feat(template): add community-health files and harden generated-project prek - #54
Merged
Conversation
…ct prek Add always-on best-practice files to generated projects: - .gitattributes (LF normalization, Linguist overrides, export-ignore) - SUPPORT.md community-health file - AGENTS.md + CLAUDE.md pointer for AI coding agents - OpenSSF Scorecard workflow + README badge - dependency-review workflow (fails PRs on high-severity CVEs) Fix pre-existing prek failures so a freshly scaffolded project passes `prek run --all-files` cleanly across all component/framework/broker combinations (previously the generated hooks CI job was red out of the box). Root cause: auto-fixing hooks raced on a freshly-rendered dirty tree and corrupted files, so the template now emits byte-perfect output: - Jinja whitespace control in pyproject.toml, README.md, mise.toml, and docs/usage.rst so disabled components leave no trailing whitespace or blank-line runs - workflow YAML blank-line/indentation/document-start fixes - markdown fixes in CONTRIBUTING, CODE_OF_CONDUCT, bug_report, enhancement - scope the prek mypy hook to src/ and mirror all enabled component deps - ruff-format component sources (worker, mcp/web/worker tests) Verified with tox -e style and prek across all-off, FastAPI/Redis, Litestar/RabbitMQ, Kafka, and NATS renders.
Contributor
There was a problem hiding this comment.
Sorry @hasansezertasan, you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 00d736841c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Move `*.svg text` out of the "Explicit binaries" block into its own commented section — SVG is XML and is intentionally kept as text so it normalizes and diffs line-by-line, which contradicted the surrounding "never diff as text" header.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds five always-on best-practice files to generated projects and fixes a pre-existing defect where a freshly scaffolded project failed
prek run --all-filesout of the box.New files (feat)
.gitattributes— LF normalization, Linguist overrides,export-ignoreSUPPORT.md— community-health "where to get help" fileAGENTS.md+CLAUDE.mdpointer — AI-agent onboarding (single source of truth)scorecard.yml— OpenSSF Scorecard + README badgedependency-review.yml— blocks PRs introducing high-severity CVEsprek hardening (fix)
Root cause: auto-fixing hooks raced on a freshly-rendered dirty tree and corrupted files. Fixed by making the template emit byte-perfect output so every fixer is a no-op:
pyproject.toml,README.md,mise.toml,docs/usage.rstci,release-please,issue-manager)CONTRIBUTING,CODE_OF_CONDUCT,bug_report,enhancement)src/and mirrored all enabled component deps (pydantic-settings,faststream[<broker>],litestar,mcp)Test plan
tox -e stylepasses (all-off example)prek run --all-filesgreen across all-off, FastAPI/Redis, Litestar/RabbitMQ, Kafka, NATS🤖 Generated with Claude Code