From 1fbe4a4fb2981d76fd357a5b5365f427be125f51 Mon Sep 17 00:00:00 2001 From: Carlo Costanzo Date: Fri, 18 Sep 2026 17:11:58 -0400 Subject: [PATCH] Add public repository safety guard --- .github/workflows/config-validation.yml | 6 +++- .gitignore | 3 +- README.md | 2 +- config/packages/README.md | 2 +- tools/check_public_repo_safety.ps1 | 46 +++++++++++++++++++++++++ tools/ha_ui_smoke.ps1 | 2 +- 6 files changed, 56 insertions(+), 5 deletions(-) create mode 100644 tools/check_public_repo_safety.ps1 diff --git a/.github/workflows/config-validation.yml b/.github/workflows/config-validation.yml index 2a9566a4..04734888 100644 --- a/.github/workflows/config-validation.yml +++ b/.github/workflows/config-validation.yml @@ -4,7 +4,7 @@ # Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig # ------------------------------------------------------------------- # Config Validation - Deterministic repository validation gate. -# Runs mutation-sensitive tests plus strict dashboard and holiday checks. +# Blocks private/generated artifacts, then runs strict repository checks. # ------------------------------------------------------------------- ###################################################################### name: Config Validation @@ -30,6 +30,10 @@ jobs: - name: Check out repository uses: actions/checkout@v7 + - name: Reject private or generated artifacts + shell: pwsh + run: ./tools/check_public_repo_safety.ps1 + - name: Set up Python uses: actions/setup-python@v7 with: diff --git a/.gitignore b/.gitignore index ca6a27b6..276827b0 100755 --- a/.gitignore +++ b/.gitignore @@ -59,6 +59,8 @@ AGENTS.override.md docs/agent_ops_baselines.md # Directories +/.playwright-cli/ +/output/ llmvision backups deps @@ -74,7 +76,6 @@ config/custom_components/* !config/custom_components/alexa_camera_compat/ !config/custom_components/alexa_camera_compat/** config/custom_components/alexa_camera_compat/__pycache__/ -output/playwright/ config/www/community config/www/ookla_speedtest/ config/.cache/ diff --git a/README.md b/README.md index 0074d115..2b92f932 100755 --- a/README.md +++ b/README.md @@ -38,7 +38,7 @@ This walkthrough turns the read-only status pages on an AT&T gateway into a smal ### Repo layout and files you won't see - Reusable config lives under `config/` (see the quick navigation paths above). -- Runtime artifacts are hidden by `.gitignore` and won't show up on GitHub (e.g., `home-assistant_v2.db*`, logs, `deps/`, `.venv/`, backups). Look at the YAML and scripts for the actual logic and regenerate your own `secrets.yaml`. +- Runtime and agent-generated artifacts are hidden by `.gitignore` and blocked by CI (e.g., `home-assistant_v2.db*`, logs, `deps/`, `.venv/`, backups, `output/`, and `.playwright-cli/`). Private agent instructions and editor workspace files also stay local. Look at the YAML and scripts for the actual logic and regenerate your own `secrets.yaml`. ### Platform - Runs on Docker/compose today; this README is a browsing guide, not a how-to-install. Current HA version is tracked in `config/.HA_VERSION` (see the badge above). diff --git a/config/packages/README.md b/config/packages/README.md index 0f2bf508..c23c7f7f 100755 --- a/config/packages/README.md +++ b/config/packages/README.md @@ -65,7 +65,7 @@ Kitchen Show note: `kiosk_tablet.yaml` uses Kiosk Satellite's native ESPHome ent | [![YAML source: processmonitor](https://img.shields.io/static/v1?label=YAML&message=processmonitor&color=lightgrey&logo=github&logoColor=181717)](processmonitor.yaml) | Root filesystem disk-pressure monitoring with immediate digest/logbook notes at 80%, Joanna review after 10 minutes above 80%, and delayed phone alerts only if the issue stays unresolved after dispatch. | `sensor.disk_use_percent`, `repairs.create`, `script.joanna_dispatch`, `tts.clear_cache` | | [![YAML source: tugtainer_updates](https://img.shields.io/static/v1?label=YAML&message=tugtainer_updates&color=lightgrey&logo=github&logoColor=181717)](tugtainer_updates.yaml) | Tugtainer container update reports via webhook, with Available-only reports processed without persistent alerts, visible `### Updated:` / `### Failed:` / `### Rolled-back:` outcomes, immediate Joanna recovery dispatch for failures, and Joanna review dispatch for every `### Available:` report. Home Assistant core participates in the 07:00 automatic rollout after a mandatory Tugtainer pre-update config check, with HTTP health and image rollback safeguards. Protected Tugtainer control-plane containers are updated one host at a time through their owning Compose stacks; duplicate Portainer image-update entities are auto-disabled because Tugtainer and Compose own rollout decisions. [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/4NNOkXzUyYw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/home-assistant-tugtainer-docker-updates.html) | `automation.tugtainer_disable_duplicate_portainer_image_updates`, `persistent_notification.create`, `event: tugtainer_available_detected`, `script.joanna_dispatch`, `input_datetime.tugtainer_last_update` | | [![YAML source: printer](https://img.shields.io/static/v1?label=YAML&message=printer&color=lightgrey&logo=github&logoColor=181717)](printer.yaml) | Epson ink watchdog with one-day and one-week mobile snooze actions for low-ink reminders. | `input_datetime.printer_ink_snooze_until`, `sensor.epson_*`, mobile app action events | -| [![YAML source: bearclaw](https://img.shields.io/static/v1?label=YAML&message=bearclaw&color=lightgrey&logo=github&logoColor=181717)](bearclaw.yaml) | Joanna/BearClaw bridge automations forward Telegram commands to codex_appliance, include LLM-first routing context for freeform text, relay replies, deliver compact adaptive TeslaMate road-trip milestone, destination-arrival, and final summaries to Carlo and Stacey, emit an active-trip vacation signal, ingest `/api/bearclaw/status` telemetry, and expose dispatch, distinct BearClaw working-memory and federated OneNote KB health, compact scheduled-job warning/error health for Systems, user-keyed 7/28/90 step trends, personal records for Overview Health, and 48-hour Carlo/Stacey bowling highlights for Kitchen Show. Full Joanna reports add directional route comparisons, charging strategy, trip-aware morning context, and a private final route map. Retired QMD telemetry is not imported. Road-trip companion: [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/9-9T6v17NEw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/teslamate-road-trip-reports-codex.html). | `rest_command.bearclaw_*`, `event: tesla_road_trip_active`, `sensor.bearclaw_status_telemetry`, `sensor.bearclaw_scheduled_job_health`, `sensor.joanna_onenote_kb_health`, `sensor.joanna_*`, `binary_sensor.joanna_*`, `automation.bearclaw_*`, `script.notify_engine`, `script.send_to_logbook` | +| [![YAML source: bearclaw](https://img.shields.io/static/v1?label=YAML&message=bearclaw&color=lightgrey&logo=github&logoColor=181717)](bearclaw.yaml) | Joanna/BearClaw bridge automations dispatch trusted Home Assistant machine jobs to codex_appliance, relay lifecycle callbacks and outbound notifications, deliver compact adaptive TeslaMate road-trip milestone, destination-arrival, and final summaries to Carlo and Stacey, emit an active-trip vacation signal, ingest `/api/bearclaw/status` telemetry, and expose dispatch, distinct BearClaw working-memory and federated OneNote KB health, compact scheduled-job warning/error health for Systems, user-keyed 7/28/90 step trends, personal records for Overview Health, and 48-hour Carlo/Stacey bowling highlights for Kitchen Show. Authenticated human Telegram stays on the appliance's single agent-first Luna path; Home Assistant is not its semantic router. Full Joanna reports add directional route comparisons, charging strategy, trip-aware morning context, and a private final route map. Retired QMD telemetry is not imported. Road-trip companion: [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/9-9T6v17NEw) [![vCloudInfo Blog Post](https://img.shields.io/static/v1?label=vCloudInfo&message=Blog%20Post&color=21759B&logo=wordpress&logoColor=white)](https://www.vcloudinfo.com/2026/07/teslamate-road-trip-reports-codex.html). | `rest_command.bearclaw_*`, `event: tesla_road_trip_active`, `sensor.bearclaw_status_telemetry`, `sensor.bearclaw_scheduled_job_health`, `sensor.joanna_onenote_kb_health`, `sensor.joanna_*`, `binary_sensor.joanna_*`, `automation.bearclaw_*`, `script.notify_engine`, `script.send_to_logbook` | | [![YAML source: telegram_bot](https://img.shields.io/static/v1?label=YAML&message=telegram_bot&color=lightgrey&logo=github&logoColor=181717)](telegram_bot.yaml) | Legacy Telegram transport marker for BearClaw; the shared `joanna_send_telegram` helper now forwards through the codex_appliance direct Telegram API. | `rest_command.bearclaw_telegram_send`, `script.joanna_send_telegram` | | [![YAML source: rheem_econet](https://img.shields.io/static/v1?label=YAML&message=rheem_econet&color=lightgrey&logo=github&logoColor=181717)](rheem_econet.yaml) | Rheem EcoNet water-heater monitoring with normalized alert and telemetry-stale states, event snapshots, persistent Repairs, parent notifications, Joanna diagnostic dispatch, and safe electric-mode enforcement during the current warranty repair. | `binary_sensor.rheem_wh_active_alert`, `binary_sensor.rheem_wh_telemetry_stale`, `binary_sensor.rheem_wh_problem`, `sensor.rheem_wh_diagnostic_status`, `sensor.rheem_wh_last_alert_snapshot`, `repairs.create`, `script.joanna_dispatch` | | [![YAML source: phynplus](https://img.shields.io/static/v1?label=YAML&message=phynplus&color=lightgrey&logo=github&logoColor=181717)](phynplus.yaml) | Phyn shutoff automations with leak-test guard, Activity Feed context, Repairs tracking, and critical push recovery when the valve closes. [![Watch on YouTube](https://img.shields.io/badge/Watch-YouTube-FF0000?logo=youtube&logoColor=white)](https://youtu.be/xbhgWnomFYI) | `valve.phyn_shutoff_valve`, `binary_sensor.phyn_leak_test_running`, `script.phyn_send_actionable_leak_notification`, `repairs.create` | diff --git a/tools/check_public_repo_safety.ps1 b/tools/check_public_repo_safety.ps1 new file mode 100644 index 00000000..e6f32b22 --- /dev/null +++ b/tools/check_public_repo_safety.ps1 @@ -0,0 +1,46 @@ +###################################################################### +# @CCOSTAN - Follow Me on X +# For more info visit https://www.vcloudinfo.com/click-here +# Original Repo : https://github.com/CCOSTAN/Home-AssistantConfig +# ------------------------------------------------------------------- +# Public Repository Safety - Reject private and generated tracked paths. +# Secret content scanning remains owned by the Secret Scan workflow. +# ------------------------------------------------------------------- +###################################################################### + +[CmdletBinding()] +param() + +$repoRoot = Split-Path -Parent $PSScriptRoot +$blockedPatterns = @( + '^\.playwright-cli(?:/|$)', + '^output(?:/|$)', + '^homeassistant\.code-workspace$', + '^\.vscode(?:/|$)', + '^AGENTS(?:\.override)?\.md$', + '^docs/agent_ops_baselines\.md$' +) + +Push-Location $repoRoot +try { + $candidateFiles = @(git ls-files --cached --others --exclude-standard) + if ($LASTEXITCODE -ne 0) { + throw 'Unable to list public repository candidate files.' + } +} finally { + Pop-Location +} + +$blockedFiles = @( + $candidateFiles | Where-Object { + $path = $_ + $blockedPatterns | Where-Object { $path -match $_ } | Select-Object -First 1 + } +) + +if ($blockedFiles.Count -gt 0) { + $formatted = ($blockedFiles | Sort-Object | ForEach-Object { " - $_" }) -join [Environment]::NewLine + throw "Public repository safety check failed. Remove these private or generated tracked paths:$([Environment]::NewLine)$formatted" +} + +Write-Host "Public repository safety check passed ($($candidateFiles.Count) public candidate files inspected)." diff --git a/tools/ha_ui_smoke.ps1 b/tools/ha_ui_smoke.ps1 index 57879470..770135eb 100644 --- a/tools/ha_ui_smoke.ps1 +++ b/tools/ha_ui_smoke.ps1 @@ -16,7 +16,7 @@ if ([string]::IsNullOrWhiteSpace($BaseUrl)) { $BaseUrl = 'http://192.168.10.10:8123' } if ([string]::IsNullOrWhiteSpace($OutputDir)) { - $OutputDir = Join-Path $repoRoot 'output/playwright/ha-ui-smoke' + $OutputDir = Join-Path ([IO.Path]::GetTempPath()) 'Codex/homeassistant/ha-ui-smoke' } if ([string]::IsNullOrWhiteSpace($NodePath)) {