-
-
Notifications
You must be signed in to change notification settings - Fork 0
chore: configure CodeAnt AI and sync the other reviewer configs #84
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,109 @@ | ||
| # CodeAnt AI configuration | ||
|
|
||
| Repository-level configuration for [CodeAnt AI](https://docs.codeant.ai), | ||
| checked in so the settings are reviewed like any other change instead of | ||
| living only in a dashboard. CodeAnt resolves configuration as **inline CI | ||
| parameters > this directory > dashboard settings**, and each level overrides | ||
| only the fields it defines. | ||
|
|
||
| This is the third reviewer configured for this repo, alongside | ||
| `.coderabbit.yaml` and `.greptile/`. The rule ids below deliberately match | ||
| `.greptile/config.json` where the rule is the same, so one invariant has one | ||
| name across every tool. | ||
|
|
||
| | File | Purpose | Reference | | ||
| | --- | --- | --- | | ||
| | `configuration.json` | Which analyses run, and over which files | [Analysis Configuration](https://docs.codeant.ai/repositories/analysis_configuration) | | ||
| | `review.json` | Repo-specific review rules, merged by `id` | [Rules](https://docs.codeant.ai/pull_request/customize/rules) | | ||
| | `instructions.json` | Context that prevents false positives, merged by `id` | [Instructions](https://docs.codeant.ai/pull_request/customize/instructions) | | ||
| | `quality_gates_conditions.json` | Conditions that gate a PR | [Quality Gates](https://docs.codeant.ai/pull_request/quality_gates/repository_configuration) | | ||
|
|
||
| Anything an organization-wide global config repo defines is merged in | ||
| underneath these files; a local `id` or `metric` always wins. | ||
|
|
||
| ## What is enabled, and why | ||
|
|
||
| Two analyses are off. Both are switched off because CI already answers the | ||
| same question more accurately for this codebase, not because the question | ||
| does not matter: | ||
|
|
||
| - **`deadcode_analysis`** — this is a published library, so an exported | ||
| identifier with no in-repo caller is the public API rather than dead code. | ||
| `golangci-lint`'s `unused` runs in `make ci` and understands that | ||
| distinction; a generic reachability pass would report the whole exported | ||
| surface, plus the optional driver-interface methods in | ||
| `middleware/driver.go` that exist so `database/sql`'s type assertions | ||
| succeed. | ||
| - **`duplicatecode_analysis`** — the four `Query`/`Exec` branches in | ||
| `middleware/driver.go` and the six `integrations/*` adapters are | ||
| deliberately parallel; each branch forwards to a different optional base | ||
| interface, and collapsing them changes fallback behaviour. AGENTS.md | ||
| records this as an invariant. | ||
|
|
||
| Everything else stays on. `sast_analysis`, `secrets_analysis`, `sca_analysis` | ||
| and `iac_analysis` matter most here: sqlguard is a defensive security tool, | ||
| and `SECURITY.md` treats a missed dangerous query, a leaked literal or an | ||
| executed `EXPLAIN` as vulnerabilities rather than style nits. | ||
| `complex_function_analysis` keeps the default maintainability index of 15, | ||
| which pairs with `gocyclo`'s `min-complexity: 15` in `.golangci.yml`. | ||
|
|
||
| ## File filters | ||
|
|
||
| Two separate keys, because they scope different things: | ||
|
|
||
| - `file_filters.config.exclude_files` scopes **analysis**. It drops build | ||
| output, `node_modules`, the frozen docs snapshots and the static assets. | ||
| `go.mod` and `go.sum` stay in scope — they are how software composition | ||
| analysis sees the dependency graph. | ||
| - `review_configuration.exclude` scopes **PR review**, and additionally drops | ||
| `go.sum`, `package-lock.json` and `testdata`, where a line-by-line AI | ||
| comment has nothing useful to say. | ||
|
|
||
| `include_files` is left empty on purpose: when it is set it takes precedence | ||
| and the exclude patterns are ignored entirely. | ||
|
|
||
| `website/versioned_docs/**` and `website/versioned_sidebars/**` are excluded | ||
| from both. They are frozen release snapshots produced by | ||
| `npm run cut-version`; a suggestion there is unactionable by definition, | ||
| since editing a snapshot rewrites history for users still on that version. | ||
|
|
||
| ## Quality gates | ||
|
|
||
| Security-first and deliberately small, so a red gate always means something: | ||
|
|
||
| | Metric | Condition | Effect | | ||
| | --- | --- | --- | | ||
| | `secrets` | `GREATER_THAN 0` | Any new secret fails the commit or PR | | ||
| | `sast_rating` | `LESS_THAN B` | Requires A or better (fails on a medium-or-worse finding) | | ||
| | `sca_rating` | `LESS_THAN B` | Same bar for dependency vulnerabilities | | ||
|
|
||
| The secrets condition excludes `test/integration/docker-compose.yml`, whose | ||
| user, password and database are all the literal string `sqlguard`. Those are | ||
| fixtures for ephemeral local containers on deliberately non-default host | ||
| ports, used by `make db-up`; they are not a credential for anything. The | ||
| exclusion is scoped to that one file so a real secret anywhere else still | ||
