Skip to content

ci: run core and info tests when shared workspace packages change - #194

Merged
FliPPeDround merged 2 commits into
uni-helper:mainfrom
MarkAlex1234:ci/test-workflow-paths
Oct 5, 2026
Merged

FliPPeDround merged 2 commits into
uni-helper:mainfrom
MarkAlex1234:ci/test-workflow-paths

Conversation

@MarkAlex1234

@MarkAlex1234 MarkAlex1234 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

What

Commit 1 (the fix).

  • packages/core depends on @create-uni/config and @create-uni/shared (workspace:*, imported from src/index.ts, src/command/actions/gui.ts and others). But core_test.yml and core_test_template.yml only trigger on packages/core/**. A PR that only changes packages/shared or packages/config never runs the core build or the template generation tests.
  • packages/info depends on @create-uni/shared, but info_test.yml only watches packages/info/**.
  • core_test_template.yml lists .github/workflows/core_test.yml as its own workflow file, so edits to the template workflow itself don't trigger it. It now points at core_test_template.yml.

That's 12 lines added and 2 changed, all inside on.*.paths.

Left alone: gui_release.yml. @create-uni/ui depends on @create-uni/config, so by the same logic packages/config/** belongs there too. But that is a release trigger, so I didn't want to change when releases happen without asking. Happy to add it if you want.

Commit 2 (optional). This adds .github/workflows/path-filter-audit.yml, a small pull_request job that warns when a workflow's paths: stops covering the workspace packages it depends on. It keeps these lists from drifting again. It only annotates and never fails the build; drop the commit if you'd rather not add a workflow.

On main today the audit reports 11 findings across 4 workflows, for example: "packages/shared/** is missing from on.pull_request.paths: create-uni depends on @create-uni/shared, so a change there skips this workflow." With commit 1 applied, only the gui_release.yml one above remains.

Disclosure: the audit is a GitHub Action I maintain, dynamic-monorepo.

Verification

All workflow YAML parses. I ran the audit locally (npx github:Continuous-Actions/dynamic-monorepo audit) before and after: 11 findings, then 1.

Summary by CodeRabbit

  • Tests
    • Core checks now run for changes to shared and configuration packages, in addition to existing core and workflow-file changes.
    • Info checks now run for changes to the shared package.
    • Added a pull-request check that reports path-filter findings as warnings without failing the build.

packages/core depends on @create-uni/config and @create-uni/shared, and packages/info on @create-uni/shared (workspace:*), but their test workflows only watched their own folder. Also point core_test_template.yml at its own file instead of core_test.yml.
Warns on PRs when a workflow's on.paths list no longer covers the workspace packages it builds. Warning only; never fails the build.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1f7ef56b-920d-4eb8-858a-a27f385362f4
📥 Commits

Reviewing files that changed from the base of the PR and between 3c3cebc and 372a2da.

📒 Files selected for processing (4)
  • .github/workflows/core_test.yml
  • .github/workflows/core_test_template.yml
  • .github/workflows/info_test.yml
  • .github/workflows/path-filter-audit.yml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The core and info test workflows now include additional package paths in their triggers. A new pull-request workflow runs an audit of path filters with warning-level findings.

Changes

Workflow path filters

Layer / File(s) Summary
Update test workflow triggers
.github/workflows/core_test.yml, .github/workflows/core_test_template.yml, .github/workflows/info_test.yml
Core workflow filters now include packages/config/** and packages/shared/**. The template workflow watches its own file path. Info workflow filters now include packages/shared/**.
Add path-filter audit
.github/workflows/path-filter-audit.yml
A new pull-request workflow checks out the repository and runs Continuous-Actions/dynamic-monorepo@v1 with audit: warn and read-only contents permission.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: flippedround

Merge Risk: ⚪ Minimal · up to 372a2

Core and info tests now trigger for changes to their declared dependencies, and the audit reports warnings without blocking pull requests. A separate gui_release trigger gap remains unchanged and is a follow-up, not a regression from this PR.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 372a2

The expanded test triggers preserve existing execution behavior. The new audit explicitly requests read-only repository access and declares no secrets or deployment steps. Its external implementation and effective repository policies remain unverified, so the assessment is low risk rather than a complete security assurance.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The new external-action execution path applies to every pull request accepted for execution, without a path filter. Its declared exposure is the hosted job, checked-out repository contents, and read-scoped repository credential; the supplied workflow establishes no production or release authority.

Trust Boundaries and Controls

  • observed — The audit uses the ordinary pull_request execution model with explicit read-only permission, not a privileged pull_request_target model. These are meaningful containment controls, but they do not verify how the external action processes PR-controlled files or credentials.

Resilience and Maintainability Implications

  • observed — The existing executable-cache transition remains unchanged: build precedes save, tests require build, producer and consumer use the same source-SHA/lockfile/OS/Node key, and a cache miss rebuilds the executable. Both core workflows share this identity scheme. No new privileged promotion was established; concurrent-save, fork-isolation, and cancellation semantics remain platform-dependent and unverified.

Hardening Proposals

  • proposed — Review the external action implementation and pin the approved version to an immutable commit to make the newly introduced executable dependency reproducible. This is a hardening proposal, not evidence of malicious behavior or a verified vulnerability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: core and info test workflows now run when shared workspace packages change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@FliPPeDround
FliPPeDround merged commit 4a83bd0 into uni-helper:main Oct 5, 2026
113 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants