From f2170fc2bc356d47c2fdb4d337d5c9e58b81d758 Mon Sep 17 00:00:00 2001 From: Stefan Deissler <214100949+stefandeissler@users.noreply.github.com> Date: Thu, 10 Sep 2026 17:57:25 +0100 Subject: [PATCH 01/23] Update Makefile, based on keh-template and keh-github-policy audit Signed-off-by: Stefan Deissler --- Makefile | 125 ++++++++++++++++++++++++++++++++++++---------------- src/main.py | 13 +++--- 2 files changed, 95 insertions(+), 43 deletions(-) diff --git a/Makefile b/Makefile index f934ec7..db60758 100644 --- a/Makefile +++ b/Makefile @@ -1,61 +1,112 @@ -.DEFAULT_GOAL := all +.DEFAULT_GOAL := help -.PHONY: all -all: ## Show the available make targets. - @echo "Usage: make " - @echo "" - @echo "Targets:" - @fgrep "##" Makefile | fgrep -v fgrep +# The spacing and comments in this Makefile are intentionally formatted to +# allow the `make` command to display a nicely formatted list of available +# targets and their descriptions. + +# Single hash symbols (#) are used for comments that are not displayed in +# the `make` output, while double hash symbols (##) are used for comments +# that are displayed when running `make` without any arguments or with the +# `make help` command. + +# To add breaks between sections in the `make` output, simply add a comment line with +# double hash symbols and some spacing, as shown below. + +## +## ----------------------------------------------- +## Makefile for GitHub Repositry Archive Script +## ----------------------------------------------- +## + +.PHONY: help +help: ## This help message. + @sed -ne '/@sed/!s/## //p' $(MAKEFILE_LIST) + +## .PHONY: clean -clean: ## Clean the temporary files. - rm -rf .pytest_cache - rm -rf .mypy_cache - rm -rf .coverage - rm -rf .ruff_cache +clean: ## Clean the temporary files. rm -rf megalinter-reports - rm -rf debug.log rm -rf site + rm -rf dist + rm -rf build + rm -rf tmp + rm -rf outputs + rm -rf .ruff_cache + rm -rf .mypy_cache + rm -rf .pytest_cache + rm -rf .coverage + find . -type d -name '__pycache__' -exec rm -rf {} + + rm -rf build + rm -rf tmp + +## + +# Dependency installation + +.PHONY: install +install: ## Install the dependencies excluding dev. + poetry install --only main + +## + +.PHONY: install-dev +install-dev: ## Install the dependencies including dev. + poetry install + +## + +.PHONY: install-docs +install-docs: ## Install only the documentation dependencies + poetry install --only docs + +## + +# Formatting .PHONY: format -format: ## Format the code. +format: ## Format the code. poetry run black src poetry run ruff check src --fix +## + +# Linting + .PHONY: md-fix -md-fix: ## Run markdown linting with Markdownlint and fix issues. +md-fix: ## Run markdown linting with Markdownlint and fix issues. sh ./shell_scripts/md_fix.sh -.PHONY: lint -lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). - poetry run black --check src - poetry run ruff check src - make md-fix - make mypy - -.PHONY: test -test: ## Run the tests and check coverage. - poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=95 +## .PHONY: mypy -mypy: ## Run mypy. +mypy: ## Run mypy. poetry run mypy src -.PHONY: install -install: ## Install the dependencies excluding dev. - poetry install --only main +## -.PHONY: install-dev -install-dev: ## Install the dependencies including dev. - poetry install +.PHONY: lint +lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). + poetry run black --check src + poetry run ruff check src + make md-fix + make mypy -.PHONY: install-docs -install-docs: ## Install only the documentation dependencies - poetry install --only docs +## .PHONY: megalint -megalint: ## Run the mega-linter. +megalint: ## Run the mega-linter. docker run --platform linux/amd64 --rm \ -v /var/run/docker.sock:/var/run/docker.sock:rw \ -v $(shell pwd):/tmp/lint:rw \ - oxsecurity/megalinter:v8 \ No newline at end of file + oxsecurity/megalinter:v8 + +## + +# Testing + +.PHONY: test +test: ## Run the tests and check coverage. + poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=95 + +## diff --git a/src/main.py b/src/main.py index 26f295a..03e7d22 100644 --- a/src/main.py +++ b/src/main.py @@ -4,8 +4,9 @@ import json import os import time +from collections.abc import Callable from functools import wraps -from typing import Any, Callable, ParamSpec, Tuple, TypeVar, Union +from typing import Any, ParamSpec, TypeVar import boto3 import github_api_toolkit @@ -85,7 +86,7 @@ def get_environment_variable(variable_name: str) -> str: return variable -def get_access_token(secret_manager: Any, secret_name: str, org: str, app_client_id: str) -> Tuple[str, str]: +def get_access_token(secret_manager: Any, secret_name: str, org: str, app_client_id: str) -> tuple[str, str]: """Gets the access token from the AWS Secret Manager. Args: @@ -162,7 +163,7 @@ def wrapper(*args: P.args, **kwargs: P.kwargs) -> Any | None: def get_repository_page( logger: wrapped_logging, ql: github_api_toolkit.github_graphql_interface, - variables: dict[str, Union[str, int, None]], + variables: dict[str, str | int | None], ) -> Any: """Gets a page of non-archived repositories from a GitHub organization. @@ -257,7 +258,7 @@ def filter_response(logger: wrapped_logging, response_json: dict) -> Any: return response_repositories -def get_environment_variables() -> Tuple[str, str, str, str]: +def get_environment_variables() -> tuple[str, str, str, str]: """Gets the environment variables required for the script. Raises: @@ -328,7 +329,7 @@ def get_repositories( return repositories, number_of_pages -def load_archive_rules(archive_rules: dict) -> Tuple[int, int, str, list[str], int]: +def load_archive_rules(archive_rules: dict) -> tuple[int, int, str, list[str], int]: """Loads the archive rules from the configuration file. Args: @@ -372,7 +373,7 @@ def process_repositories( # noqa: C901, PLR0915 repositories: list[dict], archive_criteria: list[str], notification_content: list[str], -) -> Tuple[list, list]: +) -> tuple[list, list]: """Processes the repositories to archive them if they meet the criteria, or create issues to notify the owners/contributors. Args: From 5750fba56e27b79c2b459c20d75a27f9842bd7c4 Mon Sep 17 00:00:00 2001 From: Stefan Deissler <214100949+stefandeissler@users.noreply.github.com> Date: Thu, 10 Sep 2026 18:00:30 +0100 Subject: [PATCH 02/23] Update Makefile 2, based on keh-template and keh-github-policy audit Signed-off-by: Stefan Deissler --- Makefile | 36 +++++++++++++++++++++++++----------- 1 file changed, 25 insertions(+), 11 deletions(-) diff --git a/Makefile b/Makefile index db60758..abf20f2 100644 --- a/Makefile +++ b/Makefile @@ -14,12 +14,12 @@ ## ## ----------------------------------------------- -## Makefile for GitHub Repositry Archive Script +## Makefile for GitHub Repository Archive Script ## ----------------------------------------------- ## .PHONY: help -help: ## This help message. +help: ## This help message. @sed -ne '/@sed/!s/## //p' $(MAKEFILE_LIST) ## @@ -42,24 +42,42 @@ clean: ## Clean the temporary files. ## -# Dependency installation +# Environment specific dependencies .PHONY: install install: ## Install the dependencies excluding dev. poetry install --only main -## - .PHONY: install-dev install-dev: ## Install the dependencies including dev. poetry install ## -.PHONY: install-docs -install-docs: ## Install only the documentation dependencies +# MkDocs + +.PHONY: docs-install +docs-install: ## Install the dependencies for MkDocs. poetry install --only docs +.PHONY: docs-serve +docs-serve: docs-install ## Serve the documentation locally. + poetry run mkdocs serve + +.PHONY: docs-build +docs-build: docs-install ## Build the documentation. + poetry run mkdocs build --site-dir site + +.PHONY: docs-lint +docs-lint: ## Install and run the documentation linter (Markdownlint). + npm install -g markdownlint-cli + markdownlint . + +.PHONY: docs-fix +docs-fix: ## Install and run the documentation linter with auto-fix (Markdownlint). + npm install -g markdownlint-cli + markdownlint . --fix + ## # Formatting @@ -77,14 +95,10 @@ format: ## Format the code. md-fix: ## Run markdown linting with Markdownlint and fix issues. sh ./shell_scripts/md_fix.sh -## - .PHONY: mypy mypy: ## Run mypy. poetry run mypy src -## - .PHONY: lint lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). poetry run black --check src From 173acb2d402d1dece85402cef0c0b1be0852de3e Mon Sep 17 00:00:00 2001 From: Stefan Deissler <214100949+stefandeissler@users.noreply.github.com> Date: Fri, 11 Sep 2026 12:07:26 +0100 Subject: [PATCH 03/23] Extend Makefile and remove black formatter Signed-off-by: Stefan Deissler --- Makefile | 14 +++--- poetry.lock | 118 +++---------------------------------------------- pyproject.toml | 1 - 3 files changed, 13 insertions(+), 120 deletions(-) diff --git a/Makefile b/Makefile index abf20f2..e35315b 100644 --- a/Makefile +++ b/Makefile @@ -57,7 +57,7 @@ install-dev: ## Install the dependencies including dev. # MkDocs .PHONY: docs-install -docs-install: ## Install the dependencies for MkDocs. +docs-install: ## Install the dependencies for MkDocs. poetry install --only docs .PHONY: docs-serve @@ -69,12 +69,12 @@ docs-build: docs-install ## Build the documentation. poetry run mkdocs build --site-dir site .PHONY: docs-lint -docs-lint: ## Install and run the documentation linter (Markdownlint). +docs-lint: ## Install and run the documentation linter (Markdownlint). npm install -g markdownlint-cli markdownlint . .PHONY: docs-fix -docs-fix: ## Install and run the documentation linter with auto-fix (Markdownlint). +docs-fix: ## Install and run the documentation linter with auto-fix (Markdownlint). npm install -g markdownlint-cli markdownlint . --fix @@ -83,7 +83,7 @@ docs-fix: ## Install and run the documentation linter with auto-fix (Markdown # Formatting .PHONY: format -format: ## Format the code. +format: ## Run all formatters. poetry run black src poetry run ruff check src --fix @@ -91,6 +91,8 @@ format: ## Format the code. # Linting +# Primary Linting + .PHONY: md-fix md-fix: ## Run markdown linting with Markdownlint and fix issues. sh ./shell_scripts/md_fix.sh @@ -106,8 +108,6 @@ lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). make md-fix make mypy -## - .PHONY: megalint megalint: ## Run the mega-linter. docker run --platform linux/amd64 --rm \ @@ -121,6 +121,6 @@ megalint: ## Run the mega-linter. .PHONY: test test: ## Run the tests and check coverage. - poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=95 + poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=80 ## diff --git a/poetry.lock b/poetry.lock index 984f1bf..2e39195 100644 --- a/poetry.lock +++ b/poetry.lock @@ -1,4 +1,4 @@ -# This file is automatically @generated by Poetry 2.1.3 and should not be changed by hand. +# This file is automatically @generated by Poetry 2.4.3 and should not be changed by hand. [[package]] name = "astroid" @@ -46,57 +46,6 @@ files = [ [package.extras] extras = ["regex"] -[[package]] -name = "black" -version = "26.5.1" -description = "The uncompromising code formatter." -optional = false -python-versions = ">=3.10" -groups = ["dev"] -files = [ - {file = "black-26.5.1-cp310-cp310-macosx_10_9_x86_64.whl", hash = "sha256:9942db8888e06943c5dde66ca0037dcff82a2a4ec1ad0ada9e0d2ee9d9823893"}, - {file = "black-26.5.1-cp310-cp310-macosx_11_0_arm64.whl", hash = "sha256:89c93167a74d3a75dfaa38a5c7cca015537d5820dd7f17d63267d674a61cae90"}, - {file = "black-26.5.1-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:22f2cd76d069cc54c71f10360744ba8983fbb616903b4304a85b734915c8e1b4"}, - {file = "black-26.5.1-cp310-cp310-win_amd64.whl", hash = "sha256:87ed5c6f450580a2f6790bc7cbfb016dfc73bc750249762268a3695361315eef"}, - {file = "black-26.5.1-cp310-cp310-win_arm64.whl", hash = "sha256:58b4bd92cf88aacf83d88479c8f9caee044b1ec55f2451a337354a7ea2590a22"}, - {file = "black-26.5.1-cp311-cp311-macosx_10_9_x86_64.whl", hash = "sha256:96ae2c733b2aabdd9986e2c5df628ff3473676cd1c5faded1ff496cf6d74083c"}, - {file = "black-26.5.1-cp311-cp311-macosx_11_0_arm64.whl", hash = "sha256:0e48b87e03bf109288e55cfceadcfa15ff5470aca2851a851950ed2926f450d7"}, - {file = "black-26.5.1-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:5119fa92ae61f786e8c3662fd60aece1d0a2dd5cca5d0c79417a95e7a4272a59"}, - {file = "black-26.5.1-cp311-cp311-win_amd64.whl", hash = "sha256:30d3c14661f2792e9142cce3eeeb1cbc175b3eb5f733be0c8eeb99651e52b0c3"}, - {file = "black-26.5.1-cp311-cp311-win_arm64.whl", hash = "sha256:1ef92b76f7733f282fd096ea406200b5a286c42947412b0eaff3a74e3616cefe"}, - {file = "black-26.5.1-cp312-cp312-macosx_10_13_x86_64.whl", hash = "sha256:4ad6fa01f941920f54f2bbb35f3df7673428a0ef98a0b0840c2eaef3b110efa8"}, - {file = "black-26.5.1-cp312-cp312-macosx_11_0_arm64.whl", hash = "sha256:3915f256e75a2d7cf88d8953d37f780455dc586cc72dee059c528fe77f581217"}, - {file = "black-26.5.1-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:9d98d4137277c75dfb898ec8d846c4fd68ba1e9cf77f95e2865c203dc18f4c3d"}, - {file = "black-26.5.1-cp312-cp312-win_amd64.whl", hash = "sha256:a1dca32d9f1784af512a13410ec204c6f7f0aa9797a111c42e1c03449821c264"}, - {file = "black-26.5.1-cp312-cp312-win_arm64.whl", hash = "sha256:1037d5ac7b7b310b2632ad867ec8d0e4c4819dcdb0b820f63135da746a24e418"}, - {file = "black-26.5.1-cp313-cp313-macosx_10_13_x86_64.whl", hash = "sha256:2b36cf2ddf5566e205f6535f782a62194a184d33e175b64ae8c40b1737522be3"}, - {file = "black-26.5.1-cp313-cp313-macosx_11_0_arm64.whl", hash = "sha256:1f7ea64ebfa01b50f693508fc39f875e264446d3b097088f84f203b9d09618a0"}, - {file = "black-26.5.1-cp313-cp313-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:ecb3e624844c798144e9bd986954e0adc81d8911a1f30f375e1252fe26e8c294"}, - {file = "black-26.5.1-cp313-cp313-win_amd64.whl", hash = "sha256:e1a26503279b6b310669fb0b219c39e4820b77e8189fe80f522bb511f247db0a"}, - {file = "black-26.5.1-cp313-cp313-win_arm64.whl", hash = "sha256:5c34b25da232ead53a6f335b76dbea124f4d152ad568b9080d6f944bc2b34b52"}, - {file = "black-26.5.1-cp314-cp314-macosx_10_15_x86_64.whl", hash = "sha256:e88976690a64b0af98312ca958415849cb42423423c5f2ee74af4b49a97a2168"}, - {file = "black-26.5.1-cp314-cp314-macosx_11_0_arm64.whl", hash = "sha256:32d5ea7f6c8bdfa6e648326ebca1f02b0764e2a029edc6f8dce2627e19d468c3"}, - {file = "black-26.5.1-cp314-cp314-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:ea8d16dc41655aa113cd64665e7219446cd7e4ff2248d7178eaa905190c86b18"}, - {file = "black-26.5.1-cp314-cp314-win_amd64.whl", hash = "sha256:577f21094ea469ef92ec1adaf2c9441a226d2144d01a5be2fa823cecf6543e50"}, - {file = "black-26.5.1-cp314-cp314-win_arm64.whl", hash = "sha256:ed1a20af114c301a0269bf01163d51dbef72737fd65f850001e7cbe7f3c7abae"}, - {file = "black-26.5.1-py3-none-any.whl", hash = "sha256:4ed7f7da04046d2e488437170797d3b4a4ad83906683bcb7dfc68b673bbce5e2"}, - {file = "black-26.5.1.tar.gz", hash = "sha256:dd321f668053961824bcc1be1cc1df748b2d7e4fa28086b08331e577b0100a73"}, -] - -[package.dependencies] -click = ">=8.0.0" -mypy-extensions = ">=0.4.3" -packaging = ">=22.0" -pathspec = ">=1.0.0" -platformdirs = ">=2" -pytokens = ">=0.4.0,<0.5.0" - -[package.extras] -colorama = ["colorama (>=0.4.3)"] -d = ["aiohttp (>=3.10)"] -jupyter = ["ipython (>=7.8.0)", "tokenize-rt (>=3.2.0)"] -uvloop = ["uvloop (>=0.15.2) ; sys_platform != \"win32\"", "winloop (>=0.5.0) ; sys_platform == \"win32\""] - [[package]] name = "boto3" version = "1.43.78" @@ -451,7 +400,7 @@ version = "8.4.2" description = "Composable command line interface toolkit" optional = false python-versions = ">=3.10" -groups = ["dev", "docs"] +groups = ["docs"] files = [ {file = "click-8.4.2-py3-none-any.whl", hash = "sha256:e6f9f66136c816745b9d65817da91d61d957fb16e02e4dcd0552553c5a197b76"}, {file = "click-8.4.2.tar.gz", hash = "sha256:9a6cea6e60b17ebe0a44c5cc636d94f09bd66142c1cd7d8b4cd731c4917a15f6"}, @@ -471,7 +420,7 @@ files = [ {file = "colorama-0.4.6-py2.py3-none-any.whl", hash = "sha256:4f1d9991f5acc0ca119f9d443620b77f9d6b33703e51011c16baf57afb285fc6"}, {file = "colorama-0.4.6.tar.gz", hash = "sha256:08695f5cb7ed6e0531a20572697297273c47b8cae5a63ffc6d6ed5c201be6e44"}, ] -markers = {dev = "sys_platform == \"win32\" or platform_system == \"Windows\""} +markers = {dev = "sys_platform == \"win32\""} [[package]] name = "coverage" @@ -1617,61 +1566,6 @@ files = [ [package.dependencies] six = ">=1.5" -[[package]] -name = "pytokens" -version = "0.4.1" -description = "A Fast, spec compliant Python 3.14+ tokenizer that runs on older Pythons." -optional = false -python-versions = ">=3.8" -groups = ["dev"] -files = [ - {file = "pytokens-0.4.1-cp310-cp310-macosx_11_0_arm64.whl", hash = "sha256:2a44ed93ea23415c54f3face3b65ef2b844d96aeb3455b8a69b3df6beab6acc5"}, - {file = "pytokens-0.4.1-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:add8bf86b71a5d9fb5b89f023a80b791e04fba57960aa790cc6125f7f1d39dfe"}, - {file = "pytokens-0.4.1-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:670d286910b531c7b7e3c0b453fd8156f250adb140146d234a82219459b9640c"}, - {file = "pytokens-0.4.1-cp310-cp310-musllinux_1_2_x86_64.whl", hash = "sha256:4e691d7f5186bd2842c14813f79f8884bb03f5995f0575272009982c5ac6c0f7"}, - {file = "pytokens-0.4.1-cp310-cp310-win_amd64.whl", hash = "sha256:27b83ad28825978742beef057bfe406ad6ed524b2d28c252c5de7b4a6dd48fa2"}, - {file = "pytokens-0.4.1-cp311-cp311-macosx_11_0_arm64.whl", hash = "sha256:d70e77c55ae8380c91c0c18dea05951482e263982911fc7410b1ffd1dadd3440"}, - {file = "pytokens-0.4.1-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:4a58d057208cb9075c144950d789511220b07636dd2e4708d5645d24de666bdc"}, - {file = "pytokens-0.4.1-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:b49750419d300e2b5a3813cf229d4e5a4c728dae470bcc89867a9ad6f25a722d"}, - {file = "pytokens-0.4.1-cp311-cp311-musllinux_1_2_x86_64.whl", hash = "sha256:d9907d61f15bf7261d7e775bd5d7ee4d2930e04424bab1972591918497623a16"}, - {file = "pytokens-0.4.1-cp311-cp311-win_amd64.whl", hash = "sha256:ee44d0f85b803321710f9239f335aafe16553b39106384cef8e6de40cb4ef2f6"}, - {file = "pytokens-0.4.1-cp312-cp312-macosx_11_0_arm64.whl", hash = "sha256:140709331e846b728475786df8aeb27d24f48cbcf7bcd449f8de75cae7a45083"}, - {file = "pytokens-0.4.1-cp312-cp312-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:6d6c4268598f762bc8e91f5dbf2ab2f61f7b95bdc07953b602db879b3c8c18e1"}, - {file = "pytokens-0.4.1-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:24afde1f53d95348b5a0eb19488661147285ca4dd7ed752bbc3e1c6242a304d1"}, - {file = "pytokens-0.4.1-cp312-cp312-musllinux_1_2_x86_64.whl", hash = "sha256:5ad948d085ed6c16413eb5fec6b3e02fa00dc29a2534f088d3302c47eb59adf9"}, - {file = "pytokens-0.4.1-cp312-cp312-win_amd64.whl", hash = "sha256:3f901fe783e06e48e8cbdc82d631fca8f118333798193e026a50ce1b3757ea68"}, - {file = "pytokens-0.4.1-cp313-cp313-macosx_11_0_arm64.whl", hash = "sha256:8bdb9d0ce90cbf99c525e75a2fa415144fd570a1ba987380190e8b786bc6ef9b"}, - {file = "pytokens-0.4.1-cp313-cp313-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:5502408cab1cb18e128570f8d598981c68a50d0cbd7c61312a90507cd3a1276f"}, - {file = "pytokens-0.4.1-cp313-cp313-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:29d1d8fb1030af4d231789959f21821ab6325e463f0503a61d204343c9b355d1"}, - {file = "pytokens-0.4.1-cp313-cp313-musllinux_1_2_x86_64.whl", hash = "sha256:970b08dd6b86058b6dc07efe9e98414f5102974716232d10f32ff39701e841c4"}, - {file = "pytokens-0.4.1-cp313-cp313-win_amd64.whl", hash = "sha256:9bd7d7f544d362576be74f9d5901a22f317efc20046efe2034dced238cbbfe78"}, - {file = "pytokens-0.4.1-cp314-cp314-macosx_11_0_arm64.whl", hash = "sha256:4a14d5f5fc78ce85e426aa159489e2d5961acf0e47575e08f35584009178e321"}, - {file = "pytokens-0.4.1-cp314-cp314-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:97f50fd18543be72da51dd505e2ed20d2228c74e0464e4262e4899797803d7fa"}, - {file = "pytokens-0.4.1-cp314-cp314-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:dc74c035f9bfca0255c1af77ddd2d6ae8419012805453e4b0e7513e17904545d"}, - {file = "pytokens-0.4.1-cp314-cp314-musllinux_1_2_x86_64.whl", hash = "sha256:f66a6bbe741bd431f6d741e617e0f39ec7257ca1f89089593479347cc4d13324"}, - {file = "pytokens-0.4.1-cp314-cp314-win_amd64.whl", hash = "sha256:b35d7e5ad269804f6697727702da3c517bb8a5228afa450ab0fa787732055fc9"}, - {file = "pytokens-0.4.1-cp314-cp314t-macosx_11_0_arm64.whl", hash = "sha256:8fcb9ba3709ff77e77f1c7022ff11d13553f3c30299a9fe246a166903e9091eb"}, - {file = "pytokens-0.4.1-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:79fc6b8699564e1f9b521582c35435f1bd32dd06822322ec44afdeba666d8cb3"}, - {file = "pytokens-0.4.1-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:d31b97b3de0f61571a124a00ffe9a81fb9939146c122c11060725bd5aea79975"}, - {file = "pytokens-0.4.1-cp314-cp314t-musllinux_1_2_x86_64.whl", hash = "sha256:967cf6e3fd4adf7de8fc73cd3043754ae79c36475c1c11d514fc72cf5490094a"}, - {file = "pytokens-0.4.1-cp314-cp314t-win_amd64.whl", hash = "sha256:584c80c24b078eec1e227079d56dc22ff755e0ba8654d8383b2c549107528918"}, - {file = "pytokens-0.4.1-cp38-cp38-macosx_11_0_arm64.whl", hash = "sha256:da5baeaf7116dced9c6bb76dc31ba04a2dc3695f3d9f74741d7910122b456edc"}, - {file = "pytokens-0.4.1-cp38-cp38-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:11edda0942da80ff58c4408407616a310adecae1ddd22eef8c692fe266fa5009"}, - {file = "pytokens-0.4.1-cp38-cp38-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:0fc71786e629cef478cbf29d7ea1923299181d0699dbe7c3c0f4a583811d9fc1"}, - {file = "pytokens-0.4.1-cp38-cp38-musllinux_1_2_x86_64.whl", hash = "sha256:dcafc12c30dbaf1e2af0490978352e0c4041a7cde31f4f81435c2a5e8b9cabb6"}, - {file = "pytokens-0.4.1-cp38-cp38-win_amd64.whl", hash = "sha256:42f144f3aafa5d92bad964d471a581651e28b24434d184871bd02e3a0d956037"}, - {file = "pytokens-0.4.1-cp39-cp39-macosx_11_0_arm64.whl", hash = "sha256:34bcc734bd2f2d5fe3b34e7b3c0116bfb2397f2d9666139988e7a3eb5f7400e3"}, - {file = "pytokens-0.4.1-cp39-cp39-manylinux2014_aarch64.manylinux_2_17_aarch64.manylinux_2_28_aarch64.whl", hash = "sha256:941d4343bf27b605e9213b26bfa1c4bf197c9c599a9627eb7305b0defcfe40c1"}, - {file = "pytokens-0.4.1-cp39-cp39-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl", hash = "sha256:3ad72b851e781478366288743198101e5eb34a414f1d5627cdd585ca3b25f1db"}, - {file = "pytokens-0.4.1-cp39-cp39-musllinux_1_2_x86_64.whl", hash = "sha256:682fa37ff4d8e95f7df6fe6fe6a431e8ed8e788023c6bcc0f0880a12eab80ad1"}, - {file = "pytokens-0.4.1-cp39-cp39-win_amd64.whl", hash = "sha256:30f51edd9bb7f85c748979384165601d028b84f7bd13fe14d3e065304093916a"}, - {file = "pytokens-0.4.1-py3-none-any.whl", hash = "sha256:26cef14744a8385f35d0e095dc8b3a7583f6c953c2e3d269c7f82484bf5ad2de"}, - {file = "pytokens-0.4.1.tar.gz", hash = "sha256:292052fe80923aae2260c073f822ceba21f3872ced9a68bb7953b348e561179a"}, -] - -[package.extras] -dev = ["black", "build", "mypy", "pytest", "pytest-cov", "setuptools", "tox", "twine", "wheel"] - [[package]] name = "pyyaml" version = "6.0.3" @@ -1833,10 +1727,10 @@ files = [ ] [package.dependencies] -botocore = ">=1.37.4,<2.0a.0" +botocore = ">=1.37.4,<2.0a0" [package.extras] -crt = ["botocore[crt] (>=1.37.4,<2.0a.0)"] +crt = ["botocore[crt] (>=1.37.4,<2.0a0)"] [[package]] name = "six" @@ -1953,4 +1847,4 @@ watchmedo = ["PyYAML (>=3.10)"] [metadata] lock-version = "2.1" python-versions = "^3.12" -content-hash = "fd1f9b498026b313a78d7ddd802903c757fe9dfab2d29a89f47bf59b5adeaf2c" +content-hash = "7ddf5772d78ceeb3668b293891488a9aa459b66fb65e4423b24d30637cf7ad1f" diff --git a/pyproject.toml b/pyproject.toml index 5a78ea6..cb1ab75 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -15,7 +15,6 @@ requests = "^2.33.0" [tool.poetry.group.dev.dependencies] pylint = "^3.3.1" -black = "^26.3.1" pytest = "^9.0.3" pytest-xdist = "^3.6.1" ruff = "^0.7.1" From 5fd399eb8351bd5c38ef8c22e7230d45d9d78fff Mon Sep 17 00:00:00 2001 From: Stefan Deissler <214100949+stefandeissler@users.noreply.github.com> Date: Fri, 11 Sep 2026 16:36:32 +0100 Subject: [PATCH 04/23] Update megalint target in Makefile Signed-off-by: Stefan Deissler --- Makefile | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/Makefile b/Makefile index e35315b..049d0e0 100644 --- a/Makefile +++ b/Makefile @@ -83,9 +83,9 @@ docs-fix: ## Install and run the documentation linter with auto-fix (Markdownl # Formatting .PHONY: format -format: ## Run all formatters. - poetry run black src - poetry run ruff check src --fix +format: ## Run formatters. + poetry run ruff check src tests --fix + poetry run ruff format src tests ## @@ -99,21 +99,20 @@ md-fix: ## Run markdown linting with Markdownlint and fix issues. .PHONY: mypy mypy: ## Run mypy. - poetry run mypy src + poetry run mypy src tests .PHONY: lint lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). - poetry run black --check src - poetry run ruff check src - make md-fix - make mypy + poetry run ruff check src tests + poetry run ruff format src tests --check + poetry run mypy src tests .PHONY: megalint megalint: ## Run the mega-linter. - docker run --platform linux/amd64 --rm \ - -v /var/run/docker.sock:/var/run/docker.sock:rw \ + podman run --platform linux/amd64 --rm \ + -v /var/run/docker.sock:/var/run/podman.sock:rw \ -v $(shell pwd):/tmp/lint:rw \ - oxsecurity/megalinter:v8 + ghcr.io/oxsecurity/megalinter:v10.1.0 ## From a988caf42471680ab804db004e8b37f00e632066 Mon Sep 17 00:00:00 2001 From: Stefan Deissler <214100949+stefandeissler@users.noreply.github.com> Date: Mon, 14 Sep 2026 09:59:34 +0100 Subject: [PATCH 05/23] Test commit for gpg Signed-off-by: Stefan Deissler --- Makefile | 21 +++++++++++++++++++-- shell_scripts/md_fix.sh | 2 +- 2 files changed, 20 insertions(+), 3 deletions(-) diff --git a/Makefile b/Makefile index 049d0e0..c199e85 100644 --- a/Makefile +++ b/Makefile @@ -102,10 +102,11 @@ mypy: ## Run mypy. poetry run mypy src tests .PHONY: lint -lint: ## Run all linters (black/ruff/pylint/mypy/markdownlint). +lint: ## Run all linters. poetry run ruff check src tests poetry run ruff format src tests --check poetry run mypy src tests + make md-fix .PHONY: megalint megalint: ## Run the mega-linter. @@ -116,10 +117,26 @@ megalint: ## Run the mega-linter. ## +# Terraform + +.PHONY: tf-validate +tf-validate: ## Validate the Terraform configuration. + terraform -chdir=terraform validate + +.PHONY: tf-lint +tf-lint: ## Lint the Terraform configuration. + terraform -chdir=terraform fmt -check -recursive + +.PHONY: tf-fmt +tf-fmt: ## Format the Terraform configuration. + terraform -chdir=terraform fmt -recursive + +## + # Testing .PHONY: test test: ## Run the tests and check coverage. - poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=80 + poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=90 ## diff --git a/shell_scripts/md_fix.sh b/shell_scripts/md_fix.sh index e8359b2..db1805d 100644 --- a/shell_scripts/md_fix.sh +++ b/shell_scripts/md_fix.sh @@ -1,3 +1,3 @@ #!