Fix/release install syft - #14
Merged
Merged
Conversation
* Develop (#6) * chore: gitignore agenticscope artifacts; note show-before-fire in M2 roadmap (#2) Keep all agenticscope dev-tooling artifacts out of the Go repo (node_modules, .scope/, .mcp.json, generated vendor files). Add the show-before-fire security hard rule to the M2 roadmap so the malicious-cheatsheet injection mitigation is designed in, not retrofitted. Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> * docs: scaffold in-repo docs; wire README; add Discussions/wiki to roadmap (#3) Add versioned docs/ (schema, CLI, MCP, install) that track the release. Fix stale README YAML note (YAML shipped in M1). Roadmap: launch-day GitHub Discussions and the docs-vs-wiki split under M2 ship. Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> * chore: gitignore agenticscope artifacts; note show-before-fire in M2 roadmap (#4) Keep all agenticscope dev-tooling artifacts out of the Go repo (node_modules, .scope/, .mcp.json, generated vendor files). Add the show-before-fire security hard rule to the M2 roadmap so the malicious-cheatsheet injection mitigation is designed in, not retrofitted. Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> * Feat/m2 tui core (#5) * feat(engine): include command id in fuzzy search haystack Operators can recall a command by its stable id (e.g. nmap-sv), not only its name/intent/tags. Covered by TestSearchFindsByID. * feat(tui): interactive search/fill/confirm loop with show-before-fire Bubble Tea frontend over the engine: fuzzy search, sequential variable prompts, and a confirm screen that displays the fully resolved command before it is printed to stdout. nock never executes — emit is stdout only, gated on explicit confirm (ADR 009/015). Headless flow tests drive the model via key messages. * ci: add Scorecard + Codecov + standalone govulncheck; regroup README badges Split govulncheck into its own workflow for a standalone badge, upload coverage to Codecov, add an OpenSSF Scorecard workflow, and reorganize the README badges (build/quality, activity, community). Privacy-respecting: no third-party visitor or traffic trackers. * fix(tui): use fmt.Fprintf to satisfy staticcheck QF1012; pin golangci-lint CI runs golangci-lint latest (v2.12.2) which flagged WriteString(fmt.Sprintf). Pin the linter version so new rules can't break CI silently. --------- Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> --------- Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> * chore(deps): bump the actions group with 3 updates (#7) Bumps the actions group with 3 updates: [codecov/codecov-action](https://github.com/codecov/codecov-action), [github/codeql-action](https://github.com/github/codeql-action) and [ossf/scorecard-action](https://github.com/ossf/scorecard-action). Updates `codecov/codecov-action` from 5 to 7 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@v5...v7) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `ossf/scorecard-action` from 2.4.0 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@v2.4.0...v2.4.3) --- updated-dependencies: - dependency-name: codecov/codecov-action dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs(readme): fix codecov badge, drop vanity badges Fix the codecov badge URL (old /branch/main/ path) and wire CODECOV_TOKEN in CI (tokenless uploads are no longer accepted). Remove downloads/stars/forks/watchers badges; replace with Conventional Commits, gitleaks, and CodeRabbit. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Jesse Ngolab <jessengolab.dev@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The .gitignore binary rule 'nock' was unanchored, so it also matched the cmd/nock/ directory — the program entry point was never committed. CI 'go build ./...' only sees tracked packages, so it passed; the release failed (couldn't find cmd/nock). Anchor the rule to /nock and add the missing main.go.
GoReleaser's sboms step shells out to syft, which isn't preinstalled on the runner -> 'syft: executable file not found'. Add anchore/sbom-action/download-syft before the GoReleaser step. Validated locally: full snapshot incl. SBOM + cask succeeds. Binaries, archives, and .deb/.rpm/.apk already built fine.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe release workflow gains a single new step that installs Syft via ChangesRelease Workflow – Syft Dependency
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix/release install syft
Summary by CodeRabbit