Add secret scanning, Dockerfile lint, ruff lint/format gate, coverage gate, and automatic CVE remediation PRs

- gitleaks (via docker cp, dockerignore-agnostic) and hadolint scan every push/PR
- new ruff lint stage (ruff.toml pins known-first-party for host/container
  consistency; B905 in env_config.py's zip() left un-fixed — app-logic change,
  see feedback-no-app-logic-changes)
- pytest --cov-fail-under=75 gate on the test stage
- scheduled Trivy critical failures now attempt an apk upgrade rebuild and open a PR
  if it clears the finding, instead of just failing red
- ruff --fix/--format applied to existing code to start the gate clean
This commit is contained in:
Djeex
2026-08-26 14:49:38 +02:00
parent d6cf5bb41f
commit 30c9b83c17
10 changed files with 316 additions and 132 deletions
+60 -1
View File
@@ -18,6 +18,21 @@ jobs:
fetch-depth: 0 fetch-depth: 0
persist-credentials: false persist-credentials: false
- name: Scan for secrets
run: |
# docker cp, not a build COPY: a repo's own .dockerignore (e.g. one that
# excludes .git for prod builds) would otherwise silently give an empty,
# falsely-clean scan.
CID=$(docker create zricethezav/gitleaks:v8.30.1 detect --source=/repo --no-banner -v)
docker cp . "$CID:/repo"
docker start -a "$CID"
STATUS=$?
docker rm "$CID" > /dev/null
exit $STATUS
- name: Lint Dockerfile with hadolint
run: docker run --rm -i hadolint/hadolint:v2.15.1-alpine hadolint --failure-threshold error - < Dockerfile
- name: Build Docker image - name: Build Docker image
run: | run: |
docker build -t nvidia-stock-bot:ci . 2>&1 | tee build.log docker build -t nvidia-stock-bot:ci . 2>&1 | tee build.log
@@ -46,7 +61,10 @@ jobs:
- name: Run unit tests - name: Run unit tests
run: | run: |
docker build --target test -t nvidia-stock-bot:test . docker build --target test -t nvidia-stock-bot:test .
docker run --rm nvidia-stock-bot:test pytest -v docker run --rm nvidia-stock-bot:test pytest -v --cov=. --cov-report=term-missing --cov-fail-under=75
- name: Lint with ruff
run: docker build --target lint -t nvidia-stock-bot:lint .
- name: Check deprecation warnings - name: Check deprecation warnings
run: | run: |
@@ -60,12 +78,53 @@ jobs:
fi fi
- name: Scan with Trivy (critical - blocking) - name: Scan with Trivy (critical - blocking)
id: trivy_critical
continue-on-error: true
run: | run: |
docker run --rm \ docker run --rm \
-e DOCKER_HOST=tcp://dockerhost:2375 \ -e DOCKER_HOST=tcp://dockerhost:2375 \
--add-host=dockerhost:host-gateway \ --add-host=dockerhost:host-gateway \
aquasec/trivy:0.74.0 image --exit-code 1 --severity CRITICAL nvidia-stock-bot:ci aquasec/trivy:0.74.0 image --exit-code 1 --severity CRITICAL nvidia-stock-bot:ci
- name: Handle CRITICAL findings
if: steps.trivy_critical.outcome == 'failure'
run: |
if [ "${{ github.event_name }}" != "schedule" ]; then
echo "::error::CRITICAL vulnerabilities found, failing the build."
exit 1
fi
echo "Scheduled scan found CRITICAL vulnerabilities — attempting an automatic apk upgrade + rescan."
sed -i '/^FROM .* AS base$/a RUN apk upgrade --no-cache' Dockerfile
docker build -t nvidia-stock-bot:remediated .
if docker run --rm \
-e DOCKER_HOST=tcp://dockerhost:2375 \
--add-host=dockerhost:host-gateway \
aquasec/trivy:0.74.0 image --exit-code 1 --severity CRITICAL nvidia-stock-bot:remediated; then
echo "apk upgrade clears the CRITICAL finding(s) — opening a PR for review."
BRANCH="auto/cve-fix-$(date +%Y%m%d)-$(echo "${{ github.sha }}" | cut -c1-7)"
git config user.name "nvidia-stock-bot-ci"
git config user.email "[email protected]"
git checkout -b "$BRANCH"
git add Dockerfile
git commit -m "Auto-remediate CRITICAL CVE via apk upgrade"
git config --unset-all http.https://git.djeex.fr/.extraheader || true
git push "https://Djeex:${{ secrets.CI_PUSH_TOKEN }}@git.djeex.fr/Djeex/nvidia-stock-bot.git" "HEAD:$BRANCH"
PR_JSON=$(curl -s -X POST \
-H "Authorization: token ${{ secrets.CI_PUSH_TOKEN }}" \
-H "Content-Type: application/json" \
-d "$(jq -n --arg head "$BRANCH" '{title: "🔒 Auto: remediate CRITICAL CVE via apk upgrade", head: $head, base: "main", body: "Opened automatically by the scheduled CVE scan. An `apk upgrade --no-cache` cleared the CRITICAL Trivy finding(s) in a rebuild — review the diff and merge to publish the fix."}')" \
"https://git.djeex.fr/api/v1/repos/Djeex/nvidia-stock-bot/pulls")
echo "PR API response: $(echo "$PR_JSON" | jq -r '.html_url // .message // "unknown"')"
else
echo "::error::apk upgrade does not clear the CRITICAL finding(s) — no automatic fix available, needs manual review."
