4 Commits

Author SHA1 Message Date
Alex Dunmow
ff4de855cc refactor: complete check 2c retarget from block/core to block/pluginsdk
Standalone plugins now build against git.dev.alexdunmow.com/block/pluginsdk.
Check 2c requires a pluginsdk module require (rule missing-pluginsdk-require)
and enforces its version against the CMS anchor (rule pluginsdk-version-mismatch)
once the CMS migrates; a coexisting block/core require stays allowed
(calcomblock keeps core for captcha).

- check_sdkboundaries.go: degrade the 2c OK message gracefully when the
  pluginsdk version anchor is empty (transition period) — omit the version
  clause instead of printing "SDK version ".
- check_rbac.go: document pluginsdk in the definitions-only module comment.
- plugin_sdk_versions_test.go: retarget fixtures to pluginsdk; add cases for
  missing-pluginsdk-require, pluginsdk-version-mismatch, a forbidden core
  replace directive, and an allowed coexisting core require.
- lint_test.go: synthesized plugin repos now require pluginsdk (replace-
  directive case replaces pluginsdk).
- registry_test.go: add checks 30 and 31 to the canonical order (were added
  to the registry without updating this test).
- golden: regenerate — check count 32 -> 34 (checks 30/31 SKIP in fixtures).
- README.md: describe 2c as the pluginsdk boundary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-07 11:13:42 +08:00
Alex Dunmow
e03144e12d feat: codeless plugin repos (plugin.mod, no Go) exempt from go.mod checks (WO-WZ-020)
A codeless .bnp repo has no go.mod by design — mirror the ninja CLI
classifier (core bnp.IsCodelessRepo) and skip both the standalone-plugin
go.mod checks and the backend replace-directive parse for such roots.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 12:43:54 +08:00
Alex Dunmow
57bca429cc chore: follow CMS module rename in rule strings + test fixtures
CMS Go module renamed from git.dev.alexdunmow.com/block/ninja to
git.dev.alexdunmow.com/block/cms (along with the git remote rename
on gitea). All import paths, string-literal rules, test fixtures,
and doc references updated; (historical 'ninja-orchestrator' refs
preserved). go mod tidy regenerated checksums.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:55:47 +08:00
Alex Dunmow
cd88c808b0 initial: standalone check-safety module hoisted from CMS
Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.

This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
  blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
  install-safety-checker targets

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-06-06 13:04:02 +08:00