From edd76b1e236784a16f4e2c3481969aea97fdbdbb Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 11:19:08 +0900 Subject: [PATCH 1/7] =?UTF-8?q?ci:=20=F0=9F=A4=96=20=E5=93=81=E8=B3=AA?= =?UTF-8?q?=E5=90=91=E4=B8=8A=E3=83=AF=E3=83=BC=E3=82=AF=E3=83=95=E3=83=AD?= =?UTF-8?q?=E3=83=BC=E3=82=92=E5=B0=8E=E5=85=A5?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/PULL_REQUEST_TEMPLATE.md | 36 +++++++++++++++++++ .github/workflows/actionlint.yml | 43 ++++++++++++++++++++++ .github/workflows/codeql.yml | 47 ++++++++++++++++++++++++ .github/workflows/gitleaks.yml | 57 ++++++++++++++++++++++++++++++ .github/workflows/markdownlint.yml | 40 +++++++++++++++++++++ .markdownlint-cli2.jsonc | 35 ++++++++++++++++++ 6 files changed, 258 insertions(+) create mode 100644 .github/PULL_REQUEST_TEMPLATE.md create mode 100644 .github/workflows/actionlint.yml create mode 100644 .github/workflows/codeql.yml create mode 100644 .github/workflows/gitleaks.yml create mode 100644 .github/workflows/markdownlint.yml create mode 100644 .markdownlint-cli2.jsonc diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..b6049ae --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,36 @@ + + +## 概要 + + + +## 関連 Issue + + + +## 変更内容 + + + +- +- + +## 動作確認 + + + +- [ ] ローカルで動作確認した +- [ ] テストを追加・更新した(または不要な理由を記載) + +## セルフチェック + +- [ ] 既存の lint / typecheck / test がパスする +- [ ] 破壊的変更がある場合、README または docs を更新した +- [ ] secret / 個人情報を含むコードや設定が含まれていない + +## 補足 + + diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml new file mode 100644 index 0000000..ccf6542 --- /dev/null +++ b/.github/workflows/actionlint.yml @@ -0,0 +1,43 @@ +name: actionlint + +on: + push: + branches: [main] + paths: + - '.github/workflows/**' + - '.github/actionlint*' + pull_request: + branches: [main] + paths: + - '.github/workflows/**' + - '.github/actionlint*' + +concurrency: + group: actionlint-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + actionlint: + name: actionlint + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + + - name: Download actionlint + id: actionlint + run: | + set -euo pipefail + VERSION=1.7.7 + TARBALL="actionlint_${VERSION}_linux_amd64.tar.gz" + curl -fsSL -o "/tmp/${TARBALL}" "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/${TARBALL}" + curl -fsSL -o /tmp/checksums.txt "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/actionlint_${VERSION}_checksums.txt" + cd /tmp && grep "${TARBALL}" checksums.txt | sha256sum -c - + tar -xzf "/tmp/${TARBALL}" -C /tmp actionlint + echo "executable=/tmp/actionlint" >> "$GITHUB_OUTPUT" + + - name: Run actionlint + run: | + "${{ steps.actionlint.outputs.executable }}" -color diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml new file mode 100644 index 0000000..edaf485 --- /dev/null +++ b/.github/workflows/codeql.yml @@ -0,0 +1,47 @@ +name: CodeQL + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + # 毎週月曜 03:00 JST (= 日曜 18:00 UTC) に main を再スキャン + - cron: '0 18 * * 0' + +concurrency: + group: codeql-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + security-events: write + actions: read + +jobs: + analyze: + name: Analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + # frontend は tsx、backend は ts。両方とも 'javascript-typescript' でまとめてスキャン。 + language: ['javascript-typescript'] + steps: + - name: Checkout + uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false + + - name: Initialize CodeQL + uses: github/codeql-action/init@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + languages: ${{ matrix.language }} + # security-extended は誤検知が増えるため、まずは security-and-quality で運用。 + # ノイズが多い場合は 'security' に下げる。 + queries: security-and-quality + + - name: Perform CodeQL Analysis + uses: github/codeql-action/analyze@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + category: '/language:${{ matrix.language }}' diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml new file mode 100644 index 0000000..bda3c0d --- /dev/null +++ b/.github/workflows/gitleaks.yml @@ -0,0 +1,57 @@ +name: Gitleaks + +on: + push: + branches: [main] + pull_request: + branches: [main] + schedule: + # 毎週月曜 05:00 JST (= 日曜 20:00 UTC) に履歴全体を再スキャン + - cron: '0 20 * * 0' + workflow_dispatch: + +concurrency: + group: gitleaks-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + security-events: write + +jobs: + gitleaks: + name: Scan for leaked secrets + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + # 履歴全体をスキャンするためフルクローン + fetch-depth: 0 + persist-credentials: false + + - name: Install gitleaks + run: | + set -euo pipefail + GITLEAKS_VERSION=8.21.2 + curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" + tar -xzf "gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" gitleaks + sudo mv gitleaks /usr/local/bin/gitleaks + gitleaks version + + - name: Run gitleaks + run: | + gitleaks detect \ + --source . \ + --redact \ + --verbose \ + --no-banner \ + --exit-code 1 \ + --report-format sarif \ + --report-path gitleaks.sarif + + - name: Upload SARIF + if: always() + uses: github/codeql-action/upload-sarif@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3 + with: + sarif_file: gitleaks.sarif + category: gitleaks diff --git a/.github/workflows/markdownlint.yml b/.github/workflows/markdownlint.yml new file mode 100644 index 0000000..c9c42b8 --- /dev/null +++ b/.github/workflows/markdownlint.yml @@ -0,0 +1,40 @@ +name: markdownlint + +on: + push: + branches: [main] + paths: + - '**/*.md' + - '.markdownlint-cli2.jsonc' + - '.github/workflows/markdownlint.yml' + pull_request: + branches: [main] + paths: + - '**/*.md' + - '.markdownlint-cli2.jsonc' + - '.github/workflows/markdownlint.yml' + +concurrency: + group: markdownlint-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + markdownlint: + name: markdownlint-cli2 + runs-on: ubuntu-latest + # 既存ドキュメントの MD040/MD031 違反を片付けるまでは赤検知にしない。 + # 整備完了後に continue-on-error を外して赤検知に切り替える。 + continue-on-error: true + steps: + - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false + + - name: Run markdownlint-cli2 + uses: DavidAnson/markdownlint-cli2-action@992badcdf24e3b8eb7e87ff9287fe931bcb00c6e # v20 + with: + config: '.markdownlint-cli2.jsonc' + globs: '**/*.md' diff --git a/.markdownlint-cli2.jsonc b/.markdownlint-cli2.jsonc new file mode 100644 index 0000000..074b6c3 --- /dev/null +++ b/.markdownlint-cli2.jsonc @@ -0,0 +1,35 @@ +{ + // markdownlint-cli2 設定 + // https://github.com/DavidAnson/markdownlint-cli2 + "config": { + "default": true, + // 行長制限: コード/表/長文を伴うドキュメントが多いので無効化 + "MD013": false, + // インライン HTML: README や PR テンプレで やテーブル装飾を使うので許可 + "MD033": false, + // 単一の H1 を強制: 既存ドキュメントが満たさないものがあるため無効化 + "MD025": false, + // 重複ヘッダ: docs で「概要」が複数出るので緩める + "MD024": { "siblings_only": true }, + // 最初の行が H1 でなくてもよい (PR テンプレなど) + "MD041": false, + // 強調を見出しに使ってよい + "MD036": false, + // bare URL を許可 (GitHub flavored Markdown で自動リンク化される) + "MD034": false, + // テーブル列スタイル: 重要度が低いため無効化 + "MD060": false, + // blockquote 内の空行: 引用節を見やすくするため許可 + "MD028": false, + }, + "globs": ["**/*.md"], + "ignores": [ + "node_modules/**", + "**/node_modules/**", + ".claude/**", + "dist/**", + "**/dist/**", + "build/**", + "**/build/**", + ], +} From 6a03db0ade2590cd0b1c34006bdae89192f696e6 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:17:06 +0900 Subject: [PATCH 2/7] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20act?= =?UTF-8?q?ionlint=E3=83=AF=E3=83=BC=E3=82=AF=E3=83=95=E3=83=AD=E3=83=BC?= =?UTF-8?q?=E3=81=ABpersist-credentials:=20false=E3=82=92=E8=BF=BD?= =?UTF-8?q?=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit git push操作を行わないワークフローでのトークン永続化リスクを排除。 レビューコメント: https://github.com/genzouw/kakezan-manabo/pull/30#discussion_r3270868366 レビュアー: coderabbitai 優先度: high --- .github/workflows/actionlint.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/actionlint.yml b/.github/workflows/actionlint.yml index ccf6542..4299723 100644 --- a/.github/workflows/actionlint.yml +++ b/.github/workflows/actionlint.yml @@ -4,13 +4,13 @@ on: push: branches: [main] paths: - - '.github/workflows/**' - - '.github/actionlint*' + - ".github/workflows/**" + - ".github/actionlint*" pull_request: branches: [main] paths: - - '.github/workflows/**' - - '.github/actionlint*' + - ".github/workflows/**" + - ".github/actionlint*" concurrency: group: actionlint-${{ github.ref }} @@ -25,6 +25,8 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6 + with: + persist-credentials: false - name: Download actionlint id: actionlint From 0fe8008bfa3bbfbd0c132a243ffb7143d015dd04 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:17:21 +0900 Subject: [PATCH 3/7] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20git?= =?UTF-8?q?leaks=E3=83=90=E3=82=A4=E3=83=8A=E3=83=AA=E3=81=AEchecksum?= =?UTF-8?q?=E6=A4=9C=E8=A8=BC=E3=82=92=E8=BF=BD=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 改ざん検知のためにchecksumファイルをダウンロードしてsha256sumで 検証してから展開するよう修正。actionlint.ymlと同様のセキュリティ方針に統一。 レビューコメント: https://github.com/genzouw/kakezan-manabo/pull/30#discussion_r3270868372 レビュアー: coderabbitai 優先度: medium --- .github/workflows/gitleaks.yml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index bda3c0d..379d204 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -7,7 +7,7 @@ on: branches: [main] schedule: # 毎週月曜 05:00 JST (= 日曜 20:00 UTC) に履歴全体を再スキャン - - cron: '0 20 * * 0' + - cron: "0 20 * * 0" workflow_dispatch: concurrency: @@ -33,8 +33,12 @@ jobs: run: | set -euo pipefail GITLEAKS_VERSION=8.21.2 - curl -fsSLO "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" - tar -xzf "gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" gitleaks + BASE_URL="https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}" + ARCHIVE="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" + curl -fsSLO "${BASE_URL}/${ARCHIVE}" + curl -fsSLO "${BASE_URL}/gitleaks_${GITLEAKS_VERSION}_checksums.txt" + grep " ${ARCHIVE}$" "gitleaks_${GITLEAKS_VERSION}_checksums.txt" | sha256sum -c - + tar -xzf "${ARCHIVE}" gitleaks sudo mv gitleaks /usr/local/bin/gitleaks gitleaks version From 742d615726dc045f11729fdd7a39199dcd4a7a01 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:17:33 +0900 Subject: [PATCH 4/7] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20PR?= =?UTF-8?q?=E3=83=86=E3=83=B3=E3=83=97=E3=83=AC=E3=83=BC=E3=83=88=E3=81=AE?= =?UTF-8?q?=E7=AE=87=E6=9D=A1=E6=9B=B8=E3=81=8D=E3=82=921=E3=81=A4?= =?UTF-8?q?=E3=81=AB=E6=95=B4=E7=90=86?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 空の項目を残さないよう変更内容セクションのプレースホルダーを 2つから1つに削減。 