exit 1
fi
- name: Scan with Trivy (high - informative) - name: Scan with Trivy (high - informative)
run: | run: |
docker run --rm \ docker run --rm \
+8 -1
View File
@@ -11,13 +11,20 @@ RUN pip install --no-cache-dir -r requirements.txt
FROM base AS test FROM base AS test
RUN pip install --no-cache-dir pytest==9.1.1 RUN pip install --no-cache-dir pytest==9.1.1 pytest-cov==7.1.0
COPY pytest.ini /app/pytest.ini COPY pytest.ini /app/pytest.ini
COPY /tests/ /app/tests/ COPY /tests/ /app/tests/
CMD ["pytest", "-v"] CMD ["pytest", "-v"]
FROM base AS lint
RUN pip install --no-cache-dir ruff==0.16.4
COPY ruff.toml /app/ruff.toml
COPY /tests/ /app/tests/
RUN ruff check . && ruff format --check .
FROM base FROM base
RUN addgroup -g 911 nvbot && adduser -D -u 911 -G nvbot nvbot RUN addgroup -g 911 nvbot && adduser -D -u 911 -G nvbot nvbot
+42 -31
View File
@@ -1,11 +1,13 @@
import json
import logging
import os import os
import re import re
import logging
import json
import sys import sys
# Read version from VERSION file # Read version from VERSION file
with open(os.path.join(os.path.dirname(os.path.dirname(__file__)), "VERSION"), "r", encoding="utf-8") as f: with open(
os.path.join(os.path.dirname(os.path.dirname(__file__)), "VERSION"), encoding="utf-8"
) as f:
VERSION = f.read().strip() VERSION = f.read().strip()
# Logger setup # Logger setup
@@ -23,13 +25,13 @@ logging.info("=" * 60)
# Env variables # Env variables
try: try:
DISCORD_WEBHOOK_URL = os.environ['DISCORD_WEBHOOK_URL'] DISCORD_WEBHOOK_URL = os.environ["DISCORD_WEBHOOK_URL"]
DISCORD_SERVER_NAME = os.environ.get('DISCORD_SERVER_NAME', 'Shared for free') DISCORD_SERVER_NAME = os.environ.get("DISCORD_SERVER_NAME", "Shared for free")
DISCORD_ROLES = os.environ.get('DISCORD_ROLES') DISCORD_ROLES = os.environ.get("DISCORD_ROLES")
COUNTRY = os.environ.get('COUNTRY') or 'US' COUNTRY = os.environ.get("COUNTRY") or "US"
REFRESH_TIME = int(os.environ.get('REFRESH_TIME') or 30) REFRESH_TIME = int(os.environ.get("REFRESH_TIME") or 30)
TEST_MODE = os.environ.get('TEST_MODE', 'False').lower() == 'true' TEST_MODE = os.environ.get("TEST_MODE", "False").lower() == "true"
PRODUCT_NAMES = os.environ['PRODUCT_NAMES'] PRODUCT_NAMES = os.environ["PRODUCT_NAMES"]
# Errors and warning # Errors and warning
except KeyError as e: except KeyError as e:
@@ -49,32 +51,32 @@ if not DISCORD_WEBHOOK_URL:
logging.error("❌ DISCORD_WEBHOOK_URL is required but not defined.") logging.error("❌ DISCORD_WEBHOOK_URL is required but not defined.")
sys.exit(1) sys.exit(1)
PRODUCT_NAMES = [name.strip() for name in PRODUCT_NAMES.split(',')] PRODUCT_NAMES = [name.strip() for name in PRODUCT_NAMES.split(",")]
# Role mapping # Role mapping
DISCORD_ROLE_MAP = {} DISCORD_ROLE_MAP = {}
if not DISCORD_ROLES or not DISCORD_ROLES.strip(): if not DISCORD_ROLES or not DISCORD_ROLES.strip():
logging.warning("⚠️ DISCORD_ROLES not defined or empty. Defaulting all roles to @everyone.") logging.warning("⚠️ DISCORD_ROLES not defined or empty. Defaulting all roles to @everyone.")
for name in PRODUCT_NAMES: for name in PRODUCT_NAMES:
DISCORD_ROLE_MAP[name] = '@everyone' DISCORD_ROLE_MAP[name] = "@everyone"
else: else:
roles = [r.strip() if r.strip() else '@everyone' for r in DISCORD_ROLES.split(',')] roles = [r.strip() if r.strip() else "@everyone" for r in DISCORD_ROLES.split(",")]
if len(roles) != len(PRODUCT_NAMES): if len(roles) != len(PRODUCT_NAMES):
logging.error("❌ The number of DISCORD_ROLES must match PRODUCT_NAMES.") logging.error("❌ The number of DISCORD_ROLES must match PRODUCT_NAMES.")
sys.exit(1) sys.exit(1)
for name, role in zip(PRODUCT_NAMES, roles): for name, role in zip(PRODUCT_NAMES, roles):
if role != '@everyone' and not re.match(r'^<@&\d{17,20}>$', role): if role != "@everyone" and not re.match(r"^<@&\d{17,20}>$", role):
logging.error(f"❌ Invalid DISCORD_ROLE format for {name}: {role}") logging.error(f"❌ Invalid DISCORD_ROLE format for {name}: {role}")
sys.exit(1) sys.exit(1)
DISCORD_ROLE_MAP[name] = role DISCORD_ROLE_MAP[name] = role
# Masked webhook in terminal # Masked webhook in terminal
match = re.search(r'/(\d+)/(.*)', DISCORD_WEBHOOK_URL) match = re.search(r"/(\d+)/(.*)", DISCORD_WEBHOOK_URL)
if match: if match:
webhook_id = match.group(1) webhook_id = match.group(1)
webhook_token = match.group(2) webhook_token = match.group(2)
masked_webhook_id = webhook_id[:len(webhook_id) - 10] + '*' * 10 masked_webhook_id = webhook_id[: len(webhook_id) - 10] + "*" * 10
masked_webhook_token = webhook_token[:len(webhook_token) - 120] + '*' * 10 masked_webhook_token = webhook_token[: len(webhook_token) - 120] + "*" * 10
wh_masked_url = f"https://discord.com/api/webhooks/{masked_webhook_id}/{masked_webhook_token}" wh_masked_url = f"https://discord.com/api/webhooks/{masked_webhook_id}/{masked_webhook_token}"
else: else:
wh_masked_url = "[Invalid webhook URL]" wh_masked_url = "[Invalid webhook URL]"
@@ -90,29 +92,33 @@ HEADERS = {
"Connection": "keep-alive", "Connection": "keep-alive",
"Sec-Fetch-Dest": "empty", "Sec-Fetch-Dest": "empty",
"Sec-Fetch-Mode": "cors", "Sec-Fetch-Mode": "cors",
"Sec-Ch-Ua": "\"Google Chrome\";v=\"131\", \"Chromium\";v=\"131\", \"Not.A/Brand\";v=\"24\"", "Sec-Ch-Ua": '"Google Chrome";v="131", "Chromium";v="131", "Not.A/Brand";v="24"',
"Sec-Ch-Ua-Platform": "\"macOS\"", "Sec-Ch-Ua-Platform": '"macOS"',
"Cache-Control": "no-cache, no-store, must-revalidate", "Cache-Control": "no-cache, no-store, must-revalidate",
"Pragma": "no-cache", "Pragma": "no-cache",
"Expires": "0" "Expires": "0",
} }
# Load country setting and localization config # Load country setting and localization config
country_code = os.environ.get("COUNTRY", "US").upper() country_code = os.environ.get("COUNTRY", "US").upper()
try: try:
with open("localization.json", "r", encoding="utf-8") as f: with open("localization.json", encoding="utf-8") as f:
localization_config = json.load(f) localization_config = json.load(f)
except FileNotFoundError: except FileNotFoundError:
logging.error("❌ localization.json file not found.") logging.error("❌ localization.json file not found.")
sys.exit(1) sys.exit(1)
# Find country entry # Find country entry
country_entry = next((entry for entry in localization_config if entry["country_code"].upper() == country_code), None) country_entry = next(
(entry for entry in localization_config if entry["country_code"].upper() == country_code), None
)
if not country_entry: if not country_entry:
logging.warning(f"⚠️ Country '{country_code}' not found in localization.json. Defaulting to US.") logging.warning(f"⚠️ Country '{country_code}' not found in localization.json. Defaulting to US.")
country_entry = next((entry for entry in localization_config if entry["country_code"].upper() == "US"), None) country_entry = next(
(entry for entry in localization_config if entry["country_code"].upper() == "US"), None
)
if not country_entry: if not country_entry:
logging.error("❌ US fallback not found in localization.json.") logging.error("❌ US fallback not found in localization.json.")
sys.exit(1) sys.exit(1)
@@ -124,7 +130,7 @@ currency = country_entry["currency"]
# Load language file # Load language file
try: try:
with open("languages.json", "r", encoding="utf-8") as f: with open("languages.json", encoding="utf-8") as f:
loc_lang = json.load(f) loc_lang = json.load(f)
except FileNotFoundError: except FileNotFoundError:
logging.error("❌ languages.json file not found.") logging.error("❌ languages.json file not found.")
@@ -141,9 +147,15 @@ if not loc:
# Ensure all required keys are present # Ensure all required keys are present
required_keys = [ required_keys = [
"in_stock_title", "out_of_stock_title", "sku_change_title", "in_stock_title",
"buy_now", "price", "time", "footer", "out_of_stock_title",
"sku_description", "imminent_drop" "sku_change_title",
"buy_now",
"price",
"time",
"footer",
"sku_description",
"imminent_drop",
] ]
missing_keys = [key for key in required_keys if key not in loc] missing_keys = [key for key in required_keys if key not in loc]
fallback = loc_lang.get("en", {}) fallback = loc_lang.get("en", {})
@@ -159,17 +171,16 @@ for key in missing_keys:
locale = full_lang_code.lower() locale = full_lang_code.lower()
API_URL_SKU = os.getenv( API_URL_SKU = os.getenv(
"API_URL_SKU", "API_URL_SKU",
f"https://api.nvidia.partners/edge/product/search?page=1&limit=100&locale={locale}&Manufacturer=Nvidia" f"https://api.nvidia.partners/edge/product/search?page=1&limit=100&locale={locale}&Manufacturer=Nvidia",
) )
API_URL_STOCK = os.getenv( API_URL_STOCK = os.getenv(
"API_URL_STOCK", "API_URL_STOCK", f"https://api.store.nvidia.com/partner/v1/feinventory?locale={locale}&skus="
f"https://api.store.nvidia.com/partner/v1/feinventory?locale={locale}&skus="
) )
PRODUCT_URL = os.getenv( PRODUCT_URL = os.getenv(
"PRODUCT_URL", "PRODUCT_URL",
f"https://marketplace.nvidia.com/{locale}/consumer/graphics-cards/?locale={locale}&page=1&limit=12&manufacturer=NVIDIA" f"https://marketplace.nvidia.com/{locale}/consumer/graphics-cards/?locale={locale}&page=1&limit=12&manufacturer=NVIDIA",
) )
# Public constants # Public constants
+21 -14
View File
@@ -1,21 +1,28 @@
import requests
import logging import logging
import time import time
from env_config import HEADERS, PRODUCT_NAMES, API_URL_SKU, API_URL_STOCK, PRODUCT_URL
from notifier import send_discord_notification, send_out_of_stock_notification, send_sku_change_notification import requests
from requests.adapters import HTTPAdapter, Retry from requests.adapters import HTTPAdapter, Retry
from env_config import API_URL_SKU, API_URL_STOCK, HEADERS, PRODUCT_NAMES, PRODUCT_URL
from notifier import (
send_discord_notification,
send_out_of_stock_notification,
send_sku_change_notification,
)
# HTTP session # HTTP session
session = requests.Session() session = requests.Session()
retries = Retry(total=5, backoff_factor=1, status_forcelist=[500, 502, 503, 504]) retries = Retry(total=5, backoff_factor=1, status_forcelist=[500, 502, 503, 504])
session.mount('https://', HTTPAdapter(max_retries=retries)) session.mount("https://", HTTPAdapter(max_retries=retries))
session.headers.update(HEADERS) session.headers.update(HEADERS)
# Keeping memory of last run # Keeping memory of last run
last_sku_dict = {} last_sku_dict = {}
global_stock_status_dict = {} global_stock_status_dict = {}
first_run_dict = {name: True for name in PRODUCT_NAMES} first_run_dict = {name: True for name in PRODUCT_NAMES}
# Stock check function # Stock check function
def check_rtx_50_founders(): def check_rtx_50_founders():
global last_sku_dict, global_stock_status_dict, first_run_dict global last_sku_dict, global_stock_status_dict, first_run_dict
@@ -24,7 +31,7 @@ def check_rtx_50_founders():
try: try:
cache_buster = int(time.time() * 1000) cache_buster = int(time.time() * 1000)
sku_url = f"{API_URL_SKU}&_t={cache_buster}" sku_url = f"{API_URL_SKU}&_t={cache_buster}"
response = session.get(sku_url, timeout=10) response = session.get(sku_url, timeout=10)
logging.info(f"SKU API response: {response.status_code}") logging.info(f"SKU API response: {response.status_code}")
response.raise_for_status() response.raise_for_status()
@@ -32,9 +39,9 @@ def check_rtx_50_founders():
except requests.exceptions.RequestException as e: except requests.exceptions.RequestException as e:
logging.error(f"SKU API error: {e}") logging.error(f"SKU API error: {e}")
return return
# Checking productSKU and productUPC for all GPU set in PRODUCT_NAME # Checking productSKU and productUPC for all GPU set in PRODUCT_NAME
all_products = data['searchedProducts']['productDetails'] all_products = data["searchedProducts"]["productDetails"]
for product_name in PRODUCT_NAMES: for product_name in PRODUCT_NAMES:
product_details = None product_details = None
@@ -47,8 +54,8 @@ def check_rtx_50_founders():
logging.warning(f"⚠️ No product with GPU '{product_name}' found.") logging.warning(f"⚠️ No product with GPU '{product_name}' found.")
continue continue
product_sku = product_details['productSKU'] product_sku = product_details["productSKU"]
product_upc = product_details.get('productUPC', "") product_upc = product_details.get("productUPC", "")
if not isinstance(product_upc, list): if not isinstance(product_upc, list):
product_upc = [product_upc] product_upc = [product_upc]
@@ -60,7 +67,7 @@ def check_rtx_50_founders():
last_sku_dict[product_name] = product_sku last_sku_dict[product_name] = product_sku
first_run_dict[product_name] = False first_run_dict[product_name] = False
# Check product availability in API_URL_STOCK for each SKU # Check product availability in API_URL_STOCK for each SKU
cache_buster = int(time.time() * 1000) cache_buster = int(time.time() * 1000)
api_stock_url = f"{API_URL_STOCK}{product_sku}&_t={cache_buster}" api_stock_url = f"{API_URL_STOCK}{product_sku}&_t={cache_buster}"
@@ -80,8 +87,8 @@ def check_rtx_50_founders():
products_price = "Price not available" products_price = "Price not available"
if isinstance(products, list) and len(products) > 0: if isinstance(products, list) and len(products) > 0:
for p in products: for p in products:
price = p.get("price", 'Price not available') price = p.get("price", "Price not available")
if price != 'Price not available': if price != "Price not available":
products_price = price products_price = price
break break
else: else:
@@ -93,7 +100,7 @@ def check_rtx_50_founders():
is_active = p.get("is_active") == "true" is_active = p.get("is_active") == "true"
if is_active and any(upc.upper() in gpu_name for upc in product_upc): if is_active and any(upc.upper() in gpu_name for upc in product_upc):
found_in_stock.add(gpu_name) found_in_stock.add(gpu_name)
# Comparing previous state and notify # Comparing previous state and notify
for upc in product_upc: for upc in product_upc:
upc_upper = upc.upper() upc_upper = upc.upper()
+6 -4
View File
@@ -1,17 +1,20 @@
import time
import logging import logging
import signal import signal
import sys import sys
from gpu_checker import check_rtx_50_founders import time
from env_config import REFRESH_TIME from env_config import REFRESH_TIME
from gpu_checker import check_rtx_50_founders
# Signal handler function # Signal handler function
def handle_exit(signum, frame): def handle_exit(signum, frame):
logging.info(f"🛑 Received signal {signum}. Exiting gracefully...") logging.info(f"🛑 Received signal {signum}. Exiting gracefully...")
