Development workflow for Security Verifiers. Use when asked to run tests, lint code, format files, set up the development environment, or perform CI checks on the codebase.
Testing, linting, formatting, and development workflow for the Security Verifiers codebase.
For a scoped review with dependencies already installed:
make review-check REVIEW_PATHS="<relevant source paths>" REVIEW_TESTS="<relevant tests>"
This uses non-fixing checks and selected tests without dependency sync. Install dependencies only when missing and needed for the task. Full setup/check below is for an intentionally broad workflow; make check and make lint can run fixing hooks over unrelated files.
# Full setup (creates venv, installs all deps)
make setup
source .venv/bin/activate
# Full run (lint + format + test); fixing hooks may modify unrelated files
make check
make test
make test-env E=network-logs
make test-env E=config-verification
make test-env E=code-vulnerability
make test-env E=phishing-detection
make test-env E=redteam-attack
make test-env E=redteam-defense
make e1 # test network-logs
make e2 # test config-verification
make e3 # test code-vulnerability
make e4 # test phishing-detection
make e5 # test redteam-attack
make e6 # test redteam-defense
make test-utils
make test-cov
uv run pytest environments/sv-env-network-logs/sv_env_network_logs_test.py::TestNetworkLogParser::test_extracts_label_and_confidence -q
make lint
make lint-fix
make format
make quick-fix
# Install and run hooks
make pre-commit
This runs:
Run the same checks as CI:
make ci
This runs:
ruff check . --exit-non-zero-on-fixpytest -q --tb=shortmake setup
Creates .venv, installs all environments and dev tools.
make venv # Create virtual environment
make install # Install all environments
make install-dev # Install dev tools (pytest, ruff, etc.)
For E2 config-verification, install pinned tool versions:
make install-linux # Installs kube-linter, opa, semgrep
make check-tools # Verify versions match ci/versions.txt
security-verifiers/
āāā environments/ # Environment packages
ā āāā sv-env-network-logs/
ā āāā sv-env-config-verification/
ā āāā ...
āāā sv_shared/ # Shared utilities (security-verifiers-utils)
āāā scripts/ # Build, eval, data scripts
āāā outputs/ # Evaluation outputs
āāā skills/ # Agent skills
Use scoped review-check for touched behavior. Use make check or the applicable CI gate when broad validation is required, understanding that fixing hooks may change files. Inspect the diff before staging; do not include unrelated formatting.
make test-env E=network-logs # test specific env
make lint # check linting
make test-utils
make test # run all tests to check for regressions
make clean # Build artifacts and caches
make clean-outputs # Eval outputs (preserves logs)
make clean-logs # Log files only
make clean-all # Everything including venv
# Install: brew install entr (macOS) or apt install entr (Ubuntu)
make watch
Automatically runs tests when Python files change.
make info # Show environment status
make list-envs # List environment names
venv issues: make clean-all && make setup
Import errors: Ensure source .venv/bin/activate
Tool version mismatch: make check-tools then make install-linux
Pre-commit fails: make lint-fix && make format