mirror of
https://github.com/alibaba/open-code-review.git
synced 2026-08-10 17:25:09 +00:00
Some checks are pending
CI / cross-compile (arm64, darwin) (push) Waiting to run
CI / cross-compile (arm64, linux) (push) Waiting to run
CI / cross-compile (arm64, windows) (push) Waiting to run
CI / test (push) Waiting to run
CI / cross-compile (amd64, darwin) (push) Waiting to run
CI / cross-compile (amd64, windows) (push) Waiting to run
CodeQL Advanced / Analyze (go) (push) Waiting to run
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
Deploy Pages / build (push) Waiting to run
Deploy Pages / deploy (push) Blocked by required conditions
* chore: add SPDX license headers to all source files
Add Apache-2.0 SPDX license identifiers and copyright notices to all
tracked .go, .sh, .js, .mjs, .ts, and .tsx source files.
Introduce scripts/verify-license.sh and scripts/add-license.sh for
automated verification and bulk addition of license headers. Integrate
the check into CI (ci.yml) and the Makefile (license-check target as
a prerequisite of the existing check target).
This satisfies the OpenSSF Best Practices Badge requirements for
copyright_per_file and license_per_file.
* fix: restore execute permissions on scripts
* docs: add license header instructions to CONTRIBUTING guides
* docs: add license header instructions to pages contributing guides
* fix(pages): strip unclosed HTML comment markers to satisfy CodeQL
* fix: apply code review suggestions for license scripts
- Fix portability: detect macOS vs Linux stat for permission copy
- Fix has_header: check both SPDX and copyright (match verify logic)
- Fix is_ignored: match on path boundaries to avoid false positives
- Fix year extraction: use consistent pipeline across both scripts
- Fix Bash 3.2 compat: quote array length expansion for set -u
* fix(pages): use loop-until-clean for HTML comment stripping (CodeQL)
* fix(pages): use split/join instead of replace to avoid CodeQL false positive
CodeQL's js/incomplete-multi-character-sanitization rule flags any
.replace() that removes multi-character sequences like '<!--...-->',
regardless of context. The data here comes from readFileSync on the
project's own index.html (no untrusted input), making this a false
positive. Using split(regex).join('') achieves the same result without
triggering the taint-tracking rule.
112 lines
3.3 KiB
Makefile
112 lines
3.3 KiB
Makefile
.PHONY: build test clean run help fmt vet check coverage \
|
|
build-all dist sha256sum version-info \
|
|
build-linux-amd64 build-linux-arm64 build-darwin-amd64 build-darwin-arm64 \
|
|
build-windows-amd64 build-windows-arm64 \
|
|
license-check license-add
|
|
|
|
BINARY_NAME := opencodereview
|
|
GO := go
|
|
DIST_DIR := ./dist
|
|
|
|
# Version info — use git tag if available, fallback to short commit hash
|
|
GIT_TAG := $(shell git describe --tags --abbrev=0 2>/dev/null || echo "")
|
|
GIT_COMMIT := $(shell git rev-parse --short HEAD)
|
