Commit Graph
38 Commits
Author SHA1 Message Date
mroberts 57e25f86f2 fix(ci): grant contents:write to the Gitea release job
CI / build (push) Successful in 10s
CI / workflows (push) Successful in 9s
Release / release (push) Successful in 20s
The top-level `permissions: contents: read` added alongside the zizmor
hardening applies to the release job too, and Gitea honours it: the built-in
gitea-actions token became read-only, so `tea releases create` failed with
"user should have a permission to write to a repo" (run 759).

The .github workflow already narrowed write to its release job; the Gitea
workflow has a single job and was left read-only. Grant it contents: write,
keeping the read-only default at the top level.
2026-07-21 15:23:29 -05:00
mroberts 250b3e98ca ci: pin actions to SHAs and gate workflows on actionlint + zizmor
CI / build (push) Successful in 49s
CI / workflows (push) Successful in 16s
Release / release (push) Failing after 19s
Pins every action to the latest release SHA within its current major, so
no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0,
upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2.

Adds a `workflows` CI job running actionlint and zizmor. actionlint comes
from `go install` (module proxy checksums cover integrity); zizmor has no
published checksums, so its release tarball is pinned by version and
verified against a recorded sha256. The gate uses --min-severity=low, which
fails on low and above while tolerating the one informational
superfluous-actions advisory.

zizmor only collects from .github/workflows: pointing it at .gitea/workflows
yields "no inputs collected", and when both directories are passed it audits
only .github and still exits 0. The gate therefore passes explicit *.yml
paths, which is the only form that actually audits the Gitea workflows.

Auditing them for the first time surfaced seven findings, now fixed:
credential persistence on checkout (persist-credentials: false), setup-go
caching on the release path (cache: false), and missing top-level
permissions (contents: read, with contents: write narrowed to the GitHub
release job that needs it).
2026-07-21 15:16:55 -05:00
mroberts 5b101bc6dd ci(release): fix Gitea repo slug; bump to 0.6.2
CI / build (push) Successful in 59s
The release workflow targeted mroberts/sush, which does not exist
(`tea releases list --repo mroberts/sush` returns "not found"), so the
release step would fail after building the binaries. Present since the
workflow was added in a7a561f.

Also bump softprops/action-gh-release to v2 in the unused .github
workflow; actionlint rejects v1 as too old to run.
2026-07-21 15:07:46 -05:00
mroberts 70188eb4ea fix(git): use jj as diff source in jujutsu repos
In a colocated jj repo, jj does not maintain git's index for git's own
consumption. git can therefore report an unmodified tracked file as a
whole-file add: for tests/integration/test_texttoentities_endpoint.py in
the IO repo, `git ls-tree HEAD` and `git ls-files -s` both showed the same
blob, yet `git status` reported `AM` and `git diff --cached --unified=0`
emitted a single `@@ -0,0 +1,330 @@` hunk.

shush treats every line in that hunk as agent-changed, so `--changes-only`
stripped all six comments from a file the agent had never touched (`jj diff`
confirmed 0 insertions). Diffing against HEAD instead of the index does not
help: it is poisoned the same way.

jj is authoritative when present, so DetectRepo now prefers `jj root` and
the three change queries route to `jj diff --git --context=0`. jj has no
staging area, so --staged, --unstaged and --changes-only all resolve to the
working-copy change; GetChangesOnly short-circuits so files are not
duplicated across the staged and unstaged passes.

Empty line ranges are overloaded to mean "process the whole file" (untracked
semantics). A deletion-only change parses to zero ranges, which would have
made shush strip an entire file whose only edit removed lines, so such files
are now skipped. New files still get correct full-file ranges from jj's
`@@ -0,0 +1,N @@` hunk, so they do not need the fallback.

Pagers are disabled explicitly on every git and jj invocation so output
stays machine-parseable regardless of the user's config.
2026-07-21 15:07:46 -05:00
mroberts 33b1b2370b ci(release): make release idempotent; bump to 0.6.1
CI / build (push) Successful in 1m34s
tea releases create fails if a release already exists, leaving stale
binaries on tag re-push. Delete any existing release for the tag first
so re-runs self-heal.
2026-07-17 12:54:00 -05:00
mroberts bb963169dd feat(hooks): add --hook-output flag reporting removed comments
Emits Claude Code PostToolUse JSON so automated comment removal is
announced in-context instead of appearing as a silent mutation.
--install-hook now writes 'shush --changes-only --hook-output'.

Bump version to 0.6.0.
2026-07-17 12:42:41 -05:00
mroberts e5536f9cce chore: bump version to 0.5.0
Also point make push at origin; upstream remote does not exist.
2026-07-08 13:24:29 -05:00
mroberts 59c48a36cb feat(config): preserve doc-style comments by default
Strip pass was eating JSDoc/Javadoc blocks. Add default preserve
patterns for /** blocks, /*! banners, /// and //! line docs.
Opt out by overriding preserve in .shush.toml.
2026-07-08 13:24:29 -05:00
mroberts 272ce89ec5 fix(git): bypass external diff driver; preserve version pins and zizmor
- git: pass --no-ext-diff so difftastic/other diff.external drivers don't
  break --unified=0 parsing (was yielding zero ranges -> whole-file strip)
- config: add /regex/ preserve patterns; keep version pins (# v2.1.6) and
  zizmor: directives by default
- bump version to 0.4.2
2026-07-03 12:49:46 -05:00
mroberts 80e93e9e15 ci: make tea login idempotent (delete stale login before add) 2026-07-03 09:23:37 -05:00
mroberts f8d3199bde chore: bump version to 0.4.1 2026-07-03 09:16:03 -05:00
mroberts 480aebfcd0 feat(config): preserve lint/tool directives by default across supported languages 2026-07-03 09:00:21 -05:00
mroberts 57bb1c4b62 chore: bump version to 0.4.0 2026-07-02 09:54:51 -05:00
mroberts a7a561fbbd ci: add Gitea release workflow using tea CLI 2026-07-02 09:20:06 -05:00
mroberts 41a491564f ci: add Gitea Actions build/test workflow 2026-07-02 09:20:06 -05:00
mroberts 85f83a8aaf test(languages): tier-1 language comment-removal goldens 2026-07-02 09:20:06 -05:00
mroberts 2f37640302 feat(languages): register tier-1 languages and chroma routing 2026-07-02 09:20:06 -05:00
mroberts 22e2c2d169 docs: tier-1 language additions plan 2026-07-02 09:20:06 -05:00
mroberts fda9a8a295 fix(processor): annotate every removed line in multi-line preview windows 2026-07-02 09:20:06 -05:00
mroberts 2711f141fd docs: note .sass routes through SCSS lexer 2026-07-02 09:20:06 -05:00
mroberts b07ea41c60 test(processor): multi-line golden fixtures; route .sass through SCSS lexer 2026-07-02 09:20:06 -05:00
mroberts bbc49efbfe feat(processor): route preview paths through StripComments 2026-07-02 09:20:06 -05:00
mroberts 7ef198016e feat(processor): route mutation paths through StripComments 2026-07-02 09:20:06 -05:00
mroberts 3e73ce7b2e build: require go 1.25 (chroma v2.27) and align release workflow 2026-07-02 09:20:06 -05:00
mroberts 811f1c13ff feat(processor): StripComments chroma engine with legacy fallback 2026-07-02 09:20:06 -05:00
mroberts 82b84c12d2 feat(processor): add chroma dep, lexer resolution and drop rules 2026-07-02 09:20:06 -05:00
mroberts c348204a47 docs: multi-line comment implementation plan (chroma) 2026-07-02 09:20:06 -05:00
mroberts 711691559b docs: rewrite multi-line comment spec around chroma tokenizer 2026-07-02 09:20:06 -05:00
mroberts c59a782d7d docs: multi-line block comment support design spec 2026-07-02 09:20:06 -05:00
mroberts 16fc10c59a test(processor): remove code comments from wholefile_test 2026-07-02 09:20:06 -05:00
mroberts 31619dc7ee test(processor): guard -update against CI misuse; drop agent report md 2026-07-02 09:20:06 -05:00
mroberts 3db4911e7a test(processor): git-mode whole-file and line-range cases 2026-07-02 09:20:06 -05:00
mroberts a117f75bba test(processor): preservation, preserve-lines, backup cases 2026-07-02 09:20:06 -05:00
mroberts 42c46aa2d5 test(processor): single-line block + inline/block flag cases 2026-07-02 09:20:06 -05:00
mroberts d3ab6a41be test(processor): line-comment, string-protection, structure cases 2026-07-02 09:20:06 -05:00
mroberts f51fb3f170 test(processor): whole-file golden driver + seed python cases 2026-07-02 09:20:06 -05:00
mroberts 9e9b292a6f refactor(processor): inject cfg into file-mutating methods 2026-07-02 09:20:06 -05:00
mroberts 27681bc56a wip: baseline before wholefile tests 2026-07-02 09:20:06 -05:00