Files
fips/.github
Johnathan Corgan 6c1fc4e83a Fail the AUR build job on namcap error-level findings
The AUR build job ran namcap on the PKGBUILD and the built package and
took its exit status as the verdict. namcap exits 0 when it reports
error-level findings, and also exits 0 when it cannot read its input at
all: a missing file, an unexpanded glob, or a file that is not a
package. The lint could therefore never fail the job, and a package with
error-level findings could still be published.

namcap-gate.sh runs namcap with informational lines and tag names on each
PKGBUILD or built package and fails a file when namcap reports an E:
finding, exits nonzero, prints a line that is not a tagged finding, or,
for a built package, omits the line that shows it analysed dependencies.
The last three stop an unreadable input from passing as a clean one.
Warnings stay advisory. Every file is examined before the verdict, and
namcap runs with /usr/bin first on PATH so an undeclared script
interpreter is reported the same way whether or not it runs as root.

The build job now lints through the gate. Because the publish job needs
the build job, a package with error-level findings is no longer
published.

test-namcap-gate.sh checks the gate against namcap output captured from
the real package and from toy packages; the build job runs it. With
--live it builds three toy packages and runs the gate with the real
namcap, and the build job runs that too, so a namcap update that stops
reporting missing dependencies as errors turns the job red.
2026-09-26 18:59:43 +00:00
..