audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
and --user-only (no system package managers, no sudo).
log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.
audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).
Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
31 lines
649 B
TOML
31 lines
649 B
TOML
[project]
|
|
name = "audit-code"
|
|
version = "0.1.0"
|
|
description = "Multi-language code review skill — runs OSS linters, normalizes findings, fans out review agents."
|
|
requires-python = ">=3.11"
|
|
dependencies = []
|
|
|
|
[dependency-groups]
|
|
tools = [
|
|
"bandit>=1.7",
|
|
"ruff>=0.6",
|
|
"mypy>=1.10",
|
|
"pip-audit>=2.7",
|
|
"vulture>=2.0",
|
|
"radon>=6.0",
|
|
"interrogate>=1.7",
|
|
"lizard>=1.17",
|
|
]
|
|
dev = [
|
|
"pytest>=8.0",
|
|
]
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
"scripts/collect-findings.py" = ["E402"]
|
|
"scripts/log-run.py" = ["E402"]
|
|
|
|
[tool.pytest.ini_options]
|
|
markers = [
|
|
"integration: end-to-end test requiring external linters on PATH",
|
|
]
|