From dfb3a9ef9b4c5bf678997affed31594c7371801d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?David=20Sp=C3=A1=C4=8Dil?= Date: Thu, 1 Oct 2026 18:45:48 +0200 Subject: [PATCH] =?UTF-8?q?chore:=20odstranit=20resources.py=20a=20konfigu?= =?UTF-8?q?raci=20flake8=20z=20bal=C3=AD=C4=8Dku=20(v2.1.4)=20(#71)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * chore: odstranit resources.py a konfiguraci flake8 z balíčku Scanner na plugins.qgis.org označil plugin jako „Validated (configured)“ kvůli amcr_viewer/.flake8. Ten potlačoval jen stylové nálezy (E302, E305, E501) ve vygenerovaném resources.py, který se nikde neimportuje – ikony se načítají přímo z PNG. resources.py repozitář pluginů nevyžaduje (validator.py v QGIS-Django, PyQGIS cookbook: „optional“). - Smazán amcr_viewer/resources.py a amcr_viewer/.flake8. - CI: flake8 běží s --isolated (výchozí pravidla jako scanner); kontrola ZIPu místo .flake8 hlídá povinný LICENSE. - check_sources.py: žádné skryté soubory v balíčku, ani config soubory scanneru. - pyproject.toml, README.md, AGENTS.md: odstraněny odkazy na oba soubory, popsán postup bez konfigurace. Ověřeno: check_sources, flake8 7.3.0, ruff 0.16.5, bandit 1.9.4, detect-secrets bez nálezů; pyqgis4-checker čistý; smoke test v QGIS 3.44.15 (Qt 5) i 4.2.3 (Qt 6); ZIP bez skrytých souborů. Připraveno s pomocí AI (Claude). * Verze 2.1.4 Povýšena verze v metadata.txt (+ changelog) a CITATION.cff po odstranění resources.py a konfigurace flake8. Připraveno s pomocí AI (Claude). --- .github/workflows/code_quality.yml | 12 ++- AGENTS.md | 13 +-- CITATION.cff | 2 +- README.md | 4 +- amcr_viewer/.flake8 | 12 --- amcr_viewer/metadata.txt | 4 +- amcr_viewer/resources.py | 128 ----------------------------- pyproject.toml | 7 +- tests/check_sources.py | 8 +- 9 files changed, 23 insertions(+), 167 deletions(-) delete mode 100644 amcr_viewer/.flake8 delete mode 100644 amcr_viewer/resources.py diff --git a/.github/workflows/code_quality.yml b/.github/workflows/code_quality.yml index 7a668e9..dfab364 100644 --- a/.github/workflows/code_quality.yml +++ b/.github/workflows/code_quality.yml @@ -74,10 +74,10 @@ jobs: print('detect-secrets: bez nálezů') " - # Na plugins.qgis.org je informativní, tady blokuje – konfigurace - # v amcr_viewer/.flake8 je stejná pro obě místa. + # Na plugins.qgis.org je informativní, tady blokuje. Bez konfigurace, + # tj. se stejnými výchozími pravidly jako scanner. - name: Flake8 - run: flake8 --config amcr_viewer/.flake8 amcr_viewer/ + run: flake8 --isolated amcr_viewer/ # Nad rámec plugins.qgis.org; konfigurace v pyproject.toml - name: Ruff @@ -162,14 +162,12 @@ jobs: exit 1 fi - # Kontrola obsahu ZIPu. Config soubory pro scanner musí být uvnitř - # vedle metadata.txt, jinak je plugins.qgis.org nenajde – a některé - # nástroje skryté soubory tiše vynechávají. + # Kontrola obsahu ZIPu: povinné soubory jsou uvnitř, git soubory ne. - name: Verify archive contents run: | unzip -l amcr_viewer.zip for soubor in amcr_viewer/metadata.txt amcr_viewer/__init__.py \ - amcr_viewer/.flake8; do + amcr_viewer/LICENSE; do unzip -l amcr_viewer.zip | grep -qF " $soubor" \ || { echo "::error::v ZIPu chybí $soubor"; exit 1; } done diff --git a/AGENTS.md b/AGENTS.md index 8fb225b..632adff 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -208,7 +208,7 @@ pip install bandit detect-secrets flake8 ruff python3 tests/check_sources.py bandit -r amcr_viewer/ detect-secrets scan --all-files amcr_viewer/ -flake8 --config amcr_viewer/.flake8 amcr_viewer/ +flake8 --isolated amcr_viewer/ ruff check . # smoke test v obou verzích QGIS (docker, bez instalace čehokoli) @@ -225,11 +225,12 @@ Na co si dát pozor: v logu. Workflow proto kontroluje, že log obsahuje jen hlavičku. - **`detect-secrets` bez `--all-files` prohledá jen soubory sledované gitem** a o nesledovaném souboru mlčí. Vypadá to jako čistý výsledek. -- **Konfigurace lintů je rozdělená schválně.** `amcr_viewer/.flake8` leží - vedle `metadata.txt`, protože scanner na plugins.qgis.org hledá config - soubory jen v kořeni balíčku uvnitř ZIPu; díky tomu platí stejná pravidla - v CI, lokálně i při uploadu. Konfigurace ruffu je naopak v kořenovém - `pyproject.toml` – ruff se do balíčku pluginu nedistribuuje. +- **Flake8 běží bez konfigurace** (`--isolated`), tedy se stejnými + výchozími pravidly jako scanner na plugins.qgis.org. Do balíčku nepatří + `.flake8`, `.bandit` ani `.secrets.baseline`: scanner by plugin označil + jako „Validated (configured)“ a nález je lepší opravit v kódu. + Konfigurace ruffu je v kořenovém `pyproject.toml` – ruff se do balíčku + pluginu nedistribuuje. Viz https://plugins.qgis.org/docs/security-scanning/config-files - **Verze nástrojů jsou v workflow napevno.** Výchozí sada pravidel ruffu se mezi verzemi mění, takže bez pinu by CI začalo padat samo od sebe. diff --git a/CITATION.cff b/CITATION.cff index 981d81b..1bc87e4 100644 --- a/CITATION.cff +++ b/CITATION.cff @@ -25,5 +25,5 @@ abstract: >- the Digital archive of the Archaeological Map of the Czech Republic (https://digiarchiv.aiscr.cz/). license: GPL-3.0 -version: '2.1.3' +version: '2.1.4' date-released: '2026-10-01' diff --git a/README.md b/README.md index e5b0133..0088aa9 100644 --- a/README.md +++ b/README.md @@ -333,9 +333,7 @@ amcr_viewer/ the plugin package (this is what gets zipped) codelists/heslar.csv cached controlled vocabularies i18n/ Qt translation files *.png toolbar and menu icons - resources.py generated by pyrcc, currently unused metadata.txt plugin metadata and changelog - .flake8 lint config, read by the plugins.qgis.org scanner tests/ check_sources.py source hygiene checks (no QGIS needed) smoke_test.py loads the plugin in a real, headless QGIS @@ -404,7 +402,7 @@ Reproducing them locally: ```bash python3 tests/check_sources.py ruff check . -flake8 --config amcr_viewer/.flake8 amcr_viewer/ +flake8 --isolated amcr_viewer/ bandit -r amcr_viewer/ docker run --rm -v "$PWD:/work:ro" -w /work --user "$(id -u):$(id -g)" \ -e HOME=/tmp qgis/qgis:stable python3 tests/smoke_test.py diff --git a/amcr_viewer/.flake8 b/amcr_viewer/.flake8 deleted file mode 100644 index 4ea6cc1..0000000 --- a/amcr_viewer/.flake8 +++ /dev/null @@ -1,12 +0,0 @@ -# Konfigurace flake8 pro plugin AMČR Viewer. -# -# Soubor leží vedle metadata.txt schválně: scanner na plugins.qgis.org -# hledá .flake8 pouze v kořeni balíčku uvnitř ZIPu, takže stejná pravidla -# platí v CI, lokálně i při uploadu. -# https://plugins.qgis.org/docs/security-scanning/config-files -[flake8] -# resources.py je vygenerovaný výstup pyrcc ("All changes made in this -# file will be lost"), není nikde importovaný a zdrojový .qrc v repu není. -# Ručně se neformátuje. -per-file-ignores = - *resources.py: E302,E305,E501 diff --git a/amcr_viewer/metadata.txt b/amcr_viewer/metadata.txt index f5c05d5..a787dd4 100644 --- a/amcr_viewer/metadata.txt +++ b/amcr_viewer/metadata.txt @@ -8,7 +8,7 @@ name=AMČR Viewer qgisMinimumVersion=3.44.0 qgisMaximumVersion=4.99.0 description=Viewing and downloading the AMČR data. -version=2.1.3 +version=2.1.4 author=David Spáčil email=spacil@arub.cz @@ -24,6 +24,8 @@ hasProcessingProvider=no # Uncomment the following line and add your changelog: changelog= Plný seznam změn v češtině je dostupný zde: https://github.com/ARUP-CAS/aiscr-qgis-amcr-viewer/releases/tag/v2.1.1 + v2.1.4 (2026-10-01) + * Removed unused generated resources.py and the bundled flake8 config, so the plugin passes the plugins.qgis.org scan without custom configuration v2.1.3 (2026-10-01) * Fixed empty person codelists (excavation leaders, finders) after updating codelists against Digiarchive v4.1.0 * A codelist that fails to download keeps its previous values and the user is warned diff --git a/amcr_viewer/resources.py b/amcr_viewer/resources.py deleted file mode 100644 index 2d64ca9..0000000 --- a/amcr_viewer/resources.py +++ /dev/null @@ -1,128 +0,0 @@ -# -*- coding: utf-8 -*- - -# Resource object code -# -# Created by: The Resource Compiler for PyQt5 (Qt v5.15.13) -# -# WARNING! All changes made in this file will be lost! - -from qgis.PyQt import QtCore - -qt_resource_data = b"\ -\x00\x00\x04\x0a\ -\x89\ -\x50\x4e\x47\x0d\x0a\x1a\x0a\x00\x00\x00\x0d\x49\x48\x44\x52\x00\ -\x00\x00\x17\x00\x00\x00\x18\x08\x06\x00\x00\x00\x11\x7c\x66\x75\ -\x00\x00\x00\x01\x73\x52\x47\x42\x00\xae\xce\x1c\xe9\x00\x00\x00\ -\x06\x62\x4b\x47\x44\x00\xff\x00\xff\x00\xff\xa0\xbd\xa7\x93\x00\ -\x00\x00\x09\x70\x48\x59\x73\x00\x00\x0b\x13\x00\x00\x0b\x13\x01\ -\x00\x9a\x9c\x18\x00\x00\x00\x07\x74\x49\x4d\x45\x07\xd9\x02\x15\ -\x16\x11\x2c\x9d\x48\x83\xbb\x00\x00\x03\x8a\x49\x44\x41\x54\x48\ -\xc7\xad\x95\x4b\x68\x5c\x55\x18\xc7\x7f\xe7\xdc\x7b\x67\xe6\xce\ -\x4c\x66\x26\x49\xd3\x24\x26\xa6\xc6\xf8\x40\x21\xa5\x04\xb3\x28\ -\xda\x98\x20\xa5\x0b\xad\x55\xa8\x2b\xc5\x50\x1f\xa0\x6e\x34\x2b\ -\x45\x30\x14\x02\xba\x52\x69\x15\x17\x66\x63\x45\x97\x95\xa0\xad\ -\x0b\xfb\xc0\x06\x25\xb6\x71\x61\x12\x41\x50\xdb\x2a\x21\xd1\xe2\ -\x24\xf3\x9e\xc9\xcc\xbd\xe7\x1c\x17\x35\x43\x1e\x33\x21\xb6\xfd\ -\x56\x87\xf3\x9d\xfb\xfb\x1e\xf7\xff\x9d\x23\x8c\x31\x43\x95\xf4\ -\x85\x1e\x3f\x3b\x35\xac\xfd\xcc\x43\xdc\xa4\x49\x3b\xfe\x9d\x1d\ -\xdb\x7b\x22\x90\x78\xf8\xb2\x28\xa7\xbe\x7d\xc1\x4b\x9d\x79\xdf\ -\x18\x15\xe5\x16\x99\x10\x56\xde\x69\xdc\x3f\x22\xfd\xec\xd4\xf0\ -\xad\x04\x03\x18\xa3\xa2\x7e\x76\x6a\x58\xde\x68\x2b\xb4\x36\xf8\ -\xbe\xc6\x18\x53\xdb\xef\xe7\xfa\xec\xed\x67\x63\x10\x42\x00\xf0\ -\xfb\xd5\x65\x2a\x15\x45\xc7\x6d\x0d\x00\xc4\xa2\xc1\xaa\x6f\x0d\ -\x3e\x6c\xab\xc2\x1c\x56\xa4\x77\x4b\xb0\xf2\x35\x15\x5f\x21\x85\ -\xe0\xc8\x6b\x5f\x92\x2d\x37\x33\x39\xf9\x03\x27\x8e\x1f\xa2\xf7\ -\xbe\x9d\x04\x1c\x0b\x37\xe4\xac\xff\xa6\x30\x87\xbd\xba\x00\x6a\ -\x06\x79\xe5\xf5\xaf\x89\xd9\x92\xc5\xcc\x0a\xd9\x7c\x19\xcf\xe9\ -\xe2\xe4\xa9\x2f\x78\x7c\xff\x01\x72\x85\x0a\x2b\x65\x1f\xa5\x4c\ -\xb5\xb2\x55\x16\x80\xbd\x31\xda\xda\x20\x1f\x7d\x3e\xcd\xc2\xfd\ -\x59\xa6\x93\x39\x92\xd1\x22\xea\x9b\x16\xce\x9d\x3f\xce\xe0\x83\ -\x03\x24\x82\x59\x3a\xdb\x7b\x88\xc7\x82\x68\x63\x58\xc9\xcc\x62\ -\x8c\x21\x18\xb0\x6a\xc3\x37\x06\x49\x16\xff\x24\x6b\xa5\x49\xbb\ -\x25\xbc\xa2\xa6\x21\xbb\x40\x7f\xdf\x00\x83\xbd\x01\x8e\x3c\xd5\ -\x45\xd7\x8e\x6b\x9c\x9c\x98\x25\x1a\xb6\xe8\xbe\x3d\xc2\xdd\x77\ -\x44\x48\xc4\x1c\x22\xe1\xeb\x58\x59\xaf\xcf\xd3\x33\x29\x2e\x34\ -\x2d\x91\x93\x3e\xbe\x34\x78\x01\xc5\xe2\x61\xc5\xae\x72\x8e\x70\ -\xc8\xc2\x0d\x5a\xbc\xf5\xee\x2f\x9c\xfa\x3e\x86\x69\x7a\x8e\xcf\ -\x26\xe6\xf9\x63\xa1\x44\xa1\xa4\xd0\xda\x6c\x0d\x2f\x15\x7c\xb4\ -\x67\x28\x59\x0a\xcf\xd6\x54\xe2\x06\x13\x87\x2b\x6f\x68\xa6\x27\ -\xaf\x31\x32\x36\xc7\xb2\x7f\x17\xef\x7d\x7c\x8c\x33\x67\xcf\x12\ -\x70\x24\x4a\x69\xd6\x6a\x46\xd6\xd3\x70\x72\xa9\x82\x67\x34\x45\ -\xad\x28\xdb\x1a\x15\x34\x98\xff\x46\xed\xef\x37\x0d\x99\xbf\x4a\ -\x3c\x30\x38\xc0\xc8\x4b\xaf\x92\x5a\x9c\xe2\xe0\x23\x6d\x74\xb4\ -\xba\x84\x5d\x0b\x29\x45\x7d\xb8\x94\x82\x96\xb6\x10\xf3\xc5\x12\ -\x2a\xef\x53\x11\x1a\x63\xad\x3f\x93\x19\x85\xf1\xb1\x77\x58\x5a\ -\xf8\x99\x97\x9f\xe9\xa6\x75\x47\x90\xc6\xb8\x43\xd8\xb5\xb6\xce\ -\xfc\xfa\xfd\x00\xfb\x3e\xf4\xc8\x05\x35\xba\x5e\xeb\x46\x21\xf9\ -\xcf\x0a\xa9\x8c\x87\xe3\x48\xdc\x90\xb5\x6e\x98\x6a\xaa\x65\xf2\ -\x52\x92\x43\x2f\x5e\xc2\x8c\x02\x1a\x10\xf5\x07\xac\xc3\x75\x70\ -\x83\x92\x80\xb3\xf9\xd0\x26\xf8\x8f\xb3\x29\xc6\x3e\xb8\x8c\x19\ -\x35\x75\x6b\x7b\x7e\x3c\xca\x45\x0c\x7e\x49\x31\xf4\x58\x3b\xf7\ -\xf6\x34\x90\x88\x39\x04\x1c\x59\x1f\xfe\xdb\xd5\x3c\x5f\x9d\x4b\ -\x32\xfd\x44\xb2\xba\xd7\xfa\xb6\x60\xcf\xde\x16\xdc\x90\x45\x4c\ -\x4a\x2a\x9e\x62\xfe\x4e\xc5\xc8\xc1\x4e\xda\x76\x86\xe8\xe9\x0a\ -\xe3\xd8\x92\x58\xd4\xc6\xb2\x44\x6d\x78\x2a\x53\xe1\xca\x7c\x99\ -\x63\x5d\xbf\x56\x9d\xbd\x9f\x44\x18\x7a\xba\x95\x27\x0f\xb4\xd3\ -\xdc\x18\xc0\xf3\x0d\x52\x40\xd8\xb5\xb0\xa4\x20\x14\xb2\x70\x6c\ -\x81\x63\xcb\xaa\x42\xd6\xfd\xb7\xf4\xec\xa3\x06\xa0\x50\x52\xd8\ -\x4e\x1b\x7e\x4a\xd3\x31\xf9\x29\xcf\xfe\xd4\x49\x7f\x5f\x13\xfb\ -\xfa\x9b\x71\x43\x92\x58\xd4\x21\x18\x90\xac\xde\xb0\x42\x50\x13\ -\x58\x33\xf3\x88\x6b\xa1\xfd\x65\x96\xf2\x79\xc6\x43\x7b\xd8\x75\ -\x38\xcc\x3d\xdd\xd1\xaa\xcf\x71\xe4\xff\x7f\x91\x56\x33\xaf\xea\ -\x37\xe7\xa1\x94\x21\x16\xb5\xd1\x06\x2c\x29\x36\xf5\x72\x9b\x96\ -\x95\xc0\xc4\xda\x9d\x78\x83\x43\x53\x22\x80\x65\x09\x1c\xfb\x86\ -\xc1\x00\xe7\x25\x70\x14\x48\x6f\x1e\x22\x51\xe3\x75\xd9\xb6\xa5\ -\x81\xa3\x32\xb1\xfb\xf4\x0c\x30\xb8\xb1\x82\x9b\xb0\x09\x60\x30\ -\xb1\xfb\xf4\xcc\xbf\xa0\xe9\x6e\xae\x5a\xdf\x4b\x81\x00\x00\x00\ -\x00\x49\x45\x4e\x44\xae\x42\x60\x82\ -" - -qt_resource_name = b"\ -\x00\x07\ -\x07\x3b\xe0\xb3\ -\x00\x70\ -\x00\x6c\x00\x75\x00\x67\x00\x69\x00\x6e\x00\x73\ -\x00\x0b\ -\x06\x1f\xb8\xc2\ -\x00\x61\ -\x00\x6d\x00\x63\x00\x72\x00\x5f\x00\x76\x00\x69\x00\x65\x00\x77\x00\x65\x00\x72\ -\x00\x08\ -\x0a\x61\x5a\xa7\ -\x00\x69\ -\x00\x63\x00\x6f\x00\x6e\x00\x2e\x00\x70\x00\x6e\x00\x67\ -" - -qt_resource_struct_v1 = b"\ -\x00\x00\x00\x00\x00\x02\x00\x00\x00\x01\x00\x00\x00\x01\ -\x00\x00\x00\x00\x00\x02\x00\x00\x00\x01\x00\x00\x00\x02\ -\x00\x00\x00\x14\x00\x02\x00\x00\x00\x01\x00\x00\x00\x03\ -\x00\x00\x00\x30\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\ -" - -qt_resource_struct_v2 = b"\ -\x00\x00\x00\x00\x00\x02\x00\x00\x00\x01\x00\x00\x00\x01\ -\x00\x00\x00\x00\x00\x00\x00\x00\ -\x00\x00\x00\x00\x00\x02\x00\x00\x00\x01\x00\x00\x00\x02\ -\x00\x00\x00\x00\x00\x00\x00\x00\ -\x00\x00\x00\x14\x00\x02\x00\x00\x00\x01\x00\x00\x00\x03\ -\x00\x00\x00\x00\x00\x00\x00\x00\ -\x00\x00\x00\x30\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\ -\x00\x00\x01\x9c\x23\xfd\x16\x70\ -" - -qt_version = [int(v) for v in QtCore.qVersion().split('.')] -if qt_version < [5, 8, 0]: - rcc_version = 1 - qt_resource_struct = qt_resource_struct_v1 -else: - rcc_version = 2 - qt_resource_struct = qt_resource_struct_v2 - -def qInitResources(): - QtCore.qRegisterResourceData(rcc_version, qt_resource_struct, qt_resource_name, qt_resource_data) - -def qCleanupResources(): - QtCore.qUnregisterResourceData(rcc_version, qt_resource_struct, qt_resource_name, qt_resource_data) - -qInitResources() diff --git a/pyproject.toml b/pyproject.toml index d60d6e9..31cda19 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -5,15 +5,14 @@ # jen k tomu, aby ruff choval stejně v CI, lokálně i za rok. Bez explicitní # konfigurace se výchozí sada pravidel mezi verzemi ruffu mění. # -# Konfigurace flake8 je záměrně jinde: v amcr_viewer/.flake8, protože ji -# musí najít i scanner na plugins.qgis.org. +# Flake8 záměrně žádnou konfiguraci nemá a běží s výchozími pravidly – stejně +# jako scanner na plugins.qgis.org. Config soubor v balíčku by plugin +# označil jako „Validated (configured)“. [tool.ruff] line-length = 79 # QGIS 3.44 běží na Pythonu 3.9 a novějším target-version = "py39" -# Generovaný výstup pyrcc, "All changes made in this file will be lost" -extend-exclude = ["amcr_viewer/resources.py"] [tool.ruff.lint] select = [ diff --git a/tests/check_sources.py b/tests/check_sources.py index fb960a2..f840a55 100644 --- a/tests/check_sources.py +++ b/tests/check_sources.py @@ -23,10 +23,6 @@ import sys ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__))) BALICEK = os.path.join(ROOT, "amcr_viewer") -# Files that belong in the plugin package even though the upload scanner -# would otherwise call them hidden -POVOLENE_SKRYTE = {".flake8", ".bandit", ".secrets.baseline"} - # Extensions that have no business inside a plugin package PODEZRELE = {".exe", ".dll", ".so", ".dylib", ".sh", ".bat", ".cmd", ".pyc", ".pyd", ".jar", ".bin"} @@ -72,7 +68,9 @@ for cesta in vsechny_soubory(): if rezim & (stat.S_IXUSR | stat.S_IXGRP | stat.S_IXOTH): nalezy.append(f"{zkratka(cesta)}: spustitelná práva " f"({stat.filemode(rezim)})") - if jmeno.startswith(".") and jmeno not in POVOLENE_SKRYTE: + # No exceptions: scanner config files (.flake8, .bandit, + # .secrets.baseline) would mark the upload "Validated (configured)" + if jmeno.startswith("."): nalezy.append(f"{zkratka(cesta)}: skrytý soubor v balíčku pluginu") if os.path.splitext(jmeno)[1].lower() in PODEZRELE: nalezy.append(f"{zkratka(cesta)}: podezřelý typ souboru")