* fix: lots of fixes and name refactoring * feat: Add workbench preferences * fix: MCP bridge status widget and just command fixes * fix(tests): Use the correct mesa-glx package * fix(ci): Add fontconfig to GUI test dependencies FreeCAD GUI was failing to start with: "Fontconfig error: Cannot load default config file: No such file" Added fontconfig and fonts-dejavu-core packages to the GUI test job dependencies to resolve the font configuration issue. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * refactor(addon): Extract path utilities into shared module Create path_utils.py module that consolidates duplicated path-finding logic from commands.py and InitGui.py: - get_addon_path(): Find addon directory with caching and fallbacks - get_icon_path(): Get full path to an icon file - get_icons_dir(): Get path to icons directory - get_workbench_icon(): Get path to workbench main icon This removes ~100 lines of duplicated code while preserving the same behavior including _addon_path_cache and all fallback methods. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(addon): Prevent stale plugin state on startup failure The StartMCPBridgeCommand.Activated method could leave _mcp_plugin in a partially initialized state if FreecadMCPPlugin.start() failed after the plugin was instantiated. Changes: - Create plugin in a local variable first - Only assign to _mcp_plugin after start() succeeds - Explicitly clear _mcp_plugin and _running_config in exception handlers to ensure clean state for subsequent retry attempts Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix: Lot of broad improvements * fix(ci): Use blocking headless_server.py for GUI tests The GUI test was using startup_bridge.py which is non-blocking (designed for interactive use). For CI, even in GUI mode, we need the blocking headless_server.py that calls run_forever() to keep FreeCAD running. GUI features are still available since we use the 'freecad' executable instead of 'freecadcmd'. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * refactor(addon): Rename headless_server.py to blocking_bridge.py The old name was misleading because: - It works with both GUI (freecad) and headless (freecadcmd) modes - The key characteristic is that it BLOCKS with run_forever() New naming convention clarifies the difference: - blocking_bridge.py: Starts bridge and blocks (for CI, servers) - startup_bridge.py: Starts bridge and returns (for interactive GUI) Updated all references across: - GitHub workflow (macro-test.yaml) - Just commands (freecad.just) - Unit tests (test_addon_structure.py) - Documentation (5 files) - CLAUDE.md Also improved the script to detect GUI mode dynamically using FreeCAD.GuiUp and display the appropriate status message. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix(just): Remove erroneous rm of startup_bridge.py on error The startup script is now a permanent source file in the repository, not a generated temporary file. The rm -f would have deleted source code if FreeCAD wasn't found. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * fix: General improvements * fix: Lots of general fixes and only stable to PyPi * fix: small cleanup * fix: Small fixes and hopefully fixes the GUI tests * fix: Add proper library paths for FreeCAD GUI in CI - Create wrapper scripts instead of symlinks for AppImage binaries - Set LD_LIBRARY_PATH, QT_PLUGIN_PATH for GUI mode - Add diagnostic output to identify startup failures * fix: Use apprun for GUI tests in CI * fix: Improving Xvfb tests * fix: GUI tests worlk * chore: remove invalid --no-splash comments * fix: ARM64 architecture support and other fixes * fix: cleanup * test: just commands test suite * test: improve just command tests * fix: more general improvements * fix: more cleanup * fix: more updates * fix: small tweaks --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
100 lines
3.8 KiB
Plaintext
100 lines
3.8 KiB
Plaintext
# Code quality commands
|
|
# Usage: just quality::check, just quality::format, etc.
|
|
#
|
|
# Note: Tools installed via mise (gitleaks, markdownlint-cli2, etc.) use `mise exec`.
|
|
# Python tools use `uv run`. This ensures commands work even without mise shell activation.
|
|
|
|
# Project root directory (justfile_directory() returns the main justfile's directory)
|
|
project_root := justfile_directory()
|
|
|
|
# Run all pre-commit checks
|
|
check: _check-safety-auth
|
|
uv run pre-commit run --all-files
|
|
|
|
# Verify Safety CLI authentication (skipped in CI where SAFETY_API_KEY is used)
|
|
_check-safety-auth:
|
|
#!/usr/bin/env bash
|
|
# Skip check if SAFETY_API_KEY is set (CI environment)
|
|
if [[ -n "${SAFETY_API_KEY:-}" ]]; then
|
|
exit 0
|
|
fi
|
|
# Check if authenticated locally
|
|
if ! uv run safety auth status >/dev/null 2>&1; then
|
|
echo "ERROR: Safety CLI not authenticated."
