Files
tatlock-ui/Makefile
T
jpmschweitzerandClaude 9385dd253a build(ci): move the pre-push gate into the Makefile
The hook carried ~50 lines of gitleaks logic and a comment explaining it was
self-contained because "this repo has no Makefile". It has one now, so the
reason is gone and the arrangement is backwards: a hook is a trigger, and
logic belongs where it can be read, run by hand, and changed under review.

.githooks/pre-push is now a byte-identical shim onto `make pre-push` in every
repo in the workspace. The scan itself moves to ci/secrets.sh unchanged, and
`make secrets` runs it on its own.

The call surface is identical everywhere; what it runs is not, and should not
be — each repo gates what it actually has. That is the point of standardising
the name rather than the contents: nobody has to read a repo to find out how
to check it.

secrets runs first, deliberately. It is the only failure here that cannot be
undone by fixing it afterwards — a failed lint costs another commit, a pushed
credential is cached and indexed whether or not it is later deleted.

Some of these gates fail today, on lint debt that predates them, and they are
left wired anyway. The board was measured once and written down in T-56
instead of being worked around here. Narrowing each gate to whatever already
passes would produce a gate that reports success for doing nothing, which is
the failure this workspace keeps rediscovering.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-09 18:57:22 +02:00

71 lines
2.7 KiB
Makefile

# tatlock-ui — the repo's command surface (D-27).
#
# Flutter rather than Python, so there is no venv and no PYTHON here. The
# reason the targets still exist under these names is the point of D-27: an
# agent or a person can run `make test` in any repo in this workspace without
# first working out which stack it is.
.DEFAULT_GOAL := help
.PHONY: help
help: ## Show this help
@grep -hE '^[a-z][a-z0-9_-]*:.*?## ' $(MAKEFILE_LIST) \
| awk 'BEGIN{FS=":.*?## "}{printf " \033[36m%-14s\033[0m %s\n", $$1, $$2}'
.PHONY: setup
setup: ## Fetch dependencies and generate code (run this after a fresh clone)
flutter pub get
$(MAKE) generate
.PHONY: generate
generate: ## Regenerate freezed/json_serializable/riverpod sources
dart run build_runner build --delete-conflicting-outputs
.PHONY: test
test: ## Run the widget and unit tests
@test -f lib/core/auth/user_preferences.freezed.dart \
|| { echo "FAIL — generated sources missing; run: make setup"; exit 69; }
flutter test
# Why the guard above: *.freezed.dart and lib/**/*.g.dart are gitignored, so a
# fresh clone has none of them and most of the suite fails to compile rather
# than to assert. On 2026-08-09 that read as "26 passed, 17 failed" — which
# looks like broken tests and is actually a missing build step. After
# generating, the same suite is 452 passed. A test run that cannot compile
# should say so in those words.
.PHONY: lint
lint: ## Static analysis (analysis_options.yaml at the repo root)
flutter analyze
.PHONY: build
build: ## Release build for the web target
flutter build web --release
.PHONY: clean
clean: ## Remove build artefacts and the pub cache for this project
flutter clean
# git hands a hook a non-login shell, which never sees ~/.local/bin — where
# gitleaks lands. Without this the scan reports "not installed" on every push,
# which is a check that fails open (D-24).
export PATH := $(HOME)/.local/bin:/usr/local/bin:$(PATH)
.PHONY: secrets
secrets: ## Scan the commits about to be pushed for credentials
@ci/secrets.sh
# The call surface is identical in every repo; what it runs is not.
#
# `secrets` runs first, deliberately: it is the only failure here that cannot be
# undone by fixing it afterwards. A failed lint costs another commit; a pushed
# credential is cached and indexed whether or not it is later deleted.
#
# Some of these fail today, and are left wired anyway. The state was measured
# once and written down in T-56 rather than being worked around here — a gate
# quietly narrowed to what already passes is a gate that reports success for
# doing nothing, which is the failure this workspace keeps rediscovering.
.PHONY: pre-push
pre-push: secrets lint ## Everything the pre-push hook runs
@echo " -- not gated here yet: test (T-56)"