Files
party2d/scripts/check_public_content.sh
2026-08-14 12:49:26 +00:00

47 lines
2.2 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
repo_root="$(git rev-parse --show-toplevel)"
cd "$repo_root"
fail() {
printf 'PUBLIC CONTENT CHECK FAILED: %s\n' "$1" >&2
exit 1
}
# The bracketed spellings intentionally prevent this guard from matching its
# own detection patterns.
content_pattern='[Rr][Ee][Vv][Ii][Ee][Ww]([Ee][Rr]|[Ss])?|[Ee][Dd][Ii][Tt][Oo][Rr]([[:space:]_-]*[Cc][Oo][Mm][Mm][Ee][Nn][Tt][Ss]?)?|[Mm][Aa][Jj][Oo][Rr][[:space:]_-]*[Rr][Ee][Vv][Ii][Ss][Ii][Oo][Nn]|[Pp][Oo][Ii][Nn][Tt][[:space:]_-]*[Bb][Yy][[:space:]_-]*[Pp][Oo][Ii][Nn][Tt]|[Rr][Ee][Vv][Ii][Ee][Ww][[:space:]_-]*[Pp][Rr][Oo][Cc][Ee][Ss][Ss]|[Ss][Uu][Bb][Mm][Ii][Ss][Ss][Ii][Oo][Nn][[:space:]_-]*[Dd][Ee][Tt][Aa][Ii][Ll][Ss]'
path_pattern='([Rr][Ee][Vv][Ii][Ee][Ww]|[Rr][Ee][Vv][Ii][Ss][Ii][Oo][Nn]|[Rr][Ee][Ss][Pp][Oo][Nn][Ss][Ee][[:space:]_.-]*[Tt][Oo])'
check_ref() {
local ref="$1"
local hits
hits="$(git grep -n -I -E "$content_pattern" "$ref" -- . ':(exclude)*.pdf' 2>/dev/null || true)"
[[ -z "$hits" ]] || fail "non-public wording found in $ref:\n$hits"
}
check_names() {
local names
names="$(git ls-tree -r --name-only HEAD | grep -E "$path_pattern" || true)"
[[ -z "$names" ]] || fail "non-public-looking tracked path(s):\n$names"
}
check_names
styling_meta_pattern='[Cc][Oo][Ll][Oo][Uu]?[Rr][ -]?[Bb][Ll][Ii][Nn][Dd]|[Gg][Rr][AaEe][Yy][ -]?[Ss][Cc][Aa][Ll][Ee]|[Mm][Oo][Nn][Oo][Cc][Hh][Rr][Oo][Mm][Ee]|[Ss][Tt][Yy][Ll][Ii][Nn][Gg][ -]?[Cc][Oo][Mm][Pp][Ll][Ii][Aa][Nn][Cc][Ee]|[Dd][Ee][Ss][Ii][Gg][Nn][ -]?[Nn][Ee][Gg][Oo][Tt][Ii][Aa][Tt][Ii][Oo][Nn]'
styling_hits="$(git grep -n -I -E "$styling_meta_pattern" HEAD -- README.md ':(glob)validation/**/*.md' 2>/dev/null || true)"
[[ -z "$styling_hits" ]] || fail "public documentation contains internal styling instructions or compliance language:\n$styling_hits"
while IFS= read -r commit; do
check_ref "$commit"
done < <(git rev-list --all)
while IFS=$'\t' read -r object subject; do
if printf '%s\n%s\n' "$object" "$subject" | grep -E -q "$content_pattern"; then
fail "non-public wording found in reachable ref or commit subject: $object $subject"
fi
done < <(git for-each-ref --format='%(refname)%09%(subject)'; git log --all --format='%H%x09%s')
printf 'OK: public-content audit passed.\n'