* ci: add caching and fix workflow failures - Add UV package caching to all workflows for faster dependency installation - Add pre-commit hook caching with OS-specific cache keys - Skip no-commit-to-branch hook in CI (fails on main branch) - Remove broken apt cache action (doesn't work with PPAs) - Simplify FreeCAD command detection (PPA installs to standard PATH) - Add FreeCAD Python version logging for debugging * ci: Add code Rabbit configuration file * ci: fix issues in CI workflows * ci: add uv.lock * ci: tweaks * ci: Fix errors and add UUID generation and checking * ci: Use the GitHub FreeCAD release latest stables * ci: skip macro test for now, due to headless mode * feat: Add a multi export macro * ci: Fix tests * ci: fix docker build workflow * ci: skip trufflehog in GitHub Actions due to wasm panic bug TruffleHog has a known wasm/go-re2 panic bug that causes failures in GitHub Actions environment. The hook still runs locally during development for secrets detection. - Add trufflehog to SKIP env var in pre-commit.yaml - Update trufflehog to v3.88.7 (latest) - Add reference to upstream issue #3321 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * test: use boolean holes instead of PartDesign::Hole in CI PartDesign::Hole has a CADKernelError bug in FreeCAD AppImage headless mode on Linux (used in GitHub Actions) where it fails with "Cannot make face from profile". The SmartCutter class already supports boolean holes as an alternative. Changes: - Modify SmartCutter.execute() to use boolean holes by default - Update all test assertions for Part::Feature output type - Update test docstrings and class descriptions - Remove PartDesign-specific checks (Group, Sketcher::SketchObject) - Update workflow comment explaining the CI limitation Boolean holes work reliably in both GUI and headless mode across all FreeCAD configurations. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> * ci: clean up GitHub Actions workflows * ci: Dependabot improvements * ci: add CodeQL scanning workflow * ci: AI review suggested improvements * ci: add coderabbit updates for intentional decisions --------- Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
235 lines
8.2 KiB
YAML
235 lines
8.2 KiB
YAML
# Pre-commit hooks configuration
|
|
# https://pre-commit.com/
|
|
|
|
default_language_version:
|
|
python: python3.11 # Must match FreeCAD's bundled Python version
|
|
|
|
repos:
|
|
# ==========================================================================
|
|
# General File Hygiene
|
|
# ==========================================================================
|
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
|
rev: v5.0.0
|
|
hooks:
|
|
- id: trailing-whitespace
|
|
exclude: \.md$ # Allow trailing spaces in markdown for line breaks
|
|
- id: end-of-file-fixer
|
|
- id: check-yaml
|
|
args: [--unsafe]
|
|
- id: check-toml
|
|
- id: check-json
|
|
- id: check-added-large-files
|
|
args: [--maxkb=1000]
|
|
- id: check-merge-conflict
|
|
- id: check-case-conflict
|
|
- id: check-symlinks
|
|
- id: check-executables-have-shebangs
|
|
- id: check-shebang-scripts-are-executable
|
|
- id: detect-private-key
|
|
- id: mixed-line-ending
|
|
args: [--fix=lf]
|
|
- id: no-commit-to-branch
|
|
args: [--branch, main, --branch, master]
|
|
- id: check-ast # Check Python syntax
|
|
types: [text]
|
|
files: \.(py|FCMacro)$
|
|
|
|
# ==========================================================================
|
|
# Python - Linting and Formatting
|
|
# ==========================================================================
|
|
- repo: https://github.com/astral-sh/ruff-pre-commit
|
|
rev: v0.8.4
|
|
hooks:
|
|
- id: ruff
|
|
args: [--fix, --exit-non-zero-on-fix]
|
|
types_or: [python, text]
|
|
files: \.(py|FCMacro)$
|
|
- id: ruff-format
|
|
types_or: [python, text]
|
|
files: \.(py|FCMacro)$
|
|
|
|
# ==========================================================================
|
|
# Python - Type Checking
|
|
# ==========================================================================
|
|
- repo: https://github.com/pre-commit/mirrors-mypy
|
|
rev: v1.14.0
|
|
hooks:
|
|
- id: mypy
|
|
additional_dependencies:
|
|
- pydantic>=2.10.0
|
|
- pydantic-settings>=2.7.0
|
|
- mcp>=1.25.0
|
|
# Note: mypy doesn't natively support .FCMacro, so we skip those files
|
|
# FCMacro files are checked by ruff and bandit instead
|
|
args: [--config-file=pyproject.toml]
|
|
|
|
# ==========================================================================
|
|
# Python - Security Scanning
|
|
# ==========================================================================
|
|
- repo: https://github.com/PyCQA/bandit
|
|
rev: 1.8.0
|
|
hooks:
|
|
- id: bandit
|
|
args: [-c, pyproject.toml, -r, src, macros]
|
|
additional_dependencies: ["bandit[toml]"]
|
|
types: [text]
|
|
files: \.(py|FCMacro)$
|
|
|
|
# ==========================================================================
|
|
# Secrets Detection - Multi-Layer Approach
|
|
# ==========================================================================
|
|
|
|
# Layer 1: Gitleaks - Fast, comprehensive secrets scanner
|
|
# Scans git history and current files using regex patterns
|
|
# Config: .gitleaks.toml
|
|
- repo: https://github.com/gitleaks/gitleaks
|
|
rev: v8.21.2
|
|
hooks:
|
|
- id: gitleaks
|
|
name: gitleaks (secrets scanner)
|
|
args: [--config, .gitleaks.toml, --verbose]
|
|
|
|
# Layer 2: detect-secrets - Yelp's enterprise-grade secrets detector
|
|
# Uses baseline file to track known/approved secrets
|
|
# Config: .secrets.baseline
|
|
- repo: https://github.com/Yelp/detect-secrets
|
|
rev: v1.5.0
|
|
hooks:
|
|
- id: detect-secrets
|
|
name: detect-secrets (baseline scan)
|
|
args:
|
|
- --baseline
|
|
- .secrets.baseline
|
|
- --exclude-files
|
|
- '\.secrets\.baseline$'
|
|
- --exclude-files
|
|
- '\.gitleaks\.toml$'
|
|
- --exclude-files
|
|
- 'uv\.lock$'
|
|
- --exclude-files
|
|
- 'poetry\.lock$'
|
|
- --exclude-files
|
|
- 'package-lock\.json$'
