You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit ebc0125
Browse filesBrowse the repository at this point in the historyBrowse files
Fix CI usage error tests, add the coverage badge and README header
- Typer styles and wraps usage errors in a panel when GITHUB_ACTIONS is set,
so four CLI tests now compare the message's plain text (usage_error)
- CI writes the coverage total as a shields.io endpoint file, and
badges.yml commits it to the badges branch after a passing run on main
- The README opens with the Libre DevOps logo and centred badges, as the
organisation profile does, with a rule between sections and a footer
`ldo`: importable Python helpers and a fast CLI for day-to-day DevOps and security work.
13
+
3
14
[](https://github.com/libre-devops/python-helpers/actions/workflows/ci.yml)
Graph insists on a ReadWrite scope even to list PIM requests; `ldo` still only ever reads.
362
389
390
+
---
391
+
363
392
## Commands
364
393
365
394
```bash
@@ -651,6 +680,8 @@ type-checks the whole of it and creates nothing: the authority the offline check
651
680
652
681
Code 3 lets a scheduled job alert on findings while still failing loudly on errors.
653
682
683
+
---
684
+
654
685
## ServiceNow
655
686
656
687
The `snow` commands sign in to a ServiceNow instance as you, and read from it:
@@ -748,6 +779,8 @@ If it is not offered there, sign in to the instance as admin and install it from
748
779
System Applications > All Available Applications, with its demo data if you want records
749
780
to work with. Then `ldo snow instance` shows it installed.
750
781
782
+
---
783
+
751
784
## Permissions
752
785
753
786
Commands run with the permissions of the profile's credential. The Azure CLI's delegated
@@ -790,6 +823,8 @@ The signature is **not** verified: this answers "is this the token I meant to ge
790
823
this token genuine?". The token value is never printed unless you pass `--raw`, and never
791
824
logged.
792
825
826
+
---
827
+
793
828
## Rebranding
794
829
795
830
To run this inside a company under the company's own name, rename it with one command.
@@ -818,7 +853,10 @@ the running tool shows come from one module (`core/brand.py`). After rewriting,
818
853
refreshes the lock file and runs every check. `LICENSE` is never changed: the MIT licence
819
854
requires its copyright and permission notice to stay with the code. A test rebrands a copy of
820
855
the repository and runs the copy's whole test suite, so the rename keeps working as the code
821
-
grows.
856
+
grows. The README's logo, badges and footer point at Libre DevOps and this repository's
857
+
GitHub pages, so replace them with your own by hand.
858
+
859
+
---
822
860
823
861
## Using it as a library
824
862
@@ -865,6 +903,8 @@ with EntraClient.for_profile(profile, tokens) as entra, XdrClient.for_profile(pr
865
903
Library code raises `LdoError` subclasses and never exits; only the CLI turns errors into
866
904
messages and exit codes.
867
905
906
+
---
907
+
868
908
## CI/CD
869
909
870
910
Every pull request and push to `main` runs `.github/workflows/ci.yml`:
@@ -875,7 +915,7 @@ Every pull request and push to `main` runs `.github/workflows/ci.yml`:
875
915
| Lint | `ruff check` and `ruff format --check`, after `uv sync --locked` |
876
916
| Dependency audit | `pip-audit` over the locked, hashed dependency tree |
877
917
| Test | pytest on Python 3.11 to 3.14 on Linux, and 3.13 on Windows and macOS, including the rebrand test |
878
-
| Coverage | line and branch coverage, failing below the floor in `pyproject.toml` (`fail_under`), with the report in the job summary |
918
+
| Coverage | line and branch coverage, failing below the floor in `pyproject.toml` (`fail_under`), with the report in the job summary and the total written for the badge |
879
919
| Build | builds the sdist and wheel once, installs the wheel in a clean environment, and keeps both as the run's artifact |
880
920
881
921
`.github/workflows/container.yml`builds both images on every pull request and push, runs
@@ -886,6 +926,10 @@ fixed critical one and reports the rest, since the Azure CLI inside it pins its
886
926
dependencies. Findings
887
927
go to the Security tab.
888
928
929
+
After a passing run on `main`, `.github/workflows/badges.yml` commits the coverage total
930
+
to the `badges` branch as a shields.io endpoint file, which is where the README's coverage
931
+
badge reads it; nothing else lives on that branch.
932
+
889
933
CodeQL scans the Python code and the workflows on every change and weekly; Dependency
890
934
Review comments on pull requests that change dependencies. Third-party actions are pinned
891
935
to a commit.
@@ -920,6 +964,8 @@ both container images for every platform, with attestations, and only then publi
920
964
files the gate built (not a rebuild) as a GitHub release with `SHA256SUMS`, after checking
921
965
the tag matches the version. A release therefore never exists without its images.
922
966
967
+
---
968
+
923
969
## Development
924
970
925
971
```bash
@@ -943,6 +989,17 @@ so an hour-long watch runs in microseconds. Runtime dependencies are kept to `re
943
989
See [CONTRIBUTING.md](CONTRIBUTING.md) before opening a pull request, and
944
990
[SECURITY.md](SECURITY.md) to report a vulnerability.
945
991
992
+
---
993
+
946
994
## Licence
947
995
948
996
[MIT](LICENSE)
997
+
998
+
---
999
+
1000
+
<div align="center">
1001
+
<sub>
1002
+
Part of <a href="https://libredevops.org">Libre DevOps</a>. Everything we publish is open and
1003
+
provided as-is; review and test it against your own requirements before production use.
0 commit comments