Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .agents/plugins/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,20 +9,20 @@
"source": {
"source": "url",
"url": "https://github.com/partme-ai/partme-codeguard-plugin.git",
"ref": "main"
"ref": "v0.6.0"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_USE"
},
"category": "Developer Tools",
"version": "0.5.4",
"version": "0.6.0",
"description": "Cross-language code lint enforcement for AI coding assistants (ZCode, Claude Code, Codex CLI, Kimi Code): Java, Rust, TypeScript, Python. PostToolUse hook auto-runs the native linter on every AI-written file and blocks on failure in strict mode.",
"icon": "https://raw.githubusercontent.com/partme-ai/partme-codeguard-plugin/main/assets/official-logo.png",
"icon": "https://cdn.jsdelivr.net/gh/full-stack-plugins/codeguard-plugin@v0.6.0/assets/official-logo.png",
"interface": {
"displayName": "代码规范守卫",
"shortDescription": "Make AI-written code pass lint on first try",
"logo": "https://raw.githubusercontent.com/partme-ai/partme-codeguard-plugin/main/assets/official-logo.png"
"logo": "https://cdn.jsdelivr.net/gh/full-stack-plugins/codeguard-plugin@v0.6.0/assets/official-logo.png"
}
}
]
Expand Down
2 changes: 1 addition & 1 deletion .codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "codeguard",
"version": "0.5.4+codex.20260919",
"version": "0.6.0+codex.20260921",
"description": "Cross-language code lint enforcement for AI coding assistants (ZCode, Claude Code, Codex CLI, Kimi Code): Java, Rust, TypeScript, Python. PostToolUse hook auto-runs the native linter on every AI-written file and blocks on failure in strict mode.",
"author": {
"name": "Full Stack Skills / PartMe.AI",
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/skills-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,13 +24,13 @@ jobs:
sync:
runs-on: ubuntu-latest
env:
GH_TOKEN: ${{ secrets.SKILLS_SYNC_TOKEN || secrets.GITHUB_TOKEN }}
GH_TOKEN: ${{ secrets.FULL_STACK_SKILLS_SYNC_TOKEN || secrets.GITHUB_TOKEN }}
REQUESTED_REF: ${{ github.event.client_payload.ref || inputs.ref }}
REQUESTED_SHA: ${{ github.event.client_payload.sha || inputs.sha }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
token: ${{ secrets.SKILLS_SYNC_TOKEN || secrets.GITHUB_TOKEN }}
token: ${{ secrets.FULL_STACK_SKILLS_SYNC_TOKEN || secrets.GITHUB_TOKEN }}
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
Expand Down Expand Up @@ -59,6 +59,7 @@ jobs:
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git fetch origin refs/heads/chore/skills-sync:refs/remotes/origin/chore/skills-sync || true
git checkout -B chore/skills-sync
git add skills/ skills.lock.json
git commit -m "chore: sync vendored skills from codeguard-skills ${REQUESTED_REF:-current-lock}"
Expand All @@ -74,5 +75,4 @@ jobs:
gh pr create \
--title "chore: sync vendored Codeguard skills ${REQUESTED_REF:-current-lock}" \
--body "Automated refresh of the checksummed skill snapshot from skills.lock.json. Requested release: ${REQUESTED_REF:-current lock}; expected commit: ${REQUESTED_SHA:-already pinned}. Externally managed skills come from full-stack-skills/codeguard-skills; plugin-local exceptions must be declared in plugin-local-skills.json." \
--head chore/skills-sync --base main \
--label skills-sync
--head chore/skills-sync --base main
27 changes: 27 additions & 0 deletions .markdownlint-cli2.jsonc
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
// codestyle-check (codeguard): markdownlint 宽松配置
// 定位:AI 产出的报告/文档不应用代码级规则拦截;本配置只保留真正影响可读性的规则。
// 使用方法:拷贝到项目根 .markdownlint-cli2.jsonc

{
"config": {
// ===== 关闭(报告/文档类高频误报)=====
"MD013": false, // line-length:报告行宽不设限
"MD022": false, // headings 应前后空行
"MD031": false, // fenced code blocks 前后空行
"MD032": false, // lists 前后空行
"MD040": false, // fenced code blocks 语言标注
"MD041": false, // 首行必须是标题(附录/片段常不满足)
"MD033": false, // 行内 HTML(报告常用表格/详情标签)
"MD036": false, // 不用强调代替标题
"MD034": false, // 不带空格的裸 URL
"MD038": false, // 行内代码中的反引号
"MD047": false, // 文件末尾单换行(工具生成文件常缺)
"MD060": false, // 表格列样式(新规则;报告表格不按它排版,同 MD013 理由)

// ===== 保留(真实影响可读性)=====
"MD009": { "br_spaces": 0 }, // 行尾空格
"MD010": { "code_blocks": false }, // 硬 tab
"MD012": { "maximum": 3 }, // 连续空行上限
"MD004": { "style": "dash" }, // 无序列表符号一致
}
}
2 changes: 1 addition & 1 deletion .zcode-plugin/plugin.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"en": "CodeGuard",
"zh-CN": "代码规范检查"
},
"version": "0.5.4",
"version": "0.6.0",
"description": "Cross-language code lint enforcement for AI coding assistants (ZCode, Claude Code, Codex CLI, Kimi Code): Java, Rust, TypeScript, Python. PostToolUse hook auto-runs the native linter on every AI-written file and blocks on failure in strict mode.",
"description_i18n": {
"en": "Cross-language code lint enforcement. PostToolUse hook auto-runs the language-specific linter on every AI-written file; failed lint blocks further writes when strict_mode is on. Ships ready-to-go .pre-commit-config.yaml templates for Java/Rust/TypeScript/Python.",
Expand Down
17 changes: 14 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,8 +79,15 @@ AI code that passes lint on first try
| Status | Languages |
|---|---|
| **Stable** (53, auto-enforced) | Java, Rust, TypeScript/JavaScript, Python, Go, C#, Kotlin, Swift, PHP, Ruby, Scala, Shell, Dockerfile, YAML, Elixir, CSS/SCSS, Markdown, SQL, TOML, HTML, Protobuf, Terraform/OpenTofu, Nix, Dart, Solidity, Ansible-playbooks, Perl, Groovy, Clojure, PowerShell, Zig, Nim, Crystal, Julia (format-only), Pascal (format-only), Elm, Lua, Luau, C++ (clang-tidy), Objective-C, CUDA, GraphQL, Protobuf digest, VB.NET, Erlang, R, CFML — and more; see LANGUAGES.md |

> **Markdown / YAML opt-in semantics**: both declare `requiresConfig` — without a root linter config
> (e.g. `.markdownlint-cli2.jsonc` / `.yamllint`) the project counts as not opted in: safely skipped,
> never blocked, never swept by tool default rules. The markdown gate is advisory (reported in skipped, non-blocking).
> Its lint command previously lacked a glob and always exited with a usage error; it now returns real results.
> `codeguard init` copies the lenient config template.
| **Planned** (4, no independent CLI linter) | Metal, ArkTS (HarmonyOS), COBOL, Liquid (Shopify theme-check 已列为工具,待接通) |
## Governance skills (Git & Security) (Git & Security)

## Governance skills (Git & Security)

Beyond linting, codeguard ships standalone governance skills sourced from the team's engineering-standards wiki:

Expand Down Expand Up @@ -150,12 +157,16 @@ ln -s $PWD/bin/codeguard /usr/local/bin/codeguard

