ci: tighten the checks and pin codecov to v7 - #118
Merged
Merged
Conversation
Three small corrections, all of them cases where CI claimed something it was not doing: - The coverage action still pinned codecov-action v5 while it is invoked from workflows written for v7. Now v7.0.0, pinned by commit SHA like every other action here. - PHP CI accepted 95% coverage while `composer test` requires 100%. The suite delivers 100%, so the gap only served to let a regression through that the local command would have caught. - The "Type-level tests" step claimed to validate `.test-d.ts` files via Vitest. There is no `.test-d.ts` in the repo and the script it ran is `tsc --noEmit` — the same command as the step right above it.
felipesauer
force-pushed
the
ci/tighten-checks
branch
from
August 26, 2026 16:39
205e4df to
e65ee84
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
felipesauer
added a commit
that referenced
this pull request
Aug 26, 2026
The last parity gap between this repo and `safeaccess-identum`. `.github/actions/setup-node-cached` is the composite `js-ci` actually calls, and it was still pinned to: | Action | Was | Now | | --- | --- | --- | | `actions/setup-node` | `53b8394…` (2026-03-02, v6.x) | `8207627…` = v7.0.0 | | `actions/cache` | `cdf6c1f…` = v5.0.3 (January) | `55cc834…` (June) | Dependabot updates `.github/workflows`, not `.github/actions`, so every JS job here has been running a March build of `setup-node` without anything flagging it. #118 fixed the coverage composite; this one closes the pair. Also removes the mention of `packages/cli` from the `eslint.config.js` header — no such package exists here. After this, the only intentional differences left between the two repos are the mutation thresholds (90/100 here, 85 there) and the package contents.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three corrections where CI was claiming something it was not doing. All of
them came out of a parity review against
safeaccess-identum.codecov-actionv5 → v7.0.0, pinned by SHAcomposer testalready requires--min=100; the 5-point gap only let through a regression the local command would catch..test-d.tsvia Vitest. There is no.test-d.tsin the repo, and the script it runs istsc --noEmit— identical to the step above it.The
test:typecheckscript stays inpackage.json; only the duplicated CIstep goes.