- .gitea/workflows/ci.yml: gateway plugin tests + Kotlin host tests on push/PR (hermes-agent cloned at pinned SHA, vendored test mirror) - .gitea/workflows/release.yml: manual dispatch; runs tests, builds signed Android APK (debug fallback) + Linux desktop app-image/deb via jpackage, creates Gitea release v<version> with artifacts (re-run safe) - androidApp: versionName from -PappVersion, CI release signing from ANDROID_KEYSTORE_* env vars - desktopApp: jpackage --app-version from -PappVersion - scripts/make_release_keystore.sh: one-time keystore + Gitea secret setup - vendor gateway-plugin/tests/test_android.py (byte-identical mirror) and ignore it in .pi-lens.json
29 lines
754 B
JSON
29 lines
754 B
JSON
{
|
|
"ignore": [
|
|
"gateway-plugin/tests/test_android.py"
|
|
],
|
|
"rules": {
|
|
"unchecked-throwing-call-python": {
|
|
"disable": [
|
|
"unchecked-throwing-call-python",
|
|
"ast-grep:unchecked-throwing-call-python"
|
|
]
|
|
},
|
|
"python-logger-credential-disclosure": {
|
|
"disable": [
|
|
"opengrep:python.lang.security.audit.logging.logger-credential-leak.python-logger-credential-disclosure"
|
|
]
|
|
},
|
|
"sqlalchemy-execute-raw-query": {
|
|
"disable": [
|
|
"opengrep:python.sqlalchemy.security.sqlalchemy-execute-raw-query.sqlalchemy-execute-raw-query"
|
|
]
|
|
},
|
|
"exported-activity": {
|
|
"disable": [
|
|
"opengrep:java.android.security.exported_activity.exported_activity"
|
|
]
|
|
}
|
|
}
|
|
}
|