Fix audit tool bootstrap and add per-run preflight
audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
and --user-only (no system package managers, no sudo).
log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.
audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).
Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
This commit is contained in:
@@ -54,6 +54,23 @@ from scripts.runner import run_tool, tool_available
|
||||
from scripts.slicing import slice_for_agent
|
||||
|
||||
|
||||
# Anything not listed here is installed by the skill's own bootstrap script.
|
||||
_INSTALL_TOOLS = f"bash {_HERE / 'install-tools.sh'} --user-only"
|
||||
_INSTALL_COMMANDS = {
|
||||
"eslint": "npm i -D eslint eslint-plugin-security",
|
||||
"tsc": "npm i -D typescript",
|
||||
"knip": "npm i -D knip",
|
||||
"jscpd": "npm i -D jscpd",
|
||||
"dotnet": "curl -fsSL https://dot.net/v1/dotnet-install.sh | bash",
|
||||
"selene": "cargo install selene",
|
||||
"luac": "install lua (ships luac) with your OS package manager",
|
||||
"actionlint": "go install github.com/rhysd/actionlint/cmd/actionlint@latest",
|
||||
"zizmor": "uv tool install zizmor",
|
||||
"gitleaks": "go install github.com/zricethezav/gitleaks/v8@latest",
|
||||
"osv-scanner": "go install github.com/google/osv-scanner/v2/cmd/osv-scanner@latest",
|
||||
}
|
||||
|
||||
|
||||
def _git_show(repo: str, ref: str, path: str) -> str:
|
||||
"""Return file content at `ref`, or empty string if not present (e.g. new file)."""
|
||||
r = subprocess.run(
|
||||
@@ -350,7 +367,7 @@ def main(argv: list[str] | None = None) -> int:
|
||||
default_branch=default_branch,
|
||||
language_breakdown=LanguageBreakdown(),
|
||||
changed_files=[], findings=[],
|
||||
package_diffs={}, tool_stats={}, tools_unavailable=[],
|
||||
package_diffs={}, tool_stats={}, tools_unavailable={},
|
||||
errors=[str(e)],
|
||||
)
|
||||
(out_dir / "manifest.json").write_text(manifest.to_json())
|
||||
@@ -396,7 +413,7 @@ def main(argv: list[str] | None = None) -> int:
|
||||
mode=args.mode, base_ref=base, head_ref=args.head,
|
||||
default_branch=default_branch, language_breakdown=breakdown,
|
||||
changed_files=[], findings=[],
|
||||
package_diffs={}, tool_stats={}, tools_unavailable=[],
|
||||
package_diffs={}, tool_stats={}, tools_unavailable={},
|
||||
errors=errors,
|
||||
)
|
||||
(out_dir / "manifest.json").write_text(manifest.to_json())
|
||||
@@ -433,7 +450,10 @@ def main(argv: list[str] | None = None) -> int:
|
||||
if stat.ran:
|
||||
stat.post_filter = sum(1 for f in filtered if f.tool == tool_name)
|
||||
|
||||
tools_unavailable = [name for name, s in tool_stats.items() if not s.ran]
|
||||
tools_unavailable = {
|
||||
name: _INSTALL_COMMANDS.get(name, _INSTALL_TOOLS)
|
||||
for name, s in tool_stats.items() if not s.ran
|
||||
}
|
||||
|
||||
package_diffs = _build_package_diffs(repo, base, dep_manifest_paths)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user