ccppccpp home
Browse the documentation

Plugins · CPO

Profiles

Ready-made, composable policy sets: set one per project or per area, with parameters and updates.

A profile is a ready-made set of policies. Guardrails (security, governance, cost) are what a security or platform team signs off; code quality (quality) is a tech lead's choice; stack profiles (frontend, backend, mobile, data-ml) extend both for a kind of project. Browse them in the profile catalog.

ccpp cpo profile list                       # available profiles, by category
ccpp cpo profile view secrets-baseline --available
ccpp cpo profile set secrets-baseline       # apply it to this project
ccpp cpo profile view                       # what is set, with integrity

Commands

Command
profile list [--category <id>]Available profiles, the ones set, and their pending updates.
profile view [<name>]Profiles set for the project and the user: scope, parameters, integrity, policies.
profile view <id> --availableAn available profile: what it extends, requires, parameters, its policies.
profile set <id> [--name n] [--scope glob]… [--param k=v]… [--user] [--force]Applies a profile in place of the scope's downloaded ones.
profile add <id> [--name n] [--scope glob]… [--param k=v]… [--user]Adds a profile next to the ones set.
profile create <name> [policy…] [--scope glob]… [--description d] [--user]A local profile: a name and a scope over policies of your own.
profile update [<name>] [--param k=v]… [--user] [--force]Re-applies downloaded profiles at their latest version, keeping name, scope and parameters.
profile update <local> [--policy id]… [--drop id]… [--description d]Changes a local profile.
profile update --checkExit 1 when a profile is behind its source, for CI.
profile scope <name> [glob…] [--user]Confines a profile to project directories; no glob: the whole project.
profile rename <name> <new-name> [--user]Renames a profile.
profile remove <name> [--user] [--force] / profile unsetRemoves one profile / every profile of the scope.

Every command is under ccpp cpo. --user targets ~/.ccpp/policies/ instead of the project. set, update, remove and unset refuse to discard edited profile files unless --force is given.

Composition: extends

profile.yml
name: TypeScript backend
category: backend
version: 2.0.0
description: …
extends: [secrets-baseline, typescript-strict]
requires: { ccpp: ">=0.2.0" }

extends names profiles of the same source. set installs them flattened, parents first: a file of the profile replaces an inherited file of the same name, which is how a profile adapts a rule it inherits. To combine an organisation baseline with a stack for the whole project, publish a profile extending both.

Parameters

params:
  maxLines: { description: Most lines a source file may grow to, default: 400 }

A policy file uses ${params.maxLines} anywhere, frontmatter or body. It is replaced at set, so hooks read plain files. A list renders as a YAML flow sequence. Parameters are inherited through extends, and a profile redeclaring one changes its default.

--param maxLines=600 overrides a value (JSON when it parses, else a string). profile.yml records the overrides, and update keeps them.

Versions

requires: { ccpp: ">=0.2.0 <1" } refuses a profile, or one it extends, with an "update ccpp" message when the running ccpp is outside the range. Policies a ccpp cannot load are refused at set the same way.

Edit this page on GitHub