From 9d69c71d77dcfb4b87c8f525e61f1f9f40c0cd67 Mon Sep 17 00:00:00 2001 From: xiaoxia Date: Mon, 13 Jul 2026 15:20:52 +0800 Subject: [PATCH] ci: add vulture dead code detection to validate job - Add vulture dead code scan step (P2 - advisory mode) - Confidence threshold: 80% - Whitelist for framework code (FastAPI, SQLAlchemy, Celery, etc.) - Exclude tests, migrations, scripts, docs - Advisory only, does not block CI --- .gitea/workflows/ci-cd.yml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/.gitea/workflows/ci-cd.yml b/.gitea/workflows/ci-cd.yml index f3711fc55..2043ef986 100755 --- a/.gitea/workflows/ci-cd.yml +++ b/.gitea/workflows/ci-cd.yml @@ -112,6 +112,39 @@ jobs: set -eu bandit -r apps packages -q -ll + + - name: Dead code detection (vulture) + shell: sh + run: | + set -eu + echo "=== Installing vulture ===" + python3 -m pip install -q vulture + vulture --version + echo "" + echo "=== Running vulture dead code scan ===" + echo "Confidence threshold: 80%" + echo "Mode: advisory (not blocking CI)" + echo "" + # 运行 vulture,使用配置文件和白名单 + set +e + vulture --config vulture.conf --min-confidence 80 --sort-by-size > /tmp/vulture-report.txt + VULTURE_EXIT=$? + set -e + # 显示结果 + cat /tmp/vulture-report.txt + echo "" + # 统计 + DEAD_CODE_COUNT=$(grep -c ':' /tmp/vulture-report.txt 2>/dev/null || echo 0) + echo "=== Summary ===" + echo "Total findings: $DEAD_CODE_COUNT" + echo "" + # 告警模式,不阻断 + echo "vulture scan completed (advisory mode - not blocking CI)" + if [ "$VULTURE_EXIT" != "0" ]; then + echo "WARNING: Dead code detected. Review the report above." + echo "This is currently advisory only." + fi + exit 0 - name: Validate release scripts syntax shell: sh run: |