Module: Carson::Runtime::Audit

Included in:
Carson::Runtime
Defined in:
lib/carson/runtime/audit.rb

Instance Method Summary collapse

Instance Method Details

#audit!Object



7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# File 'lib/carson/runtime/audit.rb', line 7

def audit!
	fingerprint_status = block_if_outsider_fingerprints!
	return fingerprint_status unless fingerprint_status.nil?
	audit_state = "ok"
	print_header "Repository"
	puts_line "root: #{repo_root}"
	puts_line "current_branch: #{current_branch}"
	print_header "Working Tree"
	puts_line git_capture!( "status", "--short", "--branch" ).strip
	print_header "Hooks"
	hooks_ok = hooks_health_report
	audit_state = "block" unless hooks_ok
	print_header "Local Lint Quality"
	local_lint_quality = local_lint_quality_report
	audit_state = "block" if local_lint_quality.fetch( :status ) == "block"
	print_header "Main Sync Status"
	ahead_count, behind_count, main_error = main_sync_counts
	if main_error
		puts_line "main_vs_remote_main: unknown"
		puts_line "WARN: unable to calculate main sync status (#{main_error})."
		audit_state = "attention" if audit_state == "ok"
	elsif ahead_count.positive?
		puts_line "main_vs_remote_main_ahead: #{ahead_count}"
		puts_line "main_vs_remote_main_behind: #{behind_count}"
		puts_line "ACTION: local #{config.main_branch} is ahead of #{config.git_remote}/#{config.main_branch} by #{ahead_count} commit#{plural_suffix( count: ahead_count )}; reset local drift before commit/push workflows."
		audit_state = "block"
	elsif behind_count.positive?
		puts_line "main_vs_remote_main_ahead: #{ahead_count}"
		puts_line "main_vs_remote_main_behind: #{behind_count}"
		puts_line "ACTION: local #{config.main_branch} is behind #{config.git_remote}/#{config.main_branch} by #{behind_count} commit#{plural_suffix( count: behind_count )}; run carson sync."
		audit_state = "attention" if audit_state == "ok"
	else
		puts_line "main_vs_remote_main_ahead: 0"
		puts_line "main_vs_remote_main_behind: 0"
		puts_line "ACTION: local #{config.main_branch} is in sync with #{config.git_remote}/#{config.main_branch}."
	end
	print_header "PR and Required Checks (gh)"
	monitor_report = pr_and_check_report
	audit_state = "attention" if audit_state == "ok" && monitor_report.fetch( :status ) != "ok"
	print_header "Default Branch CI Baseline (gh)"
	default_branch_baseline = default_branch_ci_baseline_report
	audit_state = "block" if default_branch_baseline.fetch( :status ) == "block"
	audit_state = "attention" if audit_state == "ok" && default_branch_baseline.fetch( :status ) != "ok"
	scope_guard = print_scope_integrity_guard
	audit_state = "attention" if audit_state == "ok" && scope_guard.fetch( :status ) == "attention"
		write_and_print_pr_monitor_report(
			report: monitor_report.merge(
				local_lint_quality: local_lint_quality,
				default_branch_baseline: default_branch_baseline,
				audit_status: audit_state
			)
		)
	print_header "Audit Result"
	puts_line "status: #{audit_state}"
	puts_line( audit_state == "block" ? "ACTION: local policy block must be resolved before commit/push." : "ACTION: no local hard block detected." )
	audit_state == "block" ? EXIT_BLOCK : EXIT_OK
end