Repository navigation
Expand file tree
/
Copy pathMakefile
More file actions
69 lines (51 loc) · 2.31 KB
/
Copy pathMakefile
File metadata and controls
69 lines (51 loc) · 2.31 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
.PHONY: help install test doctor setup update-vuln-dbs build-image lint lint-fix hooks sync status bump $(BUMP_PARTS)
.PHONY: skillsaw-lint skillsaw-fix skillsaw-badge
PROFILE ?= secure-code-audit
CLI := uv run python -m traust.cli.toolchain
PYTHON ?= python3
RELEASE := ./release.py
BUMP_PARTS := patch minor major
SKILLSAW_VERSION := 0.20.0
help: ## Show targets
@grep -E '^[a-z][-a-z]+:.*## ' $(MAKEFILE_LIST) | \
awk -F ':.*## ' '{printf " %-18s %s\n", $$1, $$2}'
sync: ## Install/sync dependencies (uv)
uv sync
test: sync ## Run unit tests (parallel via pytest-xdist)
uv run pytest tests/ -n auto
install: ## Set up TRAUST_CONFIG_HOME (scripts/install_traust; pass ARGS="--yes …" for CI)
bash scripts/install_traust $(ARGS)
doctor: ## Verify readiness: config estate loads + toolchain for PROFILE
bash scripts/install_traust --doctor --toolchain $(PROFILE) $(ARGS)
setup: sync ## Install toolchain for PROFILE
$(CLI) setup --profile $(PROFILE)
update-vuln-dbs: ## Download/update vulnerability DBs for PROFILE
$(CLI) fetch-dbs --profile $(PROFILE)
build-image: ## Build the complete toolchain image (binaries + Python + data)
bash scripts/build-toolchain-image.sh
lint: ## ruff check + format --check
uv run ruff check .
uv run ruff format --check .
lint-fix: ## ruff --fix + format
uv run ruff check --fix .
uv run ruff format .
skillsaw-badge: ## Regenerate the committed skillsaw grade badge (Podman)
podman run --rm -v "$(CURDIR):/workspace:Z" ghcr.io/stbenjam/skillsaw:v$(SKILLSAW_VERSION) badge
skillsaw-lint: skillsaw-badge ## Lint agent context with version-pinned skillsaw (Podman)
podman run --rm -v "$(CURDIR):/workspace:Z" ghcr.io/stbenjam/skillsaw:v$(SKILLSAW_VERSION) --strict
skillsaw-fix: ## Apply safe skillsaw autofixes (Podman)
podman run --rm -v "$(CURDIR):/workspace:Z" ghcr.io/stbenjam/skillsaw:v$(SKILLSAW_VERSION) fix
hooks: ## Enable .githooks for this clone
git config core.hooksPath .githooks
@chmod +x .githooks/* 2>/dev/null || true
status: ## Current version, tag, git state
$(PYTHON) $(RELEASE) status
$(BUMP_PARTS):
@:
bump: ## Bump VERSION + pyproject.toml: make bump patch|minor|major
@part="$(filter $(BUMP_PARTS),$(MAKECMDGOALS))"; \
if [ -z "$$part" ]; then \
echo "usage: make bump patch|minor|major" >&2; \
exit 1; \
fi; \
$(PYTHON) $(RELEASE) bump $$part