validate: fix path filter — explicit prune instead of "*/.*" trap
The `-not -path "*/.*"` filter on the `find` probes in lint.sh and sast.sh was intended to exclude .venv / .git / __pycache__ but also excludes any target path that lives UNDER a hidden ancestor directory. Concrete trigger: running the gauntlet on a Claude Code worktree at .../.claude/worktrees/<name>/. Every file in the tree matches `*/.*` via the .claude/ component, so the probes return empty, the scripts skip with "No Python or Go files found", and run-all.sh records the check as passed by virtue of the 0 exit. The check never actually ran. Switch to explicit prunes for the well-known noise dirs. As a free bonus, replace `| head -1` with `-print -quit` so the probe also stops being susceptible to SIGPIPE under `set -o pipefail` (relevant on dense trees with many matches). Verified: probe now returns first .py file in both .claude/-rooted and normal project paths. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
47f48873e0
commit
172f426ccd
@ -11,8 +11,17 @@ errors=0
|
||||
|
||||
echo "=== Lint Scan ==="
|
||||
|
||||
has_python=$(find "$TARGET" -name "*.py" -not -path "*/.*" | head -1)
|
||||
has_go=$(find "$TARGET" -name "*.go" -not -path "*/.*" | head -1)
|
||||
# Probe for source files. Explicit prunes (rather than -not -path "*/.*")
|
||||
# so that target paths under hidden ancestor dirs (e.g. a Claude Code
|
||||
# worktree at .../.claude/worktrees/<name>/) still match real source.
|
||||
# -print -quit instead of `| head -1` avoids SIGPIPE under `set -o pipefail`.
|
||||
has_python=$(find "$TARGET" \
|
||||
\( -path '*/__pycache__' -o -path '*/.venv' -o -path '*/venv' \
|
||||
-o -path '*/.git' -o -path '*/node_modules' \) -prune \
|
||||
-o -name '*.py' -print -quit)
|
||||
has_go=$(find "$TARGET" \
|
||||
\( -path '*/.git' -o -path '*/vendor' -o -path '*/node_modules' \) -prune \
|
||||
-o -name '*.go' -print -quit)
|
||||
|
||||
if [ -z "$has_python" ] && [ -z "$has_go" ]; then
|
||||
printf "${YELLOW}!${NC} No Python or Go files found — skipping\n"
|
||||
|
||||
@ -16,8 +16,17 @@ if ! command -v semgrep &>/dev/null; then
|
||||
exit 2
|
||||
fi
|
||||
|
||||
has_python=$(find "$TARGET" -name "*.py" -not -path "*/.*" | head -1)
|
||||
has_go=$(find "$TARGET" -name "*.go" -not -path "*/.*" | head -1)
|
||||
# Probe for source files. Explicit prunes (rather than -not -path "*/.*")
|
||||
# so that target paths under hidden ancestor dirs (e.g. a Claude Code
|
||||
# worktree at .../.claude/worktrees/<name>/) still match real source.
|
||||
# -print -quit instead of `| head -1` avoids SIGPIPE under `set -o pipefail`.
|
||||
has_python=$(find "$TARGET" \
|
||||
\( -path '*/__pycache__' -o -path '*/.venv' -o -path '*/venv' \
|
||||
-o -path '*/.git' -o -path '*/node_modules' \) -prune \
|
||||
-o -name '*.py' -print -quit)
|
||||
has_go=$(find "$TARGET" \
|
||||
\( -path '*/.git' -o -path '*/vendor' -o -path '*/node_modules' \) -prune \
|
||||
-o -name '*.go' -print -quit)
|
||||
|
||||
if [ -z "$has_python" ] && [ -z "$has_go" ]; then
|
||||
printf "${YELLOW}!${NC} No Python or Go files found — skipping\n"
|
||||
|
||||
Loading…
Reference in New Issue
Block a user