Per operator guidance: the required-status-checks config gates merge on the nix flake check only, not this lint. So drop the warn|deny mode — the lint just fails (exit 1, error annotations) when it finds tracker tags, and runs as its own CI job so that failure shows red on the PR without failing the required nix flake check job or blocking merge. Once the legacy backlog is cleaned up, promoting this job to a required check flips it to a hard gate — no code change.
40 lines
1.8 KiB
Shell
Executable file
40 lines
1.8 KiB
Shell
Executable file
#!/bin/sh
|
|
# CI lint: flags tracker tags (a hash followed by an issue number) in
|
|
# source comments. The hive convention is prose, not tracker tags, in
|
|
# code (see /knowledge/hive-rules.md) — tags rot, they point at moving
|
|
# targets and leak tracker coupling into the source tree.
|
|
#
|
|
# Emits a CI error annotation per hit and exits 1 if any tag is found,
|
|
# 0 otherwise. It runs as its own CI job, deliberately kept OUT of the
|
|
# required checks while the legacy backlog is cleaned up: a hit turns
|
|
# the job red (a visible, non-blocking signal on the PR) without
|
|
# blocking merge. Promote it to a required check once the tree is clean
|
|
# to make it a hard gate — no code change, just branch-protection.
|
|
#
|
|
# Scope: tracked *.rs *.nix *.js *.ts *.css *.html. Markdown is exempt
|
|
# (prose docs may legitimately cite the tracker). The pattern matches a
|
|
# hash, 2-5 digits, then a non-hex char or end-of-line: that trailing
|
|
# class skips CSS hex colours (letter-bearing or 6/8-digit) while still
|
|
# catching tracker tags. Residual: a pure-numeric short hex (e.g. three
|
|
# identical digits) trips it — write the six-digit form to dodge.
|
|
set -eu
|
|
|
|
pattern='#[0-9]{2,5}([^0-9a-fA-F]|$)'
|
|
|
|
# `/dev/null` forces grep to always print a filename prefix, even when
|
|
# xargs hands it a single file. `-r`/`-0` keep it robust to odd paths
|
|
# and an empty file list.
|
|
hits="$(
|
|
git ls-files -z '*.rs' '*.nix' '*.js' '*.ts' '*.css' '*.html' \
|
|
| xargs -0 -r grep -nE "$pattern" /dev/null 2>/dev/null || true
|
|
)"
|
|
|
|
if [ -n "$hits" ]; then
|
|
echo "$hits" | while IFS=: read -r file lineno _; do
|
|
printf '::error file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno"
|
|
done
|
|
count="$(printf '%s\n' "$hits" | wc -l | tr -d ' ')"
|
|
printf 'check-issue-refs: %s tracker tag(s) found in source\n' "$count" >&2
|
|
exit 1
|
|
fi
|
|
exit 0
|