mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-18 05:02:15 +03:00
* feat(ci): G0 — quality rail (PR→release/**) ganha ratchets+segurança do trilho A O refactor de god-files do trilho 3.8.50→3.9.0 acontece em PRs→release/**, e esse trilho pulava o motor de ratchet, o CodeQL ratchet e todos os scanners de segurança — exatamente onde a rede era necessária (5 das 13 causas da reconciliação de 07-24 eram regressões reais shipadas por CI verde por-PR). Modo enxuto, jobs EXISTENTES (a .51 consolida lanes; nenhum job novo): - lint-guard: quality:collect + ratchet --allow-missing + require-tighten + check:codeql-ratchet. O job já escreve .artifacts/eslint-results.json, então o motor entra a custo ZERO de ESLint (um inventário, dois consumidores). Coverage ausente degrada gracioso (--allow-missing); autoridade de coverage segue no trilho A. + permissions security-events:read para o CodeQL ratchet. - fast-gates: check:cycles, check:lockfile, duplication, dead-code, type-coverage, compression-budget + install endurecido dos scanners (gh release download, zizmor PINADO 1.25.2 = mesmo auditor do ci.yml) + secrets/vuln/workflows/ openapi-breaking com --ratchet (self-skip sem binário; só regressão medida bloqueia). - Fora de propósito: bundle-size (self-skip sem build → configuração morta) e o run de coverage (fast-unit já roda a suíte cheia). Runners intocados: guard tests/unit/vps-runner-variable-scope.test.ts verde; teste novo tests/unit/quality-rail-gate-membership.test.ts pina a MEMBERSHIP dos gates no trilho B (red antes da edição, green depois). Validação no tip puro (nenhum base-red fabricado para a fila de PRs abertos): cycles OK · lockfile OK · duplication 4.26% (base 5.72%) · dead-code 226 (base 227) · type-coverage 94.13% (base 92.17%) · compression OK · secrets 0 (base 0) · vuln 5 (base 10) · codeql 0 (base 0) · oasdiff 0 (base 0) · zizmor 178 (base 190) · actionlint exit 0 no arquivo editado · quality-ratchet 56 métricas OK + require-tighten OK com --allow-missing. Refs #8084 * feat(.50): G13 golden-set, G14 import boundaries, gap34 deterministic, docs sync, R0.2 dead hooks Integra os itens restantes da 3.8.50: - G13: golden-set determinístico para combo.ts e chatCore.ts via seams públicas - G14: no-restricted-imports para localDb barrel fora de src/lib/db/ e executors em src/app/ - Gap34: teste determinístico de timeout DuckDuckGo sem rede real - Docs: golden path de contribuição + sincronização de números canônicos - R0.2: remoção dos 7 hooks mortos do BUILTIN_EVENTS + UI marketplace ajustada * fix(r0.2): remove marketplace tab remnants from plugins page — fixes dashboard typecheck regression * chore(r0.2): remove pluginWorker.ts, signing.ts, sandbox.ts — zero importers confirmed * fix(docs): remove OMNIROUTE_PLUGINS_ALLOW_EXEC reference — env var removed with pluginWorker.ts in R0.2 * fix(env): remove dead OMNIROUTE_PLUGINS_ALLOW_EXEC from .env.example — consumer removed in R0.2 * fix(test): update sidebar-visibility assertion for R0.2 marketplace removal --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
78 lines
2.5 KiB
TypeScript
78 lines
2.5 KiB
TypeScript
import assert from "node:assert/strict";
|
|
import test from "node:test";
|
|
|
|
import { ESLint } from "eslint";
|
|
|
|
const eslint = new ESLint({ cwd: process.cwd() });
|
|
|
|
async function restrictedImportMessages(code: string, filePath: string): Promise<string[]> {
|
|
const [result] = await eslint.lintText(code, { filePath });
|
|
|
|
return result.messages
|
|
.filter(({ ruleId }) => ruleId === "no-restricted-imports")
|
|
.map(({ message }) => message);
|
|
}
|
|
|
|
test("G14 rejects localDb barrel imports outside src/lib/db", async () => {
|
|
const cases = [
|
|
{
|
|
code: 'import { getSettings } from "@/lib/localDb";\nvoid getSettings;',
|
|
filePath: "src/lib/example.ts",
|
|
},
|
|
{
|
|
code: 'import { getSettings } from "@/lib/localDb.ts";\nvoid getSettings;',
|
|
filePath: "src/shared/example.ts",
|
|
},
|
|
{
|
|
code: 'import { getSettings } from "../localDb";\nvoid getSettings;',
|
|
filePath: "src/lib/feature/example.ts",
|
|
},
|
|
{
|
|
code: 'import { getSettings } from "../../lib/localDb.ts";\nvoid getSettings;',
|
|
filePath: "src/app/example.ts",
|
|
},
|
|
];
|
|
|
|
for (const fixture of cases) {
|
|
const messages = await restrictedImportMessages(fixture.code, fixture.filePath);
|
|
assert.equal(messages.length, 1, `expected ${fixture.code} to be rejected`);
|
|
assert.match(messages[0], /domain module from `@\/lib\/db\//);
|
|
}
|
|
});
|
|
|
|
test("G14 rejects executor implementation imports from src/app", async () => {
|
|
for (const importPath of [
|
|
"@omniroute/open-sse/executors/default.ts",
|
|
"open-sse/executors/default.ts",
|
|
]) {
|
|
const messages = await restrictedImportMessages(
|
|
`import { DefaultExecutor } from "${importPath}";\nvoid DefaultExecutor;`,
|
|
"src/app/api/example/route.ts"
|
|
);
|
|
|
|
assert.equal(messages.length, 1, `expected ${importPath} to be rejected from src/app`);
|
|
assert.match(messages[0], /handler or service boundary/);
|
|
}
|
|
});
|
|
|
|
test("G14 allows imports through the intended boundaries", async () => {
|
|
const cases = [
|
|
{
|
|
code: 'import { getSettings } from "@/lib/localDb";\nvoid getSettings;',
|
|
filePath: "src/lib/db/example.ts",
|
|
},
|
|
{
|
|
code: 'import { DefaultExecutor } from "@omniroute/open-sse/executors/default.ts";\nvoid DefaultExecutor;',
|
|
filePath: "src/sse/handlers/example.ts",
|
|
},
|
|
{
|
|
code: 'import { handleChat } from "@omniroute/open-sse/handlers/chat";\nvoid handleChat;',
|
|
filePath: "src/app/api/example/route.ts",
|
|
},
|
|
];
|
|
|
|
for (const fixture of cases) {
|
|
assert.deepEqual(await restrictedImportMessages(fixture.code, fixture.filePath), []);
|
|
}
|
|
});
|