ci: run core and info tests when shared workspace packages change - #194
Conversation
packages/core depends on @create-uni/config and @create-uni/shared, and packages/info on @create-uni/shared (workspace:*), but their test workflows only watched their own folder. Also point core_test_template.yml at its own file instead of core_test.yml.
Warns on PRs when a workflow's on.paths list no longer covers the workspace packages it builds. Warning only; never fails the build.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe core and info test workflows now include additional package paths in their triggers. A new pull-request workflow runs an audit of path filters with warning-level findings. ChangesWorkflow path filters
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Core and info tests now trigger for changes to their declared dependencies, and the audit reports warnings without blocking pull requests. A separate gui_release trigger gap remains unchanged and is a follow-up, not a regression from this PR. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The expanded test triggers preserve existing execution behavior. The new audit explicitly requests read-only repository access and declares no secrets or deployment steps. Its external implementation and effective repository policies remain unverified, so the assessment is low risk rather than a complete security assurance. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What
Commit 1 (the fix).
packages/coredepends on@create-uni/configand@create-uni/shared(workspace:*, imported fromsrc/index.ts,src/command/actions/gui.tsand others). Butcore_test.ymlandcore_test_template.ymlonly trigger onpackages/core/**. A PR that only changespackages/sharedorpackages/confignever runs the core build or the template generation tests.packages/infodepends on@create-uni/shared, butinfo_test.ymlonly watchespackages/info/**.core_test_template.ymllists.github/workflows/core_test.ymlas its own workflow file, so edits to the template workflow itself don't trigger it. It now points atcore_test_template.yml.That's 12 lines added and 2 changed, all inside
on.*.paths.Left alone:
gui_release.yml.@create-uni/uidepends on@create-uni/config, so by the same logicpackages/config/**belongs there too. But that is a release trigger, so I didn't want to change when releases happen without asking. Happy to add it if you want.Commit 2 (optional). This adds
.github/workflows/path-filter-audit.yml, a smallpull_requestjob that warns when a workflow'spaths:stops covering the workspace packages it depends on. It keeps these lists from drifting again. It only annotates and never fails the build; drop the commit if you'd rather not add a workflow.On
maintoday the audit reports 11 findings across 4 workflows, for example: "packages/shared/**is missing from on.pull_request.paths: create-uni depends on@create-uni/shared, so a change there skips this workflow." With commit 1 applied, only thegui_release.ymlone above remains.Disclosure: the audit is a GitHub Action I maintain, dynamic-monorepo.
Verification
All workflow YAML parses. I ran the audit locally (
npx github:Continuous-Actions/dynamic-monorepo audit) before and after: 11 findings, then 1.Summary by CodeRabbit