-
Notifications
You must be signed in to change notification settings - Fork 0
fix(ci): execute Server Tests on exact PR heads #523
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
seonghobae
wants to merge
317
commits into
develop
Choose a base branch
from
fix/server-tests-exact-head-522
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
317 commits
Select commit
Hold shift + click to select a range
7d17126
fix(coverage): instrument all Playwright specs
seonghobae f2ef71d
test(ci): require actionable coverage diagnostics
seonghobae 8326c47
fix(ci): print exact coverage misses without relaxing gate
seonghobae 6811d21
test(coverage): exercise real API edge paths
seonghobae 6c8be41
test(coverage): make rate-window edge deterministic
seonghobae 309b6eb
test(coverage): await webhook retry completion
seonghobae 77dd1c1
test(coverage): repair Stripe edge fixture syntax
seonghobae b2a8099
test(coverage): lock whole-source instrumentation
seonghobae 4336dde
test(ci): lock whole-source server coverage
seonghobae 012bae1
test(webhooks): exercise one-retry outcomes deterministically
seonghobae 0d7b0f6
test(api): cover hosted provider failure boundaries
seonghobae a5cae95
test(api): execute hosted provider edge coverage
seonghobae eaf75a8
test(api): exercise production branch alternatives
seonghobae 936520d
test(api): execute branch coverage cases
seonghobae 8e93da0
test(ci): retain branch coverage suite in API graph
seonghobae 97eba0c
test(auth): keep branch coverage aligned with token version contract
seonghobae 197788d
test(api): cover residual production control branches
seonghobae 25c64d3
test(api): execute residual branch coverage
seonghobae 6d01ad7
test(api): cover hosted OIDC fallback branches
seonghobae 420c87a
test(api): execute hosted OIDC fallback coverage
seonghobae 51e12fa
test(api): respect non-null fallback fixtures
seonghobae af7ede2
test(api): use reachable empty MIME fixture
seonghobae 1173760
test(api): await observable webhook settlement
seonghobae b640af5
test(api): cover residual public branch behavior
seonghobae 0e7ce22
test(api): model multipart filename semantics accurately
seonghobae 2fa8393
test(api): reject stale tokens for deleted accounts
seonghobae adb8086
fix(api): remove unreachable coverage fallbacks
seonghobae 6dd2ef2
test(api): always restore webhook fetch stub
seonghobae 3ce9a8b
test(auth): cover valid JWT version mismatch
seonghobae c7c1e60
test(auth): cover post-verification revocation race
seonghobae 73fd1cd
fix(perf): restore module preload contract
seonghobae d497eae
test(coverage): require served-source identity evidence
seonghobae 62be9bf
fix(coverage): bind browser evidence to served source
seonghobae 44dc7f8
fix(coverage): verify served bytes against checkout
seonghobae 2e4f0c2
test(auth): preserve statement surface in revocation fault
seonghobae ae62f22
test(coverage): reject production-script interception
seonghobae 0d44eec
fix(coverage): test exact served production bytes
seonghobae 4e692d6
merge(develop): preserve adaptive attribution in exact-head CI repair
seonghobae 1cb030c
test(e2e): probe subtree range without rewriting app source
seonghobae 9909729
test(e2e): serve CSP-safe subtree probe
seonghobae a43f699
test(e2e): require shipped subtree-range test seam
seonghobae 8c94d56
test(e2e): exercise subtree ranges through drag behavior
seonghobae ca69395
test(ci): require browser coverage failure diagnostics
seonghobae 5a0d3f0
fix(ci): diagnose the failing browser coverage report
seonghobae 67a4bb5
test(ci): require actual browser coverage diagnostics path
seonghobae 2dee0a7
fix(ci): diagnose the emitted browser coverage report
seonghobae b7392b9
test(browser): exercise cloud planning and governance workflows
seonghobae c60a1b6
fix(ci): preserve exact browser coverage failure evidence
seonghobae 85f212b
test(e2e): stabilize cloud workflow assertions
seonghobae b4345c7
fix(ui): keep cloud modal controls reachable
seonghobae 685240d
test(ci): require browser diagnostics after failed e2e
seonghobae 895a334
fix(ci): preserve browser coverage after failed e2e
