Skip to content

[SG-320] feat(local): use tirith -policy-path as a CI gate — a directory of policies, masked input, and the verdict written out - #283

Closed
refeed wants to merge 2 commits into
mainfrom
feat/local-check
Closed

[SG-320] feat(local): use tirith -policy-path as a CI gate — a directory of policies, masked input, and the verdict written out#283
refeed wants to merge 2 commits into
mainfrom
feat/local-check

[SG-320] refactor(local): put CI reporting on `tirith -policy-path` i…

5531d86
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis cancelled Aug 18, 2026 in 42s

SonarQube Cloud analysis failed

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

Annotations

Check failure on line 564 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 16 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcT&open=AaAUxytwQijCrzrkukcT&pullRequest=283

Check warning on line 84 in src/tirith/platform/cli.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Merge these implicitly concatenated strings; or did you forget a comma?

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytXQijCrzrkukcL&open=AaAUxytXQijCrzrkukcL&pullRequest=283

Check failure on line 99 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 17 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcR&open=AaAUxytwQijCrzrkukcR&pullRequest=283

Check failure on line 532 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcX&open=AaAUxytwQijCrzrkukcX&pullRequest=283

Check failure on line 88 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcJ&open=AaAUxyqYQijCrzrkukcJ&pullRequest=283

Check failure on line 116 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 21 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcF&open=AaAUxyqYQijCrzrkukcF&pullRequest=283

Check failure on line 84 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcK&open=AaAUxyqYQijCrzrkukcK&pullRequest=283

Check failure on line 192 in src/tirith/platform/cli.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 24 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytXQijCrzrkukcM&open=AaAUxytXQijCrzrkukcM&pullRequest=283

Check warning on line 272 in src/tirith/platform/report.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Function "result_document" has 14 parameters, which is greater than the 13 authorized.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytkQijCrzrkukcP&open=AaAUxytkQijCrzrkukcP&pullRequest=283

Check warning on line 320 in src/tirith/cli.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove this commented out code.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyuxQijCrzrkukcY&open=AaAUxyuxQijCrzrkukcY&pullRequest=283

Check failure on line 282 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 17 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcS&open=AaAUxytwQijCrzrkukcS&pullRequest=283

Check failure on line 91 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcV&open=AaAUxytwQijCrzrkukcV&pullRequest=283

Check failure on line 242 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape from shell sandboxes. Refactor this code to validate untrusted data before passing them to OS commands.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcG&open=AaAUxyqYQijCrzrkukcG&pullRequest=283

Check warning on line 59 in setup.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Remove this commented out code.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxywGQijCrzrkukca&open=AaAUxywGQijCrzrkukca&pullRequest=283

Check failure on line 108 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcH&open=AaAUxyqYQijCrzrkukcH&pullRequest=283

Check failure on line 41 in src/tirith/platform/cli.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytXQijCrzrkukcN&open=AaAUxytXQijCrzrkukcN&pullRequest=283

Check warning on line 415 in src/tirith/platform/report.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Add replacement fields or use a normal string instead of an f-string.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytkQijCrzrkukcQ&open=AaAUxytkQijCrzrkukcQ&pullRequest=283

Check warning on line 102 in tests/test_readme_is_current.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Split this composite assertion into separate assertions.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyvxQijCrzrkukcZ&open=AaAUxyvxQijCrzrkukcZ&pullRequest=283

Check failure on line 76 in src/tirith/platform/report.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Refactor this function to reduce its Cognitive Complexity from 28 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytkQijCrzrkukcO&open=AaAUxytkQijCrzrkukcO&pullRequest=283

Check failure on line 225 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcW&open=AaAUxytwQijCrzrkukcW&pullRequest=283

Check failure on line 91 in src/tirith/local/evaluate.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxyqYQijCrzrkukcI&open=AaAUxyqYQijCrzrkukcI&pullRequest=283

Check failure on line 511 in src/tirith/platform/check.py

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

LLMs running this code with faulty CLI arguments can escape file system restrictions. Refactor this code to validate the constructed path before accessing the file system.

See more on https://sonarcloud.io/project/issues?id=StackGuardian_policy-framework&issues=AaAUxytwQijCrzrkukcU&open=AaAUxytwQijCrzrkukcU&pullRequest=283