Documentation
¶
Overview ¶
Package checkcmd is `ovdb publisher check`: it checks the Git repository in a directory, as committed at HEAD, with the Publisher profile of package repo, and prints what it finds for a person or, with --json, as a document for a CI job. It reads no file of the working tree and never uses the network: the one thing it runs is git, through repo's reader. The command is not part of the parity matrix (it has no TUI, web or API surface).
Index ¶
Constants ¶
const ( MaxHumanBytes = 150 << 10 MaxJSONBytes = 1 << 20 )
MaxHumanBytes and MaxJSONBytes are the most that one run prints, with a margin: at most manifest.MaxFindings findings and the notice that says more were left out (TestTheLargestOutputIsBounded builds that case).
Variables ¶
var ErrRefused = errors.New("the repository is refused")
ErrRefused is what the command returns when the check ran and the repository is refused: exit code 1, and nothing more to print (the findings are the output). main's error handler stays silent for it.
Functions ¶
Types ¶
type Deps ¶
type Deps struct {
// Open returns the reader of the repository in dir (git, run through repo.ExecRunner, in the real command).
Open func(dir string) repo.Reader
// Stat is os.Stat in the real command.
Stat func(name string) (fs.FileInfo, error)
// T is the copy catalogue (uicopy.T): every word the command says is a key of copy/en.json, so that text lives in one place. The keys the command uses
// are literals of this package, and a test holds each to the catalogue.
T func(key string, params map[string]string) string
// Usage makes the error of a usage mistake (the shared error envelope with exit code 2), Unrunnable the error of an environment that cannot run the
// check (the same, for a missing tool: exit code 2 too), and JSON writes a schema-1 document, as every ovdb --json document is written.
Usage func(cmd *cobra.Command, reason string) error
Unrunnable func(message, reason, next string) error
// TimedOut is Unrunnable for a git that was found and did not finish in time: the same exit code, a code of its own in the JSON envelope.
TimedOut func(message, reason, next string) error
JSON func(v any) []byte
// WriteFailed makes the error for a result that could not be written to standard output (a closed or full pipe): exit code 2, the check could not
// deliver what it was asked for, and a pass that printed nothing must not look like one.
WriteFailed func(reason string) error
}
Deps are the seams of the command: what it reads from the machine.
type Document ¶
type Document struct {
Schema int `json:"schema"`
Command string `json:"command"`
Commit string `json:"commit"`
Profile string `json:"profile"`
OK bool `json:"ok"`
Manifests int `json:"manifests"`
Findings []Finding `json:"findings"`
Summary Summary `json:"summary"`
}
Document is the --json document, schema version 1 (envelope.Schema, as every ovdb document).
type Finding ¶
type Finding struct {
Rule string `json:"rule"`
Severity string `json:"severity"`
Path string `json:"path"`
Line int `json:"line"`
Message string `json:"message"`
}
Finding is one finding: Path is the file the finding is about, "repository" when it is about the repository as a whole.
type Summary ¶
type Summary struct {
Errors int `json:"errors"`
Capped bool `json:"capped"`
Omitted int `json:"omitted"`
}
Summary counts the findings of each severity.
Errors counts the findings, not the notice that says more were left out. Capped is true when the check left findings out (at most manifest.MaxFindings are reported) and Omitted says how many.