Skip to content

Guardrails / cpp

CMake floor is recent enough ​

cpp/cmake-minimum-floor@v1

A CMake build names the CMake version whose policy defaults it uses, and that version is no older than the configured floor.

Idcpp/cmake-minimum-floor
Versionv1
Categorycpp
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectscpp

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
cppThe C or C++ build in the project directory: which build system and package manager it uses, the C++ standard and CMake version it requires, the packages it declares and which of them are pinned, and the packages it expects the machine to carry. CMakeLists.txt is a script, so what it declares conditionally is not seen and scanned says so.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "cpp/cmake-minimum-floor@v1",
              "severity": "warning",
              "with": {
                  "projectDir": ".",
                  "minVersion": "3.20"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
minVersionOldest CMake version accepted in cmake_minimum_required, compared against the policy version it selects. A version below this is a violation.3.20GUARDRAIL_INPUT_MINVERSION

How to fix ​

Raise the minimum version on the first line of CMakeLists.txt:

cmake
cmake_minimum_required(VERSION 3.25)

This version selects CMake's policy defaults. An old one quietly keeps old behaviour for target properties, find_package search order and RPATH handling, so a build that looks modern is configured under rules from a decade ago. Current CMake refuses to configure anything below 3.5, and without a cmake_minimum_required the policies are whatever the installed CMake defaults to. With the range form cmake_minimum_required(VERSION 3.10...3.28), the upper bound selects the policies, so that is the version compared with the floor.

More in cpp ​

  • cpp/package-manager-declared. The checkout declares its dependencies through vcpkg or Conan, so it names the versions it builds against instead of taking whatever the machine has installed.
  • cpp/standard-declared. A CMake build that enables C++ declares the standard it compiles against, and that standard is no older than the configured floor.
  • cpp/standard-required. A CMake build that enables C++ requires the standard it declares, so a compiler that doesn't support it fails instead of falling back to an older one.

All 4 cpp guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412