-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy path.pre-commit-config.yaml
More file actions
60 lines (54 loc) · 1.63 KB
/
Copy path.pre-commit-config.yaml
File metadata and controls
60 lines (54 loc) · 1.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
# LinuxAgent v4 pre-commit hooks.
# Run locally: pre-commit install && pre-commit run --all-files
exclude: ^(legacy/|\.work/|configs/example\.yaml$)
repos:
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.6.0
hooks:
- id: trailing-whitespace
- id: end-of-file-fixer
- id: check-yaml
- id: check-toml
- id: check-added-large-files
args: ['--maxkb=500']
- id: detect-private-key
- id: check-merge-conflict
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: v0.6.9
hooks:
- id: ruff
args: [--fix]
- id: ruff-format
- repo: https://github.com/pre-commit/mirrors-mypy
rev: v1.11.2
hooks:
- id: mypy
files: ^src/linuxagent/
additional_dependencies:
- langchain-core>=1.3
- pydantic>=2.7
- types-PyYAML
- types-requests
- repo: https://github.com/PyCQA/bandit
rev: 1.7.10
hooks:
- id: bandit
args: [-ll, -r]
files: ^src/linuxagent/
- repo: local
hooks:
- id: redline-shell-true
name: R-SEC-01 ban shell=True
entry: bash -c '! grep -rn "shell=True" src/linuxagent/'
language: system
pass_filenames: false
- id: redline-autoadd
name: R-SEC-03 ban AutoAddPolicy
entry: bash -c '! grep -rn "AutoAddPolicy" src/linuxagent/'
language: system
pass_filenames: false
- id: redline-bare-except
name: R-QUAL-01 ban bare except
entry: bash -c '! grep -rnE "^[[:space:]]*except:[[:space:]]*$" src/linuxagent/'
language: system
pass_filenames: false