Documentation
¶
Overview ¶
Package committer holds the deterministic checks of the committer role (roles/committer). The role's pre and post scripts call them through `workline builtin committer pre|post`.
Index ¶
- func Check(message string, s Settings) ([]verdict.Finding, error)
- func Identity(repo, rng string, s Settings) ([]verdict.Finding, error)
- func MessageLeaks(repo string, messages []Message) ([]verdict.Finding, error)
- func Post(runDir, repo string) int
- func Pre(runDir, repo string) int
- func Secrets(repo, rng string) ([]verdict.Finding, error)
- func Trailers(message string) []string
- type Message
- type Settings
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Identity ¶
Identity checks the author and committer addresses git will record (rng empty), or those of every commit of rng. git var gives the effective identity, so an address given for one commit (-c user.email, --author) is caught too: the one that leaks is usually given on purpose.
func MessageLeaks ¶
MessageLeaks scans commit messages with gitleaks, with the same lists as Secrets: gitleaks reads what commits change, never what they say. All the messages go through one scan; each finding names its commit and line. Without gitleaks it finds nothing: Secrets already says so.
func Post ¶
Post is the role's judge step: a rewritten message must pass the same checks, and carry no secret or term; with no rewrite, the original findings stand.
func Pre ¶
Pre is the role's prepare step: check the message; if it fails, ask the agent to rewrite it. Exit 10 when there is nothing to do.
func Secrets ¶
Secrets scans what a commit adds (rng empty: the staged changes) or every commit of rng with gitleaks: secrets, and the terms of the user's lists. gitleaks takes, first found: GITLEAKS_CONFIG, the repository's .gitleaks.toml — which may extend the common list — then the user's common list (<config folder>/workline/gitleaks.toml), then its own rules. Matches are never printed. Without gitleaks, it says the check did not run.
Types ¶
type Message ¶
type Message struct{ Commit, Text string }
A Message is a commit message, and the commit it belongs to (empty for the one being written).
type Settings ¶
type Settings struct {
SubjectMax int `json:"subject-max"`
BodyMaxLines int `json:"body-max-lines"`
Types []string `json:"types"`
InternalCodes []string `json:"internal-codes"`
InternalCodesAllow []string `json:"internal-codes-allow"`
InternalCodesMaybe []string `json:"internal-codes-maybe"`
AllowedIdentities []string `json:"allowed-identities"`
}
Settings are the role's settings, as merged by the engine.