レビューコメント: https://github.com/genzouw/kakezan-manabo/pull/30#discussion_r3270868077 レビュアー: gemini-code-assist 優先度: low --- .github/PULL_REQUEST_TEMPLATE.md | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index b6049ae..f13c12d 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -15,7 +15,6 @@ -- - ## 動作確認 From 40c4b517b4a5560dfef2906ad82f62a8dacd8877 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:18:46 +0900 Subject: [PATCH 5/7] =?UTF-8?q?fix:=20SC2086=20shellcheck=E8=AD=A6?= =?UTF-8?q?=E5=91=8A=E3=82=92=E4=BF=AE=E6=AD=A3=20-=20=E5=A4=89=E6=95=B0?= =?UTF-8?q?=E5=B1=95=E9=96=8B=E3=81=AB=E3=83=80=E3=83=96=E3=83=AB=E3=82=AF?= =?UTF-8?q?=E3=82=A9=E3=83=BC=E3=83=88=E3=82=92=E8=BF=BD=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit complexity-check.ymlとdeploy.ymlのシェルスクリプト内でクォートなし変数展開を修正 --- .github/workflows/complexity-check.yml | 20 ++++++++++---------- .github/workflows/deploy.yml | 4 ++-- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/complexity-check.yml b/.github/workflows/complexity-check.yml index 9585c7a..46f8654 100644 --- a/.github/workflows/complexity-check.yml +++ b/.github/workflows/complexity-check.yml @@ -31,13 +31,13 @@ jobs: - name: Complexity check summary if: failure() run: | - echo "## Cyclomatic Complexity Check Failed" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "Some functions exceed the maximum cyclomatic complexity of 10." >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "### Why does this matter?" >> $GITHUB_STEP_SUMMARY - echo "- Complexity 10 or less: 25% bug introduction rate" >> $GITHUB_STEP_SUMMARY - echo "- Complexity 40 or more: 50% bug introduction rate" >> $GITHUB_STEP_SUMMARY - echo "- Complexity 75 or more: 98% bug introduction rate" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "Please refactor the flagged functions to reduce complexity." >> $GITHUB_STEP_SUMMARY + echo "## Cyclomatic Complexity Check Failed" >> "$GITHUB_STEP_SUMMARY" + echo "" >> "$GITHUB_STEP_SUMMARY" + echo "Some functions exceed the maximum cyclomatic complexity of 10." >> "$GITHUB_STEP_SUMMARY" + echo "" >> "$GITHUB_STEP_SUMMARY" + echo "### Why does this matter?" >> "$GITHUB_STEP_SUMMARY" + echo "- Complexity 10 or less: 25% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" + echo "- Complexity 40 or more: 50% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" + echo "- Complexity 75 or more: 98% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" + echo "" >> "$GITHUB_STEP_SUMMARY" + echo "Please refactor the flagged functions to reduce complexity." >> "$GITHUB_STEP_SUMMARY" diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 2aa6d32..bb27e6b 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -32,7 +32,7 @@ jobs: - name: Deploy to S3 run: | # Static assets with long cache - aws s3 sync . s3://${S3_BUCKET}/${S3_PREFIX}/ \ + aws s3 sync . "s3://${S3_BUCKET}/${S3_PREFIX}/" \ --delete \ --cache-control "max-age=31536000,public" \ --exclude ".git/*" \ @@ -47,7 +47,7 @@ jobs: --exclude "*.html" # HTML files with no cache - aws s3 sync . s3://${S3_BUCKET}/${S3_PREFIX}/ \ + aws s3 sync . "s3://${S3_BUCKET}/${S3_PREFIX}/" \ --cache-control "max-age=0,no-cache,no-store,must-revalidate" \ --exclude "*" \ --include "*.html" From d697e2c576219db01326ddbe35093b09d35a9e17 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 12:55:42 +0900 Subject: [PATCH 6/7] =?UTF-8?q?fix:=20=F0=9F=90=9B=20[Code=20Review]=20mar?= =?UTF-8?q?kdownlint=20ignores=20=E3=81=AE=E5=86=97=E9=95=B7=E3=82=A8?