Add public repository safety guard

master
Carlo Costanzo 1 week ago
parent b1ad6abd7f
commit 1fbe4a4fb2

@ -4,7 +4,7 @@
# Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig
# -------------------------------------------------------------------
# Config Validation - Deterministic repository validation gate.
# Runs mutation-sensitive tests plus strict dashboard and holiday checks.
# Blocks private/generated artifacts, then runs strict repository checks.
# -------------------------------------------------------------------
######################################################################
name: Config Validation
@ -30,6 +30,10 @@ jobs:
- name: Check out repository
uses: actions/checkout@v7
- name: Reject private or generated artifacts
shell: pwsh
run: ./tools/check_public_repo_safety.ps1
- name: Set up Python
uses: actions/setup-python@v7
with:

3
.gitignore vendored

@ -59,6 +59,8 @@ AGENTS.override.md
docs/agent_ops_baselines.md
# Directories
/.playwright-cli/
/output/
llmvision
backups
deps
@ -74,7 +76,6 @@ config/custom_components/*
!config/custom_components/alexa_camera_compat/
!config/custom_components/alexa_camera_compat/**
config/custom_components/alexa_camera_compat/__pycache__/
output/playwright/
config/www/community
config/www/ookla_speedtest/
config/.cache/

@ -38,7 +38,7 @@ This walkthrough turns the read-only status pages on an AT&T gateway into a smal
### Repo layout and files you won't see
- Reusable config lives under `config/` (see the quick navigation paths above).
- Runtime artifacts are hidden by `.gitignore` and won't show up on GitHub (e.g., `home-assistant_v2.db*`, logs, `deps/`, `.venv/`, backups). Look at the YAML and scripts for the actual logic and regenerate your own `secrets.yaml`.
- Runtime and agent-generated artifacts are hidden by `.gitignore` and blocked by CI (e.g., `home-assistant_v2.db*`, logs, `deps/`, `.venv/`, backups, `output/`, and `.playwright-cli/`). Private agent instructions and editor workspace files also stay local. Look at the YAML and scripts for the actual logic and regenerate your own `secrets.yaml`.
### Platform
- Runs on Docker/compose today; this README is a browsing guide, not a how-to-install. Current HA version is tracked in `config/.HA_VERSION` (see the badge above).

@ -65,7 +65,7 @@ Kitchen Show note: `kiosk_tablet.yaml` uses Kiosk Satellite's native ESPHome ent
| [![YAML source: processmonitor](https://img.shields.io/static/v1?label=YAML&message=processmonitor&color=lightgrey&logo=github&logoColor=181717)](processmonitor.yaml) | Root filesystem disk-pressure monitoring with immediate digest/logbook notes at 80%, Joanna review after 10 minutes above 80%, and delayed phone alerts only if the issue stays unresolved after dispatch. | `sensor.disk_use_percent`, `repairs.create`, `script.joanna_dispatch`, `tts.clear_cache` |
| [![YAML source: tugtainer_updates](https://img.shields.io/static/v1?label=YAML&message=tugtainer_updates&color=lightgrey&logo=github&logoColor=181717)](tugtainer_updates.yaml) | Tugtainer container update reports via webhook, with Available-only reports processed without persistent alerts, visible `### Updated:` / `### Failed:` / `### Rolled-back:` outcomes, immediate Joanna recovery dispatch for failures, and Joanna review dispatch for every `### Available:` report. Home Assistant core participates in the 07:00 automatic rollout after a mandatory Tugtainer pre-update config check, with HTTP health and image rollback safeguards. Protected Tugtainer control-plane containers are updated one host at a time through their owning Compose stacks; duplicate Portainer image-update entities are auto-disabled because Tugtainer and Compose own rollout decisions. [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/4NNOkXzUyYw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/home-assistant-tugtainer-docker-updates.html) | `automation.tugtainer_disable_duplicate_portainer_image_updates`, `persistent_notification.create`, `event: tugtainer_available_detected`, `script.joanna_dispatch`, `input_datetime.tugtainer_last_update` |
| [![YAML source: printer](https://img.shields.io/static/v1?label=YAML&message=printer&color=lightgrey&logo=github&logoColor=181717)](printer.yaml) | Epson ink watchdog with one-day and one-week mobile snooze actions for low-ink reminders. | `input_datetime.printer_ink_snooze_until`, `sensor.epson_*`, mobile app action events |
| [![YAML source: bearclaw](https://img.shields.io/static/v1?label=YAML&message=bearclaw&color=lightgrey&logo=github&logoColor=181717)](bearclaw.yaml) | Joanna/BearClaw bridge automations forward Telegram commands to codex_appliance, include LLM-first routing context for freeform text, relay replies, deliver compact adaptive TeslaMate road-trip milestone, destination-arrival, and final summaries to Carlo and Stacey, emit an active-trip vacation signal, ingest `/api/bearclaw/status` telemetry, and expose dispatch, distinct BearClaw working-memory and federated OneNote KB health, compact scheduled-job warning/error health for Systems, user-keyed 7/28/90 step trends, personal records for Overview Health, and 48-hour Carlo/Stacey bowling highlights for Kitchen Show. Full Joanna reports add directional route comparisons, charging strategy, trip-aware morning context, and a private final route map. Retired QMD telemetry is not imported. Road-trip companion: [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/9-9T6v17NEw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/teslamate-road-trip-reports-codex.html). | `rest_command.bearclaw_*`, `event: tesla_road_trip_active`, `sensor.bearclaw_status_telemetry`, `sensor.bearclaw_scheduled_job_health`, `sensor.joanna_onenote_kb_health`, `sensor.joanna_*`, `binary_sensor.joanna_*`, `automation.bearclaw_*`, `script.notify_engine`, `script.send_to_logbook` |
| [![YAML source: bearclaw](https://img.shields.io/static/v1?label=YAML&message=bearclaw&color=lightgrey&logo=github&logoColor=181717)](bearclaw.yaml) | Joanna/BearClaw bridge automations dispatch trusted Home Assistant machine jobs to codex_appliance, relay lifecycle callbacks and outbound notifications, deliver compact adaptive TeslaMate road-trip milestone, destination-arrival, and final summaries to Carlo and Stacey, emit an active-trip vacation signal, ingest `/api/bearclaw/status` telemetry, and expose dispatch, distinct BearClaw working-memory and federated OneNote KB health, compact scheduled-job warning/error health for Systems, user-keyed 7/28/90 step trends, personal records for Overview Health, and 48-hour Carlo/Stacey bowling highlights for Kitchen Show. Authenticated human Telegram stays on the appliance's single agent-first Luna path; Home Assistant is not its semantic router. Full Joanna reports add directional route comparisons, charging strategy, trip-aware morning context, and a private final route map. Retired QMD telemetry is not imported. Road-trip companion: [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/9-9T6v17NEw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/teslamate-road-trip-reports-codex.html). | `rest_command.bearclaw_*`, `event: tesla_road_trip_active`, `sensor.bearclaw_status_telemetry`, `sensor.bearclaw_scheduled_job_health`, `sensor.joanna_onenote_kb_health`, `sensor.joanna_*`, `binary_sensor.joanna_*`, `automation.bearclaw_*`, `script.notify_engine`, `script.send_to_logbook` |
| [![YAML source: telegram_bot](https://img.shields.io/static/v1?label=YAML&message=telegram_bot&color=lightgrey&logo=github&logoColor=181717)](telegram_bot.yaml) | Legacy Telegram transport marker for BearClaw; the shared `joanna_send_telegram` helper now forwards through the codex_appliance direct Telegram API. | `rest_command.bearclaw_telegram_send`, `script.joanna_send_telegram` |
| [![YAML source: rheem_econet](https://img.shields.io/static/v1?label=YAML&message=rheem_econet&color=lightgrey&logo=github&logoColor=181717)](rheem_econet.yaml) | Rheem EcoNet water-heater monitoring with normalized alert and telemetry-stale states, event snapshots, persistent Repairs, parent notifications, Joanna diagnostic dispatch, and safe electric-mode enforcement during the current warranty repair. | `binary_sensor.rheem_wh_active_alert`, `binary_sensor.rheem_wh_telemetry_stale`, `binary_sensor.rheem_wh_problem`, `sensor.rheem_wh_diagnostic_status`, `sensor.rheem_wh_last_alert_snapshot`, `repairs.create`, `script.joanna_dispatch` |
| [![YAML source: phynplus](https://img.shields.io/static/v1?label=YAML&message=phynplus&color=lightgrey&logo=github&logoColor=181717)](phynplus.yaml) | Phyn shutoff automations with leak-test guard, Activity Feed context, Repairs tracking, and critical push recovery when the valve closes. [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/xbhgWnomFYI) | `valve.phyn_shutoff_valve`, `binary_sensor.phyn_leak_test_running`, `script.phyn_send_actionable_leak_notification`, `repairs.create` |

@ -0,0 +1,46 @@
######################################################################
# @CCOSTAN - Follow Me on X
# For more info visit https://www.vcloudinfo.com/click-here
# Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig
# -------------------------------------------------------------------
# Public Repository Safety - Reject private and generated tracked paths.
# Secret content scanning remains owned by the Secret Scan workflow.
# -------------------------------------------------------------------
######################################################################
[CmdletBinding()]
param()
$repoRoot = Split-Path -Parent $PSScriptRoot
$blockedPatterns = @(
'^\.playwright-cli(?:/|$)',
'^output(?:/|$)',
'^homeassistant\.code-workspace$',
'^\.vscode(?:/|$)',
'^AGENTS(?:\.override)?\.md$',
'^docs/agent_ops_baselines\.md$'
)
Push-Location $repoRoot
try {
$candidateFiles = @(git ls-files --cached --others --exclude-standard)
if ($LASTEXITCODE -ne 0) {
throw 'Unable to list public repository candidate files.'
}
} finally {
Pop-Location
}
$blockedFiles = @(
$candidateFiles | Where-Object {
$path = $_
$blockedPatterns | Where-Object { $path -match $_ } | Select-Object -First 1
}
)
if ($blockedFiles.Count -gt 0) {
$formatted = ($blockedFiles | Sort-Object | ForEach-Object { " - $_" }) -join [Environment]::NewLine
throw "Public repository safety check failed. Remove these private or generated tracked paths:$([Environment]::NewLine)$formatted"
}
Write-Host "Public repository safety check passed ($($candidateFiles.Count) public candidate files inspected)."

@ -16,7 +16,7 @@ if ([string]::IsNullOrWhiteSpace($BaseUrl)) {
$BaseUrl = 'http://192.168.10.10:8123'
}
if ([string]::IsNullOrWhiteSpace($OutputDir)) {
$OutputDir = Join-Path $repoRoot 'output/playwright/ha-ui-smoke'
$OutputDir = Join-Path ([IO.Path]::GetTempPath()) 'Codex/homeassistant/ha-ui-smoke'
}
if ([string]::IsNullOrWhiteSpace($NodePath)) {

Loading…
Cancel
Save

Powered by TurnKey Linux.