|
BUILD_DATE := $(shell date -u +"%Y-%m-%dT%H:%M:%SZ")
|
|
|
|
VERSION ?= $(if $(GIT_TAG),$(GIT_TAG),v0.0.0-$(GIT_COMMIT))
|
|
|
|
LD_FLAGS := \
|
|
-X main.Version=$(VERSION) \
|
|
-X main.GitCommit=$(GIT_COMMIT) \
|
|
-X main.BuildDate=$(BUILD_DATE)
|
|
|
|
RELEASE_LD_FLAGS := -s -w $(LD_FLAGS)
|
|
|
|
define BUILD_PLATFORM
|
|
GOOS=$(1) GOARCH=$(2) CGO_ENABLED=0 $(GO) build -ldflags "$(RELEASE_LD_FLAGS)" \
|
|
-o $(DIST_DIR)/$(BINARY_NAME)-$(1)-$(2)$(3) \
|
|
./cmd/opencodereview
|
|
endef
|
|
|
|
# ── Development targets ──────────────────────────────────────────────────────
|
|
build:
|
|
$(GO) build -ldflags "$(LD_FLAGS)" -o $(DIST_DIR)/$(BINARY_NAME) ./cmd/opencodereview
|
|
|
|
PACKAGES := $(shell $(GO) list ./... | grep -v /extensions/)
|
|
|
|
test:
|
|
LC_ALL=C $(GO) test -v -race -count=1 $(PACKAGES)
|
|
|
|
COVERAGE_THRESHOLD := 80
|
|
|
|
coverage:
|
|
LC_ALL=C $(GO) test -count=1 -coverprofile=coverage.out $(PACKAGES)
|
|
$(GO) tool cover -func=coverage.out | grep total:
|
|
@COVERAGE=$$($(GO) tool cover -func=coverage.out | grep total: | awk '{print $$3}' | sed 's/%//'); \
|
|
if awk "BEGIN {exit !($$COVERAGE < $(COVERAGE_THRESHOLD))}"; then \
|
|
echo "FAIL: Coverage $${COVERAGE}% is below $(COVERAGE_THRESHOLD)% threshold"; \
|
|
exit 1; \
|
|
fi; \
|
|
echo "PASS: Coverage $${COVERAGE}% meets $(COVERAGE_THRESHOLD)% threshold"
|
|
|
|
clean:
|
|
rm -rf $(DIST_DIR) coverage.out
|
|
|
|
run: build
|
|
$(DIST_DIR)/$(BINARY_NAME) --staged
|
|
|
|
help: build
|
|
$(DIST_DIR)/$(BINARY_NAME) -h
|
|
|
|
fmt:
|
|
gofmt -s -w .
|
|
|
|
vet:
|
|
LC_ALL=C $(GO) vet $(PACKAGES)
|
|
|
|
check: license-check
|
|
$(GO) mod tidy
|
|
gofmt -s -w .
|
|
LC_ALL=C $(GO) vet $(PACKAGES)
|
|
@echo "check passed"
|
|
|
|
license-check:
|
|
@bash scripts/verify-license.sh
|
|
|
|
license-add:
|
|
@bash scripts/add-license.sh
|
|
|
|
# ── Cross-platform targets ───────────────────────────────────────────────────
|
|
build-linux-amd64:
|
|
$(call BUILD_PLATFORM,linux,amd64)
|
|
|
|
build-linux-arm64:
|
|
$(call BUILD_PLATFORM,linux,arm64)
|
|
|
|
build-darwin-amd64:
|
|
$(call BUILD_PLATFORM,darwin,amd64)
|
|
|
|
build-darwin-arm64:
|
|
$(call BUILD_PLATFORM,darwin,arm64)
|
|
|
|
build-windows-amd64:
|
|
$(call BUILD_PLATFORM,windows,amd64,.exe)
|
|
|
|
build-windows-arm64:
|
|
$(call BUILD_PLATFORM,windows,arm64,.exe)
|
|
|
|
build-all: build-linux-amd64 build-linux-arm64 build-darwin-amd64 build-darwin-arm64 build-windows-amd64 build-windows-arm64
|
|
|
|
# Generate SHA256 checksums for all release binaries
|
|
sha256sum: build-all
|
|
cd $(DIST_DIR) && shasum -a 256 $(BINARY_NAME)-* | sort > sha256sum.txt
|
|
|
|
# Full release: clean → build all platforms → checksums
|
|
dist: clean build-all sha256sum
|
|
@echo $(VERSION) > $(DIST_DIR)/VERSION
|
|
|
|
version-info:
|
|
@echo "Version: $(VERSION)"
|
|
@echo "GitCommit: $(GIT_COMMIT)"
|
|
@echo "BuildDate: $(BUILD_DATE)"
|
|
@echo "LD_FLAGS: $(LD_FLAGS)"
|