From c2d57c316cd16b35b0e04e865ea8c113c5541d3b Mon Sep 17 00:00:00 2001 From: Charis Daniels Date: Tue, 29 Sep 2026 21:12:57 +0000 Subject: [PATCH] docs: fix CODEOWNERS onchain paths and document full check suite in CONTRIBUTING.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - CODEOWNERS (issue #520): replace the nonexistent onchain/src/ and onchain/tests/ paths with the real contract crates under onchain/contracts/, correct "Cairo" to "Rust / Soroban", and drop the leftover template placeholder comment. Every path in the file now exists in the repository. - CONTRIBUTING.md (issue #524): add a "Backend E2E Tests" section (backend/test/, jest-e2e.json, make test-backend-e2e) and a "Running the full check suite" section documenting make ci, the onchain cargo deny audit, npm audit gates and the gitleaks secret scan, each marked required or advisory with links to the workflow files. Closes #520 Closes #524 Generated with Codebuff 🤖 Co-Authored-By: Codebuff --- .github/CODEOWNERS | 16 ++++++------- CONTRIBUTING.md | 58 ++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 66 insertions(+), 8 deletions(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 4acbd3ae..42dcfeec 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -4,9 +4,7 @@ # https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners # for the full specification. -# Default owners for everything in the repo. Replace the placeholder -# handles below with the GitHub usernames that have write access to -# this repository. +# Default owners for everything in the repo. * @UnityChainxx @eulami # Frontend (Next.js / React) @@ -24,11 +22,13 @@ /backend/test/ @UnityChainxx @eulami /backend/config/ @UnityChainxx @eulami -# Onchain (Cairo smart contracts) -/onchain/ @UnityChainxx @eulami -/onchain/src/ @UnityChainxx @eulami -/onchain/src/contracts/ @UnityChainxx @eulami -/onchain/tests/ @UnityChainxx @eulami +# Onchain (Rust / Soroban smart contracts) +/onchain/ @UnityChainxx @eulami +/onchain/contracts/ @UnityChainxx @eulami +/onchain/contracts/stellar_hunts/ @UnityChainxx @eulami +/onchain/contracts/stellar_hunts_nft/ @UnityChainxx @eulami +/onchain/contracts/stellar_hunts_receiver/ @UnityChainxx @eulami +/onchain/contracts/stellar_hunts_types/ @UnityChainxx @eulami # CI / CD and project-wide tooling /.github/ @UnityChainxx @eulami diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index a29a9835..55cfd902 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -240,6 +240,22 @@ cd frontend && npm test -- puzzleReviewService Tests live in `frontend/tests/` and use `.test.js` (or `.test.jsx`) extensions. +### Backend E2E Tests + +The backend e2e specs live in `backend/test/` and run against a real PostgreSQL +instance (plus Redis). Jest config: `backend/test/jest-e2e.json`. + +```bash +# Run the backend e2e suite (requires PostgreSQL + Redis) +cd backend && npm run test:e2e + +# Or via the Makefile (from the repository root) +make test-backend-e2e + +# Run a single e2e spec by name +cd backend && npm run test:e2e -- security-headers +``` + ### Onchain Tests ```bash @@ -258,6 +274,48 @@ The CI workflow (`.github/workflows/build.yml`) runs automatically on push to `m All checks must pass before a pull request can be merged. +### Running the full check suite + +CI enforces more than the contract checks. The commands below reproduce every +workflow check locally; each is marked **required** (CI blocks the PR) or +**advisory** (CI reports it but does not block). + +```bash +# Everything CI runs, in one command (from the repository root) +make ci + +# Backend unit tests (required — .github/workflows/build.yml) +cd backend && npm test + +# Backend e2e suite — backend/test/*.e2e-spec.ts, config backend/test/jest-e2e.json +# (required; the workflow provisions Postgres + Redis service containers first) +cd backend && npm run test:e2e +# same as: make test-backend-e2e + +# Onchain contract checks (required — .github/workflows/build.yml) +cd onchain && cargo fmt --all -- --check +cd onchain && cargo build --workspace --release +cd onchain && cargo test --workspace + +# Onchain dependency/supply-chain audit (required — .github/workflows/build.yml) +cd onchain && cargo deny --locked check advisories licenses bans sources + +# npm dependency audit in frontend and backend (critical = required, high = advisory) +cd backend && npm audit --audit-level=critical +cd frontend && npm audit --audit-level=high # advisory; see SECURITY.md + +# Secret scanning (advisory — .github/workflows/security.yml) +gitleaks git --redact --no-banner --exit-code=1 \ + --report-format sarif --report-path gitleaks.sarif +``` + +Security scanning jobs — **CodeQL** (JavaScript/TypeScript analysis), +**Gitleaks** (secret scanning) and **dependency review** — run from +`.github/workflows/security.yml` and cannot all be reproduced locally; CodeQL +needs the GitHub Actions runner. The local equivalents of what can be run are +the `npm audit` / `cargo deny` commands above. See [SECURITY.md](SECURITY.md) +for the current advisory-versus-required status of every security gate. + ### One command before you open a PR Before opening a pull request, run the full check suite locally with a