Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
<!--
PR の説明テンプレート。
該当しないセクションは削除して構いません。
-->

## 概要

<!-- このPRが何を解決するか / 何を追加するかを1〜3行で。 -->

## 関連 Issue

<!-- 例: Closes #123, Refs #456 -->

## 変更内容

<!-- 主要な変更点を箇条書きで。 -->

-

## 動作確認

<!-- ローカルで確認した内容、テスト結果、スクショなど。 -->

- [ ] ローカルで動作確認した
- [ ] テストを追加・更新した(または不要な理由を記載)

## セルフチェック

- [ ] 既存の lint / typecheck / test がパスする
- [ ] 破壊的変更がある場合、README または docs を更新した
- [ ] secret / 個人情報を含むコードや設定が含まれていない

## 補足

<!-- 追加で共有しておきたいことがあれば。なければ削除。 -->
45 changes: 45 additions & 0 deletions .github/workflows/actionlint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
name: actionlint

on:
push:
branches: [main]
paths:
- ".github/workflows/**"
- ".github/actionlint*"
pull_request:
branches: [main]
paths:
- ".github/workflows/**"
- ".github/actionlint*"

concurrency:
group: actionlint-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
actionlint:
name: actionlint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
Comment thread
coderabbitai[bot] marked this conversation as resolved.
with:
persist-credentials: false

- name: Download actionlint
id: actionlint
run: |
set -euo pipefail
VERSION=1.7.7
TARBALL="actionlint_${VERSION}_linux_amd64.tar.gz"
curl -fsSL -o "/tmp/${TARBALL}" "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/${TARBALL}"
curl -fsSL -o /tmp/checksums.txt "https://github.com/rhysd/actionlint/releases/download/v${VERSION}/actionlint_${VERSION}_checksums.txt"
cd /tmp && grep "${TARBALL}" checksums.txt | sha256sum -c -
tar -xzf "/tmp/${TARBALL}" -C /tmp actionlint
echo "executable=/tmp/actionlint" >> "$GITHUB_OUTPUT"

- name: Run actionlint
run: |
"${{ steps.actionlint.outputs.executable }}" -color
47 changes: 47 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
name: CodeQL

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# 毎週月曜 03:00 JST (= 日曜 18:00 UTC) に main を再スキャン
- cron: '0 18 * * 0'

concurrency:
group: codeql-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
security-events: write
actions: read

jobs:
analyze:
name: Analyze (${{ matrix.language }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# frontend は tsx、backend は ts。両方とも 'javascript-typescript' でまとめてスキャン。
language: ['javascript-typescript']
steps:
- name: Checkout
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
persist-credentials: false

- name: Initialize CodeQL
uses: github/codeql-action/init@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3
with:
languages: ${{ matrix.language }}
# security-extended は誤検知が増えるため、まずは security-and-quality で運用。
# ノイズが多い場合は 'security' に下げる。
queries: security-and-quality

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3
with:
category: '/language:${{ matrix.language }}'
22 changes: 12 additions & 10 deletions .github/workflows/complexity-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,13 +31,15 @@ jobs:
- name: Complexity check summary
if: failure()
run: |
echo "## Cyclomatic Complexity Check Failed" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "Some functions exceed the maximum cyclomatic complexity of 10." >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "### Why does this matter?" >> $GITHUB_STEP_SUMMARY
echo "- Complexity 10 or less: 25% bug introduction rate" >> $GITHUB_STEP_SUMMARY
echo "- Complexity 40 or more: 50% bug introduction rate" >> $GITHUB_STEP_SUMMARY
echo "- Complexity 75 or more: 98% bug introduction rate" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "Please refactor the flagged functions to reduce complexity." >> $GITHUB_STEP_SUMMARY
{
echo "## Cyclomatic Complexity Check Failed"
echo ""
echo "Some functions exceed the maximum cyclomatic complexity of 10."
echo ""
echo "### Why does this matter?"
echo "- Complexity 10 or less: 25% bug introduction rate"
echo "- Complexity 40 or more: 50% bug introduction rate"
echo "- Complexity 75 or more: 98% bug introduction rate"
echo ""
echo "Please refactor the flagged functions to reduce complexity."
} >> "$GITHUB_STEP_SUMMARY"
4 changes: 2 additions & 2 deletions .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
- name: Deploy to S3
run: |
# Static assets with long cache
aws s3 sync . s3://${S3_BUCKET}/${S3_PREFIX}/ \
aws s3 sync . "s3://${S3_BUCKET}/${S3_PREFIX}/" \
--delete \
--cache-control "max-age=31536000,public" \
--exclude ".git/*" \
Expand All @@ -47,7 +47,7 @@ jobs:
--exclude "*.html"

# HTML files with no cache
aws s3 sync . s3://${S3_BUCKET}/${S3_PREFIX}/ \
aws s3 sync . "s3://${S3_BUCKET}/${S3_PREFIX}/" \
--cache-control "max-age=0,no-cache,no-store,must-revalidate" \
--exclude "*" \
--include "*.html"
Expand Down
61 changes: 61 additions & 0 deletions .github/workflows/gitleaks.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
name: Gitleaks

on:
push:
branches: [main]
pull_request:
branches: [main]
schedule:
# 毎週月曜 05:00 JST (= 日曜 20:00 UTC) に履歴全体を再スキャン
- cron: "0 20 * * 0"
workflow_dispatch:

concurrency:
group: gitleaks-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
security-events: write

jobs:
gitleaks:
name: Scan for leaked secrets
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
# 履歴全体をスキャンするためフルクローン
fetch-depth: 0
persist-credentials: false

- name: Install gitleaks
run: |
set -euo pipefail
GITLEAKS_VERSION=8.21.2
BASE_URL="https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}"
ARCHIVE="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
curl -fsSLO "${BASE_URL}/${ARCHIVE}"
curl -fsSLO "${BASE_URL}/gitleaks_${GITLEAKS_VERSION}_checksums.txt"
grep " ${ARCHIVE}$" "gitleaks_${GITLEAKS_VERSION}_checksums.txt" | sha256sum -c -
tar -xzf "${ARCHIVE}" gitleaks
sudo mv gitleaks /usr/local/bin/gitleaks
gitleaks version
Comment thread
coderabbitai[bot] marked this conversation as resolved.

- name: Run gitleaks
run: |
gitleaks detect \
--source . \
--redact \
--verbose \
--no-banner \
--exit-code 1 \
--report-format sarif \
--report-path gitleaks.sarif

- name: Upload SARIF
if: always()
uses: github/codeql-action/upload-sarif@78ed0c7291d93e40c51b085850dc669a4c3ab73b # v3
with:
sarif_file: gitleaks.sarif
category: gitleaks
40 changes: 40 additions & 0 deletions .github/workflows/markdownlint.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: markdownlint

on:
push:
branches: [main]
paths:
- '**/*.md'
- '.markdownlint-cli2.jsonc'
- '.github/workflows/markdownlint.yml'
pull_request:
branches: [main]
paths:
- '**/*.md'
- '.markdownlint-cli2.jsonc'
- '.github/workflows/markdownlint.yml'

concurrency:
group: markdownlint-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
markdownlint:
name: markdownlint-cli2
runs-on: ubuntu-latest
# 既存ドキュメントの MD040/MD031 違反を片付けるまでは赤検知にしない。
# 整備完了後に continue-on-error を外して赤検知に切り替える。
continue-on-error: true
steps:
- uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
persist-credentials: false

- name: Run markdownlint-cli2
uses: DavidAnson/markdownlint-cli2-action@992badcdf24e3b8eb7e87ff9287fe931bcb00c6e # v20
with:
config: '.markdownlint-cli2.jsonc'
globs: '**/*.md'
27 changes: 27 additions & 0 deletions .markdownlint-cli2.jsonc
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{
// markdownlint-cli2 設定
// https://github.com/DavidAnson/markdownlint-cli2
"config": {
"default": true,
// 行長制限: コード/表/長文を伴うドキュメントが多いので無効化
"MD013": false,
// インライン HTML: README や PR テンプレで <!-- --> やテーブル装飾を使うので許可
"MD033": false,
// 単一の H1 を強制: 既存ドキュメントが満たさないものがあるため無効化
"MD025": false,
// 重複ヘッダ: docs で「概要」が複数出るので緩める
"MD024": { "siblings_only": true },
// 最初の行が H1 でなくてもよい (PR テンプレなど)
"MD041": false,
// 強調を見出しに使ってよい
"MD036": false,
// bare URL を許可 (GitHub flavored Markdown で自動リンク化される)
"MD034": false,
// テーブル列スタイル: 重要度が低いため無効化
"MD060": false,
Comment thread
genzouw marked this conversation as resolved.
// blockquote 内の空行: 引用節を見やすくするため許可
"MD028": false,
},
"globs": ["**/*.md"],
"ignores": ["**/node_modules/**", ".claude/**", "**/dist/**", "**/build/**"],
}
9 changes: 9 additions & 0 deletions commitlint.config.cjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
module.exports = {
extends: ["@commitlint/config-conventional"],
rules: {
"header-max-length": [2, "always", 70],
"scope-case": [2, "always", ["camel-case", "kebab-case", "upper-case"]],
"subject-case": [0, "always"],
"body-max-line-length": [2, "always", 120],
},
};
Loading