Public Access
b491241a58
Universal: Sync Feature Branch Versions / Sync feature branches with dev (push) Has been skipped
# Conflicts: # .mokogitea/CLAUDE.md # .mokogitea/ISSUE_TEMPLATE/config.yml # .mokogitea/ISSUE_TEMPLATE/documentation.md # .mokogitea/ISSUE_TEMPLATE/feature_request.md # .mokogitea/ISSUE_TEMPLATE/security.md # .mokogitea/branch-protection.yml # .mokogitea/bulk-repo-sync.yml # .mokogitea/pr-branch-check.yml # .mokogitea/renovate.yml # .mokogitea/sync-wikis.yml # .mokogitea/workflows/auto-bump.yml # .mokogitea/workflows/auto-release.yml # .mokogitea/workflows/ci-platform.yml # .mokogitea/workflows/cleanup.yml # .mokogitea/workflows/gitleaks.yml # .mokogitea/workflows/issue-branch.yml # .mokogitea/workflows/notify.yml # .mokogitea/workflows/pre-release.yml # .mokogitea/workflows/repo-health.yml # .mokogitea/workflows/security-audit.yml # .script-registry.json # CHANGELOG.md # PLUGIN_SCRIPTS.md # README.md # analysis/index.md # automation/bulk_joomla_template.php # automation/bulk_sync.php # automation/enrich_manifest_xml.php # automation/enrich_mokostandards_xml.php # automation/index.md # automation/migrate_to_gitea.php # automation/push_files.php # automation/push_manifest_xml.php # automation/push_mokostandards_xml.php # automation/repo_cleanup.php # bin/moko # cli/archive_repo.php # cli/audit_query.php # cli/badge_update.php # cli/branch_rename.php # cli/bulk_workflow_push.php # cli/bulk_workflow_trigger.php # cli/changelog_promote.php # cli/changelog_prune.php # cli/client_dashboard.php # cli/client_health_check.php # cli/client_inventory.php # cli/client_provision.php # cli/completion.php # cli/create_project.php # cli/create_repo.php # cli/deploy_joomla.php # cli/dev_branch_reset.php # cli/grafana_dashboard.php # cli/joomla_build.php # cli/joomla_compat_check.php # cli/joomla_metadata_validate.php # cli/joomla_release.php # cli/license_manage.php # cli/manifest_element.php # cli/manifest_licensing.php # cli/manifest_read.php # cli/package_build.php # cli/platform_detect.php # cli/release.php # cli/release_body_update.php # cli/release_cascade.php # cli/release_create.php # cli/release_manage.php # cli/release_mirror.php # cli/release_notes.php # cli/release_package.php # cli/release_promote.php # cli/release_publish.php # cli/release_validate.php # cli/release_verify.php # cli/scaffold_client.php # cli/sync_rulesets.php # cli/theme_lint.php # cli/updates_xml_build.php # cli/updates_xml_sync.php # cli/version_auto_bump.php # cli/version_bump.php # cli/version_bump_remote.php # cli/version_check.php # cli/version_read.php # cli/version_reset_dev.php # cli/version_set_platform.php # cli/wiki_sync.php # cli/workflow_sync.php # composer.json # deploy/backup-before-deploy.php # deploy/deploy-dolibarr.php # deploy/deploy-joomla.php # deploy/deploy-sftp.php # deploy/health-check.php # deploy/rollback-joomla.php # deploy/sync-joomla.php # fix/fix_line_endings.php # fix/fix_permissions.php # fix/fix_tabs.php # fix/fix_trailing_spaces.php # fix/index.md # index.md # lib/CliBase.php # lib/Common.php # lib/Enterprise/AbstractProjectPlugin.php # lib/Enterprise/ApiClient.php # lib/Enterprise/AuditLogger.php # lib/Enterprise/CheckpointManager.php # lib/Enterprise/CliFramework.php # lib/Enterprise/Config.php # lib/Enterprise/ConfigValidator.php # lib/Enterprise/EnterpriseReadinessValidator.php # lib/Enterprise/ErrorRecovery.php # lib/Enterprise/FileFixUtility.php # lib/Enterprise/GitHubAdapter.php # lib/Enterprise/GitPlatformAdapter.php # lib/Enterprise/InputValidator.php # lib/Enterprise/ManifestParser.php # lib/Enterprise/ManifestReader.php # lib/Enterprise/MetricsCollector.php # lib/Enterprise/MokoGiteaAdapter.php # lib/Enterprise/PackageBuilder.php # lib/Enterprise/PlatformAdapterFactory.php # lib/Enterprise/PluginFactory.php # lib/Enterprise/PluginRegistry.php # lib/Enterprise/Plugins/ApiPlugin.php # lib/Enterprise/Plugins/DocumentationPlugin.php # lib/Enterprise/Plugins/DolibarrPlugin.php # lib/Enterprise/Plugins/GenericPlugin.php # lib/Enterprise/Plugins/JoomlaPlugin.php # lib/Enterprise/Plugins/McpServerPlugin.php # lib/Enterprise/Plugins/MobilePlugin.php # lib/Enterprise/Plugins/NodeJsPlugin.php # lib/Enterprise/Plugins/PythonPlugin.php # lib/Enterprise/Plugins/TerraformPlugin.php # lib/Enterprise/Plugins/WordPressPlugin.php # lib/Enterprise/ProjectConfigValidator.php # lib/Enterprise/ProjectMetricsCollector.php # lib/Enterprise/ProjectPluginInterface.php # lib/Enterprise/ProjectTypeDetector.php # lib/Enterprise/RecoveryError.php # lib/Enterprise/RecoveryManager.php # lib/Enterprise/RepositoryHealthChecker.php # lib/Enterprise/RepositorySynchronizer.php # lib/Enterprise/RetryHelper.php # lib/Enterprise/SecurityValidator.php # lib/Enterprise/SourceResolver.php # lib/Enterprise/SynchronizationException.php # lib/Enterprise/TransactionManager.php # lib/Enterprise/UnifiedValidation.php # lib/index.md # lib/plugins/Joomla/UpdateXmlGenerator.php # maintenance/index.md # maintenance/pin_action_shas.php # maintenance/repo_inventory.php # maintenance/rotate_secrets.php # maintenance/setup_labels.php # maintenance/sync_dolibarr_readmes.php # maintenance/update_repo_inventory.php # maintenance/update_sha_hashes.php # maintenance/update_version_from_readme.php # mcp/config.example.json # mcp/package.json # mcp/src/config.ts # mcp/src/index.ts # mcp/src/runner.ts # mcp/src/types.ts # phpcs.xml # plugin_health_check.php # plugin_list.php # plugin_metrics.php # plugin_readiness.php # plugin_validate.php # release/generate_dolibarr_version_txt.php # release/generate_joomla_update_xml.php # src/functions.php # templates/configs/README.md # templates/configs/index.md # templates/configs/manifest.xml.template # templates/configs/manifest.yml.template # templates/configs/mokostandards.xml.template # templates/configs/mokostandards.yml.template # templates/configs/phpcs.xml # templates/docs/README.md # templates/docs/extra/README.md # templates/docs/extra/index.md # templates/docs/index.md # templates/docs/required/GOVERNANCE.md # templates/docs/required/README.md # templates/docs/required/index.md # templates/docs/required/template-CONTRIBUTING.md # templates/docs/required/template-README.md # templates/docs/required/template-SECURITY.md # templates/index.md # templates/licenses/README.md # templates/licenses/index.md # templates/makefiles/README.md # templates/mokogitea/CLAUDE.dolibarr.md.template # templates/mokogitea/CLAUDE.joomla.md.template # templates/mokogitea/CLAUDE.md.template # templates/mokogitea/ISSUE_TEMPLATE/config.yml # templates/mokogitea/ISSUE_TEMPLATE/documentation.md # templates/mokogitea/ISSUE_TEMPLATE/dolibarr_module_id_request.md # templates/mokogitea/ISSUE_TEMPLATE/feature_request.md # templates/mokogitea/ISSUE_TEMPLATE/security.md # templates/mokogitea/README.md # templates/mokogitea/copilot-instructions.dolibarr.md.template # templates/mokogitea/copilot-instructions.joomla.md.template # templates/mokogitea/copilot-instructions.md.template # templates/mokogitea/dependabot.yml.template # templates/mokogitea/override.tf.template # templates/required/README.md # templates/schemas/README.md # templates/schemas/manifest-schema.xsd # templates/schemas/moko-platform-schema.xsd # templates/schemas/mokostandards-schema.xsd # templates/schemas/schemas/README.md # templates/schemas/template-repository-structure.xml # templates/scripts/README.md # templates/scripts/common/CliBase.template.php # templates/scripts/fix/index.md # templates/scripts/index.md # templates/scripts/release/index.md # templates/scripts/release/package_dolibarr.php # templates/scripts/release/package_joomla.php # templates/scripts/sftp-config/README.md # templates/scripts/validate/dolibarr_module.php # templates/scripts/validate/index.md # templates/scripts/validate/validate_manifest.php # templates/scripts/validate/validate_structure.php # templates/security/README.md # templates/security/index.php # templates/stubs/dolibarr.php # templates/stubs/joomla.php # templates/web/index.php # tests/Enterprise/GitPlatformAdapterTest.php # tests/Unit/VersionBumpTest.php # tests/Unit/VersionReadTest.php # tests/index.md # tests/test_circuit_breaker_handling.php # tests/test_enterprise_libraries.php # validate/SECURITY_SCANNING.md # validate/auto_detect_platform.php # validate/check_changelog.php # validate/check_client_theme.php # validate/check_composer_deps.php # validate/check_dolibarr_module.php # validate/check_enterprise_readiness.php # validate/check_file_integrity.php # validate/check_joomla_manifest.php # validate/check_language_structure.php # validate/check_license_headers.php # validate/check_no_secrets.php # validate/check_paths.php # validate/check_php_syntax.php # validate/check_repo_health.php # validate/check_structure.php # validate/check_tabs.php # validate/check_version_consistency.php # validate/check_wiki_health.php # validate/check_xml_wellformed.php # validate/index.md # validate/scan_drift.php # wrappers/auto_detect_platform.php # wrappers/bulk_sync.php # wrappers/check_changelog.php # wrappers/check_dolibarr_module.php # wrappers/check_enterprise_readiness.php # wrappers/check_joomla_manifest.php # wrappers/check_language_structure.php # wrappers/check_license_headers.php # wrappers/check_no_secrets.php # wrappers/check_paths.php # wrappers/check_php_syntax.php # wrappers/check_repo_health.php # wrappers/check_structure.php # wrappers/check_tabs.php # wrappers/check_version_consistency.php # wrappers/check_xml_wellformed.php # wrappers/deploy_sftp.php # wrappers/fix_line_endings.php # wrappers/fix_permissions.php # wrappers/fix_tabs.php # wrappers/fix_trailing_spaces.php # wrappers/gen_wrappers.php # wrappers/index.md # wrappers/pin_action_shas.php # wrappers/plugin_health_check.php # wrappers/plugin_list.php # wrappers/plugin_metrics.php # wrappers/plugin_readiness.php # wrappers/plugin_validate.php # wrappers/scan_drift.php # wrappers/setup_labels.php # wrappers/sync_dolibarr_readmes.php # wrappers/update_sha_hashes.php # wrappers/update_version_from_readme.php
628 lines
22 KiB
PHP
Executable File
628 lines
22 KiB
PHP
Executable File
#!/usr/bin/env php
|
||
<?php
|
||
|
||
/**
|
||
* Copyright (C) 2026 Moko Consulting <hello@mokoconsulting.tech>
|
||
*
|
||
* This file is part of a Moko Consulting project.
|
||
*
|
||
* SPDX-License-Identifier: GPL-3.0-or-later
|
||
*
|
||
* FILE INFORMATION
|
||
<<<<<<< HEAD
|
||
* DEFGROUP: MokoCLI.Scripts.Validate
|
||
* INGROUP: MokoCLI
|
||
* REPO: https://git.mokoconsulting.tech/MokoConsulting/mokocli
|
||
=======
|
||
* DEFGROUP: MokoPlatform.Scripts.Validate
|
||
* INGROUP: MokoPlatform
|
||
* REPO: https://git.mokoconsulting.tech/MokoConsulting/mokoplatform
|
||
>>>>>>> main
|
||
* PATH: /validate/scan_drift.php
|
||
* BRIEF: Standards drift detection - scans repositories for divergence from templates
|
||
*/
|
||
|
||
declare(strict_types=1);
|
||
|
||
require_once __DIR__ . '/../vendor/autoload.php';
|
||
|
||
use MokoCli\{
|
||
ApiClient,
|
||
AuditLogger,
|
||
CliFramework,
|
||
MetricsCollector
|
||
};
|
||
|
||
/**
|
||
* Standards Drift Scanner
|
||
*
|
||
<<<<<<< HEAD
|
||
* Scans repositories for drift from MokoCLI templates
|
||
=======
|
||
* Scans repositories for drift from mokoplatform templates
