From d669b7c7366b2387d4a51be06ece34778b7ca356 Mon Sep 17 00:00:00 2001 From: xiaoxia Date: Tue, 14 Jul 2026 18:12:13 +0800 Subject: [PATCH] =?UTF-8?q?feat(ci):=20rebase=E5=88=B0=E6=9C=80=E6=96=B0de?= =?UTF-8?q?velop=EF=BC=8C=E8=A7=A3=E5=86=B3=E4=B8=8E#326=E7=89=A9=E7=90=86?= =?UTF-8?q?=E5=88=86=E5=B1=82=E7=9A=84=E5=86=B2=E7=AA=81?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .gitea/workflows/ci-cd.yml | 35 ++++++++++++++++++++++++++++------- 1 file changed, 28 insertions(+), 7 deletions(-) diff --git a/.gitea/workflows/ci-cd.yml b/.gitea/workflows/ci-cd.yml index 0d301f559..62c9ea68e 100644 --- a/.gitea/workflows/ci-cd.yml +++ b/.gitea/workflows/ci-cd.yml @@ -92,6 +92,14 @@ jobs: python3 -m flake8 apps packages tests --count --statistics ' + - name: Ruff lint (advisory mode - 摸底阶段) + if: always() + shell: sh + run: "set +e\necho \"=== Installing ruff ===\"\npython3 -m pip install -q ruff\nruff --version\necho \"\"\necho \"=== Running ruff lint (advisory mode) ===\"\necho \"告警模式,不阻断CI。用于摸底问题数量,后续分批修复后正式替换flake8。\"\necho \"\"\nruff check apps packages tests scripts --statistics --output-format concise 2>&1 | tail -30\nEXIT_CODE=$?\necho \"\"\nif [ \"$EXIT_CODE\" != \"0\" ]; then\n echo \"ruff 发现 lint 问题(告警模式,不阻断)\"\n echo \"问题分类统计见上方,后续将分批修复\"\nelse\n echo \"ruff 检查全部通过 ✅\"\nfi\nexit 0\n" + - name: Type check (mypy, advisory mode) + if: always() + shell: sh + run: "set +e\necho \"=== Installing mypy ===\"\npython3 -m pip install -q mypy\nmypy --version\necho \"\"\necho \"=== Running mypy type check (advisory mode) ===\"\necho \"告警模式,不阻断CI\"\necho \"\"\n# 只检查核心业务代码,跳过测试和迁移\nEXIT_CODE=0\nmypy apps/api/app packages --ignore-missing-imports --no-site-packages --no-strict-optional --explicit-package-bases --exclude 'tests/|test_|migrations/|alembic/' --no-error-summary 2>&1 | head -60 || EXIT_CODE=$?\necho \"\"\nif [ \"$EXIT_CODE\" != \"0\" ]; then\n echo \"mypy 发现类型问题(告警模式,不阻断)\"\n echo \"建议后续逐步修复\"\nelse\n echo \"mypy 类型检查通过 ✅\"\nfi\nexit 0\n" - name: Run security scan (bandit) shell: sh run: 'set -eu @@ -103,8 +111,9 @@ jobs: shell: sh run: "set -eu\necho \"=== Installing pip-audit ===\"\npython3 -m pip install -q pip-audit\npip-audit --version\necho \"\"\necho \"=== Scanning Python dependencies ===\"\nEXIT_CODE=0\nfor req_file in requirements.txt requirements-base.txt requirements-dev.txt; do\n if [ -f \"$req_file\" ]; then\n echo \"--- Scanning $req_file ---\"\n pip-audit -r \"$req_file\" --desc on 2>&1 | head -40 || EXIT_CODE=$?\n echo \"\"\n fi\ndone\necho \"pip-audit scan completed (advisory mode - warnings only, not blocking CI)\"\nif [ \"$EXIT_CODE\" != \"0\" ]; then\n echo \"WARNING: Potential vulnerabilities found in dependencies.\"\nfi\nexit 0\n" - name: Dead code detection (vulture) + if: always() shell: sh - run: "set -eu\necho \"=== Installing vulture ===\"\npython3 -m pip install -q vulture\nvulture --version\necho \"\"\necho \"=== Running vulture dead code scan ===\"\nEXIT_CODE=0\nvulture apps packages scripts \\\n --exclude \"tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py\" \\\n --min-confidence 80 \\\n 2>&1 | head -60 || EXIT_CODE=$?\necho \"\"\necho \"vulture scan completed (advisory mode - P2, for reference only)\"\nif [ \"$EXIT_CODE\" != \"0\" ]; then\n echo \"NOTE: Potential dead code found (may include false positives from framework code).\"\nfi\nexit 0\n" + run: "set +e\necho \"=== Installing vulture ===\"\npython3 -m pip install -q vulture\nvulture --version\necho \"\"\necho \"=== Running vulture dead code scan (confidence >= 70%) ===\"\necho \"告警模式,不阻断CI。置信度>=90%建议尽快确认。\"\necho \"\"\n# 按置信度从高到低输出,便于优先查看高价值条目\nvulture apps packages scripts \\\n --exclude \"tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py\" \\\n --min-confidence 70 \\\n 2>&1 | sort -t'(' -k2 -rn | head -80\nEXIT_CODE=$?\necho \"\"\necho \"=== vulture scan summary ===\"\nif [ \"$EXIT_CODE\" != \"0\" ]; then\n echo \"发现潜在死代码(可能包含框架装饰器注册的函数,为误报)\"\n echo \"建议:定期人工审查高置信度(>=90%)条目\"\nelse\n echo \"未发现明显死代码 ✅\"\nfi\nexit 0\n" - name: Validate release scripts syntax shell: sh run: 'set -eu @@ -388,7 +397,9 @@ jobs: ' build-staging-api: name: Build Staging API Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate @@ -447,7 +458,9 @@ jobs: ' build-staging-worker: name: Build Staging Worker Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate @@ -506,7 +519,9 @@ jobs: ' build-staging-web: name: Build Staging Web Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate @@ -722,7 +737,9 @@ jobs: ' build-production-api: name: Build Production API Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate @@ -794,7 +811,9 @@ jobs: ' build-production-worker: name: Build Production Worker Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate @@ -866,7 +885,9 @@ jobs: ' build-production-web: name: Build Production Web Image - runs-on: saas + runs-on: + - saas + - build-farm timeout-minutes: 20 needs: - validate