Skip to content

fix(hooks): 위반 경고마다 file:line 과 걸린 규칙을, 요약 줄에도 위치를 실어요 - #37

Merged
bluecheat merged 1 commit into
mainfrom
fix/violation-file-line
Oct 3, 2026
Merged

bluecheat merged 1 commit into
mainfrom
fix/violation-file-line

Conversation

@bluecheat

Copy link
Copy Markdown
Owner

무엇이 좋아지나

  • 어느 모드든 위반마다 file:line — 규칙 한 줄이에요. 실측(one-tenth): 한 커밋은 파일 이름이 나왔고, 다른 커밋은 ⚠ CRITICAL 위반 1건 — 경고만 (mode=warning) 한 줄만 보여서 위치를 diff 에서 손으로 찾았어요
  • 시크릿도 줄까지 — 예전엔 Secrets 추정 패턴 — N개 파일: a b 처럼 파일 이름뿐이었어요. 이제 src/cfg.ts:4 — secrets:kv-detect (값은 안 찍어요). 줄 내용은 여전히 안 찍어요
  • 요약 줄에도 위치를 실어요 (앞 3곳 + "외 N건"). 출력이 잘리거나 다른 훅 출력과 섞여 요약 한 줄만 보여도 어디를 고칠지 남아요
  • check-mistake-secrets 도 같은 규약 — 파일 목록에 줄 번호(file:3,7), 요약 줄에 위치

출력 예 (mode=warning):

[goax] CRITICAL 룰 검사 (mode=warning) — 대상 1개 파일
  ⚠ src/cfg.ts:4 — secrets:kv-detect (값은 안 찍어요)
[goax] ⚠ CRITICAL 위반 1건 — 경고만 (mode=warning) — src/cfg.ts:4 (secrets:kv-detect). 기록 원하면 mistake skill 호출

바뀐 파일

  • templates/default/.ax/hooks/pre-commit/critical-rule-grep.sh — report <category> <file:line> <규칙> + locs_tail. 예전 2인자 호출(프로젝트가 채웠을 수 있는 스캐폴드)도 그대로 찍혀요
  • templates/default/.ax/hooks/pre-commit/check-mistake-secrets.sh
  • templates/default/.ax/hooks/README.md
  • tests/smoke.sh 새 §60

검증 (빨강 → 초록)

수정 전 훅에 §60 만 얹었을 때:

✗ critical-rule-grep (mode=warning) — 위반 줄에 file:line·규칙 없음:   ⚠ Secrets 추정 패턴 — 2개 파일: .ax/mistakes/2026-10-01-secrets.md src/cfg.ts
✗ critical-rule-grep (mode=warning) — 요약 줄에 위치 없음: [goax] ⚠ CRITICAL 위반 2건 — 경고만 (mode=warning). 기록 원하면 mistake skill 호출
✗ check-mistake-secrets (mode=warning) — 줄 번호 없음: [goax pre-commit] mistake 파일에 시크릿 추정 패턴이 남아있어요 (1건):
✗ critical-rule-grep (mode=fail) — 위반 줄에 file:line·규칙 없음: ...
✗ critical-rule-grep (mode=fail) — 요약 줄에 위치 없음: [goax] ✗ CRITICAL 위반 2건 — 차단 (mode=fail)
✗ check-mistake-secrets (mode=fail) — 줄 번호 없음: ...
✗ critical-rule-grep — 요약 줄 축약 실패: [goax] ✗ CRITICAL 위반 5건 — 차단 (mode=fail)
FAILS=7

수정 후:

✓ critical-rule-grep (mode=warning) — 위반마다 file:line — 규칙 (시크릿도 줄까지, 내용은 안 찍음)
✓ critical-rule-grep (mode=warning) — 요약 줄 하나만 보여도 위치가 있어요
✓ check-mistake-secrets (mode=warning) — file:line 을 목록과 요약 줄에
✓ critical-rule-grep (mode=fail) — 위반마다 file:line — 규칙 (시크릿도 줄까지, 내용은 안 찍음)
✓ critical-rule-grep (mode=fail) — 요약 줄 하나만 보여도 위치가 있어요
✓ check-mistake-secrets (mode=fail) — file:line 을 목록과 요약 줄에
✓ critical-rule-grep — 요약 줄은 앞 3곳 + 외 N건

버전·changelog 는 올리지 않았어요 (#30 과 같은 이유).

🤖 Generated with Claude Code

https://claude.ai/code/session_01C8rZ6V3FW3nwYA9T7iygPd

#31 을 다시 연 PR 이에요 (#30 이 머지되면서 base 브랜치가 지워져 #31 이 닫혔어요).

실측(one-tenth): 한 커밋은 파일 이름이 나왔고, 다른 커밋은 "⚠ CRITICAL 위반 1건 — 경고만
(mode=warning)" 한 줄만 보여서 위치를 diff 에서 손으로 찾았어요. 시크릿은 줄 없이 파일 이름만
찍었고, 요약 줄에는 위치가 없어서 출력이 잘리거나 다른 훅 출력과 섞이면 위치가 사라졌어요.

- critical-rule-grep: `report <category> <file:line> <규칙>` — 위반마다 `  ⚠ file:line — 규칙` 한 줄.
  시크릿도 걸린 줄마다 `file:line — secrets:<라벨>` (줄 내용은 여전히 안 찍어요).
  예전 2인자 호출(프로젝트가 채운 스캐폴드)도 그대로 찍혀요
- 요약 줄 `CRITICAL 위반 N건 — …` 에 앞 3곳 + "외 N건" 을 실어요 — 모드(warning·fail) 무관
- check-mistake-secrets: 파일 목록에 줄 번호(`file:3,7`)를, 요약 줄에 위치를

smoke §60: warning·fail 두 모드에서 위반 줄과 요약 줄 양쪽에 file:line·규칙, 시크릿 값 비노출,
mistake 파일 줄 번호, 요약 축약(앞 3곳 + 외 2건).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C8rZ6V3FW3nwYA9T7iygPd
@bluecheat
bluecheat merged commit 0c1d0c3 into main Oct 3, 2026
2 checks passed
@bluecheat
bluecheat deleted the fix/violation-file-line branch October 3, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant