affaan-m/ECC

django-verification

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

82CollectingRuns scriptsNetwork access
See how to use itView GitHub source
npx skills add https://github.com/affaan-m/ECC --skill "docs/ja-JP/skills/django-verification"
Automated source guide

Source checked Jul 28, 2026·Refresh due Oct 26, 2026

Reorganized from the pinned upstream SKILL.md

Turn django-verification's source instructions into a guide you can follow

According to the pinned SKILL.md from affaan-m/ECC: PR前、大きな変更後、デプロイ前に実行して、Djangoアプリケーションの品質とセキュリティを確保します。

npx skills add https://github.com/affaan-m/ECC --skill "docs/ja-JP/skills/django-verification"
Check the pinned source

Best fit

  • Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

Bring this context

  • A concrete task that matches the documented purpose of django-verification.
  • The files, examples, or context the task depends on.
  • Your constraints, target environment, and definition of done.

Expected outputs

  • uses: actions/checkout@v3
  • name: Set up Python
  • name: Cache pip

Key source sections

Read django-verification through these 5 source sections

Sections are extracted automatically from the pinned SKILL.md and link back to the source.

02

フェーズ1: 環境チェック

Review the “フェーズ1: 環境チェック” section in the pinned source before continuing.

SKILL.md · フェーズ1: 環境チェック
Review and apply the “フェーズ1: 環境チェック” source section.
05

環境変数を確認

python -c "import os; import environ; print('DJANGOSECRETKEY set' if os.environ.get('DJANGOSECRETKEY') else 'MISSING: DJANGOSECRETKEY')" bash

SKILL.md · 環境変数を確認
python -c "import os; import environ; print('DJANGOSECRETKEY set' if os.environ.get('DJANGOSECRETKEY') else 'MISSING: DJANGOSECRETKEY')" bash

SkillSignal prompt templates

Provide the task, context, and acceptance criteria

These prompts were written by SkillSignal from the source structure; they are not upstream text.

Task-start prompt

Confirm source fit, inputs, and outputs before acting.

Use django-verification to help me with: [specific task]. Context: [files, data, or background]. Constraints: [environment, scope, and prohibited actions]. Before acting, check the pinned SKILL.md and explain which sections apply, what inputs are still missing, and what you will deliver.

Source-guided execution

Make the Agent explicitly follow the key extracted sections.

Apply the pinned django-verification source to [task]. Pay particular attention to these source sections: “.github/workflows/django-verification.yml”, “フェーズ1: 環境チェック”, “Pythonバージョンを確認”, “仮想環境をチェック”, “環境変数を確認”. Preserve the important decision at each step. Mark facts not covered by the source as “needs confirmation” instead of inventing them. Then verify the result against my acceptance criteria: [criteria].

Result-review prompt

Check omissions, permissions, and source drift before delivery.

Review the current django-verification result: (1) does it satisfy the original task; (2) were any applicable steps or limits in the pinned SKILL.md missed; (3) did it perform any unauthorized file, command, network, or data action; and (4) which conclusions remain unverified? List issues first, then fix only what the source or user authorization supports.

Output checklist

Verify each item before delivery

The task matches the purpose documented in the SKILL.md.

The source section “.github/workflows/django-verification.yml” has been checked.

The source section “フェーズ1: 環境チェック” has been checked.

The source section “Pythonバージョンを確認” has been checked.

The source section “仮想環境をチェック” has been checked.

Inputs, constraints, and acceptance criteria are explicit.

Unverified facts, compatibility, and outcome claims are clearly marked.

Any file, command, network, or data action has been reviewed.

Choose a different workflow

When another Skill is the better fit

FAQ

What does django-verification do?

PR前、大きな変更後、デプロイ前に実行して、Djangoアプリケーションの品質とセキュリティを確保します。

How do I start using django-verification?

The catalog detected this source-specific install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/ja-JP/skills/django-verification". Inspect the command and pinned source before running it.

Which Agent platforms does it declare?

No dedicated Agent platform is declared in the pinned source record.

Repository stars
234,327
Repository forks
35,711
Quality
82/100
Source repository last pushed

Quality breakdown

Based on traceable docs and repository signals; stars are not treated as quality.

82/100
Documentation27/30
Specificity18/25
Maintenance18/20
Trust signals19/25

Compare before choosing

Related Agent Skills and source variants

These links are selected from shared tasks, functions, stacks, platforms, and same-name variants. Compare the source owner, documentation, permissions, and maintenance signals.

django-verification by affaan-m

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

django-verification by affaan-m

Django项目的验证循环:迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或PR前的部署就绪检查。

simpy by k-dense-ai

Build, inspect, test, and analyze bounded process-based discrete-event simulations with SimPy, including events, resources, interrupts, monitoring, replications, warm-up, and reproducible output analysis.

flowstudio-power-automate-build by github

Build, scaffold, and deploy Power Automate cloud flows using the FlowStudio MCP server. Your agent constructs flow definitions, wires connections, deploys, and tests — all via MCP without opening the portal. Load this skill when asked to: create a flow, build a new flow, deploy a flow definition, scaffold a Power Automate workflow, construct a flow JSON, update an existing flow's actions, patch a flow definition, add actions to a flow, wire up connections, or generate a workflow definition from

uncertainty-and-units by k-dense-ai

Track physical units and propagate measurement uncertainty in scientific calculations using pint and uncertainties. Use for unit conversion and dimensional checking, GUM uncertainty budgets, Type A and Type B evaluation, coverage factors and expanded uncertainty, Monte Carlo propagation, significant-figure and plus-minus reporting, error propagation through curve fits, CODATA constants, auditing Python code for stripped units or broken uncertainty propagation, and order-of-magnitude plausibility

View original Skill.mdThis page is parsed directly from the repository SKILL.md without editorial rewriting. Collected: Jul 28, 2026 · about 1 min

Django 検証ループ

PR前、大きな変更後、デプロイ前に実行して、Djangoアプリケーションの品質とセキュリティを確保します。

フェーズ1: 環境チェック

# Pythonバージョンを確認
python --version  # プロジェクト要件と一致すること

# 仮想環境をチェック
which python
pip list --outdated

# 環境変数を確認
python -c "import os; import environ; print('DJANGO_SECRET_KEY set' if os.environ.get('DJANGO_SECRET_KEY') else 'MISSING: DJANGO_SECRET_KEY')"

環境が誤って構成されている場合は、停止して修正します。

フェーズ2: コード品質とフォーマット

# 型チェック
mypy . --config-file pyproject.toml

# ruffでリンティング
ruff check . --fix

# blackでフォーマット
black . --check
black .  # 自動修正

# インポートソート
isort . --check-only
isort .  # 自動修正

# Django固有のチェック
python manage.py check --deploy

一般的な問題:

  • パブリック関数の型ヒントの欠落
  • PEP 8フォーマット違反
  • ソートされていないインポート
  • 本番構成に残されたデバッグ設定

フェーズ3: マイグレーション

# 未適用のマイグレーションをチェック
python manage.py showmigrations

# 欠落しているマイグレーションを作成
python manage.py makemigrations --check

# マイグレーション適用のドライラン
python manage.py migrate --plan

# マイグレーションを適用(テスト環境)
python manage.py migrate

# マイグレーションの競合をチェック
python manage.py makemigrations --merge  # 競合がある場合のみ

レポート:

  • 保留中のマイグレーション数
  • マイグレーションの競合
  • マイグレーションのないモデルの変更

フェーズ4: テスト + カバレッジ

# pytestですべてのテストを実行
pytest --cov=apps --cov-report=html --cov-report=term-missing --reuse-db

# 特定のアプリテストを実行
pytest apps/users/tests/

# マーカーで実行
pytest -m "not slow"  # 遅いテストをスキップ
pytest -m integration  # 統合テストのみ

# カバレッジレポート
open htmlcov/index.html

レポート:

  • 合計テスト: X成功、Y失敗、Zスキップ
  • 全体カバレッジ: XX%
  • アプリごとのカバレッジ内訳

カバレッジ目標:

コンポーネント目標
モデル90%+
シリアライザー85%+
ビュー80%+
サービス90%+
全体80%+

フェーズ5: セキュリティスキャン

# 依存関係の脆弱性
pip-audit
safety check --full-report

# Djangoセキュリティチェック
python manage.py check --deploy

# Banditセキュリティリンター
bandit -r . -f json -o bandit-report.json

# シークレットスキャン(gitleaksがインストールされている場合)
gitleaks detect --source . --verbose

# 環境変数チェック
python -c "from django.core.exceptions import ImproperlyConfigured; from django.conf import settings; settings.DEBUG"

レポート:

  • 見つかった脆弱な依存関係
  • セキュリティ構成の問題
  • ハードコードされたシークレットが検出
  • DEBUGモードのステータス(本番環境ではFalseであるべき)

フェーズ6: Django管理コマンド

# モデルの問題をチェック
python manage.py check

# 静的ファイルを収集
python manage.py collectstatic --noinput --clear

# スーパーユーザーを作成(テストに必要な場合)
echo "from apps.users.models import User; User.objects.create_superuser('admin@example.com', 'admin')" | python manage.py shell

