ci: 🎡 CI/CD、自動化、セキュリティおよび品質チェック設定の統一 - #55
Conversation
## Summary - パブリックリポジトリ共通の最新のCI/CDパイプライン、自動化ツール、SaaS連携、セキュリティスキャン設定を導入。 - CodeQL(高度なコード脆弱性スキャン)ワークフローを追加。 - Gitleaks(シークレット漏洩防止スキャン)ワークフローを追加。 - Trivy(FS脆弱性・設定不備スキャン)ワークフローを追加。 - Actionlint、Markdownlint、Stale Issue/PR管理、PR競合自動通知などの自動化設定を追加。 - CodeRabbit(AI PR日本語自動レビュー)設定を追加。 - 共通コードフォーマット(Prettier)およびドキュメント品質用のルールを追加。 - 開発時・PR時のセルフチェックを促すPRテンプレート(PULL_REQUEST_TEMPLATE.md)を導入。
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! 本プルリクエストは、リポジトリ全体の CI/CD パイプライン、自動化ツール、およびセキュリティ設定を包括的に刷新・統一するものです。開発からデプロイに至るまでのプロセスを自動化し、セキュリティ脆弱性や機密情報の漏洩を未然に防ぐための堅牢な基盤を構築することを目的としています。 Highlights
Ignored Files
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughリポジトリのレビュー方針(CodeRabbit)、PR テンプレート、複数の GitHub Actions ワークフロー追加・更新、Husky フック、および lint/format/devDependencies を一括で整備する変更です。 Changesリポジトリ設定・CI 整備
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
There was a problem hiding this comment.
Code Review
このプルリクエストは、CodeRabbitの設定変更、プルリクエストテンプレートの更新、Huskyによるコミットフック(commitlint、lint-staged、gitleaks)の導入、およびPrettierとmarkdownlintの設定追加を行っています。レビューでは、追加された設定やスクリプトがプロジェクトの実態(vanilla JS、単一パッケージ構成、npm使用)と乖離しており、backend/frontendディレクトリやBun、Hono、Reactなどの存在しない環境を前提としている点が複数指摘されました。また、commitlintの依存関係への追加漏れや、markdownlint設定におけるパス指定の重複についても改善が求められています。
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/codeql.yml:
- Around line 5-10: Prettier is failing due to array spacing in the workflow
YAML; update the array notation for the branches keys and any other arrays
(e.g., the top-level branches, pull_request.branches and schedule entries) to
match the project's Prettier style (remove or add spaces around bracketed arrays
so they match other files), then run prettier --check to confirm the file (keys:
branches and pull_request.branches and schedule) now passes.
In @.github/workflows/pr_conflict_notify.yml:
- Around line 3-12: Add a top-level concurrency stanza to the workflow to
prevent simultaneous runs from schedule/push/workflow_dispatch colliding;
specifically, add a concurrency block (e.g., group: "pr-conflict-notify" and
cancel-in-progress: true) at the root of the workflow so runs share the same
concurrency group and in-progress runs are cancelled when a new run starts,
referencing the existing triggers (schedule, push, workflow_dispatch) so this
behaviour applies to those events.