/bin/bash -docker run -v "$PWD:/workdir" ghcr.io/igorshubovych/markdownlint-cli:latest "**/*.md" --fix +podman run -v "$PWD:/workdir" ghcr.io/igorshubovych/markdownlint-cli:latest "**/*.md" --fix From fa6680607125d9a875cea26b370d325c1ac78cd6 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 14 Sep 2026 10:26:20 +0100 Subject: [PATCH 06/23] Another gpg test commit Signed-off-by: Stefan Deissler --- Makefile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Makefile b/Makefile index c199e85..2c052b5 100644 --- a/Makefile +++ b/Makefile @@ -137,6 +137,6 @@ tf-fmt: ## Format the Terraform configuration. .PHONY: test test: ## Run the tests and check coverage. - poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=90 + poetry run pytest -n auto --cov=src --cov-report term-missing --cov-fail-under=95 ## From 9d78ec508ec4bd15a0f41680bcbb300f5312d851 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 14 Sep 2026 15:37:18 +0100 Subject: [PATCH 07/23] Implement ci-docs.yml --- .github/workflows/ci-docs.yml | 0 .github/workflows/ci-fmt.zzz | 0 .github/workflows/ci-terraform.zzz | 0 .github/workflows/ci-test.zzz | 34 ++++++++++++++++++++++++++++++ Makefile | 2 +- 5 files changed, 35 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/ci-docs.yml create mode 100644 .github/workflows/ci-fmt.zzz create mode 100644 .github/workflows/ci-terraform.zzz create mode 100644 .github/workflows/ci-test.zzz diff --git a/.github/workflows/ci-docs.yml b/.github/workflows/ci-docs.yml new file mode 100644 index 0000000..e69de29 diff --git a/.github/workflows/ci-fmt.zzz b/.github/workflows/ci-fmt.zzz new file mode 100644 index 0000000..e69de29 diff --git a/.github/workflows/ci-terraform.zzz b/.github/workflows/ci-terraform.zzz new file mode 100644 index 0000000..e69de29 diff --git a/.github/workflows/ci-test.zzz b/.github/workflows/ci-test.zzz new file mode 100644 index 0000000..2ac7e8d --- /dev/null +++ b/.github/workflows/ci-test.zzz @@ -0,0 +1,34 @@ +--- +name: Testing +on: + push: + branches: [main] + paths: + - src/** + - tests/** + pull_request: + branches: [main] + paths: + - src/** + - tests/** +permissions: + contents: read +jobs: + unit-tests: + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Implement unit tests (TODO) + run: | + echo "TODO: Implement unit tests" + ui-tests: + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Implement UI tests (TODO) + run: | + echo "TODO: Implement UI tests" + + # Add more test jobs as needed, such as integration tests, end-to-end tests, etc. \ No newline at end of file diff --git a/Makefile b/Makefile index 2c052b5..b939d9e 100644 --- a/Makefile +++ b/Makefile @@ -42,7 +42,7 @@ clean: ## Clean the temporary files. ## -# Environment specific dependencies +# Dependencies .PHONY: install install: ## Install the dependencies excluding dev. From c34190a46cac836d483d14f1479dc3c2e07e383c Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 14 Sep 2026 15:59:45 +0100 Subject: [PATCH 08/23] Implement ci-test.yml --- .github/workflows/ci-docs.yml | 0 .github/workflows/ci-docs.zzz | 53 +++++++++++++++++++ .../workflows/{ci-test.zzz => ci-test.yml} | 0 3 files changed, 53 insertions(+) delete mode 100644 .github/workflows/ci-docs.yml create mode 100644 .github/workflows/ci-docs.zzz rename .github/workflows/{ci-test.zzz => ci-test.yml} (100%) diff --git a/.github/workflows/ci-docs.yml b/.github/workflows/ci-docs.yml deleted file mode 100644 index e69de29..0000000 diff --git a/.github/workflows/ci-docs.zzz b/.github/workflows/ci-docs.zzz new file mode 100644 index 0000000..1ef7999 --- /dev/null +++ b/.github/workflows/ci-docs.zzz @@ -0,0 +1,53 @@ +--- +name: Documentation CI +on: + push: + branches: [KEH-2606-Team-Best-Practice-Update] + paths: [docs/**] + pull_request: + branches: [KEH-2606-Team-Best-Practice-Update] + paths: [docs/**] +permissions: + contents: read +jobs: + lint-docs: + runs-on: ubuntu-latest + steps: + - name: Checkout code + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # V4.3.1 + with: + persist-credentials: false + - name: Set up Node.js + uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # V5 + with: + node-version: "24" + - name: Install markdownlint + run: | + npm install -g markdownlint-cli + - name: Run markdownlint + run: | + markdownlint ./docs/**/*.md + verify-build: + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Checkout code + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # V4.3.1 + with: + persist-credentials: false + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # V5.6.0 + with: + python-version: 3.x + - run: echo "cache_id=$(date --utc '+%V')" >> $GITHUB_ENV + - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # V4.3.0 + with: + key: mkdocs-material-${{ env.cache_id }} + path: .cache + restore-keys: | + mkdocs-material- + - run: pip install poetry + - run: poetry config virtualenvs.create false + - run: poetry install --only docs + - run: mkdocs build \ No newline at end of file diff --git a/.github/workflows/ci-test.zzz b/.github/workflows/ci-test.yml similarity index 100% rename from .github/workflows/ci-test.zzz rename to .github/workflows/ci-test.yml From 6dbdd4ef1c977eab63dc6948b8bae37fe75d7ec4 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 14 Sep 2026 16:23:11 +0100 Subject: [PATCH 09/23] Amend ci files --- .../workflows/{ci-docs.zzz => ci-docs.yml} | 0 .github/workflows/ci-fmt.yml | 39 +++++++++++++++++++ .github/workflows/ci-fmt.zzz | 0 .github/workflows/{ci.yml => ci.old} | 0 .../{deploy_mkdocs.yml => deploy_mkdocs.old} | 0 .../{mega-linter.yml => mega-linter.old} | 0 6 files changed, 39 insertions(+) rename .github/workflows/{ci-docs.zzz => ci-docs.yml} (100%) create mode 100644 .github/workflows/ci-fmt.yml delete mode 100644 .github/workflows/ci-fmt.zzz rename .github/workflows/{ci.yml => ci.old} (100%) rename .github/workflows/{deploy_mkdocs.yml => deploy_mkdocs.old} (100%) rename .github/workflows/{mega-linter.yml => mega-linter.old} (100%) diff --git a/.github/workflows/ci-docs.zzz b/.github/workflows/ci-docs.yml similarity index 100% rename from .github/workflows/ci-docs.zzz rename to .github/workflows/ci-docs.yml diff --git a/.github/workflows/ci-fmt.yml b/.github/workflows/ci-fmt.yml new file mode 100644 index 0000000..088f670 --- /dev/null +++ b/.github/workflows/ci-fmt.yml @@ -0,0 +1,39 @@ +--- +name: Linting and Formatting +on: + push: + branches: [main] + paths: + - src/** + - tests/** + pull_request: + branches: [main] + paths: + - src/** + - tests/** +permissions: + contents: read +jobs: + lint: + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Checkout code + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # V4.3.1 + with: + persist-credentials: false + - name: Install Poetry + run: | + pip install poetry + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # V5.6.0 + with: + python-version-file: ".python-version" + cache: poetry + - name: Install dependencies + run: | + make install-dev + - name: Run linters + run: | + make lint \ No newline at end of file diff --git a/.github/workflows/ci-fmt.zzz b/.github/workflows/ci-fmt.zzz deleted file mode 100644 index e69de29..0000000 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.old similarity index 100% rename from .github/workflows/ci.yml rename to .github/workflows/ci.old diff --git a/.github/workflows/deploy_mkdocs.yml b/.github/workflows/deploy_mkdocs.old similarity index 100% rename from .github/workflows/deploy_mkdocs.yml rename to .github/workflows/deploy_mkdocs.old diff --git a/.github/workflows/mega-linter.yml b/.github/workflows/mega-linter.old similarity index 100% rename from .github/workflows/mega-linter.yml rename to .github/workflows/mega-linter.old From b8d67f86ed2992abf499cddcd53a944d024b301f Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 14 Sep 2026 16:33:23 +0100 Subject: [PATCH 10/23] Implement all ci workflows other than terraform --- .github/workflows/ci-docs.yml | 2 +- .github/workflows/{deploy_mkdocs.old => deploy_mkdocs.yml} | 0 .github/workflows/{mega-linter.old => mega-linter.yml} | 0 3 files changed, 1 insertion(+), 1 deletion(-) rename .github/workflows/{deploy_mkdocs.old => deploy_mkdocs.yml} (100%) rename .github/workflows/{mega-linter.old => mega-linter.yml} (100%) diff --git a/.github/workflows/ci-docs.yml b/.github/workflows/ci-docs.yml index 1ef7999..2112b11 100644 --- a/.github/workflows/ci-docs.yml +++ b/.github/workflows/ci-docs.yml @@ -5,7 +5,7 @@ on: branches: [KEH-2606-Team-Best-Practice-Update] paths: [docs/**] pull_request: - branches: [KEH-2606-Team-Best-Practice-Update] + branches: [main] paths: [docs/**] permissions: contents: read diff --git a/.github/workflows/deploy_mkdocs.old b/.github/workflows/deploy_mkdocs.yml similarity index 100% rename from .github/workflows/deploy_mkdocs.old rename to .github/workflows/deploy_mkdocs.yml diff --git a/.github/workflows/mega-linter.old b/.github/workflows/mega-linter.yml similarity index 100% rename from .github/workflows/mega-linter.old rename to .github/workflows/mega-linter.yml From 6220cfd847468cc54687fabbb8e8d54b366215a3 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 09:53:23 +0100 Subject: [PATCH 11/23] Amend test_main.py to make it pass linting --- .github/workflows/ci-test.yml | 26 ++++++++++++++------------ tests/test_main.py | 16 ++++++++-------- 2 files changed, 22 insertions(+), 20 deletions(-) diff --git a/.github/workflows/ci-test.yml b/.github/workflows/ci-test.yml index 2ac7e8d..c3f62f2 100644 --- a/.github/workflows/ci-test.yml +++ b/.github/workflows/ci-test.yml @@ -14,21 +14,23 @@ on: permissions: contents: read jobs: - unit-tests: + test: runs-on: ubuntu-latest