audit

package
v0.8.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 4, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Overview

Package audit reports workflow-conformance findings over a branch's git history. It is advisory (ADR-0017): standalone, never wired into the gate. Most rules are pure over the commit range; the uncommitted-changes rule (ADR-0025) additionally inspects the live working tree.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Action

type Action int

Action is how a file changed in a commit.

const (
	Added Action = iota
	Modified
	Deleted
)

type Commit

type Commit struct {
	Hash    string
	Subject string
	Body    string
	IsMerge bool
	Changes []FileChange
}

Commit is a neutral view of one range commit. The rule engine reads only this.

func Collect

func Collect(repoRoot, baseBranch string) ([]Commit, error)

Collect returns the commits reachable from HEAD but not from baseBranch, as neutral Commit values. Empty range -> nil. Not-a-repo, an unresolvable base, and unrelated histories are errors.

type FileChange

type FileChange struct {
	Path             string // repo-relative path (the new path; old path for a delete)
	OldPath          string // repo-relative pre-image path (differs only on rename)
	Action           Action
	Added, Deleted   int
	OldText, NewText string
}

FileChange is one file touched by a commit. OldText/NewText are populated only for ".md" files (cheap; the rules need ADR frontmatter), empty otherwise.

type Finding

type Finding struct {
	Severity Severity
	Rule     string
	Commit   string // short hash, "" for a branch-level finding
	Subject  string
	Detail   string
}

Finding is one reported conformance issue.

func CheckConventionalCommit added in v0.3.0

func CheckConventionalCommit(c Commit, s Settings) []Finding

CheckConventionalCommit validates one commit's subject against the Conventional Commits settings and returns any violations. It is the single definition of the rule — consumed by the audit range loop above and by the blocking `awf commit-gate` command (ADR-0036), so neither re-implements the regex, the type/scope allow-lists, or the subject-length limit. Merge commits are exempt. invariant: audit-conventional-commits invariant: commit-gate-shared-rule

func Run

func Run(repoRoot string, in Inputs) ([]Finding, error)

Run collects the branch range and evaluates the rules.

type Inputs

type Inputs struct {
	Settings
	GeneratedPaths    map[string]bool
	ADRDir            string   // e.g. "docs/decisions"
	ActiveMd          string   // e.g. "docs/decisions/ACTIVE.md"
	PlansDir          string   // e.g. "docs/plans"
	ConfiguredDomains []string // config.Domains; staleness limited to these, undocumented-domain fires outside them
	DomainsPartsDir   string   // e.g. ".awf/domains/parts"
	DomainsIndexDir   string   // e.g. "docs/domains"; rendered per-domain index dir (adr-domain-cochange)
}

Inputs are the resolved audit settings plus the project-derived layout the rules need. The embedded Settings carries the resolved knobs (BaseBranch, AllowedTypes, AllowedScopes, SubjectMaxLength, DependencyManifests, DiffThreshold, DomainDocStaleness, UndocumentedDomain, UncommittedChanges), promoted so the rules read in.AllowedTypes etc. directly.

type Settings

type Settings struct {
	BaseBranch          string
	AllowedTypes        []string
	AllowedScopes       []config.ScopeSpec
	DependencyManifests []string
	SubjectMaxLength    int
	DiffThreshold       int
	DomainDocStaleness  bool
	UndocumentedDomain  bool
	UncommittedChanges  bool
}

Settings is the resolved, default-applied audit configuration the rules consume.

func Resolve

func Resolve(a *config.AuditConfig) Settings

Resolve resolves the effective audit settings from the raw config, applying defaults. A nil AuditConfig yields the full default set.

func (Settings) ScopeNames added in v0.8.0

func (s Settings) ScopeNames() []string

ScopeNames returns just the allowed scope names, for gate matching.

type Severity

type Severity int

Severity ranks a finding. Only Error findings make the command exit non-zero.

const (
	Warning Severity = iota
	Error
)

func (Severity) String

func (s Severity) String() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL