intelligence* - EOF - - cat hypatia-report.md >> $GITHUB_STEP_SUMMARY - - name: Comment on PR with findings - if: github.event_name == 'pull_request' && steps.scan.outputs.findings_count > 0 - # Advisory only — posting findings as a PR comment must never gate - # the scan (hypatia#213 gate decoupling). Belt-and-braces alongside - # the pull-requests: write permission above: a token/API hiccup or - # a fork PR (read-only token) skips the comment, not the check. - continue-on-error: true - uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v7 - with: - script: "const fs = require('fs');\nconst findings = JSON.parse(fs.readFileSync('hypatia-findings.json', 'utf8'));\n\nconst critical = findings.filter(f => f.severity === 'critical').length;\nconst high = findings.filter(f => f.severity === 'high').length;\n\nlet comment = `## \U0001F50D Hypatia Security Scan\\n\\n`;\ncomment += `**Findings:** ${findings.length} issues detected\\n\\n`;\ncomment += `| Severity | Count |\\n|----------|-------|\\n`;\ncomment += `| \U0001F534 Critical | ${critical} |\\n`;\ncomment += `| \U0001F7E0 High | ${high} |\\n`;\ncomment += `| \U0001F7E1 Medium | ${findings.length - critical - high} |\\n\\n`;\n\nif (critical > 0) {\n comment += `⚠️ **Action Required:** Critical security issues found!\\n\\n`;\n}\n\ncomment += `
View findings\\n\\n`;\ncomment += `\\`\\`\\`json\\n${JSON.stringify(findings.slice(0, 10), null, 2)}\\n\\`\\`\\`\\n`;\ncomment += `
\\n\\n`;\ncomment += `*Powered by Hypatia Neurosymbolic CI/CD Intelligence*`;\n\ngithub.rest.issues.createComment({\n owner: context.repo.owner,\n repo: context.repo.repo,\n issue_number: context.issue.number,\n body: comment\n});" + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@5a93d9d57cc04de4002d6d0ecd336fc7a8698910 diff --git a/.github/workflows/scorecard-enforcer.yml b/.github/workflows/scorecard-enforcer.yml deleted file mode 100644 index e06550c..0000000 --- a/.github/workflows/scorecard-enforcer.yml +++ /dev/null @@ -1,78 +0,0 @@ -# // Copyright (c) Jonathan D.A. Jewell -# SPDX-License-Identifier: MPL-2.0 -# Prevention workflow - runs OpenSSF Scorecard and fails on low scores -name: OpenSSF Scorecard Enforcer -on: - push: - branches: [main] - schedule: - - cron: '0 6 * * 1' # Weekly on Monday - workflow_dispatch: -# Estate guardrail: cancel superseded runs so re-pushes / rebased PR -# updates do not pile up queued runs against the shared account-wide -# Actions concurrency pool. Applied only to read-only check workflows -# (no publish/mutation), so cancelling a superseded run is always safe. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true -permissions: - contents: read -jobs: - scorecard: - runs-on: ubuntu-latest - timeout-minutes: 15 - permissions: - security-events: write - id-token: write # For OIDC - steps: - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - with: - persist-credentials: false - - name: Run Scorecard - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 - with: - results_file: results.sarif - results_format: sarif - # publish_results intentionally omitted: the dedicated - # scorecard.yml workflow owns OSSF publishing. A publishing - # scorecard-action may not share a job/file with `run:` steps - # (OSSF "uses-only" constraint — hypatia WF014), and this - # enforcer needs a local `run:` threshold gate below. - - name: Upload SARIF - uses: github/codeql-action/upload-sarif@87557b9c84dde89fdd9b10e88954ac2f4248e463 # v4 - with: - sarif_file: results.sarif - - name: Check minimum score - run: | - # Parse score from results - SCORE=$(jq -r '.runs[0].tool.driver.properties.score // 0' results.sarif 2>/dev/null || echo "0") - - echo "OpenSSF Scorecard Score: $SCORE" - - # Minimum acceptable score (0-10 scale) - MIN_SCORE=5 - - if [ "$(echo "$SCORE < $MIN_SCORE" | bc -l)" = "1" ]; then - echo "::error::Scorecard score $SCORE is below minimum $MIN_SCORE" - exit 1 - fi - # Check specific high-priority items - check-critical: - runs-on: ubuntu-latest - timeout-minutes: 15 - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Check SECURITY.md exists - run: | - if [ ! -f "SECURITY.md" ]; then - echo "::error::SECURITY.md is required" - exit 1 - fi - - name: Check for pinned dependencies - run: | - # Check workflows for unpinned actions - unpinned=$(grep -r "uses:.*@v[0-9]" .github/workflows/*.yml 2>/dev/null | grep -v "#" | head -5 || true) - if [ -n "$unpinned" ]; then - echo "::warning::Found unpinned actions:" - echo "$unpinned" - fi diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index a28b67c..47acbb5 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,38 +1,16 @@ -# // Copyright (c) Jonathan D.A. Jewell -# SPDX-License-Identifier: MPL-2.0 -name: Scorecards supply-chain security +# SPDX-License-Identifier: PMPL-1.0-or-later +name: OSSF Scorecard on: - branch_protection_rule: + push: + branches: [main, master] schedule: - cron: '0 4 * * *' workflow_dispatch: -# Estate guardrail: cancel superseded runs so re-pushes / rebased PR -# updates do not pile up queued runs against the shared account-wide -# Actions concurrency pool. Applied only to read-only check workflows -# (no publish/mutation), so cancelling a superseded run is always safe. -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true + permissions: contents: read + jobs: - analysis: - runs-on: ubuntu-latest - timeout-minutes: 15 - permissions: - security-events: write - id-token: write - steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - with: - persist-credentials: false - - name: Run Scorecard - uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.3.1 - with: - results_file: results.sarif - results_format: sarif - - name: Upload results - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v3.31.8 - with: - sarif_file: results.sarif + scorecard: + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@5a93d9d57cc04de4002d6d0ecd336fc7a8698910 diff --git a/deno.json b/deno.json index 504b5b2..fb5c684 100644 --- a/deno.json +++ b/deno.json @@ -4,7 +4,7 @@ "exports": "./EmptyLinter.deno.js", "tasks": { "build": "affinescript compile --deno-esm EmptyLinter.affine -o EmptyLinter.deno.js && affinescript compile --deno-esm src/cli/Main.affine -o src/cli/Main.deno.js", - "build-all": "for f in stdlib/SafeHex.affine stdlib/SafeWhitespace.affine stdlib/SafePath.affine stdlib/SafeString.affine src/core/ByteDetector.affine src/core/TextTransform.affine src/core/PathHandler.affine EmptyLinter.affine src/cli/Main.affine; do affinescript compile --deno-esm $f -o ${f%.affine}.deno.js; done", + "build-all": "bash scripts/build-all.sh", "clean": "find . -name '*.deno.js' ! -path './stdlib/*' -delete", "dev": "while true; do affinescript compile --deno-esm EmptyLinter.affine -o EmptyLinter.deno.js 2>&1; sleep 2; done", "test": "deno test --allow-read --allow-write tests/", diff --git a/deno.lock b/deno.lock index e69de29..b6ea69d 100644 --- a/deno.lock +++ b/deno.lock @@ -0,0 +1,23 @@ +{ + "version": "5", + "specifiers": { + "jsr:@std/assert@*": "1.0.19", + "jsr:@std/internal@^1.0.12": "1.0.14" + }, + "jsr": { + "@std/assert@1.0.19": { + "integrity": "eaada96ee120cb980bc47e040f82814d786fe8162ecc53c91d8df60b8755991e", + "dependencies": [ + "jsr:@std/internal" + ] + }, + "@std/internal@1.0.14": { + "integrity": "291516b3d4c35024d6ffbc0a9df5bf4c64116e05b50012cf846710152d2ffdf7" + } + }, + "workspace": { + "dependencies": [ + "jsr:@std/assert@1" + ] + } +} diff --git a/scripts/build-all.sh b/scripts/build-all.sh new file mode 100755 index 0000000..0f77587 --- /dev/null +++ b/scripts/build-all.sh @@ -0,0 +1,36 @@ +#!