permissions: contents: read steps: - - name: Implement unit tests (TODO) - run: | - echo "TODO: Implement unit tests" - ui-tests: - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Implement UI tests (TODO) - run: | - echo "TODO: Implement UI tests" + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + persist-credentials: false + - name: Set up Node.js + uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 release + with: + node-version: '24' + + - name: Install dependencies + run: make install-dev + + - name: Test + run: make test # Add more test jobs as needed, such as integration tests, end-to-end tests, etc. \ No newline at end of file diff --git a/tests/test_main.py b/tests/test_main.py index 955dbe7..888a6e0 100644 --- a/tests/test_main.py +++ b/tests/test_main.py @@ -694,7 +694,7 @@ def test_process_repositories_max_notifications(self, mock_rest, mock_logger): ) assert repositories_archived == [] - assert issues_created == ["repo1", "repo2", "repo3", "repo4", "repo5"] # noqa: PLR2004 + assert issues_created == ["repo1", "repo2", "repo3", "repo4", "repo5"] assert mock_rest_instance.post.call_count == 5 # noqa: PLR2004 mock_logger_instance.log_info.assert_called_with( "Maximum number of notifications reached. No more notifications will be made." @@ -795,7 +795,7 @@ def test_process_repositories_issue_logging(self, mock_rest, mock_logger): ) assert repositories_archived == [] - assert issues_created == ["repo1", "repo2", "repo3", "repo4", "repo5"] # noqa: PLR2004 + assert issues_created == ["repo1", "repo2", "repo3", "repo4", "repo5"] assert mock_rest_instance.post.call_count == 5 # noqa: PLR2004 mock_logger_instance.log_info.assert_called_with( "Skipping repository. Maximum number of notifications reached." @@ -1054,7 +1054,7 @@ def test_handler_success( # noqa: PLR0913 mock_get_dict_value.assert_any_call(mock_get_config_file.return_value, "archive_configuration") mock_wrapped_logging.assert_called_once_with(True) mock_get_environment_variables.assert_called_once() - assert mock_boto3_session.return_value.client.call_count == 2 + assert mock_boto3_session.return_value.client.call_count == 2 # noqa: PLR2004 mock_boto3_session.return_value.client.assert_any_call( service_name="secretsmanager", region_name="mock_aws_default_region" ) @@ -1080,7 +1080,7 @@ def test_handler_success( # noqa: PLR0913 ["repo1", "repo2"], ["365", "30", "archive-notice", "5"], [ - 'Repository Archive Notice', + 'Repository Archive Notice', "## Important Notice \n\nThis repository has not been updated in over 365 days and will be archived in 30 days if no action is taken. \n## Actions Required to Prevent Archive \n\n1. Update the repository by creating/updating an exemption file. \n - The exemption file should be named one of the following: \n - ArchiveExemption.txt \n - ArchiveExemption.md \n\n - This file should contain the reason why the repository should not be archived. \n - If the file already exists, please update it with the latest information. \n2. Close this issue. \n\nAfter these actions, the repository will be exempt from archive for another 365 days. \n\n## Manual Archive \n\nIf you wish to archive this repository manually, please ensure the following: \n1. A notice is added to the repository `README.md` file indicating that the repository is archived. \n2. All issues and pull requests are closed (Optional but strongly recommended). \n3. Repository Admins / CODEOWNERS are up to date before archiving. This will make it easier to unarchive the repository in the future if needed. \n\nAfter these actions, you can archive the repository by going to the repository settings and selecting 'Archive this repository'. \n\n## Contact \n\nIf you have any questions about the process, please refer to the [FAQ section in the documentation](https://ons-innovation.github.io/github-repository-archive-script/). \nIf you still have questions, please contact an organisation administrator. \n\n" ], ) @@ -1166,7 +1166,7 @@ class TestCloudConfig: @patch("src.main.load_archive_rules") @patch("src.main.process_repositories") @patch("src.main.wrapped_logging") - def test_handler_success( + def test_handler_success( # noqa: PLR0913 self, mock_wrapped_logging, mock_process_repositories, @@ -1236,7 +1236,7 @@ def get_dict_value_side_effect(config, key): @patch("src.main.load_archive_rules") @patch("src.main.process_repositories") @patch("src.main.wrapped_logging") - def test_handler_s3_config( + def test_handler_s3_config( # noqa: PLR0913 self, mock_wrapped_logging, mock_process_repositories, @@ -1306,7 +1306,7 @@ def get_dict_value_side_effect(config, key): @patch("src.main.load_archive_rules") @patch("src.main.process_repositories") @patch("src.main.wrapped_logging") - def test_handler_s3_config_no_bucket( + def test_handler_s3_config_no_bucket( # noqa: PLR0913 self, mock_wrapped_logging, mock_process_repositories, @@ -1361,7 +1361,7 @@ def get_dict_value_side_effect(config, key): @patch("src.main.load_archive_rules") @patch("src.main.process_repositories") @patch("src.main.wrapped_logging") - def test_handler_s3_config_no_key( + def test_handler_s3_config_no_key( # noqa: PLR0913 self, mock_wrapped_logging, mock_process_repositories, From c1dc0af0c01c414b08a9520e7b09a1f13e0a899b Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 10:13:48 +0100 Subject: [PATCH 12/23] Format code using ruff formatter --- src/main.py | 5 ----- tests/test_logger.py | 1 - tests/test_main.py | 4 ++-- 3 files changed, 2 insertions(+), 8 deletions(-) diff --git a/src/main.py b/src/main.py index 03e7d22..a352d98 100644 --- a/src/main.py +++ b/src/main.py @@ -399,7 +399,6 @@ def process_repositories( # noqa: C901, PLR0915 notice_issued = False for repository in repositories: - last_update_string = get_dict_value(repository, "updatedAt") last_update = datetime.datetime.strptime(last_update_string, "%Y-%m-%dT%H:%M:%SZ") @@ -417,7 +416,6 @@ def process_repositories( # noqa: C901, PLR0915 # Check if the repository issue has been open for more than 30 days # If the issue has been open for more than 30 days, archive the repository if len(repository["issues"]["nodes"]): - issue_created_at = datetime.datetime.strptime( repository["issues"]["nodes"][0]["createdAt"], "%Y-%m-%dT%H:%M:%SZ" ) @@ -455,7 +453,6 @@ def process_repositories( # noqa: C901, PLR0915 # Create an issue with the label and a message to the repository owner/contributors if issues_created < int(maximum_notifications): - # Create Issue Label for Archive Notice if it does not exist label_endpoint = f"/repos/{org}/{repository['name']}/labels/{notification_issue_tag}" @@ -519,7 +516,6 @@ def process_repositories( # noqa: C901, PLR0915 def handler(event, context) -> str: # type: ignore[no-untyped-def] - # Load the configuration file config_file_path = "./config/config.json" @@ -539,7 +535,6 @@ def handler(event, context) -> str: # type: ignore[no-untyped-def] # Check whether to use local config or cloud config if not get_dict_value(features, "use_local_config"): - bucket_name = os.getenv("S3_BUCKET_NAME") if not bucket_name: diff --git a/tests/test_logger.py b/tests/test_logger.py index 7969169..2689ec0 100644 --- a/tests/test_logger.py +++ b/tests/test_logger.py @@ -2,7 +2,6 @@ class TestWrappedLogging: - def test_log_info(self, caplog): logger = wrapped_logging(debug=False) logger.log_info("Info message") diff --git a/tests/test_main.py b/tests/test_main.py index 888a6e0..81994ab 100644 --- a/tests/test_main.py +++ b/tests/test_main.py @@ -1080,8 +1080,8 @@ def test_handler_success( # noqa: PLR0913 ["repo1", "repo2"], ["365", "30", "archive-notice", "5"], [ - 'Repository Archive Notice', - "## Important Notice \n\nThis repository has not been updated in over 365 days and will be archived in 30 days if no action is taken. \n## Actions Required to Prevent Archive \n\n1. Update the repository by creating/updating an exemption file. \n - The exemption file should be named one of the following: \n - ArchiveExemption.txt \n - ArchiveExemption.md \n\n - This file should contain the reason why the repository should not be archived. \n - If the file already exists, please update it with the latest information. \n2. Close this issue. \n\nAfter these actions, the repository will be exempt from archive for another 365 days. \n\n## Manual Archive \n\nIf you wish to archive this repository manually, please ensure the following: \n1. A notice is added to the repository `README.md` file indicating that the repository is archived. \n2. All issues and pull requests are closed (Optional but strongly recommended). \n3. Repository Admins / CODEOWNERS are up to date before archiving. This will make it easier to unarchive the repository in the future if needed. \n\nAfter these actions, you can archive the repository by going to the repository settings and selecting 'Archive this repository'. \n\n## Contact \n\nIf you have any questions about the process, please refer to the [FAQ section in the documentation](https://ons-innovation.github.io/github-repository-archive-script/). \nIf you still have questions, please contact an organisation administrator. \n\n" + "Repository Archive Notice", + "## Important Notice \n\nThis repository has not been updated in over 365 days and will be archived in 30 days if no action is taken. \n## Actions Required to Prevent Archive \n\n1. Update the repository by creating/updating an exemption file. \n - The exemption file should be named one of the following: \n - ArchiveExemption.txt \n - ArchiveExemption.md \n\n - This file should contain the reason why the repository should not be archived. \n - If the file already exists, please update it with the latest information. \n2. Close this issue. \n\nAfter these actions, the repository will be exempt from archive for another 365 days. \n\n## Manual Archive \n\nIf you wish to archive this repository manually, please ensure the following: \n1. A notice is added to the repository `README.md` file indicating that the repository is archived. \n2. All issues and pull requests are closed (Optional but strongly recommended). \n3. Repository Admins / CODEOWNERS are up to date before archiving. This will make it easier to unarchive the repository in the future if needed. \n\nAfter these actions, you can archive the repository by going to the repository settings and selecting 'Archive this repository'. \n\n## Contact \n\nIf you have any questions about the process, please refer to the [FAQ section in the documentation](https://ons-innovation.github.io/github-repository-archive-script/). \nIf you still have questions, please contact an organisation administrator. \n\n", ], ) From 2f24acccd8096c7e319a163efef32c866259b0ec Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 10:21:51 +0100 Subject: [PATCH 13/23] Add Install poetry to ci-test.yml --- .github/workflows/ci-test.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/ci-test.yml b/.github/workflows/ci-test.yml index c3f62f2..0f6d9d2 100644 --- a/.github/workflows/ci-test.yml +++ b/.github/workflows/ci-test.yml @@ -18,7 +18,14 @@ jobs: runs-on: ubuntu-latest permissions: contents: read + steps: + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + with: + persist-credentials: false + - name: Install Poetry + run: pip install poetry + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: persist-credentials: false From 19d591570cb8d2c379c7146f341e4c9d34b37063 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 10:41:38 +0100 Subject: [PATCH 14/23] Remove /tests from linting --- Makefile | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Makefile b/Makefile index b939d9e..b2386f0 100644 --- a/Makefile +++ b/Makefile @@ -99,13 +99,13 @@ md-fix: ## Run markdown linting with Markdownlint and fix issues. .PHONY: mypy mypy: ## Run mypy. - poetry run mypy src tests + poetry run mypy src .PHONY: lint lint: ## Run all linters. - poetry run ruff check src tests - poetry run ruff format src tests --check - poetry run mypy src tests + poetry run ruff check src + poetry run ruff format src --check + poetry run mypy src make md-fix .PHONY: megalint From 4adb65f195160296652907de6f7f5a59da4f827c Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 11:12:55 +0100 Subject: [PATCH 15/23] Correct trigger in ci-docs.yml --- .github/workflows/ci-docs.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci-docs.yml b/.github/workflows/ci-docs.yml index 2112b11..eaff043 100644 --- a/.github/workflows/ci-docs.yml +++ b/.github/workflows/ci-docs.yml @@ -2,7 +2,7 @@ name: Documentation CI on: push: - branches: [KEH-2606-Team-Best-Practice-Update] + branches: [main] paths: [docs/**] pull_request: branches: [main] From fb9785d6b7210d4ffadd442d0c393a05902d9f36 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Tue, 15 Sep 2026 11:27:05 +0100 Subject: [PATCH 16/23] Format yml files with prettier --- .github/workflows/ci-docs.yml | 2 +- .github/workflows/ci-fmt.yml | 2 +- .github/workflows/ci-test.yml | 6 +++--- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ci-docs.yml b/.github/workflows/ci-docs.yml index eaff043..a2ac558 100644 --- a/.github/workflows/ci-docs.yml +++ b/.github/workflows/ci-docs.yml @@ -50,4 +50,4 @@ jobs: - run: pip install poetry - run: poetry config virtualenvs.create false - run: poetry install --only docs - - run: mkdocs build \ No newline at end of file + - run: mkdocs build diff --git a/.github/workflows/ci-fmt.yml b/.github/workflows/ci-fmt.yml index 088f670..9230a87 100644 --- a/.github/workflows/ci-fmt.yml +++ b/.github/workflows/ci-fmt.yml @@ -36,4 +36,4 @@ jobs: make install-dev - name: Run linters run: | - make lint \ No newline at end of file + make lint diff --git a/.github/workflows/ci-test.yml b/.github/workflows/ci-test.yml index 0f6d9d2..1fa9efa 100644 --- a/.github/workflows/ci-test.yml +++ b/.github/workflows/ci-test.yml @@ -25,14 +25,14 @@ jobs: persist-credentials: false - name: Install Poetry run: pip install poetry - + - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 with: persist-credentials: false - name: Set up Node.js uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 release with: - node-version: '24' + node-version: "24" - name: Install dependencies run: make install-dev @@ -40,4 +40,4 @@ jobs: - name: Test run: make test - # Add more test jobs as needed, such as integration tests, end-to-end tests, etc. \ No newline at end of file + # Add more test jobs as needed, such as integration tests, end-to-end tests, etc. From 53ba35c8547505856478878059996a9ca7df83f6 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Wed, 16 Sep 2026 12:55:30 +0100 Subject: [PATCH 17/23] Update README.md and documentation in /docs --- README.md | 178 +++++++++--------- config/config.json | 2 +- docs/documentation.md | 4 +- docs/technical_documentation/configuration.md | 2 +- 4 files changed, 93 insertions(+), 93 deletions(-) diff --git a/README.md b/README.md index e53cf02..6c9862b 100644 --- a/README.md +++ b/README.md @@ -32,8 +32,8 @@ A Python utility used to archive old, unused GitHub repositories from an organis ## Prerequisites -- A Docker Daemon (Colima is recommended) - - [Colima](https://github.com/abiosoft/colima) +- Podman container engine (daemonless, compatible with Docker) + - [Podman](https://podman.io/) - Terraform (For deployment) - [Terraform](https://www.terraform.io/) - Python >3.12 @@ -43,10 +43,10 @@ A Python utility used to archive old, unused GitHub repositories from an organis ## Makefile -This repository makes use of a Makefile to execute common commands. To view all commands, execute `make all`. +This repository makes use of a Makefile to execute common commands. To view all commands, execute `make help`. ```bash -make all +make help ``` ## Documentation @@ -56,13 +56,13 @@ This project uses [MkDocs](https://www.mkdocs.org/) for documentation. The docum 1. Install MkDocs and its dependencies: ```bash - make install-docs + make docs-install ``` 2. Serve the documentation locally: ```bash - mkdocs serve + make docs-serve ``` 3. Open your web browser and navigate to `http://localhost:8000`. @@ -76,13 +76,13 @@ To work on this project, you need to: Create: ```python - python3 -m venv venv + conda create -n venv python=3.12 ``` Activate: ```python - source venv/bin/activate + conda activate venv ``` 2. Install dependencies @@ -103,22 +103,76 @@ To run the project during development, we recommend you [run the project outside ## Running the Project -### Containerised (Recommended) +### Outside of a Container (Preferred) -To run the project, a Docker Daemon is required to containerise and execute the project. We recommend using [Colima](https://github.com/abiosoft/colima). +To run the Lambda function outside of a container, we need to execute the `handler()` function. + +1. Uncomment the following at the bottom of `main.py`. + + ```python + ... + # if __name__ == "__main__": + # handler(None, None) + ... + ``` + + **Please Note:** If uncommenting the above in `main.py`, make sure you re-comment the code _before_ pushing back to GitHub. + +2. Sign in with AWS SSO, and export the correct profile for this service: + + ```bash + aws sso login + + export AWS_PROFILE=github-repository-archive-script + ``` + + This allows you to assume the AWS IAM role for the service, enabling the most secure development experience. This also means you will have limited permissions until you exit out of the profile. + + **Note:** See the Developer Onboarding Guide on the "Using AWS SSO for Local Development" page on Confluence to set up service profile selection on your local machine. + +3. Export the required environment variables: + + ```bash + export AWS_DEFAULT_REGION=eu-west-2 + export AWS_SECRET_NAME= + export S3_BUCKET_NAME= + export GITHUB_ORG= + export GITHUB_APP_CLIENT_ID= + ``` + + An explanation of each variable: + + | Variable | Description | + |-----------------------------|----------------------------------------------------------------------------------------------------| + | GITHUB_ORG | The organisation you would like to run the tool in. | + | GITHUB_APP_CLIENT_ID | The Client ID for the GitHub App which the tool uses to authenticate with the GitHub API. | + | AWS_DEFAULT_REGION | The AWS Region which the Secret Manager Secret is