index: regen after estate rescan (run 36966507547) (#159) #338
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| # This workflow is managed by gh actions-lock. | |
| # RSR Anti-Pattern CI Check | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # | |
| # Enforces: No Ruby, No TypeScript, No Go, No Python (except SaltStack), No npm | |
| # Allows: AffineScript, Deno, WASM, Rust, OCaml, Haskell, Guile/Scheme | |
| # | |
| # Ruby is a banned language for this estate; the sole exception is an adapter | |
| # under a path that declares itself one (bindings|integrations|adapters)/*/ruby/ | |
| # — see docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc. | |
| name: RSR Anti-Pattern Check | |
| on: | |
| push: | |
| branches: [main, master, develop] | |
| pull_request: | |
| branches: [main, master, develop] | |
| permissions: read-all | |
| jobs: | |
| antipattern-check: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v7.0.1 | |
| - name: Check for TypeScript | |
| run: | | |
| # Exclude bindings/deno/ - those are Deno FFI files using Deno.dlopen, not plain TypeScript | |
| # Exclude .d.ts files - those are TypeScript type declarations for ReScript FFI | |
| TS_FILES=$(find . \( -name "*.ts" -o -name "*.tsx" \) | grep -v node_modules | grep -v 'bindings/deno' | grep -v '\.d\.ts$' || true) | |
| if [ -n "$TS_FILES" ]; then | |
| echo "❌ TypeScript files detected - use AffineScript instead" | |
| echo "$TS_FILES" | |
| exit 1 | |
| fi | |
| echo "✅ No TypeScript files (Deno FFI bindings excluded)" | |
| - name: Check for Go | |
| run: | | |
| if find . -name "*.go" | grep -q .; then | |
| echo "❌ Go files detected - use Rust/WASM instead" | |
| find . -name "*.go" | |
| exit 1 | |
| fi | |
| echo "✅ No Go files" | |
| - name: Check for Python (non-SaltStack) | |
| run: | | |
| PY_FILES=$(find . -name "*.py" | grep -v salt | grep -v _states | grep -v _modules | grep -v pillar | grep -v venv | grep -v __pycache__ || true) | |
| if [ -n "$PY_FILES" ]; then | |
| echo "❌ Python files detected - only allowed for SaltStack" | |
| echo "$PY_FILES" | |
| exit 1 | |
| fi | |
| echo "✅ No non-SaltStack Python files" | |
| - name: Check for Ruby (banned for this estate; adapters only) | |
| run: | | |
| set -euo pipefail | |
| # `explore` is an SSG-family repository: Ruby/Jekyll is its product, | |
| # not an incidental estate tool. Its exemption is recorded in ADR-0002. | |
| if case "${GITHUB_REPOSITORY:-}" in explore|*/explore) true ;; *) false ;; esac; then | |
| echo "✅ Ruby policy exempted: explore is an SSG-family repository" | |
| exit 0 | |
| fi | |
| # Ruby is a banned implementation language. The only permitted Ruby is an | |
| # *adapter* that lets a Ruby host application call into estate code, and it | |
| # must declare itself as one by living under bindings/|integrations/|adapters/. | |
| # Exemptions below are policy, not convenience: | |
| # */ruby/, */helpers/ — adapter code, permitted by ADR-0002 | |
| # Formula/, */homebrew/ — Homebrew formulae are a Ruby DSL; the formula is | |
| # packaging metadata, not estate implementation | |
| # vendor/, satellites/, macports-ports/ — mirrors of other projects' trees, | |
| # which this policy does not own | |
| RUBY_SOURCES=$(find . \( -name '*.rb' -o -name '*.rake' -o -name '*.gemspec' \ | |
| -o -name 'Gemfile' -o -name 'Gemfile.lock' -o -name 'Rakefile' \ | |
| -o -name '.ruby-version' \) \ | |
| -not -path './.git/*' -type f 2>/dev/null \ | |
| | grep -Ev '^\./(bindings|integrations|adapters)(/[A-Za-z0-9._-]+)?/(ruby|helpers)/' \ | |
| | grep -Ev '^\./(Formula|Casks)/|/(homebrew|tap)/' \ | |
| | grep -Ev '^\./(vendor|macports-ports)/|/satellites/' \ | |
| || true) | |
| if [ -n "$RUBY_SOURCES" ]; then | |
| echo "::error::Ruby source detected. Ruby is banned for this estate." | |
| echo "$RUBY_SOURCES" | |
| echo "" | |
| echo "Convert it: Bun/Node for tooling and site builds, Julia or Rust for" | |
| echo "computation, Zig for FFI, Elixir for concurrency, AffineScript where a" | |
| echo "face exists. Adapter Ruby is fine only under" | |
| echo "bindings/*/ruby/ or integrations/*/ruby/. See" | |
| echo "docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc." | |
| exit 1 | |
| fi | |
| echo "✅ No Ruby outside permitted adapter paths" | |
| - name: Check for Ruby on the build path | |
| run: | | |
| set -euo pipefail | |
| # `explore` is an SSG-family repository: its Jekyll build is the | |
| # product and is exempt by ADR-0002, including its CI runtime. | |
| if case "${GITHUB_REPOSITORY:-}" in explore|*/explore) true ;; *) false ;; esac; then | |
| echo "✅ Ruby CI policy exempted: explore is an SSG-family repository" | |
| exit 0 | |
| fi | |
| # A repo can pass the file audit and still boot Ruby in CI — that is | |
| # exactly the shape this estate's dependabot noise came from: a bump PR | |
| # for ruby/setup-ruby in a repo with nothing Ruby left to build. So the | |
| # pin/invocation surface is audited too, not just *.rb files. | |
| # | |
| # Three deliberate constraints: | |
| # --exclude=rsr-antipattern.yml — this file contains the pattern list, | |
| # so it would match itself (a bug this estate has hit before). | |
| # comment lines are dropped — prose that *describes* the retired Ruby | |
| # tooling is how a migration explains itself; only instructions count. | |
| # patterns are anchored to invocation shapes, not substrings. A loose | |
| # substring match flags `echidna`, whose CI greps for the literal text | |
| # "bundle install failed" in a container build log — it has no Ruby. | |
| # An estate-wide check that cries wolf gets switched off by the next | |
| # person who has to triage it, so precision here is the whole game. | |
| # (the `.?` on the second line is the quote in a lockfile entry, e.g. | |
| # ` - 'ruby/setup-ruby@v1.324.0'` — written as `.` because a | |
| # single quote cannot appear inside this single-quoted shell string.) | |
| RUBY_CI=$(grep -rnIE --exclude=rsr-antipattern.yml \ | |
| -e 'uses:[[:space:]]*(ruby/setup-ruby|actions/jekyll-build-pages)' \ | |
| -e '^[[:space:]]*(-[[:space:]]+)?.?(ruby/setup-ruby|actions/jekyll-build-pages)@' \ | |
| -e '^[[:space:]]*(-[[:space:]]+)?(run:[[:space:]]*)?(sudo[[:space:]]+)?(gem install|bundle exec|bundle install|rake[[:space:]])' \ | |
| .github/workflows .github/actions .gitlab-ci.yml Justfile justfile 2>/dev/null \ | |
| | grep -vE '^[^:]+:[0-9]+:[[:space:]]*#' || true) | |
| if [ -n "$RUBY_CI" ]; then | |
| echo "::error::Ruby on the build path. Ruby is banned for this estate." | |
| echo "$RUBY_CI" | |
| echo "" | |
| echo "Pages/docs builds use scripts/build-site.mjs (Bun tier 1, Node >= 18" | |
| echo "fallback) driven by site.json; see" | |
| echo "docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc." | |
| exit 1 | |
| fi | |
| echo "✅ No Ruby in CI configuration" | |
| - name: Check for npm lockfiles | |
| run: | | |
| if [ -f "package-lock.json" ] || [ -f "yarn.lock" ]; then | |
| echo "❌ npm/yarn lockfile detected - use Deno instead" | |
| exit 1 | |
| fi | |
| echo "✅ No npm lockfiles" | |
| - name: Check for tsconfig | |
| run: | | |
| if [ -f "tsconfig.json" ]; then | |
| echo "❌ tsconfig.json detected - use AffineScript instead" | |
| exit 1 | |
| fi | |
| echo "✅ No tsconfig.json" | |
| - name: Verify Deno presence (if package.json exists) | |
| run: | | |
| if [ -f "package.json" ]; then | |
| if [ ! -f "deno.json" ] && [ ! -f "deno.jsonc" ]; then | |
| echo "⚠️ Warning: package.json without deno.json - migration recommended" | |
| fi | |
| fi | |
| echo "✅ Deno configuration check complete" | |
| - name: Summary | |
| run: | | |
| echo "╔════════════════════════════════════════════════════════════╗" | |
| echo "║ RSR Anti-Pattern Check Passed ✅ ║" | |
| echo "║ ║" | |
| echo "║ Allowed: AffineScript, Deno, WASM, Rust, OCaml, Haskell, ║" | |
| echo "║ Guile/Scheme, SaltStack (Python) ║" | |
| echo "║ ║" | |
| echo "║ Blocked: Ruby (outside adapters), TypeScript, Go, npm, ║" | |
| echo "║ Python (non-Salt) ║" | |
| echo "╚════════════════════════════════════════════════════════════╝" |