test(ci-gates): assert every validate:*/check:* gate is actually run in CI - #742
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
tests/workflow-scripts.test.mjs guards that package.json scripts, the files under scripts/, the linter configs they reference, and the npm run calls in .github/workflows/ all name something real, but never asserts that the repository's gates are actually invoked by a workflow. A gate nobody runs is inert: it passes when run by hand, the unit suite stays green, and the breakage it was written to catch reaches main. Adds a guard over the validate:* and check:* scripts, with an explicit exemption map recording the two gates CI deliberately does not run (check:links reaches the live internet, check:community-group-links needs GH_TOKEN and rewrites data). The map is itself guarded against rot: entries must name a defined script, carry a reason, and not name a gate a workflow already runs. Signed-off-by: hivecommons-hive[bot] <hivecommons-hive@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "quality" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
Member
|
Superseded by #750, which consolidates this and 14 other test-only coverage PRs into a single reviewable change (commit cherry-picked unmodified, authorship and DCO preserved). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test Improvement
Adds five guards to
tests/workflow-scripts.test.mjs. No production code, noworkflow file is touched.
That suite already checks that
package.jsonscripts, the files underscripts/, the linter configs those scripts pass, and thenpm runcallsinside
.github/workflows/all name something real. It never checks that therepository's gates — the
validate:*andcheck:*scripts — are invoked bya workflow at all. A gate nobody runs is inert: it passes when a contributor
runs it by hand, the unit suite stays green, and the regression it exists to
catch reaches
main.New tests:
every validate:*/check:* gate is run by a workflow or recorded as exempt—the guard itself, resolving
npm runtargets across every workflow'srun:steps.
every gate this suite recognises is a real package.json script— pins thevalidate:|check:filter to evidence so the guard above cannot passvacuously if the filter stops matching.
every recorded CI exemption still names a defined scriptevery recorded CI exemption carries a reasonno recorded CI exemption names a gate a workflow already runsThe exemption map
GATES_NOT_RUN_BY_CIis seeded with the two gates CI does notrun today, each with its reason on the record:
check:linksresolves outboundURLs against the live internet, and
check:community-group-linkscalls theGitHub API, needs
GH_TOKEN, and rewritesdata/community-groups.json(arefresh job rather than a pass/fail check). The three guards over the map keep
it from rotting into a standing untruth.
Verification
TZ=UTC node --test tests/workflow-scripts.test.mjs— 13 pass, 0 fail.npm run validate:awardsfrom all three workflowsthat invoke it (
ci.yml,deploy-gh-pages.yml,import-architectures.yml)makes the new guard fail naming
validate:awards. Removing it fromci.ymlalone correctly does not fail, since the gate still runs elsewhere.
npx prettier --check tests/workflow-scripts.test.mjs— clean.TZ=UTC node tests/tools/coverage-report.mjs --check 97 --check-source 99—passes;
src filesstay at 100.00% lines / 97.95% regions, and this file'sregion coverage rises from 87.23% to 88.79%. Every added line is executed.
Scope
Touches only
tests/workflow-scripts.test.mjs, which no other open PR modifies.This is deliberately not a coverage-gap fix: every source file currently below
100% region coverage is already claimed by an open hold-gated PR.
Heads-up for review ordering: open PR #684 adds a
validate:projects-bornscript with no CI step. If it merges before this, the new guard will fail naming
validate:projects-bornuntil.github/workflows/ci.ymlgains a step for it.That is the guard working as intended, but landing that step needs a human —
this lane cannot push changes under
.github/workflows/.Related Issue
Closes #741
Filed by quality agent (hold-gated mode). Human review required.
— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88