# データベースの整合性
python manage.py check --database default

# キャッシュの検証(Redisを使用している場合)
python -c "from django.core.cache import cache; cache.set('test', 'value', 10); print(cache.get('test'))"

フェーズ7: パフォーマンスチェック

# Django Debug Toolbar出力(N+1クエリをチェック)
# DEBUG=Trueで開発モードで実行してページにアクセス
# SQLパネルで重複クエリを探す

# クエリ数分析
django-admin debugsqlshell  # django-debug-sqlshellがインストールされている場合

# 欠落しているインデックスをチェック
python manage.py shell << EOF
from django.db import connection
with connection.cursor() as cursor:
    cursor.execute("SELECT table_name, index_name FROM information_schema.statistics WHERE table_schema = 'public'")
    print(cursor.fetchall())
EOF

レポート:

  • ページあたりのクエリ数(典型的なページで50未満であるべき)
  • 欠落しているデータベースインデックス
  • 重複クエリが検出

フェーズ8: 静的アセット

# npm依存関係をチェック(npmを使用している場合)
npm audit
npm audit fix

# 静的ファイルをビルド(webpack/viteを使用している場合)
npm run build

# 静的ファイルを検証
ls -la staticfiles/
python manage.py findstatic css/style.css

フェーズ9: 構成レビュー

# Pythonシェルで実行して設定を検証
python manage.py shell << EOF
from django.conf import settings
import os

# 重要なチェック
checks = {
    'DEBUG is False': not settings.DEBUG,
    'SECRET_KEY set': bool(settings.SECRET_KEY and len(settings.SECRET_KEY) > 30),
    'ALLOWED_HOSTS set': len(settings.ALLOWED_HOSTS) > 0,
    'HTTPS enabled': getattr(settings, 'SECURE_SSL_REDIRECT', False),
    'HSTS enabled': getattr(settings, 'SECURE_HSTS_SECONDS', 0) > 0,
    'Database configured': settings.DATABASES['default']['ENGINE'] != 'django.db.backends.sqlite3',
}

for check, result in checks.items():
    status = '✓' if result else '✗'
    print(f"{status} {check}")
EOF

フェーズ10: ログ設定

# ログ出力をテスト
python manage.py shell << EOF
import logging
logger = logging.getLogger('django')
logger.warning('Test warning message')
logger.error('Test error message')
EOF

# ログファイルをチェック(設定されている場合)
tail -f /var/log/django/django.log

フェーズ11: APIドキュメント(DRFの場合)

# スキーマを生成
python manage.py generateschema --format openapi-json > schema.json

# スキーマを検証
# schema.jsonが有効なJSONかチェック
python -c "import json; json.load(open('schema.json'))"

# Swagger UIにアクセス(drf-yasgを使用している場合)
# ブラウザで http://localhost:8000/swagger/ を訪問

フェーズ12: 差分レビュー

# 差分統計を表示
git diff --stat

# 実際の変更を表示
git diff

# 変更されたファイルを表示
git diff --name-only

# 一般的な問題をチェック
git diff | grep -i "todo\|fixme\|hack\|xxx"
git diff | grep "print("  # デバッグステートメント
git diff | grep "DEBUG = True"  # デバッグモード
git diff | grep "import pdb"  # デバッガー

チェックリスト:

  • デバッグステートメント(print、pdb、breakpoint())なし
  • 重要なコードにTODO/FIXMEコメントなし
  • ハードコードされたシークレットや資格情報なし
  • モデル変更のためのデータベースマイグレーションが含まれている
  • 構成の変更が文書化されている
  • 外部呼び出しのエラーハンドリングが存在
  • 必要な場所でトランザクション管理

出力テンプレート

DJANGO 検証レポート
==========================

フェーズ1: 環境チェック
  ✓ Python 3.11.5
  ✓ 仮想環境がアクティブ
  ✓ すべての環境変数が設定済み

フェーズ2: コード品質
  ✓ mypy: 型エラーなし
  ✗ ruff: 3つの問題が見つかりました(自動修正済み)
  ✓ black: フォーマット問題なし
  ✓ isort: インポートが適切にソート済み
  ✓ manage.py check: 問題なし

フェーズ3: マイグレーション
  ✓ 未適用のマイグレーションなし
  ✓ マイグレーションの競合なし
  ✓ すべてのモデルにマイグレーションあり

フェーズ4: テスト + カバレッジ
  テスト: 247成功、0失敗、5スキップ
  カバレッジ:
    全体: 87%
    users: 92%
    products: 89%
    orders: 85%
    payments: 91%