in. | + | AWS_SECRET_NAME | The name of the AWS Secret Manager Secret to get. | + | AWS_BUCKET_NAME | The name of the S3 bucket which has the cloud config in (Only used when `use_local_config=False`). | + | AWS_LAMBDA_FUNCTION_TIMEOUT | The timeout time in seconds (Default: 300s / 5 minutes). | + +4. Run the script. + + ```bash + python3 src/main.py + ``` + +### Containerised -Before the doing the following, make sure your Daemon is running. If using Colima, run `colima start` to check this. +To run the project, a Podman machine (Podman VM) is required to containerise and execute the project. + +Before the doing the following, make sure your Podman VM is running. Run `podman machine init` and `podman machine start` to check this. 1. Containerise the project. ```bash - docker build -t github-repository-archive-script . + podman build -t github-repository-archive-script . ``` 2. Check the image exists (Optional). ```bash - docker images + podman images ``` Example Output: @@ -139,7 +193,7 @@ Before the doing the following, make sure your Daemon is running. If using Colim 4. Run the image. ```bash - docker run --platform linux/amd64 -p 9000:8080 \ + podman run --platform linux/amd64 -p 9000:8080 \ -v ~/.aws:/root/.aws \ -e AWS_PROFILE=github-repository-archive-script \ -e AWS_DEFAULT_REGION=eu-west-2 \ @@ -150,24 +204,14 @@ Before the doing the following, make sure your Daemon is running. If using Colim -e AWS_LAMBDA_FUNCTION_TIMEOUT=300 \ github-repository-archive-script ``` - - When running the container, you are required to pass some environment variables: - - | Variable | Description | - |-----------------------------|----------------------------------------------------------------------------------------------------| - | GITHUB_ORG | The organisation you would like to run the tool in. | - | GITHUB_APP_CLIENT_ID | The Client ID for the GitHub App which the tool uses to authenticate with the GitHub API. | - | AWS_DEFAULT_REGION | The AWS Region which the Secret Manager Secret is in. | - | AWS_SECRET_NAME | The name of the AWS Secret Manager Secret to get. | - | AWS_BUCKET_NAME | The name of the S3 bucket which has the cloud config in (Only used when `use_local_config=False`). | - | AWS_LAMBDA_FUNCTION_TIMEOUT | The timeout time in seconds (Default: 300s / 5 minutes). | + (See section `Running the project - Outside of a container` for environment variables) Once the container is running, a local endpoint is created at `localhost:9000/2015-03-31/functions/function/invocations`. 5. Check the container is running (Optional). ```bash - docker ps + podman ps ``` Example Output: @@ -188,52 +232,7 @@ Before the doing the following, make sure your Daemon is running. If using Colim 7. After testing stop the container. ```bash - docker stop - ``` - -### Outside of a Container (Development only) - -To run the Lambda function outside of a container, we need to execute the `handler()` function. - -1. Uncomment the following at the bottom of `main.py`. - - ```python - ... - # if __name__ == "__main__": - # handler(None, None) - ... - ``` - - **Please Note:** If uncommenting the above in `main.py`, make sure you re-comment the code _before_ pushing back to GitHub. - -2. Sign in with AWS SSO, and export the correct profile for this service: - - ```bash - aws sso login - - export AWS_PROFILE=github-repository-archive-script - ``` - - This allows you to assume the AWS IAM role for the service, enabling the most secure development experience. This also means you will have limited permissions until you exit out of the profile. - - **Note:** See the Developer Onboarding Guide on the "Using AWS SSO for Local Development" page on Confluence to set up service profile selection on your local machine. - -3. Export the required environment variables: - - ```bash - export AWS_DEFAULT_REGION=eu-west-2 - export AWS_SECRET_NAME= - export S3_BUCKET_NAME= - export GITHUB_ORG= - export GITHUB_APP_CLIENT_ID= - ``` - - An explanation of each variable is available within the [containerised instructions](#containerised-recommended). - -4. Run the script. - - ```bash - python3 src/main.py + podman stop ``` ## Deployment @@ -326,23 +325,22 @@ The following instructions deploy to an ECR repository called `sdp-dev-repositor All of the commands (steps 2-5) are available for your environment within the AWS GUI. Navigate to ECR > {repository_name} > View push commands. -1. Export AWS credential into the environment. This makes it easier to ensure you are using the correct credentials. +1. Log in to AWS ```bash - export AWS_ACCESS_KEY_ID="" - export AWS_SECRET_ACCESS_KEY="" + aws sso login ``` -2. Login to AWS. +2. Login to AWS ECR. ```bash - aws ecr get-login-password --region eu-west-2 | docker login --username AWS --password-stdin .dkr.ecr.eu-west-2.amazonaws.com + aws ecr get-login-password --region eu-west-2 | podman login --username AWS --password-stdin .dkr.ecr.eu-west-2.amazonaws.com ``` -3. Ensuring you're at the root of the repository, build a docker image of the project. +3. Ensuring you're at the root of the repository, build a podman image of the project. ```bash - docker build -t sdp-dev-github-repository-archive-script . + podman build -t sdp-dev-github-repository-archive-script . ``` **Please Note:** Change `sdp-dev-github-repository-archive-script` within the above command to `-`. @@ -350,7 +348,7 @@ All of the commands (steps 2-5) are available for your environment within the AW 4. Tag the docker image to push to AWS, using the correct versioning mentioned in [prerequisites](#deployment-prerequisites). ```bash - docker tag sdp-dev-github-repository-archive-script:latest .dkr.ecr.eu-west-2.amazonaws.com/sdp-dev-github-repository-archive-script: + podman tag sdp-dev-github-repository-archive-script:latest .dkr.ecr.eu-west-2.amazonaws.com/sdp-dev-github-repository-archive-script: ``` **Please Note:** Change `sdp-dev-github-repository-archive-script` within the above command to `-`. @@ -358,7 +356,7 @@ All of the commands (steps 2-5) are available for your environment within the AW 5. Push the image to ECR. ```bash - docker push .dkr.ecr.eu-west-2.amazonaws.com/sdp-dev-github-repository-archive-script: + podman push .dkr.ecr.eu-west-2.amazonaws.com/sdp-dev-github-repository-archive-script: ``` Once pushed, you should be able to see your new image version within the ECR repository. @@ -384,18 +382,19 @@ Within the terraform directory, there is a [service](./terraform/service/) subdi **It is crucial that the completed `.tfvars` file does not get committed to GitHub.** 3. Initialise the terraform using the appropriate `.tfbackend` file for the environment (`env/dev/backend-dev.tfbackend` or `env/prod/backend-prod.tfbackend`). + + To execute this step, you need to be logged in to AWS: ```bash - terraform init -backend-config=env/dev/backend-dev.tfbackend -reconfigure + aws sso login ``` - **Please Note:** This step requires an AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY to be loaded into the environment if not already in place. This can be done using: - ```bash - export AWS_ACCESS_KEY_ID="" - export AWS_SECRET_ACCESS_KEY="" + terraform init -backend-config=env/dev/backend-dev.tfbackend -reconfigure ``` + + 4. Refresh the local state to ensure it is in sync with the backend, using the appropriate `.tfvars` file for the environment (`env/dev/dev.tfvars` or `env/prod/prod.tfvars`). ```bash @@ -437,9 +436,10 @@ terraform destroy -var-file=env/dev/dev.tfvars ### GitHub Actions -This file contains 2 GitHub Actions to automatically lint and test code on pull request creation and pushing to the main branch. +This file contains 3 GitHub Actions to automatically lint and test code on pull request creation and pushing to the main branch. -- [`ci.yml`](./.github/workflows/ci.yml) +- [`ci-fmt.yml`](./.github/workflows/ci-fmt.yml) +- [`ci-test.yml`](./.github/workflows/ci-test.yml) - [`mega-linter.yml`](./.github/workflows/mega-linter.yml) ### Running Tests Locally @@ -470,4 +470,4 @@ To lint and test locally, you need to: make megalint ``` -**Please Note:** This requires a docker daemon to be running. We recommend using [Colima](https://github.com/abiosoft/colima) if using MacOS or Linux. A docker daemon is required because Megalinter is ran from a docker image. +**Please Note:** This requires a running Podman VM. diff --git a/config/config.json b/config/config.json index f6ffc63..899afbc 100644 --- a/config/config.json +++ b/config/config.json @@ -8,6 +8,6 @@ "notification_period": 30, "notification_issue_tag": "Archive Notice", "exemption_filename": ["ArchiveExemption.txt", "ArchiveExemption.md"], - "maximum_notifications": 1 + "maximum_notifications": 0 } } diff --git a/docs/documentation.md b/docs/documentation.md index 0cc33ff..53f4e67 100644 --- a/docs/documentation.md +++ b/docs/documentation.md @@ -20,7 +20,7 @@ Each `README.md` should contain: The `/docs` folder should contain: - A description of what the project is -- An overview of how the everything fits together in the project +- An overview of how everything fits together in the project - An explanation of the tech stack - Details of the underlying dataset @@ -35,7 +35,7 @@ In order to build an MkDocs deployment or serve the documentation locally, we ne 2. Install MkDocs and its dependencies. ```bash - make install-docs + make docs-install ``` 3. You can now use MkDocs. To see a list of commands run the following: diff --git a/docs/technical_documentation/configuration.md b/docs/technical_documentation/configuration.md index b078cc1..17485bf 100644 --- a/docs/technical_documentation/configuration.md +++ b/docs/technical_documentation/configuration.md @@ -24,7 +24,7 @@ The `config.json` file contains the following: ### `features` Section -This section contains feature flags that control which the tool's features are enabled or disabled. +This section contains feature flags that control which of the tool's features are enabled or disabled. #### `show_log_locally` From 057206cc627c1d484cb4cc1e55f529a31b609566 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Wed, 16 Sep 2026 14:44:19 +0100 Subject: [PATCH 18/23] Fix README.md links to headlines --- README.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 6c9862b..4099073 100644 --- a/README.md +++ b/README.md @@ -11,8 +11,8 @@ A Python utility used to archive old, unused GitHub repositories from an organis - [Documentation](#documentation) - [Development](#development) - [Running the Project](#running-the-project) - - [Containerised (Recommended)](#containerised-recommended) - - [Outside of a Container (Development only)](#outside-of-a-container-development-only) + - [Containerised](#containerised) + - [Outside of a Container](#outside-of-a-container) - [Deployment](#deployment) - [Deployments with Concourse](#deployments-with-concourse) - [Allowlisting your IP](#allowlisting-your-ip) @@ -99,11 +99,11 @@ To work on this project, you need to: make install-dev ``` -To run the project during development, we recommend you [run the project outside of a container](#outside-of-a-container-development-only) +To run the project during development, we recommend you run the project [Outside of a Container](#outside-of-a-container) ## Running the Project -### Outside of a Container (Preferred) +### Outside of a Container To run the Lambda function outside of a container, we need to execute the `handler()` function. From 7bd6bc6b331aa5888b4684739426819207eddb18 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Wed, 16 Sep 2026 14:56:21 +0100 Subject: [PATCH 19/23] Fix README.md formatting errors --- README.md | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 4099073..1f1ed5b 100644 --- a/README.md +++ b/README.md @@ -11,8 +11,8 @@ A Python utility used to archive old, unused GitHub repositories from an organis - [Documentation](#documentation) - [Development](#development) - [Running the Project](#running-the-project) - - [Containerised](#containerised) - [Outside of a Container](#outside-of-a-container) + - [Containerised](#containerised) - [Deployment](#deployment) - [Deployments with Concourse](#deployments-with-concourse) - [Allowlisting your IP](#allowlisting-your-ip) @@ -204,6 +204,7 @@ Before the doing the following, make sure your Podman VM is running. Run `podman -e AWS_LAMBDA_FUNCTION_TIMEOUT=300 \ github-repository-archive-script ``` + (See section `Running the project - Outside of a container` for environment variables) Once the container is running, a local endpoint is created at `localhost:9000/2015-03-31/functions/function/invocations`. @@ -382,7 +383,7 @@ Within the terraform directory, there is a [service](./terraform/service/) subdi **It is crucial that the completed `.tfvars` file does not get committed to GitHub.** 3. Initialise the terraform using the appropriate `.tfbackend` file for the environment (`env/dev/backend-dev.tfbackend` or `env/prod/backend-prod.tfbackend`). - + To execute this step, you need to be logged in to AWS: ```bash @@ -393,8 +394,6 @@ Within the terraform directory, there is a [service](./terraform/service/) subdi terraform init -backend-config=env/dev/backend-dev.tfbackend -reconfigure ``` - - 4. Refresh the local state to ensure it is in sync with the backend, using the appropriate `.tfvars` file for the environment (`env/dev/dev.tfvars` or `env/prod/prod.tfvars`). ```bash From a264dd363c9e76aa5c624adcb07129b1a6652e7c Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Wed, 16 Sep 2026 15:03:34 +0100 Subject: [PATCH 20/23] Eliminate trailing spaces from README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 1f1ed5b..8660eba 100644 --- a/README.md +++ b/README.md @@ -204,7 +204,7 @@ Before the doing the following, make sure your Podman VM is running. Run `podman -e AWS_LAMBDA_FUNCTION_TIMEOUT=300 \ github-repository-archive-script ``` - + (See section `Running the project - Outside of a container` for environment variables) Once the container is running, a local endpoint is created at `localhost:9000/2015-03-31/functions/function/invocations`. From 1e98ca6f47f80c26ce844199cd21f70085e41a39 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Wed, 16 Sep 2026 15:18:34 +0100 Subject: [PATCH 21/23] Update pull_request_template.md --- .github/pull_request_template.md | 49 ++++++++++++++++---------------- 1 file changed, 24 insertions(+), 25 deletions(-) diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md index 4296043..21ea598 100644 --- a/.github/pull_request_template.md +++ b/.github/pull_request_template.md @@ -1,38 +1,37 @@ -# What type of PR is this? (check all applicable) + -- [ ] Refactor -- [ ] Feature -- [ ] Bug Fix -- [ ] Optimization -- [ ] Documentation Update +## Overview -## What + -Describe what you have changed and why. +## Related Issues -### Testing + + -Have any new tests been added as part of this issue? If not, try to explain why test coverage is not needed here. +## Testing -- [ ] Yes -- [ ] No - Please write a brief description of why test coverage is not necessary here. -- [ ] Not as part of this ticket. (Could be done at a later point) + -### Documentation +## Checklist -Has any new documentation been written as part of this issue? We should try to keep documentation up to date -as new code is added, rather than leaving it for the future. + + -- [ ] Yes -- [ ] No - Please write a brief description of why documentation is not necessary here. -- [ ] Not as part of this ticket. (Could be done at a later point) +- [ ] I have reviewed the changes in this pull request +- [ ] I have tested the changes locally +- [ ] I have updated/created any relevant documentation +- [ ] I have updated/created any relevant tests +- [ ] All CI checks have passed +- [ ] I have used a development Concourse pipeline to test the changes within a development environment +- [ ] I have added any necessary labels to this pull request +- [ ] I have assigned myself to this pull request +- [ ] I have assigned the appropriate reviewers to this pull request -### Related issues +### Exemptions -Provide links to any related issues. + -### How to review +## Additional Notes -Describe the steps required to test the changes. + \ No newline at end of file From e44541c605b4f1b28fbdb3e343e5bfe0eeb490af Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Thu, 17 Sep 2026 12:21:38 +0100 Subject: [PATCH 22/23] Delete excess/old ci yml files --- .github/workflows/ci-terraform.zzz | 0 .github/workflows/ci.old | 40 ------------------------------ 2 files changed, 40 deletions(-) delete mode 100644 .github/workflows/ci-terraform.zzz delete mode 100644 .github/workflows/ci.old diff --git a/.github/workflows/ci-terraform.zzz b/.github/workflows/ci-terraform.zzz deleted file mode 100644 index e69de29..0000000 diff --git a/.github/workflows/ci.old b/.github/workflows/ci.old deleted file mode 100644 index dd470e2..0000000 --- a/.github/workflows/ci.old +++ /dev/null @@ -1,40 +0,0 @@ ---- -name: CI - -on: # yamllint disable-line rule:truthy - push: - branches: [main] - pull_request: - branches: [main] - -permissions: read-all - -concurrency: - group: "${{ github.head_ref || github.ref }}-${{ github.workflow }}" - cancel-in-progress: true - -jobs: - lint-test: - name: Lint and Test - runs-on: ubuntu-22.04 - steps: - - uses: actions/checkout@1e31de5234b9f8995739874a8ce0492dc87873e2 # v4.0.0 - with: - persist-credentials: false - - name: Install Poetry - run: pipx install poetry==1.8.3 - - - name: Set up Python - uses: actions/setup-python@0a5c61591373683505ea898e09a3ea4f39ef2b9c # v5.0.0 - with: - python-version-file: .python-version - cache: poetry - - - name: Install dependencies - run: make install-dev - - - name: Lint Python - run: make lint - - - name: Test - run: make test From 6e58791b26a606f47ed9fbc87f8d820d90a4b352 Mon Sep 17 00:00:00 2001 From: Stefan Deissler Date: Mon, 21 Sep 2026 09:06:44 +0100 Subject: [PATCH 23/23] Remove duplicate lines from Makefile --- Makefile | 2 -- 1 file changed, 2 deletions(-) diff --git a/Makefile b/Makefile index b2386f0..d725ea9 100644 --- a/Makefile +++ b/Makefile @@ -37,8 +37,6 @@ clean: ## Clean the temporary files. rm -rf .pytest_cache rm -rf .coverage find . -type d -name '__pycache__' -exec rm -rf {} + - rm -rf build - rm -rf tmp ##