-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathMakefile
More file actions
57 lines (46 loc) · 2 KB
/
Copy pathMakefile
File metadata and controls
57 lines (46 loc) · 2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
SHELL := /usr/bin/env bash
COMPOSE ?= $(shell if docker compose version >/dev/null 2>&1; then printf 'docker compose'; elif command -v docker-compose >/dev/null 2>&1; then printf 'docker-compose'; else printf 'docker compose'; fi)
.PHONY: help install validate test build docker-build compose-config security-check public-check clean
help:
@printf "Targets disponiveis:\n"
@printf " make install - instala dependencias dos tres apps\n"
@printf " make validate - valida Prisma, testes da API e builds frontend\n"
@printf " make docker-build - builda imagens locais\n"
@printf " make compose-config - valida arquivos Docker Compose\n"
@printf " make security-check - executa Trivy via Docker quando disponivel\n"
@printf " make public-check - checa secrets e marcadores internos\n"
@printf " make clean - remove artefatos locais comuns\n"
install:
npm ci --prefix apps/api
npm ci --prefix apps/web
npm ci --prefix apps/admin
test:
npm run test:api
build:
npm run build
validate:
npm run validate
docker-build:
TAG=local REGISTRY_NAMESPACE=local ./scripts/build-images.sh
compose-config:
$(COMPOSE) -f docker-compose.yml config >/dev/null
$(COMPOSE) -f docker-compose-dev.yml config >/dev/null
security-check:
@if ! command -v docker >/dev/null 2>&1; then \
printf "[AVISO] Docker nao encontrado; pulando Trivy local.\n"; \
exit 0; \
fi
@if ! docker info >/dev/null 2>&1; then \
printf "[AVISO] Docker daemon indisponivel; pulando Trivy local.\n"; \
exit 0; \
fi
docker run --rm -v "$$PWD:/workspace" -w /workspace \
ghcr.io/aquasecurity/trivy@sha256:be1190afcb28352bfddc4ddeb71470835d16462af68d310f9f4bca710961a41e \
fs --scanners misconfig,secret --severity HIGH,CRITICAL --exit-code 1 --no-progress \
--skip-dirs .git --skip-dirs node_modules --skip-dirs dist .
public-check:
./scripts/check-sensitive-files.sh
./scripts/check-public-readiness.sh
clean:
rm -rf apps/api/coverage apps/web/dist apps/admin/dist
find . -name "*.log" -not -path "./.git/*" -delete