Auditor plugin: lychee (docs) — broken link checking - #574
Merged
Merged
Conversation
New plugin under plugins/auditors-documentation wrapping lychee on the
shared ExternalToolAuditorBase. Runs `lychee --format json --offline .`
by default: file-scheme links and in-repo fragments are checked
deterministically with no credentials and no network; remote URLs are
reported as excluded, not findings. CheckRemoteLinks opts in to remote
checking and declares AuditCapabilities.Network so the audit sandbox
gets egress.
lychee's exit convention is not the common one: 0 = clean, 2 = link
check failures, 1 = runtime/config errors, 3 = config-file errors; only
{0, 2} are findings-producing. error_map entries map to Error, timeout_map
entries to Warning, with synthesized rule ids (lychee/broken-link,
lychee/timeout) so IncludedRules/ExcludedRules work.
Repo-authored suppression fails closed by default: a repo-root
.lycheeignore (loaded unconditionally by lychee) is an infrastructure
failure, and --config /dev/null pins out the default config-file lookup
(lychee.toml and friends). TrustRepositorySuppression or an explicit
ConfigPath opts back in. Vendored/generated trees are excluded at crawl
time via --exclude-path derived from ExcludePaths and at finding level.
The pinned tool version (default 0.24.2) is probed before every run.
CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
…probes in PluginSdk Addresses audit rework findings for the lychee auditor plugin: - The scan now passes --no-ignore by default: lychee's walker previously honored .gitignore/.ignore/global ignore files, so the audit subject could commit a doc file and exclude it from the crawl — a silent false pass. The .lycheeignore presence gate stays (it is a URL-exclusion file untouched by --no-ignore) and --config /dev/null still pins out repo config files. TrustRepositorySuppression opts back in to all three surfaces. The ExcludePaths defaults widen (bin/, obj/, target/, .venv/, venv/) since gitignored build output is now walked. - The repo-file presence gate is now a shared fail-closed helper on ExternalToolAuditorBase (ProbeRepositoryFilesPresentAsync): the probe echoes present paths on stdout and any non-zero exit is "could not confirm absence" -> AuditUnavailableException, ending the divergence where lychee's fork treated every non-zero exit as "absent". Gitleaks uses the same probe; its git-history check stays gitleaks-specific. - The pinned-version precondition is now declared, not implemented: plugins set VersionPin (new ToolVersionPin record carrying plugin id, a per-invocation ExpectedVersion accessor, the default release, and the probe arguments) and RunAsync enforces it before VerifyToolAsync. This removes the fourth copy of the version-probe scaffolding across gitleaks/eslint/spectral/lychee. The ExpectedVersion scoped key is now the named constant ToolVersionPin.ExpectedVersionKey. - Operator flag detection in ExtraArguments is shared (ExtraArgumentsSupplyFlag) and matches --flag, --flag=value, and the joined short form (-cfoo), so an operator --config=path or --root-dir=path is honored instead of producing a duplicate flag. ExcludePaths normalization is shared (NormalizeExcludePathEntry) so the findings filter and --exclude-path translation cannot drift, and ExternalToolAuditorOptions.SplitCommaSeparatedList replaces the private SplitList copies. - Tests: ignore-probe fakes follow the new convention (exit 0 + names = present); new coverage for probe-error fail-closed, --no-ignore argv, attached-form config overrides, and the shared helpers' path validation; ProbeInstalledLycheeVersion now drains stdout and stderr concurrently (previously a full stderr pipe could deadlock ahead of the timeout); the vacuous baseline-provisioning assertion is removed. Not done: a "--" separator before positional Inputs is deliberately omitted — the base appends operator ExtraArguments after the built argv, so a mid-argv "--" would reclassify those extras as inputs. Inputs is operator configuration, and a leading-dash input fails closed as a lychee usage error (infrastructure), not a pass. CodeyBox-Prompt-Revision: 1 Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
CodeyBox-WorkItem: 9caa60332e93422aac2f1d571a054260 CodeyBox-Agent: copilot/muse-spark-1.3-contributor Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated via CodeyBox — work item 9caa60332e93422aac2f1d571a054260
Initiated by CodeyBox operator
Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox