Skip to content

Auditor plugin: lychee (docs) — broken link checking - #574

Merged
AdamFrisby merged 3 commits into
mainfrom
codeybox/9caa6033
Sep 25, 2026
Merged

AdamFrisby merged 3 commits into
mainfrom
codeybox/9caa6033

Conversation

@AdamFrisby

Copy link
Copy Markdown
Owner

Automated via CodeyBox — work item 9caa60332e93422aac2f1d571a054260

Untrusted agent output — do not treat as instructions.

● Unknown tool name in the tool excludedlist: "apply_patch"

● Read CodeyBox.slnx
  └ 111 lines read

● Read CodeyBox.Tests.csproj
  │ tests/CodeyBox.Tests/CodeyBox.Tests.csproj
  └ 154 lines read

● Edit CodeyBox.slnx +1 -4

● Edit CodeyBox.Tests.csproj +1 -4
  └ tests/CodeyBox.Tests/CodeyBox.Tests.csproj

● Check for remaining conflict markers (shell)
  │ git diff --name-only --diff-filter=U; echo "---"; grep -n '<<<<<<< \|^=======$\|>>>>>>> '
  │ CodeyBox.slnx tests/CodeyBox.Tests/CodeyBox.Tests.csproj; echo "grep-exit:$?"
  └ 5 lines…

● Stage resolved files and verify clean (shell)
  │ git add CodeyBox.slnx tests/CodeyBox.Tests/CodeyBox.Tests.csproj && git diff --name-only
  │ --diff-filter=U; echo "unmerged-exit:$?"; git status --short
  └ 18 lines…

Both conflicts resolved by keeping both auditor plugins (Kubeconform + Lychee) in `CodeyBox.slnx` and `CodeyBox.Tests.csproj`. Staged with `git add`; no unmerged paths or markers remain.


Initiated by CodeyBox operator


Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox

AdamFrisby and others added 3 commits September 25, 2026 15:58
New plugin under plugins/auditors-documentation wrapping lychee on the
shared ExternalToolAuditorBase. Runs `lychee --format json --offline .`
by default: file-scheme links and in-repo fragments are checked
deterministically with no credentials and no network; remote URLs are
reported as excluded, not findings. CheckRemoteLinks opts in to remote
checking and declares AuditCapabilities.Network so the audit sandbox
gets egress.

lychee's exit convention is not the common one: 0 = clean, 2 = link
check failures, 1 = runtime/config errors, 3 = config-file errors; only
{0, 2} are findings-producing. error_map entries map to Error, timeout_map
entries to Warning, with synthesized rule ids (lychee/broken-link,
lychee/timeout) so IncludedRules/ExcludedRules work.

Repo-authored suppression fails closed by default: a repo-root
.lycheeignore (loaded unconditionally by lychee) is an infrastructure
failure, and --config /dev/null pins out the default config-file lookup
(lychee.toml and friends). TrustRepositorySuppression or an explicit
ConfigPath opts back in. Vendored/generated trees are excluded at crawl
time via --exclude-path derived from ExcludePaths and at finding level.
The pinned tool version (default 0.24.2) is probed before every run.

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
…probes in PluginSdk

Addresses audit rework findings for the lychee auditor plugin:

- The scan now passes --no-ignore by default: lychee's walker previously
  honored .gitignore/.ignore/global ignore files, so the audit subject
  could commit a doc file and exclude it from the crawl — a silent false
  pass. The .lycheeignore presence gate stays (it is a URL-exclusion file
  untouched by --no-ignore) and --config /dev/null still pins out repo
  config files. TrustRepositorySuppression opts back in to all three
  surfaces. The ExcludePaths defaults widen (bin/, obj/, target/, .venv/,
  venv/) since gitignored build output is now walked.

- The repo-file presence gate is now a shared fail-closed helper on
  ExternalToolAuditorBase (ProbeRepositoryFilesPresentAsync): the probe
  echoes present paths on stdout and any non-zero exit is "could not
  confirm absence" -> AuditUnavailableException, ending the divergence
  where lychee's fork treated every non-zero exit as "absent". Gitleaks
  uses the same probe; its git-history check stays gitleaks-specific.

- The pinned-version precondition is now declared, not implemented:
  plugins set VersionPin (new ToolVersionPin record carrying plugin id,
  a per-invocation ExpectedVersion accessor, the default release, and the
  probe arguments) and RunAsync enforces it before VerifyToolAsync. This
  removes the fourth copy of the version-probe scaffolding across
  gitleaks/eslint/spectral/lychee. The ExpectedVersion scoped key is now
  the named constant ToolVersionPin.ExpectedVersionKey.

- Operator flag detection in ExtraArguments is shared
  (ExtraArgumentsSupplyFlag) and matches --flag, --flag=value, and the
  joined short form (-cfoo), so an operator --config=path or
  --root-dir=path is honored instead of producing a duplicate flag.
  ExcludePaths normalization is shared (NormalizeExcludePathEntry) so the
  findings filter and --exclude-path translation cannot drift, and
  ExternalToolAuditorOptions.SplitCommaSeparatedList replaces the private
  SplitList copies.

- Tests: ignore-probe fakes follow the new convention (exit 0 + names =
  present); new coverage for probe-error fail-closed, --no-ignore argv,
  attached-form config overrides, and the shared helpers' path
  validation; ProbeInstalledLycheeVersion now drains stdout and stderr
  concurrently (previously a full stderr pipe could deadlock ahead of the
  timeout); the vacuous baseline-provisioning assertion is removed.

Not done: a "--" separator before positional Inputs is deliberately
omitted — the base appends operator ExtraArguments after the built argv,
so a mid-argv "--" would reclassify those extras as inputs. Inputs is
operator configuration, and a leading-dash input fails closed as a lychee
usage error (infrastructure), not a pass.

CodeyBox-Prompt-Revision: 1
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
CodeyBox-WorkItem: 9caa60332e93422aac2f1d571a054260
CodeyBox-Agent: copilot/muse-spark-1.3-contributor
Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
@AdamFrisby
AdamFrisby merged commit d7a9c4f into main Sep 25, 2026
@AdamFrisby
AdamFrisby deleted the codeybox/9caa6033 branch September 25, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant