ci: standardize quick extension tooling and security - #29
Merged
Merged
Conversation
Adopt the immutable shared workflows and tooling, generate consistent installation and development docs, and fix findings exposed by strict checks without suppressing them.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
napalm255
marked this pull request as ready for review
October 3, 2026 21:37
Analyze PR changes and the full main branch using exact revisions. Report Python tooling coverage without excluding first-party files.
Pin the merged canonical revision and cover publication boundaries. Report all runtime JavaScript and Python tooling without exclusions. Install native packaging tools for Python tests in the Sonar job.
napalm255
enabled auto-merge (squash)
October 3, 2026 22:30
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Standardize CI, security, packaging, badges, and common documentation with the same 33 managed files from Ghost-Assembly/quick-template. Immutable archive verification rejects drift and CI overrides; project hooks and metadata retain extension-specific behavior.
Require local just ci, CodeQL JavaScript/Python security-extended, and authenticated Sonar through SONAR_TOKEN. Sonar Free-compatible PR analysis checks changed code, and main analysis checks all source; both require exact revisions, zero security/reliability/maintainability/hotspots/duplicated lines, and no dismissed findings. Real JavaScript and Python coverage includes untested files. OSV, Trivy, Gitleaks source/full history, actionlint, and Zizmor use the same strict commands everywhere.
Generate consistent install, uninstall, testing, packaging, releasing, and development instructions plus live README badges. Packages match GNOME's official packer, releases promote the tested artifact for the tagged commit, and Pages deploys only after main CI passes. GitHub topics and public security settings are aligned. No website or profile listing was added for the canonical repository.
Validation: full local CI, Chromium/Firefox accessibility and behavior checks, deterministic/official packer comparison, strict scanner audits, staged secret scans, and isolated GNOME 50 lifecycle checks pass. Shared Python publication-boundary tests raise tooling coverage to 91% with no exclusions. Final hosted checks and the merged canonical revision remain required before this PR merges. GNOME 49 testing and real Spotify pairing/playback remain manual where applicable.