|
|
echo ""
|
|
echo "Safety CLI requires a free account for dependency vulnerability scanning."
|
|
echo "Run the following command to authenticate:"
|
|
echo ""
|
|
echo " uv run safety auth login"
|
|
echo ""
|
|
echo "This only needs to be done once per machine."
|
|
echo "See CLAUDE.md for more details."
|
|
exit 1
|
|
fi
|
|
|
|
# Format code with ruff
|
|
format:
|
|
uv run ruff format {{project_root}}/src {{project_root}}/tests
|
|
uv run ruff check --fix {{project_root}}/src {{project_root}}/tests
|
|
|
|
# Run linting
|
|
lint:
|
|
uv run ruff check {{project_root}}/src {{project_root}}/tests
|
|
|
|
# Run type checking
|
|
typecheck:
|
|
cd {{project_root}} && uv run mypy src
|
|
|
|
# Run security scanning (code vulnerabilities)
|
|
security:
|
|
uv run bandit -c {{project_root}}/pyproject.toml -r {{project_root}}/src
|
|
cd {{project_root}} && uv run safety scan --detailed-output
|
|
|
|
# Run spell checking
|
|
spellcheck:
|
|
uv run codespell --ignore-words {{project_root}}/.codespell-ignore-words.txt {{project_root}}/src {{project_root}}/tests {{project_root}}/docs
|
|
|
|
# =============================================================================
|
|
# Secrets Scanning (quality::scan-* commands)
|
|
# =============================================================================
|
|
|
|
# Run all secrets scanners
|
|
scan: scan-gitleaks scan-detect scan-trufflehog # pragma: allowlist secret
|
|
@echo "All secrets scans complete!"
|
|
|
|
# Run gitleaks secrets scanner (installed via mise)
|
|
scan-gitleaks:
|
|
mise exec -- gitleaks detect --source {{project_root}} --config {{project_root}}/.gitleaks.toml --verbose
|
|
|
|
# Run gitleaks on git history
|
|
scan-gitleaks-history:
|
|
mise exec -- gitleaks detect --source {{project_root}} --config {{project_root}}/.gitleaks.toml --verbose --log-opts="--all"
|
|
|
|
# Run detect-secrets scanner (installed via uv)
|
|
scan-detect:
|
|
uv run detect-secrets scan --baseline {{project_root}}/.secrets.baseline
|
|
|
|
# Audit detect-secrets baseline (interactive)
|
|
scan-audit:
|
|
uv run detect-secrets audit {{project_root}}/.secrets.baseline
|
|
|
|
# Update detect-secrets baseline with new findings (preserves audit metadata)
|
|
scan-baseline-update:
|
|
uv run detect-secrets scan --baseline {{project_root}}/.secrets.baseline --update {{project_root}}
|
|
|
|
# Run trufflehog for verified secrets (via pre-commit - not installed standalone)
|
|
scan-trufflehog:
|
|
uv run pre-commit run trufflehog --all-files
|
|
|
|
# =============================================================================
|
|
# Markdown Linting
|
|
# =============================================================================
|
|
|
|
# Lint all markdown files (markdownlint-cli2 installed via mise)
|
|
markdown-lint:
|
|
cd {{project_root}} && mise exec -- markdownlint-cli2 "**/*.md" "#.venv" "#.pytest_cache" "#node_modules" "#site" "#htmlcov"
|
|
|
|
# Lint and fix markdown files
|
|
markdown-fix:
|
|
cd {{project_root}} && mise exec -- markdownlint-cli2 --fix "**/*.md" "#.venv" "#.pytest_cache" "#node_modules" "#site" "#htmlcov"
|