| fails the gate. | ||
|
|
||
| Coverage metrics (`new_coverage_percentage`, `total_coverage_percentage`) are | ||
| **not** configured. Coverage in this repo is merged by `make coverage` and | ||
| uploaded to Codecov (`codecov.yml`); CodeAnt would need its own | ||
| [coverage upload step](https://docs.codeant.ai/control_center/test_coverage/github) | ||
| in `ci.yml` plus an API token before such a gate could pass, and a gate that | ||
| cannot pass is worse than no gate. Add the upload first if you want one. | ||
|
|
||
| Auto-approval (`.codeant/approval.json`) is also not configured. `main` takes | ||
| changes through pull requests that a human merges, so nothing here should | ||
| approve itself. | ||
|
|
||
| ## Changing this | ||
|
|
||
| - Rules and instructions are merged **by `id`** — keep ids stable and | ||
| descriptive so a global config, or a future override, can address them. | ||
| - A rule says what the reviewer should *enforce*; an instruction gives context | ||
| that stops it reporting something deliberate. Adding an instruction is | ||
| usually the right fix for a false positive. | ||
| - `scope` must contain `"pr"` for a rule to apply during pull request review; | ||
| `"ide"` applies it in the editor extensions. | ||
| - Prefer findings CI cannot already produce. `make ci` runs gofmt, `go vet`, | ||
| `golangci-lint`, `govulncheck`, `go test -race` and markdownlint across all | ||
| nine modules, and a separate workflow runs CodeQL. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,42 @@ | ||
| { | ||
| "code_analysis": { | ||
| "enabled": true, | ||
| "features": { | ||
| "sast_analysis": "enabled", | ||
| "secrets_analysis": "enabled", | ||
| "sca_analysis": "enabled", | ||
| "iac_analysis": "enabled", | ||
| "antipatterns_analysis": "enabled", | ||
| "docstring_analysis": "enabled", | ||
| "complex_function_analysis": "enabled", | ||
| "deadcode_analysis": "disabled", | ||
| "duplicatecode_analysis": "disabled" | ||
| }, | ||
| "config": { | ||
| "complexity": { | ||
| "maintainability_index": 15 | ||
| } | ||
| } | ||
| }, | ||
| "file_filters": { | ||
| "config": { | ||
| "include_files": "", | ||
| "exclude_files": "bin/**,dist/**,**/node_modules/**,website/build/**,website/.docusaurus/**,website/versioned_docs/**,website/versioned_sidebars/**,website/static/**" | ||
| } | ||
| }, | ||
| "review_configuration": { | ||
| "exclude": [ | ||
| "bin/**", | ||
| "dist/**", | ||
| "**/node_modules/**", | ||
| "**/package-lock.json", | ||
| "**/go.sum", | ||
| "**/testdata/**", | ||
| "website/build/**", | ||
| "website/.docusaurus/**", | ||
| "website/versioned_docs/**", | ||
| "website/versioned_sidebars/**", | ||
| "website/static/**" | ||
| ] | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,58 @@ | ||
| { | ||
| "instructions": [ | ||
| { | ||
| "id": "repo-context", | ||
| "description": "sqlguard (github.com/KARTIKrocks/sqlguard) is a near-zero-dependency, security-conscious SQL query analyzer for Go: a database/sql driver-layer middleware, a static CLI scanner and an EXPLAIN-plan analyzer sharing one analyzer/reporter core. It is a defensive security tool - a bug that lets it silently miss a dangerous query, leak a raw literal, or actually execute a statement during EXPLAIN is a security bug rather than a style nit (see SECURITY.md). Prioritise fail-closed behaviour, PII redaction, concurrency safety and not altering query semantics over style. The project is pre-release with no backward-compatibility guarantee: prefer the clean redesign over preserving an existing public API, and do not suggest deprecation shims, compat layers or add-alongside variants. AGENTS.md is the authoritative description of the architecture and its invariants; read it before proposing a structural change.", | ||
| "files": ["**/*"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "deliberate-driver-chain-shape", | ||
| "description": "middleware/driver.go hand-implements the standard database/sql wrapping chain (Driver + DriverContext, Connector, Conn, Stmt, Tx) with zero dependencies. Its parallel Query/Exec branches and its per-type optional-interface methods are deliberately repetitive: each branch forwards to a different optional base interface, and collapsing them changes fallback behaviour. Do not report this file for duplication, and do not report the //nolint:staticcheck deprecated delegations - they are required for a faithful wrapper and each carries an explanation (nolintlint enforces that).", | ||
| "files": ["middleware/driver.go", "middleware/*_test.go"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "explain-keeps-query-raw", | ||
| "description": "The explain package deliberately keeps Result.Query - and the Query of the analyzer.Results it builds - RAW rather than redacted, because the user typed the statement on their own CLI and it never reaches a log or telemetry sink. Fingerprint is still always set. Do not report explain findings as a redaction miss. Likewise, the EXPLAIN string is built by concatenation because EXPLAIN takes no bind parameters; do not suggest parameterizing it.", | ||
| "files": ["explain/**/*.go"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "cli-driver-imports-are-intentional", | ||
| "description": "cmd/sqlguard/db.go blank-imports github.com/jackc/pgx/v5/stdlib and github.com/go-sql-driver/mysql so `sqlguard explain` can connect. Only this package imports them, and Go links per imported package, so a library consumer of analyzer or middleware never links them. Do not report these as a core-dependency violation and do not suggest moving them into explain/ - that WOULD put database drivers in the library import graph.", | ||
| "files": ["cmd/sqlguard/**/*.go"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "library-not-application", | ||
| "description": "This is a published library, so exported identifiers with no in-repo caller are the public API, not dead code - consumers are the callers. The same applies to the optional driver interface methods in middleware/driver.go, which exist so database/sql's type assertions succeed. golangci-lint's `unused` runs in CI and understands these Go semantics; prefer its verdict over a generic reachability heuristic.", | ||
| "files": ["**/*.go"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "test-conventions", | ||
| "description": "Run anything touching middleware with -race: the driver chain, QueryTracker and the caches are concurrent. A test for a fixed bug should prove the failure mode - the convention here is that a regression test must fail against the unfixed code, and several assert exact analysis counts for that reason. errcheck, gosec, bodyclose, errorlint, noctx and perfsprint are intentionally relaxed in _test.go files (see .golangci.yml exclusions), so do not report those there. test/integration is a separate, unpublished module behind the `integration` build tag so `go test ./...` stays Docker-free; do not suggest removing the tag, folding it into the core module, or replacing its live-database assertions with mocks - the tabular EXPLAIN output it pins is server-version-dependent, which is exactly why it cannot be a unit test.", | ||
| "files": ["**/*_test.go", "test/integration/**/*"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "test-fixture-credentials", | ||
| "description": "test/integration/docker-compose.yml contains throwaway credentials (user, password and database all 'sqlguard') for local, ephemeral containers on deliberately non-default host ports. They are fixtures for `make db-up`, are never used against a real server, and are not a leaked secret. Report a credential in this file only if it looks like a real one.", | ||
| "files": ["test/integration/docker-compose.yml"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "docs-site-conventions", | ||
| "description": "The docs site is Docusaurus under website/, linted and formatted by Biome (website/biome.json) and type-checked by TypeScript; prose is linted repo-wide by markdownlint (.markdownlint-cli2.jsonc) via `make lint-docs`, not by Biome. website/docs is the unreleased tree and website/versioned_docs holds frozen snapshots that are cut with `npm run cut-version` and never hand-edited - do not propose changes there. Node-side files (docusaurus.config.ts, sidebars, scripts) must not use browser APIs, and both docusaurus.config.ts and scripts/cut-version.mjs read MAX_LIVE_VERSIONS from versions.config.json rather than duplicating it.", | ||
| "files": ["website/**/*"], | ||
| "scope": ["pr", "ide"] | ||
| }, | ||
| { | ||
| "id": "ci-already-covers", | ||
| "description": "`make ci` runs gofmt/goimports checks, go vet, golangci-lint (v2 schema, .golangci.yml - including gosec, staticcheck, unused, gocyclo at min-complexity 15, revive's exported rule, errorlint, bodyclose, nilerr, contextcheck and the allocation linters), govulncheck, `go test -race`, and markdownlint, across all nine modules; a separate workflow runs CodeQL. Prefer findings those tools cannot produce - design, invariant and cross-module reasoning - over restating a lint that already gates the build.", | ||
| "files": ["**/*"], | ||
| "scope": ["pr", "ide"] | ||
| } | ||
| ] | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| { | ||
| "quality_gate": { | ||
| "enabled": true, | ||
| "conditions": [ | ||
| { | ||
| "metric": "secrets", | ||
| "operator": "GREATER_THAN", | ||
| "value": "0", | ||
| "scope": ["commit", "pull_request"], | ||
| "exclude_files": ["test/integration/docker-compose.yml"] | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win Keep real secrets in the fixture file within the gate. If a contributor adds a real token to 🤖 Prompt for AI Agents |
||
| }, | ||
| { | ||
| "metric": "sast_rating", | ||
| "operator": "LESS_THAN", | ||
| "value": "B", | ||
| "scope": ["pull_request"] | ||
| }, | ||
| { | ||
| "metric": "sca_rating", | ||
| "operator": "LESS_THAN", | ||
| "value": "B", | ||
| "scope": ["pull_request"] | ||
| } | ||
| ] | ||
| } | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggestion: The secrets gate suppresses every finding in this file, so any real credential later added to the integration compose file bypasses the security gate.
Assessment: 🔴
Critical· 🔁Occurrence: Rarely· 🏷️SecurityPrompt for AI Agent 🤖