Static safety/lint runner for the BlockNinja codebase. ~25 invariant
checks across Go and frontend sources. Was at git.dev.alexdunmow.com:block/ninja
in backend/cmd/check-safety/ until the 2026-06-06 consolidation moved
the BlockNinja repos under a shared ~/src/blockninja/ parent.
This repo is the standalone extraction:
- Own go.mod (git.dev.alexdunmow.com/block/check-safety, go 1.26.4)
- Vendored internal/{helpers,theme} from CMS (Go's internal/ rule
blocks cross-module imports; vendoring is the workaround)
- CLI contract unchanged: `check-safety <target-dir> [--flags]`
- CMS Makefile shells into ../check-safety for safety-check /
install-safety-checker targets
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
38 lines
1.1 KiB
Go
38 lines
1.1 KiB
Go
package main
|
|
|
|
// ScanContext holds all resolved scan state, built once before any check runs.
|
|
// It is read-only to checks.
|
|
type ScanContext struct {
|
|
repoRoot string
|
|
backendDir string
|
|
orchestratorOnly bool
|
|
includeCoreTargets bool
|
|
backendTargets []backendScanTarget
|
|
pluginTargets []pluginScanTarget // filtered
|
|
resolvedPluginTargets []pluginScanTarget // pre-filter
|
|
frontendTargets []frontendScanTarget
|
|
unresolvedPluginRoots []string
|
|
pluginPageDirs []string
|
|
}
|
|
|
|
// Reporter accumulates the process exit code across checks.
|
|
type Reporter struct {
|
|
exitCode int
|
|
}
|
|
|
|
// Fail marks the overall run as failed (exit code 1).
|
|
func (r *Reporter) Fail() { r.exitCode = 1 }
|
|
|
|
// Check is one registered safety check. Run prints its own header and results
|
|
// and calls rep.Fail() on violations, exactly as the original inline block did.
|
|
type Check struct {
|
|
Seq int
|
|
ID string
|
|
Title string
|
|
Run func(ctx *ScanContext, rep *Reporter)
|
|
}
|
|
|
|
var registry []Check
|
|
|
|
func register(c Check) { registry = append(registry, c) }
|