mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-10 03:27:59 +00:00
Five reviewers (maintainability, reliability, testing, agent-native,
adversarial) flagged that ci-report.yml's sticky PR comment ignores
scope-parity entirely. Add scope_parity_result to the artifact read
step, render it in the Pipeline Status table, and include it in the
OVERALL pass/fail condition. Skipped is now visualised distinctly from
cancelled (skipped → ⏭, cancelled → 🛑).
Add `.github/scripts/check-language-filters.py` and wire it into
ci-quality.yml's workflow-convention job. The script parses
MIGRATED_LANGUAGES from registry-primary-flag.ts and asserts:
1. ci.yml has a per-language filter block for every migrated slug
2. ci.yml's FULL_LANG_LIST env var matches
3. ci-scope-parity.yml's changed-languages default matches
This catches the most common drift mode: adding a language to
MIGRATED_LANGUAGES without updating the two YAML hardcoded lists,
which would silently make scope-parity skip the new language. Negative-
tested with a synthetic flag.ts that adds Kotlin without updating the
filter blocks — script correctly fails with all three location-
specific errors.
Move the resolver test-file existence check from the parity matrix
job into the discover job, iterating the full MIGRATED_LANGUAGES set
rather than just the filtered matrix. A missing test file now fails
the gate even on docs-only PRs that prune the matrix to empty,
holding the invariant regardless of which slugs were filtered.
Dismissed (verified out-of-scope): the performance reviewer's
suggestion to replace setup-gitnexus with a lighter setup in the
discover job. gitnexus-shared/package.json exports only ./dist/, so
`tsx` cannot resolve `import 'gitnexus-shared'` without the build
step. The optimisation would require modifying gitnexus-shared's
exports field to expose ./src/, which is a separate refactor.
87 lines
3.1 KiB
YAML
87 lines
3.1 KiB
YAML
name: Quality Checks
|
|
|
|
on:
|
|
workflow_call:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
format:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: 22
|
|
cache: npm
|
|
cache-dependency-path: package-lock.json
|
|
- run: npm ci
|
|
- run: npx prettier --check .
|
|
|
|
lint:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: 22
|
|
cache: npm
|
|
cache-dependency-path: package-lock.json
|
|
- run: npm ci
|
|
- run: npx eslint .
|
|
|
|
typecheck:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: ./.github/actions/setup-gitnexus
|
|
- run: npx tsc --noEmit
|
|
working-directory: gitnexus
|
|
|
|
typecheck-web:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- uses: ./.github/actions/setup-gitnexus-web
|
|
- run: npx tsc -b --noEmit
|
|
working-directory: gitnexus-web
|
|
|
|
# Enforces the convention documented in CONTRIBUTING.md → "GitHub Actions —
|
|
# Concurrency Convention":
|
|
# 1. Every entry-point (non-reusable) workflow declares a top-level
|
|
# `concurrency:` block.
|
|
# 2. Reusable workflows (`on: workflow_call` only) do NOT declare one —
|
|
# they inherit concurrency from the caller.
|
|
# 3. The concurrency group key starts with `${{ github.workflow }}` or
|
|
# the literal `CI-` prefix (the documented ci.yml exception for
|
|
# reusable-workflow-safe grouping).
|
|
# Reusability is detected by parsing each workflow's `on:` block, not an
|
|
# allowlist, so new reusable workflows never produce false positives.
|
|
workflow-convention:
|
|
name: Workflow conventions
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
- name: Validate workflow concurrency convention
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
python3 .github/scripts/check-workflow-concurrency.py .github/workflows
|
|
# Asserts ci.yml's per-language filter blocks AND the FULL_LANG_LIST
|
|
# / changed-languages defaults agree with MIGRATED_LANGUAGES in
|
|
# registry-primary-flag.ts. Catches the most common scope-parity
|
|
# drift mode: a contributor adds a language to MIGRATED_LANGUAGES
|
|
# but forgets to add the corresponding `<slug>:` filter block in
|
|
# ci.yml, which would silently make path-aware pruning skip the
|
|
# new language's parity entry.
|
|
- name: Validate per-language filter consistency
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
python3 .github/scripts/check-language-filters.py
|