Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Shared editor defaults for ODC repositories.
# Bootstrapped from dev-kit by common.mk. Commit a local .editorconfig file to override it.
#
# Kept in sync with treefmt.toml on purpose: shfmt reads this file for shell
# style, so the editor and `make fmt` cannot disagree.

root = true

[*]
charset = utf-8
end_of_line = lf
insert_final_newline = true
trim_trailing_whitespace = true
indent_style = space
indent_size = 2

[*.go]
indent_style = tab
indent_size = 4

[{Makefile,*.mk}]
indent_style = tab

[*.md]
trim_trailing_whitespace = false

[*.{sh,bash}]
switch_case_indent = true
space_redirects = true

[*.{json,yml,yaml,toml}]
indent_size = 2
3 changes: 1 addition & 2 deletions .github/actions/setup-nix/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,7 @@ inputs:
default: opendefensecloud
cachix-auth-token:
description: >-
Cachix auth token. Leave empty to fall back to a read-only cache, which
is what happens on fork pull requests, where secrets are unavailable.
Cachix auth token. Leave empty to fall back to a read-only cache, which is what happens on fork pull requests, where secrets are unavailable.
required: false
default: ''
cachix-signing-key:
Expand Down
6 changes: 6 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,18 +1,24 @@
## What

<!-- One sentence summary -->

Closes #

## Why

<!-- Motivation / problem being solved. Skip if obvious from the linked issue. -->

## Testing

<!-- How was this tested? e.g. unit, envtest, manual against vX.Y.Z -->

## Notes for reviewers

<!-- CRD/API changes, RBAC changes, new watches, breaking changes, upgrade path.
Delete if not applicable. -->

## Checklist

- [ ] Tests added/updated
- [ ] No breaking changes (or upgrade path documented above)
- [ ] Readable commit history (squashed and cleaned up as desired)
Expand Down
32 changes: 32 additions & 0 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Lint

permissions:
contents: read

on:
push:
branches: [main]
pull_request:
branches: [main]

jobs:
lint:
runs-on: ubuntu-24.04
defaults:
run:
shell: nix develop --command bash -e {0}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- name: Set up nix with the shared Cachix cache
uses: ./.github/actions/setup-nix
with:
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
cachix-signing-key: ${{ secrets.CACHIX_SIGNING_KEY }}
- name: fmt
run: make fmt
- name: verify formatting
uses: ./.github/actions/diff-check
- name: lint
run: make lint
8 changes: 4 additions & 4 deletions .github/workflows/release-drafter.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,13 @@ on:
branches:
- main

# pull_request event is required only for autolabeler
# pull_request event is required only for autolabeler.
# pull_request_target is required for the autolabeler to support PRs from forks
# pull_request_target:
# types: [opened, reopened, synchronize]
pull_request:
# Only following types are handled by the action, but one can default to all as well
types: [opened, reopened, synchronize]
# pull_request_target event is required for autolabeler to support PRs from forks
# pull_request_target:
# types: [opened, reopened, synchronize]

permissions:
contents: read
Expand Down
4 changes: 1 addition & 3 deletions .github/workflows/renovate-auto-approve.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,9 +49,7 @@ jobs:
auto-approve:
runs-on: ubuntu-latest
if: >-
github.event_name == 'pull_request' &&
github.event.pull_request.user.login == inputs.renovate-actor &&
(contains(github.event.pull_request.labels.*.name, inputs.automerge-label) ||
github.event_name == 'pull_request' && github.event.pull_request.user.login == inputs.renovate-actor && (contains(github.event.pull_request.labels.*.name, inputs.automerge-label) ||
contains(github.event.pull_request.labels.*.name, inputs.block-label))
steps:
- name: Approve an unmodified Renovate PR, or revoke a prior approval
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,4 @@
example/common.mk
example/bin/
.pre-commit-config.yaml
.common.mk-configs
100 changes: 100 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
# Baseline golangci-lint configuration for ODC repositories.
# Bootstrapped from dev-kit by common.mk; commit a local .golangci.yml file to override it.
version: "2"
linters:
default: none
settings:
dogsled:
max-blank-identifiers: 4
exhaustive:
default-signifies-exhaustive: true
godot:
scope: declarations
capital: false
gosec:
excludes:
- G101 # Look for hardcoded credentials
- G204 # Audit use of command execution
- G306 # Poor file permissions used when writing to a file
modernize:
disable:
- omitzero
nlreturn:
block-size: 2
staticcheck:
checks: ["all", "-ST1000", "-ST1001", "-ST1003", "-ST1005", "-ST1012", "-ST1016", "-ST1020", "-ST1021", "-ST1022", "-QF1001", "-QF1003", "-QF1008"]
exclusions:
generated: lax
presets: [comments, common-false-positives, legacy, std-error-handling]
paths: [third_party, builtin$, examples$]
warn-unused: true
enable:
- asasalint
- asciicheck
- bidichk
- bodyclose
- canonicalheader
- contextcheck
- copyloopvar
- decorder
- dogsled
- dupword
- durationcheck
- errcheck
- errchkjson
- errname
- exhaustive
- exptostd
- forbidigo
- ginkgolinter
- gocheckcompilerdirectives
- gochecksumtype
- gocritic
- godoclint
- godot
- goprintffuncname
- gosec
- gosmopolitan
- govet
- grouper
- ineffassign
- interfacebloat
- intrange
- loggercheck
- makezero
- mirror
- misspell
- modernize
- musttag
- nakedret
- nilerr
- nlreturn
- noctx
- nosprintfhostport
- predeclared
- promlinter
- protogetter
- reassign
- sloglint
- staticcheck
- testableexamples
- unconvert
- unparam
- unused
- usestdlibvars
- usetesting
- wastedassign
formatters:
enable: [gci, gofmt]
settings:
gci:
sections:
- standard # Standard section: captures all standard packages.
- default # Default section: contains all imports that could not be matched to another section type.
- localmodule # Local module section: contains all local packages. This section is not present unless explicitly enabled.
- blank # Blank section: contains all blank imports. This section is not present unless explicitly enabled.
- dot # Dot section: contains all dot imports. This section is not present unless explicitly enabled.
custom-order: true
exclusions:
generated: lax
paths: [third_party, builtin$, examples$]
7 changes: 7 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# dev-kit is the source of common.mk, so it includes its own copy directly. The
# self-update check skips repositories where common.mk is tracked by git, and
# DEV_KIT_CONFIGS resolves to nothing here because the shared configs live in
# this repository already.
DEV_KIT_VERSION := main
DEV_KIT_FORMATTING := on
include common.mk
Loading
Loading