codeguard check # multi-language lint gate
codeguard fix # auto-fix lint issues
codeguard cve # CVE dependency scan (Maven/npm/Python/Rust orchestration)
codeguard cve # CVE dependency scan (Maven/npm/Python/Rust + universal trivy fallback)
codeguard cve --fix # scan + auto-fix (npm audit fix)
codeguard cve --severity MEDIUM # gate threshold down to medium
codeguard cve --severity MEDIUM # threshold-and-above: MEDIUM+HIGH+CRITICAL fail
codeguard cve --ecosystem java # alias for maven; unknown values exit 3 before any scan
codeguard detect # detect project languages
```

CVE exit codes: `0` pass, `1` unverifiable (tool missing / nothing scannable), `2` findings, `3` usage error.
Ecosystems without a native scanner fall back to `trivy fs --scanners vuln` when detected; native tools are never replaced by the fallback. Severity means threshold-and-above on every scanner (maven maps to CVSS band floors: HIGH⇒7).

Maven CVE scanning uses OWASP dependency-check (pom snippet in
`linters/maven/dependency-check-pom-snippet.xml`; build fails at `CVSS>=7`).
**A finding must be fixed, not filed away**: every report ships with the fix command
Expand Down
13 changes: 11 additions & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,11 @@ AI 一次写出就过 lint 的代码
| 状态 | 语言 |
|---|---|
| **Stable**(53 种,默认强制) | Java、Rust、TypeScript/JavaScript、Python、Go、C#、Kotlin、Swift、PHP、Ruby、Scala、Shell、Dockerfile、YAML、Elixir、CSS/SCSS、Markdown、SQL、TOML、HTML、Protobuf、Terraform/OpenTofu、Nix、Dart、Solidity、Ansible、Perl、Groovy、Clojure、PowerShell、Zig、Nim、Crystal、Julia(仅格式化)、Pascal(仅格式化)、Elm、Lua、Luau、C++(clang-tidy)、Objective-C、CUDA、GraphQL、VB.NET、Erlang、R、CFML 等,详见 LANGUAGES.md |

> **Markdown / YAML 接入语义**:二者声明了 `requiresConfig`——项目根没有对应 linter 配置
> (如 `.markdownlint-cli2.jsonc` / `.yamllint`)时视为**未接入**,安全跳过、不阻塞提交,
> 不会被工具默认规则全仓报错。Markdown 门禁为 advisory(告警进 skipped,不拦截);
> 此前其 lint 命令缺 glob、恒以用法错误退出,现已返回真实结论。`codeguard init` 会拷入宽松配置模板。
| **Planned**(4 种,无独立 CLI linter) | Metal、ArkTS(HarmonyOS)、COBOL、Liquid(theme-check 待接通) |

## 外部技能来源
Expand Down Expand Up @@ -136,12 +141,16 @@ ln -s $PWD/bin/codeguard /usr/local/bin/codeguard

codeguard check # 跑多语言 lint 门禁
codeguard fix # 自动修复 lint 问题
codeguard cve # CVE 依赖漏洞扫描(Maven/npm/Python/Rust 编排)
codeguard cve # CVE 依赖漏洞扫描(Maven/npm/Python/Rust + universal trivy 兜底)
codeguard cve --fix # 扫描并自动修复(npm audit fix)
codeguard cve --severity MEDIUM # 门禁阈值调到中危
codeguard cve --severity MEDIUM # 「该级别及以上」:MEDIUM/HIGH/CRITICAL 都算失败
codeguard cve --ecosystem java # maven 的别名;未声明生态在任何扫描前退出码 3 拒绝
codeguard detect # 检测项目语言
```

CVE 退出码:`0` 通过 / `1` 无法验证(工具缺失或无可扫描生态) / `2` 存在漏洞 / `3` 参数错误。
未被原生扫描器覆盖的语言自动落 `trivy fs --scanners vuln` 通用兜底;原生工具缺失时保持「无法验证」,不用兜底顶替。`--severity` 在所有扫描器上都是「阈值及以上」(maven 按 CVSS 档位下界换算:HIGH⇒7)。

Maven 项目 CVE 扫描使用 OWASP dependency-check(pom 配置模板见
`linters/maven/dependency-check-pom-snippet.xml`;`CVSS>=7 构建失败`)。
**检查出来了得修**:报告会附带每个生态的修复命令(升级依赖 / 登记误报),npm 支持 `audit fix` 自动修复。
Expand Down
5 changes: 4 additions & 1 deletion bin/codeguard
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,10 @@
# 用法:
# codeguard check [--lang LANG] [--timeout N] [path] # 跑代码规范 lint(多语言)
# codeguard fix [--lang LANG] [path] # 自动修复 lint 问题
# codeguard cve [--json] [--severity S] [path] # CVE 依赖漏洞扫描(多生态编排)
# codeguard cve [--ecosystem E] [--severity S] [--fix] [--json] [path]
# # CVE 依赖漏洞扫描
# # 生态: maven(别名 java) / node / python / rust / universal(别名 trivy)
# # 退出码: 0 通过 / 1 无法验证 / 2 存在漏洞 / 3 参数错误
# codeguard dockerfile [--json] [path] # Dockerfile 安全风险检查(hadolint + trivy config)
# codeguard detect [path] # 检测项目语言
#
Expand Down
Loading
Loading