Skip to content

fix(ci): execute selected main lanes and enforce complete acceptance - #559

Merged
ty-everett merged 3 commits into
mainfrom
codex/ts-stack-release-readiness
Sep 23, 2026
Merged

ty-everett merged 3 commits into
mainfrom
codex/ts-stack-release-readiness

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Program and scope

Main's CI can report success while skipping runtime lanes that its scope job selected. Preparation survives the skipped PR-only Sonar/dependency jobs, but its downstream jobs inherit GitHub's implicit success condition. The aggregate checks then accept those skips. This fixes the execution conditions and independently verifies every selected lane in the final merge gate.

Related: #402 and the remaining acceptance evidence for #557. Coordination: #558.

  • A manual CI dispatch selects the complete workspace, all infrastructure build lanes and all governed mutation targets. Shared CI execution changes also select the full workspace and infrastructure for review.
  • Execution jobs honor explicit workflow cancellation so obsolete always-running preparation jobs cannot hold the concurrency slot.
  • Matrix siblings finish to preserve diagnostics; packages inside regression/coverage shards execute serially to avoid nested test-worker contention observed in the LCH integration lane.
  • Simple shares a single tested code-unit comparator across the five certificate/persistence consumers. Historian tests verify that opposite key insertion orders use the same cache identity.
  • Publication, deployment and unrelated feature work are outside this PR.
  • Exact head reviewed: 2279bc0.

Impact

  • Public package source changed: @bsv/simple.
  • Security-sensitive control changed: CI acceptance; canonical ordering is preserved byte-for-byte.
  • Documentation and generated release ledger updated.
  • No dependency, infrastructure source, public API, wire format, persisted schema or runtime-target change.
  • SemVer: compatible internal consolidation is included in the existing unpublished @bsv/simple@0.6.0 candidate. Its existing minor migration remains documented; this consolidation requires none. SDK source is unchanged, with test-only coverage improvement.

Verification

  • pnpm build: complete workspace passed; Simple rebuilt after its consolidation.
  • pnpm health:check, pnpm lint, pnpm format:check, pnpm typecheck: passed.
  • pnpm audit:security: no known vulnerabilities.
  • CI scope/orchestration/result-gate tests: 21 passed, including every selected lane returning skipped, missing, cancelled or failed while its aggregate is green; malformed scope; PR-only gates; valid empty scope.
  • pnpm --filter @bsv/sdk exec jest --coverage --watchman=false --maxWorkers=2: 206 suites / 7,324 tests passed, including global coverage thresholds.
  • pnpm --filter @bsv/simple run test:coverage: 28 suites / 455 tests passed.
  • LCH multipay integration: 5 tests passed without a timeout increase.
  • Simple build, pack:check, test:browser: passed. Clean ESM/CJS consumers, type resolution, exports and exact-tarball browser checks passed. Browser bundle budget passed (Vite 260,195 gzip bytes).
  • Generated package documentation and documentation policy: passed.
  • CHIRP iterator cleanup: 148 tests passed. Rechecked the complete fix: clear Sonar reliability bugs without changing behavior #557 production patch against its original pre-merge base, using its unchanged-file coverage plus rerun SDK/Simple/CHIRP coverage: 91.49% (43/47 points); this PR patch is 100% (12/12 points). No gate was weakened.
  • Hosted exact-head CI 35805285373: every selected lane and merge-gate passed. CodeQL and repository zero-new-Sonar gate passed; open CodeQL alerts on the PR merge ref: zero. All review threads resolved (none open).
  • Self-reviewed complete diff for correctness, security, compatibility, public API, artifacts, dependencies, docs and operations.
  • Every applicable hosted check is terminal and successful on the exact head.

Security and dependencies

  • No dependency or lockfile change.
  • No quality suppression, weakened coverage target, skipped test or advisory dismissal.
  • Workflow permissions remain least privilege: final gate gains read-only checkout with persisted credentials disabled to execute the reviewed gate script.
  • Exact-head CodeQL has no new alert.
  • Exact-head repository quality gate has zero new Sonar findings and unreviewed hotspots.

Release and operations

  • No npm publication performed from the workstation or this PR.
  • Package version decision, migration and release notes are current.
  • No service/image change. Release acceptance must use a fresh complete run after integration; a green documentation-only push is insufficient.

Completion evidence

@sonarqubecloud

Copy link
Copy Markdown

@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant