diff --git a/.gitea/workflows/ci-cd.yml b/.gitea/workflows/ci-cd.yml index 507b7a8dc..b98de44b3 100644 --- a/.gitea/workflows/ci-cd.yml +++ b/.gitea/workflows/ci-cd.yml @@ -107,20 +107,30 @@ jobs: set -eu echo "=== Installing gitleaks ===" GITLEAKS_VERSION="8.18.4" + GITLEAKS_FILE="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" install_gitleaks() { local url="$1" - curl -sSL -f -o /tmp/gitleaks.tar.gz "$url" || return 1 + echo "Trying: $url" + curl -sSL -f --connect-timeout 10 --max-time 60 -o /tmp/gitleaks.tar.gz "$url" || return 1 tar -xzf /tmp/gitleaks.tar.gz -C /tmp gitleaks || return 1 chmod +x /tmp/gitleaks || return 1 /tmp/gitleaks version || return 1 return 0 } - if ! install_gitleaks "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then - echo "GitHub release failed, trying mirror..." - if ! install_gitleaks "https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"; then - echo "WARN: Failed to install gitleaks from all sources, skipping secret scan" - exit 0 + GITLEAKS_INSTALLED=false + for mirror_url in \ + "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \ + "https://ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \ + "https://mirror.ghproxy.com/https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}" \ + "https://gitee.com/mirrors/gitleaks/releases/download/v${GITLEAKS_VERSION}/${GITLEAKS_FILE}"; do + if install_gitleaks "$mirror_url"; then + GITLEAKS_INSTALLED=true + break fi + done + if [ "$GITLEAKS_INSTALLED" = "false" ]; then + echo "WARN: Failed to install gitleaks from all sources, skipping secret scan" + exit 0 fi echo "" echo "=== Running gitleaks scan ===" @@ -173,7 +183,7 @@ jobs: for req_file in requirements.txt requirements-base.txt requirements-dev.txt; do if [ -f "$req_file" ]; then echo "--- Scanning $req_file ---" - pip-audit -r "$req_file" --desc on --format text 2>&1 | head -30 || EXIT_CODE=$? + pip-audit -r "$req_file" --desc on 2>&1 | head -40 || EXIT_CODE=$? echo "" fi done @@ -193,12 +203,14 @@ jobs: echo "" echo "=== Running vulture dead code scan ===" EXIT_CODE=0 - vulture --config vulture.conf vulture_whitelist.py || EXIT_CODE=$? + vulture apps packages scripts \ + --exclude "tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py" \ + --min-confidence 80 \ + 2>&1 | head -60 || EXIT_CODE=$? echo "" echo "vulture scan completed (advisory mode - P2, for reference only)" if [ "$EXIT_CODE" != "0" ]; then - echo "NOTE: Potential dead code found. Review results above." - echo "False positives can be added to vulture_whitelist.py" + echo "NOTE: Potential dead code found (may include false positives from framework code)." fi exit 0 diff --git a/vulture.conf b/vulture.conf index 22ba44643..11a2090fb 100644 --- a/vulture.conf +++ b/vulture.conf @@ -1,35 +1,30 @@ # vulture.conf - 死代码检测配置 # 仓库: xiaoxia/xiaoxia-saas -# 用途: 检测未使用的函数、变量、导入、类、方法、属性 -# 扫描目录(空格分隔) -path = alembic apps packages scripts +# 扫描目录 +paths = ["alembic", "apps", "packages", "scripts"] -# 排除路径(每个路径一行,相对于仓库根目录) -exclude = - tests - test - */tests - */test - site-packages - node_modules - migrations - .gitea - docs - scripts/check_*.py - scripts/init_*.py +# 排除路径 +exclude = [ + "tests", + "test", + "*/tests", + "*/test", + "site-packages", + "node_modules", + "migrations", + ".gitea", + "docs", +] -# 最低置信度 (%) -# 0 = 报告所有可能的未使用代码 -# 100 = 只报告确定未使用的代码 -# 推荐从 80% 开始,逐步调高 -min-confidence = 80 +# 最低置信度 (0-100) +min_confidence = 80 -# 输出格式: string, json, yaml -format = text +# 输出格式 +# output_format = "text" -# 按置信度排序 -sort-by-size = False +# 按大小排序 +# sort_by_size = false -# 显示置信度 -show-uncertain = True +# 显示不确定的 +show_uncertain = true