Files
meshtastic_firmware/.trunk/trunk.yaml
T
4800484d41 lint: ignore userPrefs.jsonc in trunk (#11174)
checkov/CKV_SECRET_6 flags the commented-out "large4cats" example, which
is the public default credential for the meshtastic.org MQTT broker rather
than a real secret. Ignore the file in .trunk/trunk.yaml so the example
config stays free of lint-suppression comments.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-26 08:26:27 +00:00

130 lines
3.9 KiB
YAML

version: 0.1
cli:
version: 1.25.0
plugins:
sources:
- id: trunk
ref: v1.10.0
uri: https://github.com/trunk-io/plugins
lint:
# Custom file set + formatter that rewrites Unicode em-dash (U+2014, UTF-8
# bytes e2 80 94) and en-dash (U+2013, UTF-8 bytes e2 80 93) to an ASCII
# hyphen. The sed pattern matches the byte sequences under LC_ALL=C rather
# than literal characters on purpose, so the rule survives editors/hooks
# that themselves strip Unicode dashes. These dashes only ever appear in
# comments and log/error strings (LLM-authored prose), never in code, so
# the rewrite is purely cosmetic. Runs under `trunk fmt`; enforced by
# `trunk check` and the trunk-fmt-pre-commit action.
files:
- name: ascii-dash-targets
extensions:
- c
- cc
- cpp
- h
- hpp
- ino
- md
- py
- sh
- yaml
- yml
- json
- toml
- ini
- name: cpp-sources
extensions:
- c
- cc
- cpp
- cxx
- h
- hh
- hpp
- hxx
- ino
definitions:
- name: ascii-dash
files: [ascii-dash-targets]
commands:
- name: format
output: rewrite
formatter: true
run: env LC_ALL=C sed -e 's/\xe2\x80\x94/-/g' -e 's/\xe2\x80\x93/-/g' ${target}
success_codes: [0]
# Flags preprocessor conditionals that contain too many defined() terms
# (e.g. the 13-driver display chains in main.cpp). The compiler has no
# warning for this; the fix is an umbrella feature macro (HAS_TFT /
# HAS_SCREEN, already in src/configuration.h). Tune the limit via
# MAX_DEFINED in bin/lint-ifdef-complexity.sh (default 5 -> warns at 6+).
- name: too-many-defined
files: [cpp-sources]
commands:
- name: lint
output: regex
parse_regex: (?P<path>.+):(?P<line>\d+):(?P<col>\d+):(?P<severity>\w+):(?P<message>.+):(?P<code>[a-z-]+)
run: ${workspace}/bin/lint-ifdef-complexity.sh ${target}
success_codes: [0]
read_output_from: stdout
enabled:
- ascii-dash@SYSTEM
- too-many-defined@SYSTEM
- checkov@3.2.529
- renovate@43.150.0
- prettier@3.8.3
- trufflehog@3.95.3
- yamllint@1.38.0
- bandit@1.9.4
- trivy@0.70.0
- taplo@0.10.0
- ruff@0.15.13
- isort@8.0.1
- markdownlint@0.48.0
- oxipng@10.1.1
- svgo@4.0.1
- actionlint@1.7.12
- flake8@7.3.0
- hadolint@2.14.0
- shfmt@3.6.0
- shellcheck@0.11.0
- black@26.5.1
- git-diff-check
- gitleaks@8.30.1
- clang-format@16.0.3
ignore:
- linters: [ALL]
paths:
- bin/**
# Fake-NodeDB fixture JSONL files contain deterministic synthetic
# public_key_hex (64-char hex) values that gitleaks misidentifies as
# generic-api-key. These are not secrets - they're test fixtures
# produced by bin/gen-fake-nodedb-seed.py with a fixed RNG seed.
- linters: [gitleaks]
paths:
- test/fixtures/nodedb/seed_v25_*.jsonl
# checkov/CKV_SECRET_6 flags the commented-out "large4cats" example,
# which is the public default credential for the meshtastic.org MQTT
# broker rather than a real secret. Ignore the whole file so the
# example config stays free of lint-suppression comments.
- linters: [ALL]
paths:
- userPrefs.jsonc
# The UA font's em/en dashes live only in trailing comments documenting
# each glyph's codepoint (e.g. "8212=:2549"); rewriting them would make
# those docs inaccurate. Glyph byte data is unaffected either way.
- linters: [ascii-dash]
paths:
- src/graphics/fonts/**
runtimes:
enabled:
- python@3.14.4
- go@1.21.0
- node@22.16.0
actions:
disabled:
- trunk-announce
enabled:
- trunk-fmt-pre-commit
- trunk-check-pre-push
- trunk-upgrade-available