/usr/bin/env bash +# SPDX-License-Identifier: MPL-2.0 +# SPDX-FileCopyrightText: 2026 hyperpolymath +set -euo pipefail + +SOURCES=( + stdlib/SafeHex.affine + stdlib/SafeWhitespace.affine + stdlib/SafePath.affine + stdlib/SafeString.affine + src/core/ByteDetector.affine + src/core/TextTransform.affine + src/core/PathHandler.affine + EmptyLinter.affine + src/cli/Main.affine +) + +for f in "${SOURCES[@]}"; do + affinescript compile --deno-esm "$f" -o "${f%.affine}.deno.js" +done + +# Workaround: AffineScript alpha compiler (issue #122) does not fully inline +# cross-module dependencies into TextTransform.deno.js. Inject missing symbols +# after compilation: LF/CRLF/CR (zero-arg enum constructors), is_invisible +# (private helper from SafeWhitespace), concat (string stdlib fn). +TARGET="src/core/TextTransform.deno.js" +MARKER="// ---- end runtime ----" +PATCH='const LF={tag:"LF"};const CRLF={tag:"CRLF"};const CR={tag:"CR"};\nfunction is_invisible(c){return(c===0||c===160||c===8203||c===65279||c===173||c===8206||c===8207||c===8204||c===8205||c===8288);}\nfunction concat(a,b){return __as_concat(a,b);}' +if [ -f "$TARGET" ] && ! grep -qF 'const LF={tag:"LF"}' "$TARGET"; then + awk -v marker="$MARKER" -v patch="$PATCH" ' + { print } + $0 == marker { printf "%s\n", patch } + ' "$TARGET" > "$TARGET.tmp" && mv "$TARGET.tmp" "$TARGET" +fi + +echo "build-all complete" diff --git a/src/core/ByteDetector.affine b/src/core/ByteDetector.affine index 50bc757..0d229c2 100644 --- a/src/core/ByteDetector.affine +++ b/src/core/ByteDetector.affine @@ -52,7 +52,13 @@ pub fn get_artifact_def(byte_val: Int) -> Option { } pub fn byte_to_hex(v: Int) -> String { - encode_byte(v & 255) + if v <= 255 { + encode_byte(v) + } else if v <= 65535 { + encode_byte((v >> 8) & 255) ++ encode_byte(v & 255) + } else { + encode_byte((v >> 16) & 255) ++ encode_byte((v >> 8) & 255) ++ encode_byte(v & 255) + } } pub fn scan(content: String) -> [Artifact] { diff --git a/src/core/TextTransform.affine b/src/core/TextTransform.affine index 734a50d..e279336 100644 --- a/src/core/TextTransform.affine +++ b/src/core/TextTransform.affine @@ -52,9 +52,6 @@ pub fn transform(content: String, options: TransformOptions) -> String { if options.remove_invisibles_opt { s = remove_invisibles(s); } - if options.normalize_line_endings_opt { - s = normalize_line_endings(s, options.target_line_ending); - } if options.collapse_spaces_opt { s = collapse_spaces(s); } @@ -65,6 +62,9 @@ pub fn transform(content: String, options: TransformOptions) -> String { if options.trim_document { s = trim(s); } + if options.normalize_line_endings_opt { + s = normalize_line_endings(s, options.target_line_ending); + } if options.ensure_final_newline_opt { s = ensure_final_newline(s); } diff --git a/tests/ByteDetector_test.js b/tests/ByteDetector_test.js new file mode 100644 index 0000000..c88c0dc Binary files /dev/null and b/tests/ByteDetector_test.js differ diff --git a/tests/PathHandler_test.js b/tests/PathHandler_test.js new file mode 100644 index 0000000..6ad6e63 --- /dev/null +++ b/tests/PathHandler_test.js @@ -0,0 +1,100 @@ +// SPDX-License-Identifier: MPL-2.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell +import { assertEquals } from "jsr:@std/assert"; +import { + validate, unwrap_path, path_join, sanitize, + is_within, get_parent, filename, has_extension, + is_excluded, from_trusted, + TraversalDetected, +} from "../src/core/PathHandler.deno.js"; + +Deno.test("PathHandler: validate accepts relative paths", () => { + const p = validate("src/main.affine"); + assertEquals(p.tag, "Some"); + assertEquals(unwrap_path(p.value), "src/main.affine"); +}); + +Deno.test("PathHandler: validate rejects absolute paths", () => { + assertEquals(validate("/etc/passwd").tag, "None"); +}); + +Deno.test("PathHandler: validate rejects path traversal", () => { + assertEquals(validate("../../etc/passwd").tag, "None"); +}); + +Deno.test("PathHandler: validate rejects embedded traversal", () => { + assertEquals(validate("src/../../../etc").tag, "None"); +}); + +Deno.test("PathHandler: sanitize removes dangerous characters", () => { + const clean = sanitize("file.txt"); + assertEquals(clean.includes("<"), false); + assertEquals(clean.includes(">"), false); +}); + +Deno.test("PathHandler: sanitize replaces slashes", () => { + const clean = sanitize("path/to/file"); + assertEquals(clean.includes("/"), false); +}); + +Deno.test("PathHandler: path_join creates valid joined path", () => { + const base = from_trusted("docs"); + const result = path_join(base, ["notes", "file.txt"]); + assertEquals(result.tag, "Ok"); + assertEquals(unwrap_path(result.value), "docs/notes/file.txt"); +}); + +Deno.test("PathHandler: path_join rejects traversal in components", () => { + const base = from_trusted("home"); + const result = path_join(base, ["..", "..", "etc"]); + assertEquals(result.tag, "Err"); + assertEquals(result.error.tag, "TraversalDetected"); +}); + +Deno.test("PathHandler: filename extracts basename", () => { + const p = from_trusted("docs/reports/file.pdf"); + assertEquals(filename(p), "file.pdf"); +}); + +Deno.test("PathHandler: filename handles no directory", () => { + assertEquals(filename(from_trusted("file.txt")), "file.txt"); +}); + +Deno.test("PathHandler: has_extension checks extension", () => { + const p = from_trusted("src/main.affine"); + assertEquals(has_extension(p, ".affine"), true); + assertEquals(has_extension(p, ".js"), false); +}); + +Deno.test("PathHandler: get_parent extracts directory", () => { + const p = from_trusted("home/user/docs/file.txt"); + const parent = get_parent(p); + assertEquals(parent.tag, "Some"); + assertEquals(unwrap_path(parent.value), "home/user/docs"); +}); + +Deno.test("PathHandler: get_parent returns None for no directory", () => { + assertEquals(get_parent(from_trusted("file.txt")).tag, "None"); +}); + +Deno.test("PathHandler: is_within checks path containment", () => { + const p = from_trusted("home/user/docs"); + const base = from_trusted("home/user"); + assertEquals(is_within(p, base), true); +}); + +Deno.test("PathHandler: is_within rejects unrelated paths", () => { + const p = from_trusted("etc/passwd"); + const base = from_trusted("home/user"); + assertEquals(is_within(p, base), false); +}); + +Deno.test("PathHandler: is_excluded matches excluded dirs", () => { + const p = from_trusted("project/node_modules/pkg/index.js"); + assertEquals(is_excluded(p, ["node_modules", ".git"]), true); +}); + +Deno.test("PathHandler: is_excluded allows non-excluded paths", () => { + const p = from_trusted("project/src/main.affine"); + assertEquals(is_excluded(p, ["node_modules", ".git"]), false); +}); diff --git a/tests/SafeWhitespace_test.js b/tests/SafeWhitespace_test.js new file mode 100644 index 0000000..a818528 --- /dev/null +++ b/tests/SafeWhitespace_test.js @@ -0,0 +1,77 @@ +// SPDX-License-Identifier: MPL-2.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell +import { assertEquals } from "jsr:@std/assert"; +import { + LF, CRLF, CR, + remove_invisibles, normalize_line_endings, + collapse_spaces, collapse_blank_lines, + trim_start, trim_end, ensure_final_newline, + detect_invisibles, +} from "../stdlib/SafeWhitespace.deno.js"; + +Deno.test("SafeWhitespace: trim_start removes leading whitespace", () => { + assertEquals(trim_start(" hello"), "hello"); + assertEquals(trim_start("\t\nhello"), "hello"); + assertEquals(trim_start("hello"), "hello"); +}); + +Deno.test("SafeWhitespace: trim_end removes trailing whitespace", () => { + assertEquals(trim_end("hello "), "hello"); + assertEquals(trim_end("hello\t\n"), "hello"); + assertEquals(trim_end("hello"), "hello"); +}); + +Deno.test("SafeWhitespace: collapse_spaces reduces multiple spaces", () => { + assertEquals(collapse_spaces("hello world"), "hello world"); + assertEquals(collapse_spaces("a b c"), "a b c"); +}); + +Deno.test("SafeWhitespace: collapse_spaces preserves single spaces", () => { + assertEquals(collapse_spaces("hello world"), "hello world"); +}); + +Deno.test("SafeWhitespace: collapse_blank_lines reduces excess blank lines", () => { + const result = collapse_blank_lines("para1\n\n\n\npara2", 1); + assertEquals(result.includes("\n\n\n"), false); +}); + +Deno.test("SafeWhitespace: normalize_line_endings converts CRLF to LF", () => { + const result = normalize_line_endings("line1\r\nline2", LF); + assertEquals(result.includes("\r"), false); +}); + +Deno.test("SafeWhitespace: normalize_line_endings converts LF to CRLF", () => { + const result = normalize_line_endings("line1\nline2", CRLF); + assertEquals(result.includes("\r\n"), true); +}); + +Deno.test("SafeWhitespace: ensure_final_newline adds newline when missing", () => { + assertEquals(ensure_final_newline("hello").endsWith("\n"), true); +}); + +Deno.test("SafeWhitespace: ensure_final_newline idempotent when present", () => { + const result = ensure_final_newline("hello\n"); + assertEquals(result, "hello\n"); +}); + +Deno.test("SafeWhitespace: remove_invisibles strips known invisible chars", () => { + const result = remove_invisibles("​hello"); + assertEquals(result.includes("​"), false); + assertEquals(result.includes(""), false); +}); + +Deno.test("SafeWhitespace: detect_invisibles finds NBSP", () => { + const found = detect_invisibles("hello world"); + assertEquals(found.length, 1); + assertEquals(found[0], 0xa0); +}); + +Deno.test("SafeWhitespace: detect_invisibles empty for clean string", () => { + assertEquals(detect_invisibles("hello world").length, 0); +}); + +Deno.test("SafeWhitespace: LineEnding constants have correct tags", () => { + assertEquals(LF.tag, "LF"); + assertEquals(CRLF.tag, "CRLF"); + assertEquals(CR.tag, "CR"); +}); diff --git a/tests/TextTransform_test.js b/tests/TextTransform_test.js new file mode 100644 index 0000000..b95e677 --- /dev/null +++ b/tests/TextTransform_test.js @@ -0,0 +1,111 @@ +// SPDX-License-Identifier: MPL-2.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell +import { assert, assertEquals } from "jsr:@std/assert"; +import { + default_options, transform, transform_default, + get_metrics, metrics_to_string, + check_constraints, format_for_html, format_for_js, +} from "../src/core/TextTransform.deno.js"; +import { LF, CRLF } from "../stdlib/SafeWhitespace.deno.js"; + +Deno.test("TextTransform: transform trims lines when option set", () => { + const opts = { ...default_options(), trim_document: false, ensure_final_newline: false }; + const