Skip to content

ci: standardize quick extension tooling and security - #34

Merged
napalm255 merged 7 commits into
mainfrom
ci/standardize-quick-tooling
Oct 3, 2026
Merged

napalm255 merged 7 commits into
mainfrom
ci/standardize-quick-tooling

Conversation

@napalm255

@napalm255 napalm255 commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Standardize CI, security, packaging, badges, and common documentation with the same 33 managed files from Ghost-Assembly/quick-template. Immutable archive verification rejects drift and CI overrides; project hooks and metadata retain extension-specific behavior.

Require local just ci, CodeQL JavaScript/Python security-extended, and authenticated Sonar through SONAR_TOKEN. Sonar Free-compatible PR analysis checks changed code, and main analysis checks all source; both require exact revisions, zero security/reliability/maintainability/hotspots/duplicated lines, and no dismissed findings. Real JavaScript and Python coverage includes untested files. OSV, Trivy, Gitleaks source/full history, actionlint, and Zizmor use the same strict commands everywhere.

Generate consistent install, uninstall, testing, packaging, releasing, and development instructions plus live README badges. Packages match GNOME's official packer, releases promote the tested artifact for the tagged commit, and Pages deploys only after main CI passes. GitHub topics and public security settings are aligned. No website or profile listing was added for the canonical repository.

Validation: full local CI, Chromium/Firefox accessibility and behavior checks, deterministic/official packer comparison, strict scanner audits, staged secret scans, and isolated GNOME 50 lifecycle checks pass. Shared Python publication-boundary tests raise tooling coverage to 91% with no exclusions. Final hosted checks and the merged canonical revision remain required before this PR merges. GNOME 49 testing and real Spotify pairing/playback remain manual where applicable.

Adopt the immutable shared workflows and tooling, generate consistent
installation and development docs, and fix findings exposed by strict
checks without suppressing them.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@napalm255
napalm255 marked this pull request as ready for review October 3, 2026 21:37
Analyze PR changes and the full main branch using exact revisions.
Report Python tooling coverage without excluding first-party files.
Pin the merged canonical revision and cover publication boundaries.
Report all runtime JavaScript and Python tooling without exclusions.
Install native packaging tools for Python tests in the Sonar job.
@napalm255
napalm255 enabled auto-merge (squash) October 3, 2026 22:30
@sonarqubecloud

sonarqubecloud Bot commented Oct 3, 2026

Copy link
Copy Markdown

@napalm255
napalm255 merged commit 4ef3a82 into main Oct 3, 2026
8 checks passed
@napalm255
napalm255 deleted the ci/standardize-quick-tooling branch October 3, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants