Contributing¶
Environment¶
The project targets Python 3.12+.
Quality checks¶
Before opening a merge request:
poetry run ruff check .
poetry run ruff format --check .
poetry run mypy src tests
poetry run pytest
poetry run mkdocs build --strict
Workflow¶
- Branch from
main. - Keep the change focused on one coherent concern.
- Add or update tests for behavioural changes.
- Run the local quality suite.
- Open a merge request into
main. - Merge only after required checks pass when GitLab compute capacity is available.
CI/CD¶
The repository's GitLab CI is split into local includes:
.gitlab-ci.yml
.gitlab/ci/quality.yml
.gitlab/ci/security.yml
.gitlab/ci/release.yml
.gitlab/ci/docs.yml
Merge requests run code-quality, test, security, package-build, and documentation checks. The default branch additionally deploys documentation through GitLab Pages.
Documentation¶
Documentation lives under docs/ and is configured by mkdocs.yml.
Keep CLI examples aligned with the actual parser in
src/gitlab_project_audit/cli.py. Rule IDs documented in the catalogue must match the rule
implementations exactly.
Releases¶
Tagged releases must follow the release workflow. Package versions and tags must match exactly before GitLab release artifacts are created.
Self-audit¶
After configuring GITLAB_TOKEN, run:
This uses the public CLI, checked-in self-audit policy, and regression baseline. See Self-audit.