Skip to content

M1: engine and the v0.1 check catalog - #3

Merged
hazeliscoding merged 41 commits into
mainfrom
m1
Sep 27, 2026
Merged

hazeliscoding merged 41 commits into
mainfrom
m1

Conversation

@hazeliscoding

Copy link
Copy Markdown
Owner

Milestone M1 from ROADMAP.md. The decisions it builds on are recorded there (2026-09-26).

  • Engine. One guarded query reads the server version, managed provider (RDS, Aurora, Cloud SQL, Azure, Supabase, Neon) and the role's privileges. Checks that don't apply are skipped with a reason. A check that fails is reported as errored, and the rest still run. The exit code is 1 when a finding reaches --fail-on, otherwise 2 when a check errored.
  • 15 checks. The table was revised after desk research into public postmortems. Each has fires and healthy fixtures, and passes on Postgres 14 to 18 (Debian images, stock settings). Each fires fixture is also tested as a role with only the check's declared privileges.
  • New fixture directives. -- server name = value sets a start-up setting, and -- expect error lets a statement fail.
  • Commands. list shows severity, category and minimum version. explain prints a check's note. grant prints SQL for a read-only pg_monitor role, and a test runs that SQL and scans as the new role.
  • Output. --format json (schema 1, documented in docs/json.md) and --format markdown for pull requests. Values from the database are escaped, so object names can't inject terminal or Markdown control sequences. Messages wrap to the terminal's width.
  • README. It now describes the v0.1 checks, and its recording shows a scan with the full catalog.

Errored checks show in the report, and a scan exits 2 when one errored and no finding reached --fail-on.
…ared privileges

Fixtures can now start Postgres with a setting (-- server) and expect a statement to fail (-- expect error). Each fires fixture also runs as a role with only the check's declared privileges.
grant prints SQL for a pg_monitor role that is read-only by default, plus the sequence grants integer-exhaustion needs. A test runs the printed SQL and scans as the new role.
The JSON shape is schema 1, documented in docs/json.md. Its values are the columns a finding's message uses, in raw form.
Object names are text anyone who can create a table controls. Terminal escapes in one could rewrite the report or set the clipboard, and a line break or backticks could break out of Markdown.
@hazeliscoding
hazeliscoding merged commit fb29e38 into main Sep 27, 2026
6 checks passed
@hazeliscoding
hazeliscoding deleted the m1 branch September 27, 2026 01:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant