review: external audit v0.10.0 — all 14 findings resolved #33

Merged
user2595 merged 15 commits from review/external-audit-2026-05-30 into main 2026-05-30 23:20:00 +00:00
4 changed files with 46 additions and 39 deletions
Showing only changes of commit 018484a94d - Show all commits

View File

@@ -152,25 +152,25 @@ jobs:
# ─────────────────────────────────────────────────────────────────────────────
# Job 3 — quality-gates (style + convention block)
#
# Cheap, deterministic checks that should never break unless a contributor
# introduces a regression. Each gate is a script under scripts/quality/
# and exits 0 only when its tree is clean. These ran for weeks locally
# at zero findings before being promoted here.
# Trigger: write "/quality-gates" as a comment on any pull request.
#
# Tools installed at job-start (the ci-cpp image already has python3 +
# bash; we add codespell + shellcheck on top). Total wall-time: ~30 s
# on the eulernest runner.
#
# Strictly required for merges into main/dev — a regression fails the PR.
# Cheap, deterministic checks (~30 s): license headers, CGAL conventions,
# codespell, shellcheck. Runs independently of test-fast when comment-
# triggered (no `needs:` — the caller decides when to invoke it).
# ─────────────────────────────────────────────────────────────────────────────
quality-gates:
needs: test-fast
if: |
github.event_name == 'issue_comment' &&
github.event.issue.pull_request != null &&
contains(github.event.comment.body, '/quality-gates')
runs-on: eulernest
container:
image: git.eulernest.eu/conformallab/ci-cpp:latest
steps:
- uses: actions/checkout@v4
with:
ref: refs/pull/${{ github.event.issue.number }}/head
- name: Install codespell + shellcheck (job-local)
run: |

View File

@@ -1,34 +1,38 @@
name: API Docs
# Trigger: write "/docs" as a comment on any pull request.
# Also available via workflow_dispatch for manual runs outside a PR context.
on:
push:
branches:
- main
pull_request:
issue_comment:
types: [created]
workflow_dispatch: {}
# ─────────────────────────────────────────────────────────────────────────────
# Doc-build — informational only
#
# Generates Doxygen HTML from the public headers and reports warning
# statistics. Does NOT block merges: `continue-on-error: true` ensures
# warnings or extraction issues never fail the CI gate. When Doxygen
# coverage is denser (Phase 8c), this job can be promoted to a hard
# requirement and the HTML deployed to Pages.
# warnings or extraction issues never fail.
#
# Note: Gitea Actions on GHES does not support `actions/upload-artifact@v4`,
# so HTML artifact upload is intentionally omitted. The warning summary
# in the job log is the primary reviewer signal; reviewers who want the
# HTML can rebuild it locally with `cmake --build build --target doc`.
# Trigger: "/docs" PR comment (or workflow_dispatch for manual runs).
# Checkout uses refs/pull/N/head when triggered via comment.
# ─────────────────────────────────────────────────────────────────────────────
jobs:
doc-build:
if: github.event_name == 'pull_request'
if: |
github.event_name == 'workflow_dispatch' ||
(github.event_name == 'issue_comment' &&
github.event.issue.pull_request != null &&
contains(github.event.comment.body, '/docs'))
runs-on: eulernest
container:
image: git.eulernest.eu/conformallab/ci-cpp:latest
continue-on-error: true # never block the merge
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'issue_comment' && format('refs/pull/{0}/head', github.event.issue.number) || github.ref }}
- name: Generate API documentation
run: doxygen Doxyfile 2>&1 | tee doxygen.log

View File

@@ -1,35 +1,36 @@
name: Markdown link check
# Verify every internal markdown link in the repo resolves to an existing
# file (or anchor). External http(s) links are also probed but with a
# loose timeout — flaky third-party hosts must not break our CI.
# file (or anchor).
#
# Trigger: PRs that touch any *.md file, plus a weekly cron so external
# link rot is caught even when nobody is editing docs.
# Triggers:
# - "/links" as a PR comment (manual, on the PR branch)
# - Weekly cron Mon 05:00 UTC (catches link rot without any PR activity)
# - workflow_dispatch (manual run on any branch)
on:
pull_request:
paths:
- "**/*.md"
- ".gitea/workflows/markdown-links.yml"
push:
branches:
- main
paths:
- "**/*.md"
- ".gitea/workflows/markdown-links.yml"
issue_comment:
types: [created]
schedule:
- cron: "0 5 * * 1" # Monday 05:00 UTC weekly link-rot check
workflow_dispatch: {}
jobs:
check:
if: |
github.event_name == 'schedule' ||
github.event_name == 'workflow_dispatch' ||
(github.event_name == 'issue_comment' &&
github.event.issue.pull_request != null &&
contains(github.event.comment.body, '/links'))
runs-on: eulernest
container:
image: git.eulernest.eu/conformallab/ci-cpp:latest
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'issue_comment' && format('refs/pull/{0}/head', github.event.issue.number) || github.ref }}
# ── Pure-python internal link check (no external network needed) ────
# We use the same logic that found the 2 broken links before the

View File

@@ -264,9 +264,11 @@ Three jobs in `.gitea/workflows/cpp-tests.yml`:
| Job | CMake flags | Deps | Triggers on | Status |
|---|---|---|---|---|
| `test-fast` | *(none)* | Eigen + GTest only | all branches | **active** |
| `test-cgal` | `-DWITH_CGAL_TESTS=ON -DCONFORMALLAB_LOW_MEMORY_BUILD=ON` | + Boost | `/test-cgal` PR comment | **active** (comment-triggered, 2026-05-31) |
| `quality-gates` | *(none)* | + codespell, shellcheck | all branches (`needs: test-fast`) | **active** |
| `test-fast` | *(none)* | Eigen + GTest only | all branches (auto) | **active** |
| `test-cgal` | `-DWITH_CGAL_TESTS=ON -DCONFORMALLAB_LOW_MEMORY_BUILD=ON` | + Boost | `/test-cgal` PR comment | **active** |
| `quality-gates` | *(none)* | + codespell, shellcheck | `/quality-gates` PR comment | **active** |
| `doc-build` | *(none)* | Doxygen | `/docs` PR comment or `workflow_dispatch` | **active** |
| `markdown-links` | *(none)* | python3 | `/links` PR comment, weekly cron, `workflow_dispatch` | **active** |
Runner: `eulernest` — self-hosted Raspberry Pi, ARM64, Ubuntu 22.04. Docker image: `git.eulernest.eu/conformallab/ci-cpp:latest`. `test-cgal` and `quality-gates` both need `test-fast` to pass first (`needs: test-fast`).