Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
name: CI

on:
push:
branches: [main]
pull_request:

jobs:
verify:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win

Add persist-credentials: false to the checkout step.

By default, actions/checkout@v4 persists the GITHUB_TOKEN in .git/config for subsequent steps. Since this job only needs the source tree (no git pushes), disabling credential persistence reduces the risk of token leakage if a later step is compromised.

🔒️ Proposed fix
     steps:
-      - uses: actions/checkout@v4
+      - uses: actions/checkout@v4
+        with:
+          persist-credentials: false
       - uses: actions/setup-go@v5
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
persist-credentials: false
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml at line 12, Update the actions/checkout@v4 step to
disable persisted GitHub credentials by setting persist-credentials to false,
while leaving the checkout behavior otherwise unchanged.

Source: Linters/SAST tools

- uses: actions/setup-go@v5
with:
go-version: "1.24.2"
- name: Install golangci-lint
run: |
curl -sSf https://raw.githubusercontent.com/golangci/golangci-lint/master/install.sh | sh -s -- -b $(go env GOPATH)/bin v1.62.2
- run: go vet ./...
- run: gofmt -l . | tee /dev/stderr | (! read) # fail if any file needs formatting
- run: golangci-lint run
- run: go test ./...
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,6 @@ Thumbs.db
vendor/
.superpowers/
.worktrees/

# Backup files
*.bak
8 changes: 7 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
.PHONY: build test lint clean
.PHONY: build test lint vet fmt-check clean

build:
go build -o shenron ./cmd/shenron/
Expand All @@ -9,5 +9,11 @@ test:
lint:
golangci-lint run

vet:
go vet ./...

fmt-check:
@test -z "$$(gofmt -l . | tee /dev/stderr)" || (echo "files need gofmt" && exit 1)

clean:
rm -f shenron
19 changes: 11 additions & 8 deletions docs/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,16 +109,16 @@ duplicates, missing required values, invalid cross-references, conflicting
prompt sources, missing prompt files, invalid temperatures, and unsupported
permission values are rejected before any target generation or write occurs.

The parser currently accepts YAML fields that are unknown to the Go structs,
because it uses the default `yaml.Unmarshal` behavior rather than strict known-
field decoding.
Package loads use `pivot.ParseStrict`, which rejects unknown YAML fields. The
legacy `pivot.Parse` used by the library escape hatch still accepts unknown
fields.

## Synchronization pipeline

`diff <name>` and `push <name>` share the preparation path in
`internal/cli`. Every command operates on a package snapshot under
`~/.shenron/packages/<name>/<active-digest>/`, with state under
`~/.shenron/state/<name>/`:
`~/.shenron/packages/packages/<name>/<active-digest>/`, with state under
`~/.shenron/packages/state/<name>/`:

```mermaid
sequenceDiagram
Expand Down Expand Up @@ -187,9 +187,12 @@ is classified as manually modified. `push` refuses to overwrite it unless
`--force` is supplied. Files previously tracked but no longer generated are
classified as orphaned and reported; they are not deleted.

The state file lives beside the pivot as `.shenron-state.json`. It records the
content hash, path, and owning adapter for each written file. Adapter ownership
keeps a targeted push from reporting another target's files as orphaned.
The library `RunDiff`/`RunPush` escape hatch keeps the state file beside the
pivot as `.shenron-state.json`; the package flow instead stores it under
`store.StateDir(name)`, outside the immutable snapshot. Either way it records
the content hash, path, and owning adapter for each written file. Adapter
ownership keeps a targeted push from reporting another target's files as
orphaned.

### Writes

Expand Down
Loading
Loading