1e76efbe28
Skipping `tests/`, `spec/`, ... in EXCLUDED_DIRS made those trees invisible to the guard, but `plugins_loader._load_directory_module` sets `submodule_search_locations=[plugin_dir]`, so a plugin `__init__.py` doing `from .tests import evil` imports and runs whatever lives there: a `tests/evil.py` with a destructive root remove scanned `dangerous` on main and `safe` on this branch. `_walk` also matched the names at any depth, so `src/spec/handler.py` — plain runtime code — went unscanned. Keep scanning everything; instead cap a critical finding located under a ROOT-level test dir at `high`, so the verdict is `caution` (confirmation required, `--force` overridable) rather than the un-overridable `dangerous`. Fixture strings still cannot brick an install, which was the reported problem, while a critical in any runtime file (`setup.sh`, `src/spec/...`) still yields `dangerous`. Trade-off stated in the PR body: hostile code deliberately placed under `tests/` is now force-installable rather than blocked outright. Docs no longer claim test code never runs.
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.