sys.exit(0) sys.exit(0)
# Register signal handlers # Register signal handlers
signal.signal(signal.SIGINT, handle_exit) # Ctrl+C signal.signal(signal.SIGINT, handle_exit) # Ctrl+C
signal.signal(signal.SIGTERM, handle_exit) # docker stop / kill -15 signal.signal(signal.SIGTERM, handle_exit) # docker stop / kill -15
if __name__ == "__main__": if __name__ == "__main__":
@@ -24,4 +27,3 @@ if __name__ == "__main__":
except KeyboardInterrupt: except KeyboardInterrupt:
logging.info("🛑 Script interrupted by user (KeyboardInterrupt). Exiting gracefully.") logging.info("🛑 Script interrupted by user (KeyboardInterrupt). Exiting gracefully.")
sys.exit(0) sys.exit(0)
+43 -19
View File
@@ -1,15 +1,29 @@
import time
import logging import logging
import time
import requests import requests
from env_config import ( from env_config import (
DISCORD_WEBHOOK_URL, DISCORD_SERVER_NAME, DISCORD_ROLE_MAP, TEST_MODE, currency, DISCORD_ROLE_MAP,
in_stock_title, out_of_stock_title, sku_change_title, DISCORD_SERVER_NAME,
buy_now, price_label, time_label, footer, sku_description, imminent_drop DISCORD_WEBHOOK_URL,
TEST_MODE,
buy_now,
currency,
footer,
imminent_drop,
in_stock_title,
out_of_stock_title,
price_label,
sku_change_title,
sku_description,
time_label,
) )
AVATAR = "https://git.djeex.fr/Djeex/nvidia-stock-bot/raw/branch/main/assets/img/ds_wh_pp.jpg" AVATAR = "https://git.djeex.fr/Djeex/nvidia-stock-bot/raw/branch/main/assets/img/ds_wh_pp.jpg"
THUMBNAIL = "https://git.djeex.fr/Djeex/nvidia-stock-bot/raw/branch/main/assets/img/RTX5000.jpg" THUMBNAIL = "https://git.djeex.fr/Djeex/nvidia-stock-bot/raw/branch/main/assets/img/RTX5000.jpg"
# In stock # In stock
def send_discord_notification(gpu_name, product_link, products_price): def send_discord_notification(gpu_name, product_link, products_price):
timestamp = int(time.time()) timestamp = int(time.time())
@@ -24,17 +38,20 @@ def send_discord_notification(gpu_name, product_link, products_price):
"author": {"name": "Nvidia Founder Editions"}, "author": {"name": "Nvidia Founder Editions"},
"fields": [ "fields": [
{"name": price_label, "value": f"`{currency}{products_price}`", "inline": True}, {"name": price_label, "value": f"`{currency}{products_price}`", "inline": True},
{"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True} {"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True},
], ],
"description": buy_now.format(product_link=product_link), "description": buy_now.format(product_link=product_link),
"footer": {"text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME), "icon_url": AVATAR} "footer": {
"text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME),
"icon_url": AVATAR,
},
} }
payload = { payload = {
"content": DISCORD_ROLE_MAP.get(gpu_name, "@everyone"), "content": DISCORD_ROLE_MAP.get(gpu_name, "@everyone"),
"username": "NviBot", "username": "NviBot",
"avatar_url": AVATAR, "avatar_url": AVATAR,
"embeds": [embed] "embeds": [embed],
} }
try: try:
@@ -46,6 +63,7 @@ def send_discord_notification(gpu_name, product_link, products_price):
except Exception as e: except Exception as e:
logging.error(f"🚨 Error sending webhook: {e}") logging.error(f"🚨 Error sending webhook: {e}")
# Out of stock # Out of stock
def send_out_of_stock_notification(gpu_name, product_link, products_price): def send_out_of_stock_notification(gpu_name, product_link, products_price):
timestamp = int(time.time()) timestamp = int(time.time())
@@ -59,15 +77,16 @@ def send_out_of_stock_notification(gpu_name, product_link, products_price):
"thumbnail": {"url": THUMBNAIL}, "thumbnail": {"url": THUMBNAIL},
"url": product_link, "url": product_link,
"author": {"name": "Nvidia Founder Editions"}, "author": {"name": "Nvidia Founder Editions"},
"footer": {"text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME), "icon_url": AVATAR}, "footer": {
"fields": [{"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True}] "text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME),
"icon_url": AVATAR,
},
"fields": [
{"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True}
],
} }
payload = { payload = {"username": "NviBot", "avatar_url": AVATAR, "embeds": [embed]}
"username": "NviBot",
"avatar_url": AVATAR,
"embeds": [embed]
}
try: try:
response = requests.post(DISCORD_WEBHOOK_URL, json=payload) response = requests.post(DISCORD_WEBHOOK_URL, json=payload)
@@ -78,6 +97,7 @@ def send_out_of_stock_notification(gpu_name, product_link, products_price):
except Exception as e: except Exception as e:
logging.error(f"🚨 Error sending webhook: {e}") logging.error(f"🚨 Error sending webhook: {e}")
# SKU change # SKU change
def send_sku_change_notification(gpu_name, old_sku, new_sku, product_link): def send_sku_change_notification(gpu_name, old_sku, new_sku, product_link):
timestamp = int(time.time()) timestamp = int(time.time())
@@ -90,15 +110,20 @@ def send_sku_change_notification(gpu_name, old_sku, new_sku, product_link):
"url": product_link, "url": product_link,
"description": sku_description.format(old_sku=old_sku, new_sku=new_sku), "description": sku_description.format(old_sku=old_sku, new_sku=new_sku),
"color": 16776960, "color": 16776960,