result = transform(" hello \n world ", opts); + assertEquals(result.includes(" hello"), false); +}); + +Deno.test("TextTransform: transform collapses spaces", () => { + const opts = { ...default_options(), trim_document: false, ensure_final_newline_opt: false, collapse_spaces_opt: true }; + const result = transform("hello world", opts); + assertEquals(result.includes(" "), false); +}); + +Deno.test("TextTransform: transform normalizes CRLF to LF", () => { + const opts = { ...default_options(), target_line_ending: LF }; + const result = transform("line1\r\nline2\r\nline3", opts); + assertEquals(result.includes("\r\n"), false); + assertEquals(result.includes("\r"), false); +}); + +Deno.test("TextTransform: transform normalizes LF to CRLF", () => { + const opts = { ...default_options(), target_line_ending: CRLF, ensure_final_newline_opt: false }; + const result = transform("line1\nline2", opts); + assertEquals(result.includes("\r\n"), true); +}); + +Deno.test("TextTransform: transform collapses excess blank lines", () => { + const opts = { ...default_options(), max_blank_lines: 1, ensure_final_newline: false }; + const result = transform("para1\n\n\n\n\npara2", opts); + assertEquals(result.includes("\n\n\n"), false); +}); + +Deno.test("TextTransform: transform ensures final newline", () => { + const opts = { ...default_options(), ensure_final_newline: true }; + assertEquals(transform("no newline", opts).endsWith("\n"), true); +}); + +Deno.test("TextTransform: transform_default returns a string", () => { + const result = transform_default(" test "); + assertEquals(typeof result, "string"); +}); + +Deno.test("TextTransform: get_metrics counts chars", () => { + assertEquals(get_metrics("Hello World").chars, 11); +}); + +Deno.test("TextTransform: get_metrics counts words", () => { + assertEquals(get_metrics("Hello World Test").words, 3); +}); + +Deno.test("TextTransform: get_metrics counts lines", () => { + assertEquals(get_metrics("Line 1\nLine 2\nLine 3").lines, 3); +}); + +Deno.test("TextTransform: metrics_to_string includes char count", () => { + const m = get_metrics("Hello World"); + const s = metrics_to_string(m); + assertEquals(s.includes("11"), true); +}); + +Deno.test("TextTransform: check_constraints detects char limit exceeded", () => { + const c = { max_chars: { tag: "Some", value: 5 }, max_words: { tag: "None" }, max_lines: { tag: "None" }, max_bytes: { tag: "None" } }; + const violations = check_constraints("This is a long string", c); + assert(violations.length > 0); +}); + +Deno.test("TextTransform: check_constraints passes when within limit", () => { + const c = { max_chars: { tag: "Some", value: 100 }, max_words: { tag: "None" }, max_lines: { tag: "None" }, max_bytes: { tag: "None" } }; + assertEquals(check_constraints("Short", c).length, 0); +}); + +Deno.test("TextTransform: check_constraints detects word limit exceeded", () => { + const c = { max_chars: { tag: "None" }, max_words: { tag: "Some", value: 3 }, max_lines: { tag: "None" }, max_bytes: { tag: "None" } }; + const violations = check_constraints("one two three four five", c); + assert(violations.length > 0); +}); + +Deno.test("TextTransform: check_constraints detects line limit exceeded", () => { + const c = { max_chars: { tag: "None" }, max_words: { tag: "None" }, max_lines: { tag: "Some", value: 2 }, max_bytes: { tag: "None" } }; + const violations = check_constraints("a\nb\nc\nd", c); + assert(violations.length > 0); +}); + +Deno.test("TextTransform: format_for_html escapes < and >", () => { + const result = format_for_html(""); + assertEquals(result.includes("