mirror of
https://github.com/kellymichels/zscripts-token-savers
synced 2026-10-07 07:18:18 +00:00
Two commands that were private-only until now. They turned out to be useful
beyond the fleet they were written for, so they are manifested for publication
and removed from the sanitization denylist's private-only list.
zmerge merge every pull request across the org that is genuinely ready -
MERGEABLE/CLEAN and not a draft - re-checking each one immediately
before and after every merge, because merging into a default branch
can conflict a sibling PR in the same repository. Dry run by
default; -Execute or -e merges.
zpull zmerge, then git pull --ff-only in every checkout the merges
affected. Skips a checkout that is dirty or is not on its default
branch rather than guessing at it.
WHY THEY COULD BE PUBLISHED NOW. zmerge carried a hardcoded list of sixteen
repository names, which was both the reason it could not be published and a
bug: the org has thirty active repositories, so it scanned about half and
reported "Nothing open to merge" while a ready pull request sat in one it had
never heard of. It asks GitHub now, and the names went with the list.
Get-FleetRepos throws rather than returning an empty list when gh fails,
because a tool that quietly scans nothing prints the same reassuring line as
one that scanned everything and found nothing.
-e is an alias for -Execute on both, the way -s already works for -Scan.
Also: __pycache__/ is gitignored. scripts/plaintext_twins.py creates it on
every run and it was showing up as untracked work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
53 lines
3.5 KiB
PowerShell
53 lines
3.5 KiB
PowerShell
<#
|
|
Patterns the PUBLIC repo must never contain.
|
|
|
|
Extracted from Sanitization.Tests.ps1 so that the test here and the
|
|
publisher in the private tree read ONE list instead of keeping two.
|
|
They had two, and they disagreed: the publisher's scan looked only for
|
|
secrets - keys, private-key blocks, ssh targets - while these rules are
|
|
about IDENTITY: internal project names, product domains, private-only
|
|
script names, operator paths.
|
|
|
|
So the publisher reported "clean" on files this suite rejects, and would
|
|
have published a tree that fails the public repo's own tests
|
|
(evo.scripts#106). One list, and that cannot drift apart again.
|
|
|
|
A denylist proves the absence of KNOWN patterns, not the absence of
|
|
secrets. It is a regression net for a specific recurring mistake, not a
|
|
substitute for reading what you publish. Add a pattern whenever a new
|
|
private identifier appears; a stale entry costs nothing.
|
|
|
|
Kept narrow on purpose: "evomedia.net" alone is legitimate here - the
|
|
attribution header and the repo URL both carry it - so only the drive
|
|
path and specific internal hosts are matched.
|
|
#>
|
|
@{
|
|
Denied = @(
|
|
@{ Name = 'private project name'; Pattern = '\b(EvoCivilCode|EvoPlatform|DocketMail|SmartPlant\w*|ProvenSheet|evoehs|evoproven|evoaicc|evolocate|evoplatform)\b' }
|
|
# The current spellings, which the line above never saw: a dot or a
|
|
# hyphen breaks the word and an underscore hides the boundary, so
|
|
# evo.ehs, evo-ai and evoehs_app all passed (evo.scripts#138 in the
|
|
# private tree). Internal issue references travel with them.
|
|
@{ Name = 'current product name'; Pattern = '(?i)\bevo[.-](ehs|ai|edge|locate|proven|platform|civilcode|scripts)\b|\bevoehs' }
|
|
@{ Name = 'internal issue reference'; Pattern = 'evo\.scripts#\d+' }
|
|
@{ Name = 'private product domain'; Pattern = '\b(smartplantehs\.com|provensheet\.com|evoehs\.com|civilcode\.evomedia\.net|dashboard\.evomedia\.net|webmail\.evomedia\.net|mail-admin\.evomedia\.net|docketmail\.evomedia\.net|cardiff\.evomedia\.net|platform\.evomedia\.net|ai\.evomedia\.net|git\.evomedia\.net|analytics\.evomedia\.net)\b' }
|
|
@{ Name = 'private-only script'; Pattern = '\b(register_civilcode|register_docketmail|sp_seed_demo_prod|zpublish_stats|zcoverage|zresume|swag_set_owner|provision_demo|apply_platform_config_fixes)\b' }
|
|
@{ Name = 'local drive path'; Pattern = '[A-Za-z]:\\\\?evomedia\.net' }
|
|
@{ Name = 'operator home path'; Pattern = '/home/ubuntu/' }
|
|
@{ Name = 'real pem key name'; Pattern = 'evomedia-prod\.pem' }
|
|
# RFC 5737 reserves 203.0.113.0/24 for documentation - that one is the
|
|
# correct placeholder and must stay allowed, as are loopback and the
|
|
# private ranges. Anything else that looks like a public IPv4 literal is
|
|
# suspect.
|
|
#
|
|
# The boundaries are [\d.] rather than \d on purpose: this toolkit's own
|
|
# 5-segment version (v1.0.0.0.14) contains "0.0.0.14", which a plain
|
|
# digit boundary happily reads as an address. Refusing a match that
|
|
# touches another dot rules out every version string without weakening
|
|
# detection of a real address, which is always delimited by whitespace
|
|
# or quotes.
|
|
@{ Name = 'non-documentation IP'; Pattern = '(?<![\d.])(?!203\.0\.113\.)(?!127\.0\.0\.1)(?!0\.0\.0\.0)(?!255\.)(?!10\.)(?!192\.168\.)(?!172\.(1[6-9]|2\d|3[01])\.)\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}(?![\d.])' }
|
|
|
|
)
|
|
}
|