フェーズ5: セキュリティスキャン
  ✗ pip-audit: 2つの脆弱性が見つかりました(修正が必要)
  ✓ safety check: 問題なし
  ✓ bandit: セキュリティ問題なし
  ✓ シークレットが検出されず
  ✓ DEBUG = False

フェーズ6: Djangoコマンド
  ✓ collectstatic 完了
  ✓ データベース整合性OK
  ✓ キャッシュバックエンド到達可能

フェーズ7: パフォーマンス
  ✓ N+1クエリが検出されず
  ✓ データベースインデックスが構成済み
  ✓ クエリ数が許容範囲

フェーズ8: 静的アセット
  ✓ npm audit: 脆弱性なし
  ✓ アセットが正常にビルド
  ✓ 静的ファイルが収集済み

フェーズ9: 構成
  ✓ DEBUG = False
  ✓ SECRET_KEY 構成済み
  ✓ ALLOWED_HOSTS 設定済み
  ✓ HTTPS 有効
  ✓ HSTS 有効
  ✓ データベース構成済み

フェーズ10: ログ
  ✓ ログが構成済み
  ✓ ログファイルが書き込み可能

フェーズ11: APIドキュメント
  ✓ スキーマ生成済み
  ✓ Swagger UIアクセス可能

フェーズ12: 差分レビュー
  変更されたファイル: 12
  +450、-120行
  ✓ デバッグステートメントなし
  ✓ ハードコードされたシークレットなし
  ✓ マイグレーションが含まれる

推奨: WARNING: デプロイ前にpip-auditの脆弱性を修正してください

次のステップ:
1. 脆弱な依存関係を更新
2. セキュリティスキャンを再実行
3. 最終テストのためにステージングにデプロイ

デプロイ前チェックリスト

  • すべてのテストが成功
  • カバレッジ ≥ 80%
  • セキュリティ脆弱性なし
  • 未適用のマイグレーションなし
  • 本番設定でDEBUG = False
  • SECRET_KEYが適切に構成
  • ALLOWED_HOSTSが正しく設定
  • データベースバックアップが有効
  • 静的ファイルが収集され提供
  • ログが構成され動作中
  • エラー監視(Sentryなど)が構成済み
  • CDNが構成済み(該当する場合)
  • Redis/キャッシュバックエンドが構成済み
  • Celeryワーカーが実行中(該当する場合)
  • HTTPS/SSLが構成済み
  • 環境変数が文書化済み

継続的インテグレーション

GitHub Actionsの例

# .github/workflows/django-verification.yml
name: Django Verification

on: [push, pull_request]

jobs:
  verify:
    runs-on: ubuntu-latest
    services:
      postgres:
        image: postgres:14
        env:
          POSTGRES_PASSWORD: postgres
        options: >-
          --health-cmd pg_isready
          --health-interval 10s
          --health-timeout 5s
          --health-retries 5

    steps:
      - uses: actions/checkout@v3

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: '3.11'

      - name: Cache pip
        uses: actions/cache@v3
        with:
          path: ~/.cache/pip
          key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}

      - name: Install dependencies
        run: |
          pip install -r requirements.txt
          pip install ruff black mypy pytest pytest-django pytest-cov bandit safety pip-audit

      - name: Code quality checks
        run: |
          ruff check .
          black . --check
          isort . --check-only
          mypy .

      - name: Security scan
        run: |
          bandit -r . -f json -o bandit-report.json
          safety check --full-report
          pip-audit

      - name: Run tests
        env:
          DATABASE_URL: postgres://postgres:postgres@localhost:5432/test
          DJANGO_SECRET_KEY: test-secret-key
        run: |
          pytest --cov=apps --cov-report=xml --cov-report=term-missing

      - name: Upload coverage
        uses: codecov/codecov-action@v3

クイックリファレンス

チェックコマンド
環境python --version
型チェックmypy .
リンティングruff check .
フォーマットblack . --check
マイグレーションpython manage.py makemigrations --check
テストpytest --cov=apps
セキュリティpip-audit && bandit -r .
Djangoチェックpython manage.py check --deploy
静的ファイル収集python manage.py collectstatic --noinput
差分統計git diff --stat

覚えておいてください: 自動化された検証は一般的な問題を捕捉しますが、手動でのコードレビューとステージング環境でのテストに代わるものではありません。

Source repo
affaan-m/ECC
Skill path
docs/ja-JP/skills/django-verification/SKILL.md
Commit SHA
4e973d3eaf92
Repository license
MIT
Data collected