Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,26 @@ on:
branches: [main]

jobs:
commitlint:
runs-on: ubuntu-latest
if: github.event_name == 'pull_request'
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Setup Bun
uses: oven-sh/setup-bun@v2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate workflow and show relevant lines with numbers.
git ls-files '.github/workflows/ci.yml'
echo '---'
wc -l .github/workflows/ci.yml
echo '---'
cat -n .github/workflows/ci.yml | sed -n '1,120p'

Repository: gmi-software/react-native-nitro-maps

Length of output: 1874


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate workflow and show relevant lines with numbers.
git ls-files '.github/workflows/ci.yml'
echo '---'
wc -l .github/workflows/ci.yml
echo '---'
cat -n .github/workflows/ci.yml | sed -n '1,120p'

Repository: gmi-software/react-native-nitro-maps

Length of output: 1874


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate workflow and show relevant lines with numbers.
git ls-files '.github/workflows/ci.yml'
echo '---'
wc -l .github/workflows/ci.yml
echo '---'
cat -n .github/workflows/ci.yml | sed -n '1,120p'

Repository: gmi-software/react-native-nitro-maps

Length of output: 1874


🏁 Script executed:

#!/bin/bash
set -euo pipefail
git ls-files '.github/workflows/ci.yml'
echo '---'
wc -l .github/workflows/ci.yml
echo '---'
cat -n .github/workflows/ci.yml | sed -n '1,120p'

Repository: gmi-software/react-native-nitro-maps

Length of output: 1874


Pin these Actions to full SHAs. actions/checkout@v4 and oven-sh/setup-bun@v2 are still mutable tags, so this workflow keeps violating the SHA-pinning policy until both uses: entries are locked down.

🧰 Tools
🪛 zizmor (1.26.1)

[error] 15-15: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 15 - 20, The workflow still uses
mutable action tags in the checkout and Bun setup steps, so update the actions
referenced by actions/checkout and oven-sh/setup-bun to their full commit SHAs
instead of version tags. Keep the same workflow structure and step names, but
replace each uses: entry with the corresponding pinned SHA to satisfy the
SHA-pinning policy.

Source: Linters/SAST tools

with:
bun-version: latest

- name: Install dependencies
run: bun install --frozen-lockfile
Comment thread
coderabbitai[bot] marked this conversation as resolved.

- name: Validate commit messages
run: bunx commitlint --from ${{ github.event.pull_request.base.sha }} --to ${{ github.event.pull_request.head.sha }}

quality:
runs-on: ubuntu-latest
steps:
Expand Down
1 change: 1 addition & 0 deletions .husky/commit-msg
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
bunx commitlint --edit "$1"
21 changes: 21 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,10 +33,31 @@ Thank you for your interest in contributing!
| `bun run nitrogen` | Run Nitrogen codegen (when specs are ready) |
| `bun run format` | Format all files with Prettier |

## Commit messages

This project uses [Conventional Commits](https://www.conventionalcommits.org/). Commit messages are validated locally via Husky and on pull requests in CI.

Format:

```
<type>[optional scope]: <description>
```

Common types: `feat`, `fix`, `docs`, `style`, `refactor`, `test`, `chore`.

Examples:

```
feat: add marker clustering support
fix(ios): correct viewport filter for wrapped longitudes
chore: add commitlint configuration
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add fence languages so the docs stop tripping markdownlint.

Both new fenced blocks are missing a language tag. Use text here and be done with it.

Suggested fix
-```
+```text
 <type>[optional scope]: <description>

@@
- +text
feat: add marker clustering support
fix(ios): correct viewport filter for wrapped longitudes
chore: add commitlint configuration

📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
```
<type>[optional scope]: <description>
```
Common types: `feat`, `fix`, `docs`, `style`, `refactor`, `test`, `chore`.
Examples:
```
feat: add marker clustering support
fix(ios): correct viewport filter for wrapped longitudes
chore: add commitlint configuration
```
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)

[warning] 42-42: Fenced code blocks should have a language specified

(MD040, fenced-code-language)


[warning] 50-50: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CONTRIBUTING.md` around lines 42 - 54, The fenced code examples in the commit
message section are missing language identifiers, which is causing markdownlint
failures. Update the two fenced blocks in the CONTRIBUTING guidance to use the
same language tag, using the existing commit message example block markers
around the format template and examples. Keep the content unchanged and just add
the appropriate fence language to the relevant markdown snippets.

Source: Linters/SAST tools


## Pull request guidelines

- Keep changes focused and well-scoped.
- Run `bun run lint`, `bun run typecheck`, and `bun run build` before opening a PR.
- Use conventional commit messages for all commits in the PR.
- Follow existing naming conventions and avoid `any` in TypeScript.
- Update documentation when changing public APIs.

Expand Down
Loading
Loading