"footer": {"text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME), "icon_url": AVATAR}, "footer": {
"fields": [{"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True}] "text": footer.format(DISCORD_SERVER_NAME=DISCORD_SERVER_NAME),
"icon_url": AVATAR,
},
"fields": [
{"name": time_label, "value": f"<t:{timestamp}:d> <t:{timestamp}:T>", "inline": True}
],
} }
payload = { payload = {
"content": imminent_drop.format(DISCORD_ROLE=DISCORD_ROLE_MAP.get(gpu_name, '@everyone')), "content": imminent_drop.format(DISCORD_ROLE=DISCORD_ROLE_MAP.get(gpu_name, "@everyone")),
"username": "NviBot", "username": "NviBot",
"avatar_url": AVATAR, "avatar_url": AVATAR,
"embeds": [embed] "embeds": [embed],
} }
try: try:
@@ -109,4 +134,3 @@ def send_sku_change_notification(gpu_name, old_sku, new_sku, product_link):
logging.error(f"❌ Webhook error: {response.status_code} - {response.text}") logging.error(f"❌ Webhook error: {response.status_code} - {response.text}")
except Exception as e: except Exception as e:
logging.error(f"🚨 Error sending webhook: {e}") logging.error(f"🚨 Error sending webhook: {e}")
+13
View File
@@ -0,0 +1,13 @@
line-length = 100
[lint]
select = ["E", "F", "I", "UP", "B"]
# E501: handled by the formatter. B905: zip() without strict= in env_config.py —
# app-logic change, left for the user to decide (see feedback-no-app-logic-changes).
ignore = ["E501", "B905"]
[lint.isort]
# Pinned explicitly: auto-detection of first-party modules differs between the
# host (app/ subdir + .git present) and the Docker lint stage (flattened to /app,
# no .git) — without this, import-sort results silently diverge between the two.
known-first-party = ["env_config", "gpu_checker", "notifier", "main"]
+55 -34
View File
@@ -38,62 +38,83 @@ def test_missing_product_names_exits(monkeypatch):
def test_default_role_map_is_everyone(monkeypatch): def test_default_role_map_is_everyone(monkeypatch):
cfg = _reload_env_config(monkeypatch, { cfg = _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090, RTX 5080", {
}) "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
"PRODUCT_NAMES": "RTX 5090, RTX 5080",
},
)
assert cfg.DISCORD_ROLE_MAP == {"RTX 5090": "@everyone", "RTX 5080": "@everyone"} assert cfg.DISCORD_ROLE_MAP == {"RTX 5090": "@everyone", "RTX 5080": "@everyone"}
def test_role_count_mismatch_exits(monkeypatch): def test_role_count_mismatch_exits(monkeypatch):
with pytest.raises(SystemExit): with pytest.raises(SystemExit):
_reload_env_config(monkeypatch, { _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090, RTX 5080", {
"DISCORD_ROLES": "<@&123456789012345678>", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090, RTX 5080",
"DISCORD_ROLES": "<@&123456789012345678>",
},
)
def test_invalid_role_format_exits(monkeypatch): def test_invalid_role_format_exits(monkeypatch):
with pytest.raises(SystemExit): with pytest.raises(SystemExit):
_reload_env_config(monkeypatch, { _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090", {
"DISCORD_ROLES": "not-a-role", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090",
"DISCORD_ROLES": "not-a-role",
},
)
def test_valid_role_format_accepted(monkeypatch): def test_valid_role_format_accepted(monkeypatch):
cfg = _reload_env_config(monkeypatch, { cfg = _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090", {
"DISCORD_ROLES": "<@&123456789012345678>", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090",
"DISCORD_ROLES": "<@&123456789012345678>",
},
)
assert cfg.DISCORD_ROLE_MAP["RTX 5090"] == "<@&123456789012345678>" assert cfg.DISCORD_ROLE_MAP["RTX 5090"] == "<@&123456789012345678>"
def test_unknown_country_falls_back_to_us(monkeypatch): def test_unknown_country_falls_back_to_us(monkeypatch):
cfg = _reload_env_config(monkeypatch, { cfg = _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090", {
"COUNTRY": "ZZ", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090",
"COUNTRY": "ZZ",
},
)
assert cfg.currency == "$" assert cfg.currency == "$"
def test_known_country_currency(monkeypatch): def test_known_country_currency(monkeypatch):
cfg = _reload_env_config(monkeypatch, { cfg = _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090", {
"COUNTRY": "GB", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090",
"COUNTRY": "GB",
},
)
assert cfg.currency == "£" assert cfg.currency == "£"
def test_refresh_time_invalid_exits(monkeypatch): def test_refresh_time_invalid_exits(monkeypatch):
with pytest.raises(SystemExit): with pytest.raises(SystemExit):
_reload_env_config(monkeypatch, { _reload_env_config(
"DISCORD_WEBHOOK_URL": VALID_WEBHOOK, monkeypatch,
"PRODUCT_NAMES": "RTX 5090", {
"REFRESH_TIME": "not-a-number", "DISCORD_WEBHOOK_URL": VALID_WEBHOOK,
}) "PRODUCT_NAMES": "RTX 5090",
"REFRESH_TIME": "not-a-number",
},
)
+32 -16
View File
@@ -6,9 +6,7 @@ PRODUCT_NAME = "RTX 5090 Founders Edition"
SKU_PAYLOAD = { SKU_PAYLOAD = {
"searchedProducts": { "searchedProducts": {
"productDetails": [ "productDetails": [{"gpu": PRODUCT_NAME, "productSKU": "SKU-1", "productUPC": "ABC123"}]
{"gpu": PRODUCT_NAME, "productSKU": "SKU-1", "productUPC": "ABC123"}
]
} }
} }
@@ -52,9 +50,15 @@ def _queue_responses(monkeypatch, checker, *payloads):
