Skip to content

ci: tighten the checks and pin codecov to v7 - #118

Merged
felipesauer merged 1 commit into
mainfrom
ci/tighten-checks
Aug 26, 2026
Merged

felipesauer merged 1 commit into
mainfrom
ci/tighten-checks

Conversation

@felipesauer

Copy link
Copy Markdown
Owner

Three corrections where CI was claiming something it was not doing. All of
them came out of a parity review against safeaccess-identum.

Change Why
codecov-action v5 → v7.0.0, pinned by SHA The composite still pinned v5 while the workflows around it were written for v7.
PHP CI coverage floor 95 → 100 composer test already requires --min=100; the 5-point gap only let through a regression the local command would catch.
Drop the "Type-level tests" step It promises to validate .test-d.ts via Vitest. There is no .test-d.ts in the repo, and the script it runs is tsc --noEmit — identical to the step above it.

The test:typecheck script stays in package.json; only the duplicated CI
step goes.

Three small corrections, all of them cases where CI claimed something it
was not doing:

- The coverage action still pinned codecov-action v5 while it is invoked
  from workflows written for v7. Now v7.0.0, pinned by commit SHA like
  every other action here.
- PHP CI accepted 95% coverage while `composer test` requires 100%. The
  suite delivers 100%, so the gap only served to let a regression through
  that the local command would have caught.
- The "Type-level tests" step claimed to validate `.test-d.ts` files via
  Vitest. There is no `.test-d.ts` in the repo and the script it ran is
  `tsc --noEmit` — the same command as the step right above it.
@codecov

codecov Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@felipesauer
felipesauer merged commit d076360 into main Aug 26, 2026
9 checks passed
@felipesauer
felipesauer deleted the ci/tighten-checks branch August 26, 2026 16:50
felipesauer added a commit that referenced this pull request Aug 26, 2026
The last parity gap between this repo and `safeaccess-identum`.

`.github/actions/setup-node-cached` is the composite `js-ci` actually
calls,
and it was still pinned to:

| Action | Was | Now |
| --- | --- | --- |
| `actions/setup-node` | `53b8394…` (2026-03-02, v6.x) | `8207627…` =
v7.0.0 |
| `actions/cache` | `cdf6c1f…` = v5.0.3 (January) | `55cc834…` (June) |

Dependabot updates `.github/workflows`, not `.github/actions`, so every
JS
job here has been running a March build of `setup-node` without anything
flagging it. #118 fixed the coverage composite; this one closes the
pair.

Also removes the mention of `packages/cli` from the `eslint.config.js`
header
— no such package exists here.

After this, the only intentional differences left between the two repos
are
the mutation thresholds (90/100 here, 85 there) and the package
contents.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant