Plugins · CPO
Profiles
Ready-made, composable policy sets: set one per project or per area, with parameters and updates.
A profile is a ready-made set of policies. Guardrails (security, governance, cost) are what a security or
platform team signs off; code quality (quality) is a tech lead's choice; stack profiles (frontend,
backend, mobile, data-ml) extend both for a kind of project. Browse them in the
profile catalog.
ccpp cpo profile list # available profiles, by category
ccpp cpo profile view secrets-baseline --available
ccpp cpo profile set secrets-baseline # apply it to this project
ccpp cpo profile view # what is set, with integrityCommands
| Command | |
|---|---|
profile list [--category <id>] | Available profiles, the ones set, and their pending updates. |
profile view [<name>] | Profiles set for the project and the user: scope, parameters, integrity, policies. |
profile view <id> --available | An available profile: what it extends, requires, parameters, its policies. |
profile set <id> [--name n] [--scope glob]… [--param k=v]… [--user] [--force] | Applies a profile in place of the scope's downloaded ones. |
profile add <id> [--name n] [--scope glob]… [--param k=v]… [--user] | Adds a profile next to the ones set. |
profile create <name> [policy…] [--scope glob]… [--description d] [--user] | A local profile: a name and a scope over policies of your own. |
profile update [<name>] [--param k=v]… [--user] [--force] | Re-applies downloaded profiles at their latest version, keeping name, scope and parameters. |
profile update <local> [--policy id]… [--drop id]… [--description d] | Changes a local profile. |
profile update --check | Exit 1 when a profile is behind its source, for CI. |
profile scope <name> [glob…] [--user] | Confines a profile to project directories; no glob: the whole project. |
profile rename <name> <new-name> [--user] | Renames a profile. |
profile remove <name> [--user] [--force] / profile unset | Removes one profile / every profile of the scope. |
Every command is under ccpp cpo. --user targets ~/.ccpp/policies/ instead of the project. set, update,
remove and unset refuse to discard edited profile files unless --force is given.
Composition: extends
name: TypeScript backend
category: backend
version: 2.0.0
description: …
extends: [secrets-baseline, typescript-strict]
requires: { ccpp: ">=0.2.0" }extends names profiles of the same source. set installs them flattened, parents first: a file of the
profile replaces an inherited file of the same name, which is how a profile adapts a rule it inherits. To combine
an organisation baseline with a stack for the whole project, publish a profile extending both.
Parameters
params:
maxLines: { description: Most lines a source file may grow to, default: 400 }A policy file uses ${params.maxLines} anywhere, frontmatter or body. It is replaced at set, so hooks read
plain files. A list renders as a YAML flow sequence. Parameters are inherited through extends, and a profile
redeclaring one changes its default.
--param maxLines=600 overrides a value (JSON when it parses, else a string). profile.yml records the
overrides, and update keeps them.
Versions
requires: { ccpp: ">=0.2.0 <1" } refuses a profile, or one it extends, with an "update ccpp" message when the
running ccpp is outside the range. Policies a ccpp cannot load are refused at set the same way.