Based on code review feedback, made the changes.
This commit is contained in:
+31
-12
@@ -34,7 +34,9 @@ definitions:
|
|||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# Custom cache: uv stores packages in ~/.cache/uv, NOT ~/.cache/pip.
|
# Custom cache: uv stores packages in ~/.cache/uv, NOT ~/.cache/pip.
|
||||||
# Without this, every pipeline run re-downloads all dependencies.
|
# pip cache is intentionally absent — uv fully replaces pip for dependency
|
||||||
|
# management, so caching pip's download dir would waste space and never hit.
|
||||||
|
# Without this uv cache, every pipeline run re-downloads all dependencies.
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
caches:
|
caches:
|
||||||
uv: ~/.cache/uv
|
uv: ~/.cache/uv
|
||||||
@@ -49,8 +51,9 @@ definitions:
|
|||||||
# then syncs both dev and test dependency groups from pyproject.toml.
|
# then syncs both dev and test dependency groups from pyproject.toml.
|
||||||
# --locked (NOT --frozen) asserts uv.lock matches pyproject.toml and
|
# --locked (NOT --frozen) asserts uv.lock matches pyproject.toml and
|
||||||
# fails loudly on mismatch. --frozen would silently use a stale lockfile.
|
# fails loudly on mismatch. --frozen would silently use a stale lockfile.
|
||||||
- script: &install
|
# allows patch security updates, blocks breaking minor/major bumps — review uv releases quarterly
|
||||||
pip install uv==0.11.5;
|
- script: &install |
|
||||||
|
pip install "uv>=0.11.5,<0.12";
|
||||||
uv sync --locked --group dev --group test;
|
uv sync --locked --group dev --group test;
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
@@ -118,11 +121,12 @@ definitions:
|
|||||||
- export AWS_REGION=us-east-1
|
- export AWS_REGION=us-east-1
|
||||||
- export AWS_ROLE_ARN="arn:aws:iam::975049960860:role/DoczyAI-Bitbucket-OIDC"
|
- export AWS_ROLE_ARN="arn:aws:iam::975049960860:role/DoczyAI-Bitbucket-OIDC"
|
||||||
- export AWS_WEB_IDENTITY_TOKEN_FILE="$(pwd)/web-identity-token"
|
- export AWS_WEB_IDENTITY_TOKEN_FILE="$(pwd)/web-identity-token"
|
||||||
# printf (not echo) avoids appending a trailing newline to the JWT.
|
# install -m 600 atomically creates the file with restricted permissions
|
||||||
# chmod 600 restricts the token file to owner-only (defensive —
|
# BEFORE any data is written, closing the race window that exists when
|
||||||
# the container is already single-user root, but silences scanners).
|
# writing first and chmodding second (default umask would expose the
|
||||||
|
# token briefly as 644). printf (not echo) avoids a trailing newline.
|
||||||
|
- install -m 600 /dev/null "$(pwd)/web-identity-token"
|
||||||
- printf '%s' "$BITBUCKET_STEP_OIDC_TOKEN" > "$(pwd)/web-identity-token"
|
- printf '%s' "$BITBUCKET_STEP_OIDC_TOKEN" > "$(pwd)/web-identity-token"
|
||||||
- chmod 600 "$(pwd)/web-identity-token"
|
|
||||||
|
|
||||||
# Clone the review agent repo (private — needs BITBUCKET_CLONE_TOKEN)
|
# Clone the review agent repo (private — needs BITBUCKET_CLONE_TOKEN)
|
||||||
# SETUP REQUIRED: set BITBUCKET_CLONE_TOKEN (marked "Secured") in
|
# SETUP REQUIRED: set BITBUCKET_CLONE_TOKEN (marked "Secured") in
|
||||||
@@ -134,8 +138,13 @@ definitions:
|
|||||||
echo "Set it in Repository settings → Repository variables (Secured)."
|
echo "Set it in Repository settings → Repository variables (Secured)."
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
# -q flag suppresses URL output to avoid leaking the token in logs
|
# Use git credential helper to keep the token out of the command line
|
||||||
- git clone -q "https://x-token-auth:${BITBUCKET_CLONE_TOKEN}@bitbucket.org/${BITBUCKET_WORKSPACE}/code-review-agent.git"
|
# and out of git error messages. Writing the credential to a file that
|
||||||
|
# is never echoed prevents token exposure in process lists and logs.
|
||||||
|
- git config --global credential.helper store
|
||||||
|
- printf 'https://x-token-auth:%s@bitbucket.org\n' "${BITBUCKET_CLONE_TOKEN}" > ~/.git-credentials
|
||||||
|
- chmod 600 ~/.git-credentials
|
||||||
|
- git clone -q "https://bitbucket.org/${BITBUCKET_WORKSPACE}/code-review-agent.git"
|
||||||
|
|
||||||
# Build the PR URL and run the agent.
|
# Build the PR URL and run the agent.
|
||||||
# AI review is advisory for *runtime* failures: agent crashes,
|
# AI review is advisory for *runtime* failures: agent crashes,
|
||||||
@@ -380,8 +389,10 @@ pipelines:
|
|||||||
# Fail loudly with a clear error so nobody ships a bad release.
|
# Fail loudly with a clear error so nobody ships a bad release.
|
||||||
- |
|
- |
|
||||||
version=$(echo "$latest_tag" | sed 's/^v//')
|
version=$(echo "$latest_tag" | sed 's/^v//')
|
||||||
if ! [[ "$version" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
# Reject leading zeros (e.g. v01.02.03) — bash arithmetic treats
|
||||||
echo "BLOCKED: latest tag '$latest_tag' is not strict semver (expected v#.#.#)."
|
# them as octal, which silently produces wrong version numbers.
|
||||||
|
if ! [[ "$version" =~ ^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)$ ]]; then
|
||||||
|
echo "BLOCKED: latest tag '$latest_tag' is not strict semver (expected v#.#.#, no leading zeros)."
|
||||||
echo "Fix by creating a properly-formatted tag: git tag -a vX.Y.Z -m 'Release vX.Y.Z'"
|
echo "Fix by creating a properly-formatted tag: git tag -a vX.Y.Z -m 'Release vX.Y.Z'"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
@@ -420,7 +431,15 @@ pipelines:
|
|||||||
deployment: production # Bitbucket deployment environment
|
deployment: production # Bitbucket deployment environment
|
||||||
image: atlassian/default-image:4
|
image: atlassian/default-image:4
|
||||||
script:
|
script:
|
||||||
# Read the tag that was created in step 1
|
# Read the tag that was created in step 1.
|
||||||
|
# Validate the artifact exists first — a missing file means the
|
||||||
|
# tag-creation step failed partway and should not silently deploy.
|
||||||
|
- |
|
||||||
|
if [ ! -f release_tag.txt ]; then
|
||||||
|
echo "BLOCKED: release_tag.txt not found."
|
||||||
|
echo "The tag creation step may have failed before writing the artifact."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
- export RELEASE_TAG="$(cat release_tag.txt)"
|
- export RELEASE_TAG="$(cat release_tag.txt)"
|
||||||
- echo "Deploying ${RELEASE_TAG}"
|
- echo "Deploying ${RELEASE_TAG}"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user