Added missing pip-audit dev dependency and audit workflow documentation.
Dependency Audit / Dependency Audit (push) Successful in 17s
CI / Formatting (push) Successful in 14s
CI / Linting (push) Successful in 13s
CI / Tests (push) Successful in 23s
CI / Type Checking (push) Successful in 25s

This commit is contained in:
2026-02-19 10:47:08 -05:00
parent 0f70a0c602
commit a276e35fbe
3 changed files with 334 additions and 0 deletions
+2
View File
@@ -45,6 +45,7 @@ Owlbot is a modular, event-driven chat bot for Owncast.
- `uv run ruff format --check --diff .`: check formatting without changing files.
- `uv run ruff check .`: run lint checks.
- `uv run mypy .`: run strict type checking.
- `uv run pip-audit --skip-editable`: audit dependencies for known vulnerabilities.
## Creating Modules
- Read `docs/Modules.md` first, then focused references:
@@ -90,3 +91,4 @@ Since `docs/` is a git submodule, doc updates require normal submodule workflow:
## CI Parity
The pre-commit checklist mirrors `.gitea/workflows/ci.yml`. Keep local checks and CI checks aligned when adding or changing quality gates.
A separate `.gitea/workflows/audit.yml` runs `pip-audit` when dependencies change. Run `uv run pip-audit --skip-editable` locally when updating dependencies.