|
||
>>>>>>> main
|
||
*/
|
||
class DriftScanner extends CliFramework
|
||
{
|
||
private const VERSION = '09.23.00';
|
||
private const DEFAULT_ORG = 'mokoconsulting-tech';
|
||
|
||
private ApiClient $apiClient;
|
||
private MetricsCollector $metrics;
|
||
private \MokoCli\GitPlatformAdapter $adapter;
|
||
|
||
private array $driftResults = [];
|
||
private array $templates = [];
|
||
|
||
protected function configure(): void
|
||
{
|
||
$this->setDescription('Scan repositories for standards drift');
|
||
$this->addArgument('--org', 'GitHub organization', self::DEFAULT_ORG);
|
||
$this->addArgument('--repos', 'Specific repositories (comma-separated)', '');
|
||
$this->addArgument('--type', 'Filter by repository type', '');
|
||
$this->addArgument('--create-issues', 'Create GitHub issues for drift', false);
|
||
$this->addArgument('--threshold', 'Drift score threshold (0-100)', '20');
|
||
$this->addArgument('--json', 'Output as JSON', false);
|
||
}
|
||
|
||
protected function initialize(): void
|
||
{
|
||
parent::initialize();
|
||
|
||
$this->metrics = new MetricsCollector();
|
||
|
||
// Initialize API client via platform adapter
|
||
$config = \MokoCli\Config::load();
|
||
try {
|
||
$this->adapter = \MokoCli\PlatformAdapterFactory::create($config);
|
||
$this->apiClient = $this->adapter->getApiClient();
|
||
} catch (\Exception $e) {
|
||
$this->error("Platform initialization failed: " . $e->getMessage());
|
||
exit(1);
|
||
}
|
||
|
||
$this->log("Standards Drift Scanner v" . self::VERSION);
|
||
}
|
||
|
||
protected function run(): int
|
||
{
|
||
$org = $this->getArgument('--org');
|
||
$repos = $this->getArgument('--repos');
|
||
$type = $this->getArgument('--type');
|
||
$createIssues = $this->getArgument('--create-issues');
|
||
$threshold = (float)$this->getArgument('--threshold');
|
||
$jsonOutput = $this->getArgument('--json');
|
||
|
||
$this->log("Scanning organization: {$org}");
|
||
|
||
// Load templates
|
||
$this->loadTemplates();
|
||
|
||
// Get repositories to scan
|
||
$repositories = $this->getRepositories($org, $repos, $type);
|
||
|
||
if (empty($repositories)) {
|
||
$this->warn("No repositories found to scan");
|
||
return 0;
|
||
}
|
||
|
||
$this->log("Found " . count($repositories) . " repositories to scan");
|
||
|
||
// Scan each repository
|
||
$this->section('Scanning repositories');
|
||
$total = count($repositories);
|
||
$i = 0;
|
||
foreach ($repositories as $repo) {
|
||
$this->progress(++$i, $total, (string) $repo);
|
||
$this->scanRepository($org, $repo);
|
||
}
|
||
if ($total >= 3) {
|
||
$this->progress($total, $total, 'done', true);
|
||
}
|
||
|
||
// Generate report
|
||
if ($jsonOutput) {
|
||
echo json_encode($this->driftResults, JSON_PRETTY_PRINT) . PHP_EOL;
|
||
} else {
|
||
$this->displayReport($threshold);
|
||
}
|
||
|
||
// Create issues if requested
|
||
if ($createIssues) {
|
||
$this->createDriftIssues($org, $threshold);
|
||
}
|
||
|
||
// Record metrics
|
||
$this->recordMetrics();
|
||
|
||
// Return exit code based on drift threshold
|
||
$highDriftCount = count(array_filter(
|
||
$this->driftResults,
|
||
fn($r) => $r['drift_score'] >= $threshold
|
||
));
|
||
|
||
return $highDriftCount > 0 ? 1 : 0;
|
||
}
|
||
|
||
private function loadTemplates(): void
|
||
{
|
||
$this->log("Loading templates...");
|
||
|
||
$templatesDir = __DIR__ . '/../../templates';
|
||
|
||
// Workflows
|
||
$workflowsDir = "{$templatesDir}/workflows";
|
||
if (is_dir($workflowsDir)) {
|
||
$this->templates['workflows'] = $this->scanTemplateDirectory($workflowsDir);
|
||
}
|
||
|
||
// GitHub configs
|
||
$githubDir = "{$templatesDir}/github";
|
||
if (is_dir($githubDir)) {
|
||
$this->templates['github'] = $this->scanTemplateDirectory($githubDir);
|
||
}
|
||
|
||
// Issue templates
|
||
$issueTemplatesDir = "{$templatesDir}/ISSUE_TEMPLATE";
|
||
if (is_dir($issueTemplatesDir)) {
|
||
$this->templates['issue_templates'] = $this->scanTemplateDirectory($issueTemplatesDir);
|
||
}
|
||
|
||
$totalTemplates = array_sum(array_map('count', $this->templates));
|
||
$this->log("Loaded {$totalTemplates} templates");
|
||
}
|
||
|
||
private function scanTemplateDirectory(string $dir): array
|
||
{
|
||
$templates = [];
|
||
$iterator = new RecursiveIteratorIterator(
|
||
new RecursiveDirectoryIterator($dir, RecursiveDirectoryIterator::SKIP_DOTS)
|
||
);
|
||
|
||
foreach ($iterator as $file) {
|
||
if ($file->isFile()) {
|
||
$relativePath = substr($file->getPathname(), strlen($dir) + 1);
|
||
$templates[$relativePath] = [
|
||
'path' => $file->getPathname(),
|
||
'size' => $file->getSize(),
|
||
'mtime' => $file->getMTime(),
|
||
];
|
||
}
|
||
}
|
||
|
||
return $templates;
|
||
}
|
||
|
||
private function getRepositories(string $org, string $repoFilter, string $typeFilter): array
|
||
{
|
||
if (!empty($repoFilter)) {
|
||
return array_map('trim', explode(',', $repoFilter));
|
||
}
|
||
|
||
// Fetch all repositories from GitHub
|
||
try {
|
||
$response = $this->apiClient->get("/orgs/{$org}/repos", [
|
||
'type' => 'all',
|
||
'per_page' => 100,
|
||
]);
|
||
|
||
$repos = array_map(fn($r) => $r['name'], $response);
|
||
|
||
// Filter by type if specified
|
||
if (!empty($typeFilter)) {
|
||
$repos = array_filter($repos, function ($repo) use ($org, $typeFilter) {
|
||
$repoType = $this->detectRepositoryType($org, $repo);
|
||
return $repoType === $typeFilter;
|
||
});
|
||
}
|
||
|
||
return $repos;
|
||
} catch (Exception $e) {
|
||
$this->error("Failed to fetch repositories: " . $e->getMessage());
|
||
return [];
|
||
}
|
||
}
|
||
|
||
private function detectRepositoryType(string $org, string $repo): string
|
||
{
|
||
// Try to read override.tf to determine type
|
||
try {
|
||
$override = $this->apiClient->get("/repos/{$org}/{$repo}/contents/.github/override.tf");
|
||
if (!empty($override['content'])) {
|
||
$content = base64_decode($override['content']);
|
||
if (preg_match('/repository_type\s*=\s*"([^"]+)"/', $content, $matches)) {
|
||
return $matches[1];
|
||
}
|
||
}
|
||
} catch (Exception $e) {
|
||
// Override file doesn't exist, try to detect from files
|
||
}
|
||
|
||
// Detect from file presence
|
||
try {
|
||
// Check for package.json (nodejs)
|
||
$this->apiClient->get("/repos/{$org}/{$repo}/contents/package.json");
|
||
return 'nodejs';
|
||
} catch (Exception $e) {
|
||
}
|
||
|
||
try {
|
||
// Check for terraform files
|
||
$files = $this->apiClient->get("/repos/{$org}/{$repo}/contents");
|
||
foreach ($files as $file) {
|
||
if (str_ends_with($file['name'], '.tf')) {
|
||
return 'terraform';
|
||
}
|
||
}
|
||
} catch (Exception $e) {
|
||
}
|
||
|
||
return 'generic';
|
||
}
|
||
|
||
private function scanRepository(string $org, string $repo): void
|
||
{
|
||
$this->log("Scanning {$repo}...");
|
||
|
||
$drift = [
|
||
'repository' => $repo,
|
||
'type' => $this->detectRepositoryType($org, $repo),
|
||
'drift_score' => 0,
|
||
'missing_files' => [],
|
||
'outdated_files' => [],
|
||
'modified_files' => [],
|
||
'total_files_checked' => 0,
|
||
];
|
||
|
||
// Get override configuration
|
||
$overrideConfig = $this->getOverrideConfig($org, $repo);
|
||
$protectedFiles = $overrideConfig['protected_files'] ?? [];
|
||
$syncExclusions = $overrideConfig['sync_exclusions'] ?? [];
|
||
|
||
// Check workflows — scan both .github/workflows and .gitea/workflows
|
||
$drift = $this->checkFileCategory($org, $repo, 'workflows', '.github/workflows', $drift, $protectedFiles, $syncExclusions);
|
||
$drift = $this->checkFileCategory($org, $repo, 'workflows_gitea', '.mokogitea/workflows', $drift, $protectedFiles, $syncExclusions);
|
||
|
||
// Check GitHub configs
|
||
$drift = $this->checkFileCategory($org, $repo, 'github', '.github', $drift, $protectedFiles, $syncExclusions);
|
||
|
||
// Check issue templates
|
||
$drift = $this->checkFileCategory($org, $repo, 'issue_templates', '.github/ISSUE_TEMPLATE', $drift, $protectedFiles, $syncExclusions);
|
||
|
||
// Calculate drift score (0-100)
|
||
$drift['drift_score'] = $this->calculateDriftScore($drift);
|
||
|
||
// Determine drift level
|
||
$drift['drift_level'] = $this->getDriftLevel($drift['drift_score']);
|
||
|
||
$this->driftResults[$repo] = $drift;
|
||
|
||
$this->log(" Drift score: {$drift['drift_score']} ({$drift['drift_level']})");
|
||
}
|
||
|
||
private function getOverrideConfig(string $org, string $repo): array
|
||
{
|
||
try {
|
||
$override = $this->apiClient->get("/repos/{$org}/{$repo}/contents/.github/override.tf");
|
||
if (!empty($override['content'])) {
|
||
$content = base64_decode($override['content']);
|
||
|
||
// Parse Terraform HCL (simplified parsing)
|
||
$config = [
|
||
'protected_files' => [],
|
||
'sync_exclusions' => [],
|
||
];
|
||
|
||
// Extract protected_files array
|
||
if (preg_match('/protected_files\s*=\s*\[(.*?)\]/s', $content, $matches)) {
|
||
$items = explode(',', $matches[1]);
|
||
foreach ($items as $item) {
|
||
if (preg_match('/"([^"]+)"/', trim($item), $m)) {
|
||
$config['protected_files'][] = $m[1];
|
||
}
|
||
}
|
||
}
|
||
|
||
// Extract sync_exclusions array
|
||
if (preg_match('/sync_exclusions\s*=\s*\[(.*?)\]/s', $content, $matches)) {
|
||
$items = explode(',', $matches[1]);
|
||
foreach ($items as $item) {
|
||
if (preg_match('/"([^"]+)"/', trim($item), $m)) {
|
||
$config['sync_exclusions'][] = $m[1];
|
||
}
|
||
}
|
||
}
|
||
|
||
return $config;
|
||
}
|
||
} catch (Exception $e) {
|
||
// No override file
|
||
}
|
||
|
||
return [];
|
||
}
|
||
|
||
private function checkFileCategory(
|
||
string $org,
|
||
string $repo,
|
||
string $category,
|
||
string $remotePath,
|
||
array $drift,
|
||
array $protectedFiles,
|
||
array $syncExclusions
|
||
): array {
|
||
if (!isset($this->templates[$category])) {
|
||
return $drift;
|
||
}
|
||
|
||
foreach ($this->templates[$category] as $templateFile => $templateInfo) {
|
||
$remoteFile = $remotePath . '/' . str_replace('.template', '', $templateFile);
|
||
|
||
// Skip if excluded or protected
|
||
if (in_array($remoteFile, $syncExclusions) || in_array($remoteFile, $protectedFiles)) {
|
||
continue;
|
||
}
|
||
|
||
$drift['total_files_checked']++;
|
||
|
||
try {
|
||
$remoteContent = $this->apiClient->get("/repos/{$org}/{$repo}/contents/{$remoteFile}");
|
||
|
||
if (empty($remoteContent['content'])) {
|
||
$drift['missing_files'][] = $remoteFile;
|
||
continue;
|
||
}
|
||
|
||
$remoteFileContent = base64_decode($remoteContent['content']);
|
||
$templateContent = file_get_contents($templateInfo['path']);
|
||
|
||
// Remove .template extension content if present
|
||
$templateContent = str_replace('.template', '', $templateContent);
|
||
|
||
// Check for version mismatch
|
||
$remoteVersion = $this->extractVersion($remoteFileContent);
|
||
$templateVersion = $this->extractVersion($templateContent);
|
||
|
||
if ($remoteVersion !== $templateVersion && !empty($templateVersion)) {
|
||
$drift['outdated_files'][] = [
|
||
'file' => $remoteFile,
|
||
'current_version' => $remoteVersion ?: 'unknown',
|
||
'expected_version' => $templateVersion,
|
||
];
|
||
} elseif ($this->hasSignificantDifferences($remoteFileContent, $templateContent)) {
|
||
$drift['modified_files'][] = $remoteFile;
|
||
}
|
||
} catch (Exception $e) {
|
||
// File doesn't exist in remote
|
||
$drift['missing_files'][] = $remoteFile;
|
||
}
|
||
}
|
||
|
||
return $drift;
|
||
}
|
||
|
||
private function extractVersion(string $content): ?string
|
||
{
|
||
if (preg_match('/VERSION:\s*([0-9.]+)/', $content, $matches)) {
|
||
return $matches[1];
|
||
}
|
||
return null;
|
||
}
|
||
|
||
private function hasSignificantDifferences(string $remote, string $template): bool
|
||
{
|
||
// Normalize whitespace
|
||
$remote = preg_replace('/\s+/', ' ', $remote);
|
||
$template = preg_replace('/\s+/', ' ', $template);
|
||
|
||
// Calculate similarity
|
||
$similarity = 0;
|
||
similar_text($remote, $template, $similarity);
|
||
|
||
// Consider files with < 90% similarity as significantly different
|
||
return $similarity < 90;
|
||
}
|
||
|
||
private function calculateDriftScore(array $drift): float
|
||
{
|
||
if ($drift['total_files_checked'] === 0) {
|
||
return 0;
|
||
}
|
||
|
||
// Weight different types of drift
|
||
$missingWeight = 10; // Missing files are most critical
|
||
$outdatedWeight = 5; // Outdated versions are high priority
|
||
$modifiedWeight = 2; // Modified files are lower priority
|
||
|
||
$driftPoints =
|
||
(count($drift['missing_files']) * $missingWeight) +
|
||
(count($drift['outdated_files']) * $outdatedWeight) +
|
||
(count($drift['modified_files']) * $modifiedWeight);
|
||
|
||
// Normalize to 0-100 scale
|
||
$maxPoints = $drift['total_files_checked'] * $missingWeight;
|
||
$score = min(100, ($driftPoints / max(1, $maxPoints)) * 100);
|
||
|
||
return round($score, 1);
|
||
}
|
||
|
||
private function getDriftLevel(float $score): string
|
||
{
|
||
if ($score >= 50) {
|
||
return 'critical';
|
||
}
|
||
if ($score >= 30) {
|
||
return 'high';
|
||
}
|
||
if ($score >= 10) {
|
||
return 'medium';
|
||
}
|
||
return 'low';
|
||
}
|
||
|
||
private function displayReport(float $threshold): void
|
||
{
|
||
$this->section('Drift report');
|
||
|
||
$totalRepos = count($this->driftResults);
|
||
$driftedRepos = array_filter($this->driftResults, fn($r) => $r['drift_score'] > 0);
|
||
|
||
$this->log("Total repositories scanned: {$totalRepos}");
|
||
$this->log("Repositories with drift: " . count($driftedRepos));
|
||
|
||
foreach ($this->driftResults as $repo => $drift) {
|
||
$detail = sprintf(
|
||
'score: %s | missing: %d | outdated: %d | modified: %d',
|
||
$drift['drift_score'],
|
||
count($drift['missing_files']),
|
||
count($drift['outdated_files']),
|
||
count($drift['modified_files'])
|
||
);
|
||
$this->status($drift['drift_score'] < $threshold, (string) $repo, $detail);
|
||
}
|
||
|
||
$highDriftCount = count(array_filter(
|
||
$this->driftResults,
|
||
fn($r) => $r['drift_score'] >= $threshold
|
||
));
|
||
|
||
$this->printSummary(
|
||
$totalRepos - $highDriftCount,
|
||
$highDriftCount,
|
||
$this->elapsed()
|
||
);
|
||
}
|
||
|
||
private function createDriftIssues(string $org, float $threshold): void
|
||
{
|
||
$this->log("Creating drift issues...");
|
||
|
||
foreach ($this->driftResults as $repo => $drift) {
|
||
if ($drift['drift_score'] < $threshold) {
|
||
continue;
|
||
}
|
||
|
||
$this->createDriftIssue($org, $repo, $drift);
|
||
}
|
||
}
|
||
|
||
private function createDriftIssue(string $org, string $repo, array $drift): void
|
||
{
|
||
$icon = match ($drift['drift_level']) {
|
||
'critical' => '🚨',
|
||
'high' => '⚠️',
|
||
'medium' => '🟡',
|
||
'low' => 'ℹ️',
|
||
};
|
||
|
||
$title = "{$icon} Standards Drift Detected: {$drift['drift_level']} ({$drift['drift_score']}%)";
|
||
|
||
$body = "## Standards Drift Report\n\n";
|
||
$body .= "**Repository Type:** `{$drift['type']}`\n";
|
||
$body .= "**Drift Score:** {$drift['drift_score']}/100\n";
|
||
$body .= "**Drift Level:** {$drift['drift_level']}\n";
|
||
$body .= "**Detected:** " . date('Y-m-d H:i:s T') . "\n\n";
|
||
|
||
if (!empty($drift['missing_files'])) {
|
||
$body .= "### ❌ Missing Files (" . count($drift['missing_files']) . ")\n\n";
|
||
foreach ($drift['missing_files'] as $file) {
|
||
$body .= "- `{$file}`\n";
|
||
}
|
||
$body .= "\n";
|
||
}
|
||
|
||
if (!empty($drift['outdated_files'])) {
|
||
$body .= "### 📅 Outdated Files (" . count($drift['outdated_files']) . ")\n\n";
|
||
foreach ($drift['outdated_files'] as $file) {
|
||
$body .= "- `{$file['file']}`: {$file['current_version']} → {$file['expected_version']}\n";
|
||
}
|
||
$body .= "\n";
|
||
}
|
||
|
||
if (!empty($drift['modified_files'])) {
|
||
$body .= "### ✏️ Modified Files (" . count($drift['modified_files']) . ")\n\n";
|
||
foreach ($drift['modified_files'] as $file) {
|
||
$body .= "- `{$file}`\n";
|
||
}
|
||
$body .= "\n";
|
||
}
|
||
|
||
$body .= "### 🔧 Remediation\n\n";
|
||
$body .= "To fix this drift:\n\n";
|
||
$body .= "1. **Option 1:** Run bulk sync to update all files automatically\n";
|
||
$body .= " ```bash\n";
|
||
<<<<<<< HEAD
|
||
$body .= " # From MokoCLI repository\n";
|
||
=======
|
||
$body .= " # From mokoplatform repository\n";
|
||
>>>>>>> main
|
||
$body .= " php automation/bulk_sync.php --repos=\"{$repo}\"\n";
|
||
$body .= " ```\n\n";
|
||
$body .= "2. **Option 2:** If changes are intentional, update `.github/override.tf` to exclude files\n\n";
|
||
$body .= "3. **Option 3:** Manually update files to match templates\n\n";
|
||
$body .= "---\n";
|
||
$body .= "*This issue was automatically created by the standards drift scanner.*\n";
|
||
|
||
$labels = ['standards-drift', "drift-{$drift['drift_level']}", 'type: chore', 'automation'];
|
||
|
||
try {
|
||
// Check for an existing drift issue to avoid duplicates
|
||
$existing = $this->apiClient->get("/repos/{$org}/{$repo}/issues", [
|
||
'labels' => 'standards-drift',
|
||
'state' => 'all',
|
||
'per_page' => 1,
|
||
'sort' => 'created',
|
||
'direction' => 'desc',
|
||
]);
|
||
$existing = array_values($existing);
|
||
|
||
if (!empty($existing) && isset($existing[0]['number'])) {
|
||
$num = $existing[0]['number'];
|
||
$patch = ['title' => $title, 'body' => $body, 'assignees' => ['jmiller']];
|
||
if (($existing[0]['state'] ?? 'open') === 'closed') {
|
||
$patch['state'] = 'open';
|
||
}
|
||
$this->apiClient->patch("/repos/{$org}/{$repo}/issues/{$num}", $patch);
|
||
try {
|
||
$this->apiClient->post("/repos/{$org}/{$repo}/issues/{$num}/labels", ['labels' => $labels]);
|
||
} catch (Exception $le) {
|
||
/* non-fatal */
|
||
}
|
||
$this->log(" Updated drift issue #{$num} in {$repo}");
|
||
} else {
|
||
$issue = $this->apiClient->post("/repos/{$org}/{$repo}/issues", [
|
||
'title' => $title,
|
||
'body' => $body,
|
||
'labels' => $labels,
|
||
'assignees' => ['jmiller'],
|
||
]);
|
||
$num = $issue['number'] ?? '?';
|
||
$this->log(" Created drift issue #{$num} in {$repo}");
|
||
}
|
||
} catch (Exception $e) {
|
||
$this->error(" Failed to create/update issue in {$repo}: " . $e->getMessage());
|
||
}
|
||
}
|
||
|
||
private function recordMetrics(): void
|
||
{
|
||
$this->metrics->setGauge('drift_scan_total_repos', count($this->driftResults));
|
||
$this->metrics->setGauge('drift_scan_drifted_repos', count(array_filter(
|
||
$this->driftResults,
|
||
fn($r) => $r['drift_score'] > 0
|
||
)));
|
||
|
||
foreach (['critical', 'high', 'medium', 'low'] as $level) {
|
||
$count = count(array_filter(
|
||
$this->driftResults,
|
||
fn($r) => $r['drift_level'] === $level
|
||
));
|
||
$this->metrics->setGauge("drift_scan_{$level}_repos", $count);
|
||
}
|
||
}
|
||
}
|
||
|
||
// Run the application
|
||
$app = new DriftScanner();
|
||
exit($app->execute());
|