- Around line 13-16: The workflow's top-level permissions are too broad—replace
the global pull-requests: write with pull-requests: read and add issues: write
only to the job(s) that post/update/delete comments; specifically, change the
top-level permissions block to minimal read-only (contents: read, pull-requests:
read) and then add issues: write to the job(s) that call
listComments/createComment/updateComment/deleteComment so only those jobs get
comment-writing rights; update any job-level permissions blocks accordingly to
keep least privilege.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 856c666f-1d86-4ca4-a4ed-2c5245a25319
📒 Files selected for processing (13)
.coderabbit.yaml.github/PULL_REQUEST_TEMPLATE.md.github/workflows/actionlint.yml.github/workflows/codeql.yml.github/workflows/gitleaks.yml.github/workflows/markdownlint.yml.github/workflows/pr_conflict_notify.yml.github/workflows/stale.yml.github/workflows/trivy.yml.husky/commit-msg.husky/pre-commit.markdownlint-cli2.jsonc.prettierrc
.husky/commit-msg で実行される `npx commitlint` 用に、@commitlint/cli と @commitlint/config-conventional をプロジェクトの devDependencies に追加した。 これにより npx が都度ダウンロードを試みることがなくなり、commit-msg フックの 実行が安定する。 レビューコメント: #55 (comment) レビュアー: gemini-code-assist 優先度: high
本プロジェクトは vanilla JS の単一パッケージ構成のため、以下を修正した: - 未インストールの lint-staged 呼び出しを削除 - 存在しない backend/ frontend/ ディレクトリ向けの typecheck/test 実行ブロックを削除 - ルートで定義済みの npm run format:check と npm run lint を実行するよう変更 これにより pre-commit フックが現状の package.json と整合して動作する。 レビューコメント: #55 (comment) レビュアー: gemini-code-assist 優先度: high
本プロジェクトは vanilla JS (ES modules) の単一構成であり、Hono / Better Auth / Drizzle / React / backend / frontend / db といったディレクトリや技術スタックは 存在しない。CodeRabbit が誤った前提でレビューしないよう、該当する path_instructions を削除し、代わりに js/ 配下に対するクライアントコード向け レビュー指示を追加した。 レビューコメント: #55 (comment) レビュアー: gemini-code-assist 優先度: medium
本プロジェクトは npm を使用する単一パッケージ構成のため、bun および backend/frontend ディレクトリを前提とした項目を実態に合わせて修正した: - bun --cwd backend/frontend run lint → npm run lint - typecheck 行は本プロジェクトに該当スクリプトが無いため format:check に置換 - DB マイグレーション項目は本プロジェクトに DB が無いため削除 レビューコメント: #55 (comment) レビュアー: gemini-code-assist 優先度: medium
**/node_modules/** はルートを含むあらゆる階層の node_modules にマッチするため、 ルート専用の node_modules/** は冗長だった。重複を解消するため削除した。 レビューコメント: #55 (comment) レビュアー: gemini-code-assist 優先度: low
prettier --check で失敗していた配列のブラケット内スペースを除去した。 - branches: [ "main" ] → branches: [main] - language: [ 'javascript-typescript' ] → language: ['javascript-typescript'] 併せて Prettier の自動整形により、quote / インデント / step ハイフン位置が プロジェクト標準に揃った。 レビューコメント: #55 (comment) レビュアー: coderabbitai 優先度: low
- schedule / push / workflow_dispatch の同時実行による PR コメント更新の競合を 防ぐため、workflow レベルに concurrency stanza を追加した。 - 本ワークフローは Issues API (createComment / updateComment / deleteComment) でコメントを操作しているため、workflow レベルでは pull-requests: read のみと し、job レベルに issues: write を付与する最小権限構成に変更した。 レビューコメント: #55 (comment) レビュアー: coderabbitai 優先度: medium
There was a problem hiding this comment.
Actionable comments posted: 1
♻️ Duplicate comments (1)
.github/workflows/pr_conflict_notify.yml (1)
13-15:⚠️ Potential issue | 🟡 Minor | ⚡ Quick win
concurrency.groupは固定値にしてください。
${{ github.ref }}だと別ブランチからのworkflow_dispatchがmainの定期実行/Push 実行と並走できます。この workflow は全 open PR のコメントを横断更新するので、ref 単位ではまだ競合が残ります。🔧 提案差分
concurrency: - group: pr-conflict-notify-${{ github.ref }} + group: pr-conflict-notify cancel-in-progress: true🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/pr_conflict_notify.yml around lines 13 - 15, concurrency.group currently uses a dynamic key (pr-conflict-notify-${{ github.ref }}), which allows runs from different refs to run concurrently; change it to a fixed value such as "pr-conflict-notify" so all invocations serialize across branches; keep cancel-in-progress: true and leave the group name as the unique identifier "pr-conflict-notify" referenced in this workflow to ensure only one instance runs at a time (covers workflow_dispatch and scheduled/push runs).
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.husky/pre-commit:
- Around line 9-15: The pre-commit hook (.husky/pre-commit) does not propagate
failures from the invoked commands so a failing npm run format:check can be
ignored; fix by making the hook fail-fast (e.g., add set -e at the top of the
script or append || exit 1 to each command) so that npm run format:check and npm
run lint failures immediately stop the hook; update the script around the npm
run format:check and npm run lint invocations to ensure errors are propagated.
---
Duplicate comments:
In @.github/workflows/pr_conflict_notify.yml:
- Around line 13-15: concurrency.group currently uses a dynamic key
(pr-conflict-notify-${{ github.ref }}), which allows runs from different refs to
run concurrently; change it to a fixed value such as "pr-conflict-notify" so all
invocations serialize across branches; keep cancel-in-progress: true and leave
the group name as the unique identifier "pr-conflict-notify" referenced in this
workflow to ensure only one instance runs at a time (covers workflow_dispatch
and scheduled/push runs).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 7d29664f-cf2d-465c-b3b2-4e3fa8bf5c57
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json,!**/package-lock.json
📒 Files selected for processing (7)
.coderabbit.yaml.github/PULL_REQUEST_TEMPLATE.md.github/workflows/codeql.yml.github/workflows/pr_conflict_notify.yml.husky/pre-commit.markdownlint-cli2.jsoncpackage.json
💤 Files with no reviewable changes (1)
- .markdownlint-cli2.jsonc
CSS 属性セレクターのクォートをシングルクォートに統一し、 Prettier の format:check を通過するよう修正。
.husky/pre-commit 内の npm run format:check および npm run lint 実行時に、失敗時に即座にコミットを中断するよう、"|| exit 1" を追加しました。 レビューコメント: #55 (comment) レビュアー: coderabbitai 優先度: high
## Summary - 過去 8 連続 `startup_failure` の markdownlint workflow を、PR #44 と同じ npm 経由実行へ戻して復旧する - `DavidAnson/markdownlint-cli2-action` を撤去し、`allowed_actions` (`patterns_allowed`) への依存をワークフロー側から排除する - 経緯と意図を workflow 本文にコメントで残し、再々度のリグレッションを抑止する ## 失敗 Run https://github.com/genzouw/kakezan-manabo/actions/runs/26388299802 (`startup_failure`、ジョブ 0 件) 5/21 (PR #55) で action 利用へ戻して以降、`gh run list --workflow markdownlint.yml` の通り直近 8 回連続で `startup_failure`。 ## 原因 `DavidAnson/markdownlint-cli2-action` は third-party の Marketplace action。 本リポジトリの `allowed_actions` は `selected` + `github_owned_allowed=true` + `verified_allowed=true` で運用しており、`patterns_allowed` に登録されていない third-party action は SHA pin していても起動拒否 (`startup_failure`) となる。 PR #44 ではまさにこの事象を解消するため npm 経由実行へ切り替えたが、PR #55 で action 利用へ意図せず差し戻されていた。 `genzouw/genzouw.com` 側の terraform (commit `f5af9f3`、2026-05-26) で `DavidAnson/markdownlint-cli2-action@*` を `patterns_allowed` に追加して GitHub 側の許可は復旧済みだが、許可リストへの依存自体が壊れやすい構造のため、ワークフロー側でも依存を取り除く。 ## 変更内容 - `actions/setup-node@v6.4.0` で Node.js `20.19` をセットアップ (他 workflow と統一) - `npm install -g --no-fund --no-audit --ignore-scripts markdownlint-cli2@0.22.1` でインストール - `--ignore-scripts`: postinstall 経由の任意コード実行を防止 - `markdownlint-cli2 --config .markdownlint-cli2.jsonc "**/*.md"` を直接実行 - `continue-on-error: true` は既存方針 (MD040/MD031 整理後に外す) に従い据え置き - 経緯と意図を workflow に日本語コメントで明記 ## Terraform 側について `genzouw.com` の `actions_patterns_allowed` で `DavidAnson/markdownlint-cli2-action@*` は既に許可されている状態。本 PR では terraform は変更しない。 将来このパターンを掃除する場合、本 workflow に依存が無いことを確認してから削除可能。 ## Test plan - [ ] 本 PR の `pull_request` イベントで markdownlint workflow が `startup_failure` せず起動する - [ ] `markdownlint-cli2` が実行され、レポートが出力される (継続失敗時も `continue-on-error` で全体は通る) - [ ] `actionlint` が通る
概要
本リポジトリに、genzouwオーナーのパブリックリポジトリ共通の最新CI/CDパイプライン、自動化ツール、SaaS連携、およびセキュリティスキャン設定を導入します。
導入される内容
Summary by CodeRabbit