|
|
|
|
# Layer 3: TruffleHog - Deep secrets scanner with verification
|
|
# Verifies secrets are actually valid (e.g., tests AWS keys)
|
|
# Note: TruffleHog has wasm/go-re2 panic bugs in GitHub Actions.
|
|
# It's skipped in CI (via SKIP env var) but runs locally.
|
|
# See: https://github.com/trufflesecurity/trufflehog/issues/3321
|
|
- repo: https://github.com/trufflesecurity/trufflehog
|
|
rev: v3.88.7
|
|
hooks:
|
|
- id: trufflehog
|
|
name: trufflehog (verified secrets scan)
|
|
args:
|
|
- --no-update
|
|
exclude: '(^|/)uv\.lock$|\.secrets\.baseline$'
|
|
|
|
# ==========================================================================
|
|
# Markdown Linting - Comprehensive Configuration
|
|
# ==========================================================================
|
|
|
|
# Primary: markdownlint-cli2 - Comprehensive markdown linter
|
|
# Config: .markdownlint.yaml
|
|
- repo: https://github.com/DavidAnson/markdownlint-cli2
|
|
rev: v0.17.1
|
|
hooks:
|
|
- id: markdownlint-cli2
|
|
name: markdownlint (linter)
|
|
args: [] # Uses .markdownlint.yaml automatically
|
|
|
|
# Secondary: mdformat - Opinionated markdown formatter
|
|
- repo: https://github.com/executablebooks/mdformat
|
|
rev: 0.7.21
|
|
hooks:
|
|
- id: mdformat
|
|
name: mdformat (formatter)
|
|
additional_dependencies:
|
|
- mdformat-gfm # GitHub Flavored Markdown
|
|
- mdformat-frontmatter # YAML front matter
|
|
- mdformat-footnote # Footnotes
|
|
- mdformat-tables # Table formatting
|
|
- mdformat-simple-breaks # Use --- for horizontal rules
|
|
exclude: CHANGELOG\.md$ # Don't format auto-generated changelogs
|
|
|
|
# Tertiary: md-toc - Table of contents generator
|
|
# Automatically updates TOC between <!--TOC--> markers
|
|
- repo: https://github.com/frnmst/md-toc
|
|
rev: 9.0.0
|
|
hooks:
|
|
- id: md-toc
|
|
name: md-toc (table of contents)
|
|
args: ["-p", "github", "-l", "6"] # GitHub parser, max 6 levels
|
|
files: ^(README|ARCHITECTURE-MCP)\.md$
|
|
|
|
# ==========================================================================
|
|
# Spell Checking
|
|
# ==========================================================================
|
|
- repo: https://github.com/codespell-project/codespell
|
|
rev: v2.3.0
|
|
hooks:
|
|
- id: codespell
|
|
additional_dependencies:
|
|
- tomli
|
|
args:
|
|
- --ignore-words
|
|
- .codespell-ignore-words.txt
|
|
- --skip
|
|
- "*.lock,*.json,.secrets.baseline"
|
|
|
|
# ==========================================================================
|
|
# Configuration Validation
|
|
# ==========================================================================
|
|
- repo: https://github.com/abravalheri/validate-pyproject
|
|
rev: v0.23
|
|
hooks:
|
|
- id: validate-pyproject
|
|
|
|
- repo: https://github.com/python-jsonschema/check-jsonschema
|
|
rev: 0.30.0
|
|
hooks:
|
|
- id: check-github-workflows
|
|
name: validate GitHub workflows
|
|
- id: check-dependabot
|
|
name: validate Dependabot config
|
|
|
|
# ==========================================================================
|
|
# Shell Script Linting
|
|
# ==========================================================================
|
|
- repo: https://github.com/shellcheck-py/shellcheck-py
|
|
rev: v0.10.0.1
|
|
hooks:
|
|
- id: shellcheck
|
|
name: shellcheck (shell linter)
|
|
args: [--severity=warning]
|
|
|
|
# ==========================================================================
|
|
# Dockerfile Linting
|
|
# ==========================================================================
|
|
- repo: https://github.com/hadolint/hadolint
|
|
rev: v2.13.1-beta
|
|
hooks:
|
|
- id: hadolint-docker
|
|
name: hadolint (Dockerfile linter)
|
|
|
|
# ==========================================================================
|
|
# Commit Message Linting
|
|
# ==========================================================================
|
|
- repo: https://github.com/commitizen-tools/commitizen
|
|
rev: v4.1.0
|
|
hooks:
|
|
- id: commitizen
|
|
name: commitizen (commit format)
|
|
stages: [commit-msg]
|
|
|
|
# ==========================================================================
|
|
# CI Configuration
|
|
# ==========================================================================
|
|
ci:
|
|
autoupdate_schedule: monthly
|
|
autoupdate_commit_msg: "chore(deps): update pre-commit hooks"
|
|
skip:
|
|
- mypy # Needs dependencies installed
|
|
- hadolint-docker # Needs Docker
|
|
- trufflehog # Can be slow in CI
|