= =?UTF-8?q?=E3=83=B3=E3=83=88=E3=83=AA=E3=82=92=E5=89=8A=E9=99=A4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `**//**` パターンはルート直下の `/**` にもマッチするため、 個別の `node_modules/**`, `dist/**`, `build/**` エントリは冗長だった。 ローカルでパターン解決を実機確認した上で削除し、設定をシンプル化。 レビューコメント: https://github.com/genzouw/kakezan-manabo/pull/30#discussion_r3270868081 レビュアー: gemini-code-assist 優先度: low --- .markdownlint-cli2.jsonc | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/.markdownlint-cli2.jsonc b/.markdownlint-cli2.jsonc index 074b6c3..165d2c4 100644 --- a/.markdownlint-cli2.jsonc +++ b/.markdownlint-cli2.jsonc @@ -23,13 +23,5 @@ "MD028": false, }, "globs": ["**/*.md"], - "ignores": [ - "node_modules/**", - "**/node_modules/**", - ".claude/**", - "dist/**", - "**/dist/**", - "build/**", - "**/build/**", - ], + "ignores": ["**/node_modules/**", ".claude/**", "**/dist/**", "**/build/**"], } From 93f9f0bd357e583181769f3d9b9cf0253905dca0 Mon Sep 17 00:00:00 2001 From: Toshiaki Wakabayashi Date: Wed, 20 May 2026 13:27:04 +0900 Subject: [PATCH 7/7] =?UTF-8?q?fix(ci):=20shellcheck=20SC2129=20-=20?= =?UTF-8?q?=E3=82=B0=E3=83=AB=E3=83=BC=E3=83=97=E5=8C=96=E3=83=AA=E3=83=80?= =?UTF-8?q?=E3=82=A4=E3=83=AC=E3=82=AF=E3=83=88=E3=81=AB=E5=A4=89=E6=9B=B4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit complexity-check.yml の個別リダイレクト >> file を { cmd1; cmd2; } >> file 形式にまとめる --- .github/workflows/complexity-check.yml | 22 ++++++++++++---------- commitlint.config.cjs | 9 +++++++++ 2 files changed, 21 insertions(+), 10 deletions(-) create mode 100644 commitlint.config.cjs diff --git a/.github/workflows/complexity-check.yml b/.github/workflows/complexity-check.yml index 139b48c..e66eb77 100644 --- a/.github/workflows/complexity-check.yml +++ b/.github/workflows/complexity-check.yml @@ -31,13 +31,15 @@ jobs: - name: Complexity check summary if: failure() run: | - echo "## Cyclomatic Complexity Check Failed" >> "$GITHUB_STEP_SUMMARY" - echo "" >> "$GITHUB_STEP_SUMMARY" - echo "Some functions exceed the maximum cyclomatic complexity of 10." >> "$GITHUB_STEP_SUMMARY" - echo "" >> "$GITHUB_STEP_SUMMARY" - echo "### Why does this matter?" >> "$GITHUB_STEP_SUMMARY" - echo "- Complexity 10 or less: 25% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" - echo "- Complexity 40 or more: 50% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" - echo "- Complexity 75 or more: 98% bug introduction rate" >> "$GITHUB_STEP_SUMMARY" - echo "" >> "$GITHUB_STEP_SUMMARY" - echo "Please refactor the flagged functions to reduce complexity." >> "$GITHUB_STEP_SUMMARY" + { + echo "## Cyclomatic Complexity Check Failed" + echo "" + echo "Some functions exceed the maximum cyclomatic complexity of 10." + echo "" + echo "### Why does this matter?" + echo "- Complexity 10 or less: 25% bug introduction rate" + echo "- Complexity 40 or more: 50% bug introduction rate" + echo "- Complexity 75 or more: 98% bug introduction rate" + echo "" + echo "Please refactor the flagged functions to reduce complexity." + } >> "$GITHUB_STEP_SUMMARY" diff --git a/commitlint.config.cjs b/commitlint.config.cjs new file mode 100644 index 0000000..706a52d --- /dev/null +++ b/commitlint.config.cjs @@ -0,0 +1,9 @@ +module.exports = { + extends: ["@commitlint/config-conventional"], + rules: { + "header-max-length": [2, "always", 70], + "scope-case": [2, "always", ["camel-case", "kebab-case", "upper-case"]], + "subject-case": [0, "always"], + "body-max-line-length": [2, "always", 120], + }, +};