def test_transition_to_in_stock_sends_notification(monkeypatch): def test_transition_to_in_stock_sends_notification(monkeypatch):
checker = _import_gpu_checker(monkeypatch) checker = _import_gpu_checker(monkeypatch)
calls = [] calls = []
monkeypatch.setattr(checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))) monkeypatch.setattr(
monkeypatch.setattr(checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))) checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))
monkeypatch.setattr(checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))) )
monkeypatch.setattr(
checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))
)
monkeypatch.setattr(
checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))
)
_queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True)) _queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True))
checker.check_rtx_50_founders() checker.check_rtx_50_founders()
@@ -67,9 +71,15 @@ def test_transition_to_in_stock_sends_notification(monkeypatch):
def test_transition_to_out_of_stock_sends_notification(monkeypatch): def test_transition_to_out_of_stock_sends_notification(monkeypatch):
checker = _import_gpu_checker(monkeypatch) checker = _import_gpu_checker(monkeypatch)
calls = [] calls = []
monkeypatch.setattr(checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))) monkeypatch.setattr(
monkeypatch.setattr(checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))) checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))
monkeypatch.setattr(checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))) )
monkeypatch.setattr(
checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))
)
monkeypatch.setattr(
checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))
)
_queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True)) _queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True))
checker.check_rtx_50_founders() checker.check_rtx_50_founders()
@@ -84,9 +94,15 @@ def test_transition_to_out_of_stock_sends_notification(monkeypatch):
def test_no_duplicate_notification_while_still_in_stock(monkeypatch): def test_no_duplicate_notification_while_still_in_stock(monkeypatch):
checker = _import_gpu_checker(monkeypatch) checker = _import_gpu_checker(monkeypatch)
calls = [] calls = []
monkeypatch.setattr(checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))) monkeypatch.setattr(
monkeypatch.setattr(checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))) checker, "send_discord_notification", lambda *a: calls.append(("in_stock", a))
monkeypatch.setattr(checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))) )
monkeypatch.setattr(
checker, "send_out_of_stock_notification", lambda *a: calls.append(("out_of_stock", a))
)
monkeypatch.setattr(
checker, "send_sku_change_notification", lambda *a: calls.append(("sku_change", a))
)
_queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True)) _queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(True))
checker.check_rtx_50_founders() checker.check_rtx_50_founders()
@@ -101,7 +117,9 @@ def test_sku_change_triggers_notification_after_first_run(monkeypatch):
sku_change_calls = [] sku_change_calls = []
monkeypatch.setattr(checker, "send_discord_notification", lambda *a: None) monkeypatch.setattr(checker, "send_discord_notification", lambda *a: None)
monkeypatch.setattr(checker, "send_out_of_stock_notification", lambda *a: None) monkeypatch.setattr(checker, "send_out_of_stock_notification", lambda *a: None)
monkeypatch.setattr(checker, "send_sku_change_notification", lambda *a: sku_change_calls.append(a)) monkeypatch.setattr(
checker, "send_sku_change_notification", lambda *a: sku_change_calls.append(a)
)
_queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(False)) _queue_responses(monkeypatch, checker, SKU_PAYLOAD, _stock_payload(False))
checker.check_rtx_50_founders() checker.check_rtx_50_founders()
@@ -109,9 +127,7 @@ def test_sku_change_triggers_notification_after_first_run(monkeypatch):
changed_payload = { changed_payload = {
"searchedProducts": { "searchedProducts": {
"productDetails": [ "productDetails": [{"gpu": PRODUCT_NAME, "productSKU": "SKU-2", "productUPC": "ABC123"}]
{"gpu": PRODUCT_NAME, "productSKU": "SKU-2", "productUPC": "ABC123"}
]
} }
} }
_queue_responses(monkeypatch, checker, changed_payload, _stock_payload(False)) _queue_responses(monkeypatch, checker, changed_payload, _stock_payload(False))
+36 -12
View File
@@ -44,7 +44,9 @@ def test_in_stock_notification_posts_expected_payload(monkeypatch):
monkeypatch.setattr(notifier.requests, "post", fake_post) monkeypatch.setattr(notifier.requests, "post", fake_post)
notifier.send_discord_notification("RTX 5090 Founders Edition", "https://example.com/buy", "1999") notifier.send_discord_notification(
"RTX 5090 Founders Edition", "https://example.com/buy", "1999"
)
assert captured["url"] == notifier.DISCORD_WEBHOOK_URL assert captured["url"] == notifier.DISCORD_WEBHOOK_URL
assert captured["json"]["content"] == "@everyone" assert captured["json"]["content"] == "@everyone"
@@ -54,7 +56,9 @@ def test_in_stock_notification_posts_expected_payload(monkeypatch):
def test_discord_notification_survives_http_error(monkeypatch): def test_discord_notification_survives_http_error(monkeypatch):
notifier = _import_notifier(monkeypatch, test_mode="False") notifier = _import_notifier(monkeypatch, test_mode="False")
monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")) monkeypatch.setattr(
notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")
)
notifier.send_discord_notification("RTX 5090 Founders Edition", "https://example.com", "1999") notifier.send_discord_notification("RTX 5090 Founders Edition", "https://example.com", "1999")
@@ -76,7 +80,9 @@ def test_out_of_stock_test_mode_skips_network_call(monkeypatch):
calls = [] calls = []
monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: calls.append((a, k))) monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: calls.append((a, k)))
notifier.send_out_of_stock_notification("RTX 5090 Founders Edition", "https://example.com", "1999") notifier.send_out_of_stock_notification(
"RTX 5090 Founders Edition", "https://example.com", "1999"
)
assert calls == [] assert calls == []
@@ -91,17 +97,23 @@ def test_out_of_stock_notification_posts_on_success(monkeypatch):
monkeypatch.setattr(notifier.requests, "post", fake_post) monkeypatch.setattr(notifier.requests, "post", fake_post)
notifier.send_out_of_stock_notification("RTX 5090 Founders Edition", "https://example.com/buy", "1999") notifier.send_out_of_stock_notification(
"RTX 5090 Founders Edition", "https://example.com/buy", "1999"
)
assert captured["json"]["embeds"][0]["url"] == "https://example.com/buy" assert captured["json"]["embeds"][0]["url"] == "https://example.com/buy"
def test_out_of_stock_notification_survives_http_error(monkeypatch): def test_out_of_stock_notification_survives_http_error(monkeypatch):
notifier = _import_notifier(monkeypatch, test_mode="False") notifier = _import_notifier(monkeypatch, test_mode="False")
monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")) monkeypatch.setattr(
notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")
)
# Should not raise even though the webhook call "fails" # Should not raise even though the webhook call "fails"
notifier.send_out_of_stock_notification("RTX 5090 Founders Edition", "https://example.com", "1999") notifier.send_out_of_stock_notification(
"RTX 5090 Founders Edition", "https://example.com", "1999"
)
def test_out_of_stock_notification_survives_connection_error(monkeypatch): def test_out_of_stock_notification_survives_connection_error(monkeypatch):
@@ -112,7 +124,9 @@ def test_out_of_stock_notification_survives_connection_error(monkeypatch):
monkeypatch.setattr(notifier.requests, "post", raise_error) monkeypatch.setattr(notifier.requests, "post", raise_error)
notifier.send_out_of_stock_notification("RTX 5090 Founders Edition", "https://example.com", "1999") notifier.send_out_of_stock_notification(
"RTX 5090 Founders Edition", "https://example.com", "1999"
)
def test_sku_change_test_mode_skips_network_call(monkeypatch): def test_sku_change_test_mode_skips_network_call(monkeypatch):
@@ -120,16 +134,22 @@ def test_sku_change_test_mode_skips_network_call(monkeypatch):
calls = [] calls = []
monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: calls.append((a, k))) monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: calls.append((a, k)))
notifier.send_sku_change_notification("RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com") notifier.send_sku_change_notification(
"RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com"
)
assert calls == [] assert calls == []
def test_sku_change_notification_survives_http_error(monkeypatch): def test_sku_change_notification_survives_http_error(monkeypatch):
notifier = _import_notifier(monkeypatch, test_mode="False") notifier = _import_notifier(monkeypatch, test_mode="False")
monkeypatch.setattr(notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")) monkeypatch.setattr(
notifier.requests, "post", lambda *a, **k: FakeResponse(status_code=500, text="boom")
)
notifier.send_sku_change_notification("RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com") notifier.send_sku_change_notification(
"RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com"
)
def test_sku_change_notification_survives_connection_error(monkeypatch): def test_sku_change_notification_survives_connection_error(monkeypatch):
@@ -140,11 +160,15 @@ def test_sku_change_notification_survives_connection_error(monkeypatch):
monkeypatch.setattr(notifier.requests, "post", raise_error) monkeypatch.setattr(notifier.requests, "post", raise_error)
notifier.send_sku_change_notification("RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com") notifier.send_sku_change_notification(
"RTX 5090 Founders Edition", "old-sku", "new-sku", "https://example.com"
)
def test_sku_change_notification_mentions_role_and_skus(monkeypatch): def test_sku_change_notification_mentions_role_and_skus(monkeypatch):
notifier = _import_notifier(monkeypatch, test_mode="False", discord_roles="<@&123456789012345678>") notifier = _import_notifier(
monkeypatch, test_mode="False", discord_roles="<@&123456789012345678>"
)
captured = {} captured = {}
def fake_post(url, json=None, **kwargs): def fake_post(url, json=None, **kwargs):