Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
24 changes: 11 additions & 13 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -1,23 +1,21 @@
# EditorConfig — Phenotype org canonical
# https://editorconfig.org
root = true

[*]
charset = utf-8
indent_style = space
indent_size = 2
end_of_line = lf
charset = utf-8
trim_trailing_whitespace = true
insert_final_newline = true
indent_style = space

[*.md]
trim_trailing_whitespace = false

[*.rs]
indent_size = 4
trim_trailing_whitespace = true

[*.{rs,toml,py,go,md,yaml,yml,json,html,css,scss}]
[*.py]
indent_size = 4

[*.{ts,tsx,js,jsx,mjs,cjs}]
[*.toml]
indent_size = 2

[Makefile]
indent_style = tab

[*.md]
trim_trailing_whitespace = false # trailing spaces = line break in Markdown
21 changes: 21 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# CODEOWNERS — default reviewers for this repository.
# Order matters: later rules override earlier ones.

* @KooshaPari

# Governance / meta
/.github/ @KooshaPari
/SECURITY.md @KooshaPari
/CODEOWNERS @KooshaPari
/.github/CODEOWNERS @KooshaPari

# Per-ecosystem drill-down
/rust/ @KooshaPari
/electron/ @KooshaPari
/open-sse/ @KooshaPari
/desktop-electrobun/ @KooshaPari
/docs/ @KooshaPari
/crates/ @KooshaPari

# CI ownership
/.github/workflows/ @KooshaPari
48 changes: 48 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
# Dependabot configuration for OmniRoute.
version: 2

updates:
- package-ecosystem: "npm"
directory: "/"
schedule: { interval: "weekly", day: "monday", time: "09:00", timezone: "America/New_York" }
open-pull-requests-limit: 5
reviewers: ["KooshaPari"]
commit-message: { prefix: "chore(deps)", include: "scope" }
labels: ["dependencies", "automated"]
groups:
react-ecosystem:
patterns: ["react*", "@types/react*"]
testing-frameworks:
patterns: ["vitest*", "playwright*", "@testing-library/*", "jest*"]
build-tools:
patterns: ["vite*", "next*", "turbo*", "eslint*", "typescript*"]

- package-ecosystem: "npm"
directory: "/open-sse"
schedule: { interval: "weekly", day: "monday" }
open-pull-requests-limit: 3
labels: ["dependencies", "automated"]

- package-ecosystem: "npm"
directory: "/electron"
schedule: { interval: "weekly", day: "monday" }
open-pull-requests-limit: 3
labels: ["dependencies", "automated"]

- package-ecosystem: "npm"
directory: "/desktop-electrobun"
schedule: { interval: "weekly", day: "monday" }
open-pull-requests-limit: 3
labels: ["dependencies", "automated"]

- package-ecosystem: "docker"
directory: "/"
schedule: { interval: "weekly", day: "monday" }
open-pull-requests-limit: 3
labels: ["dependencies", "docker"]

- package-ecosystem: "github-actions"
directory: "/"
schedule: { interval: "weekly", day: "monday" }
open-pull-requests-limit: 5
labels: ["dependencies", "ci"]
48 changes: 48 additions & 0 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
name: OpenSSF Scorecard

on:
workflow_dispatch:
branch_protection_rule:
schedule:
- cron: '0 9 * * 1'

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions: read-all

Check warning on line 13 in .github/workflows/scorecard.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Replace "read-all" with specific permissions (e.g., "contents: read").

See more on https://sonarcloud.io/project/issues?id=KooshaPari_OmniRoute&issues=AZ6qUEtww1NiOy0GoSLK&open=AZ6qUEtww1NiOy0GoSLK&pullRequest=31

jobs:
scorecard:
name: Scorecard analysis
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
security-events: write
id-token: write
contents: read
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
with:
persist-credentials: false

- name: Run OpenSSF Scorecard
uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde
with:
results_file: results.sarif
results_format: sarif
publish_results: true

- name: Upload SARIF artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: scorecard-sarif
path: results.sarif
retention-days: 5

- name: Upload SARIF to code scanning
uses: github/codeql-action/upload-sarif@0daab03d71ff584ef619d027a3fd9146679c5d84
with:
sarif_file: results.sarif
7 changes: 7 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -167,6 +167,13 @@ http-client.private.env.json
scripts/i18n/_audit.json
scripts/i18n/_pending-keys.json

# i18n translation content (ADR-0005 — generated by scripts/i18n/sync.mjs;
# checked-in copies are 682K MD LOC of machine translation in 40+ languages.
# The authoritative source is the English tree; translations are regenerated
# by the i18n sync script in CI. Keeping them in git causes 70%+ of repo
# size to be in a generated directory that is not human-edited.)
docs/i18n/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitignore breaks docs-sync CI

High Severity

Ignoring docs/i18n/ conflicts with npm run check:docs-sync on the lint job: scripts/check/check-docs-sync.mjs fails when docs/i18n is missing. Once tracked translations are removed per ADR-0005, clones and CI lack that tree and no workflow step regenerates it before the check.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 5ddb706. Configure here.


# Private workflow / skill / command implementations
# These contain proprietary multi-phase logic and should not be committed
.agents/workflows/implement-features-ag.md
Expand Down
Loading
Loading