seonghobae 54d806a
test(ci): bound Playwright runtime installation
seonghobae 7f0a053
fix(ci): bound Playwright runtime installation
seonghobae 62af467
test(ci): allow unrelated bounded workflow steps
seonghobae 71c65e8
test(browser): cover residual planner production behavior
seonghobae 368ca0c
test(cloud): cover residual buyer-visible governance paths
seonghobae 2029921
test(dnd): exercise real dragover before subtree drop
seonghobae a25bf0f
test(browser): exercise residual behavior through public UI seams
seonghobae 9fe375b
test(dnd): poll persisted subtree order
seonghobae 27fb997
test(css): keep modal scrolling with modal styles
seonghobae a4c3ea5
test(css): scope modal scrolling contract
seonghobae 541d7f1
refactor(css): keep toast stylesheet toast-scoped
seonghobae f4f090c
refactor(css): centralize modal overflow styles
seonghobae 4b2caf9
fix(ui): preserve disabled sync and modal close behavior
seonghobae 5b798a8
test(ui): require modal close controls
seonghobae 33dc688
test(e2e): wait for cloud modals to close
seonghobae f2b9a9b
fix(ui): close team modals from nested controls
seonghobae de2444e
fix(ui): target the actual team close control
seonghobae 15d5536
test(static): require linked stylesheets on every serve path
seonghobae df0c13a
fix(static): ship modal close hit-testing on every runtime
seonghobae 4fd4a05
test(ci): reject apt-dependent Playwright installs
seonghobae 30b690d
fix(ci): avoid apt mirror dependency for Playwright
seonghobae 2842fde
test(ci): align exact-head contract with bounded browser install
seonghobae cd20200
fix(ci): harden current coverage failure contracts
seonghobae 405d3ca
test(browser): exercise empty-plan recovery actions
seonghobae c8c9d22
test(browser): cover hierarchy collapse and row editing
seonghobae 6a8b1c4
test(browser): exercise residual text safety helpers
seonghobae 9783dfa
fix(test): keep residual helper probe executable
seonghobae 819e0d9
fix(test): remove unreachable module-scope helper probe
seonghobae 6d94a4d
test(ci): reject duplicate unbounded cloud browser install
seonghobae cf3228e
fix(ci): reuse bounded cloud browser install
seonghobae 41643dc
test(api): preserve unnamed attachment metadata
seonghobae e6e1ab2
test(api): reject empty attachment filenames honestly
seonghobae c26e46d
ci(codeql): pin current v4.37.7 evidence actions
seonghobae 000731d
merge(billing): reconcile trusted checkout root with protected develop
seonghobae 4c0592d
fix(stack): preserve protected develop in billing reconciliation
seonghobae 67ebed7
test(codeql): require default workflow exact-head supply chain
seonghobae 5fd2897
fix(codeql): bind default analysis to exact contributor head
seonghobae 8fb1e6a
test(codeql): fix exact-head contract reference
seonghobae e88ea32
test(e2e): exercise aria-disabled empty actions by keyboard
seonghobae 1d8db1f
test(browser): exercise residual planner fault boundaries
seonghobae 1e89c62
test(cloud): exercise residual SaaS failure boundaries
seonghobae d1a3fc4
test(ci): require exact-head property fuzz evidence
seonghobae 96d9fac
test(ci): register protected fuzz checkout regression
seonghobae 662cfb2
fix(ci): bind property fuzz to exact contributor head
seonghobae 465a26b
test(ci): require modern immutable fuzz runtime
seonghobae 4c284d6
fix(ci): modernize protected fuzz action runtime
seonghobae 00563cd
docs(ci): preserve fuzz runtime provenance
seonghobae d0acb5e
test(changelog): preserve published release notes
seonghobae 34eb45f
fix(changelog): restore published release history
seonghobae 1aad503
test(cloud): make stale-version conflict deterministic
seonghobae 2a5ff72
test(browser): cover secure UUID compatibility fallback
seonghobae b77d81c
test(cloud): cover buyer-visible team and account boundaries
seonghobae e465e30
test(cloud): scope member removal assertion to roster
seonghobae 721b509
test(browser): exercise defensive production boundaries
seonghobae cec680d
fix(test): keep drag event payload in browser context
seonghobae 510f7fd
test(browser): exercise commercial cloud boundaries
seonghobae 169a394
test(browser): correct offline cloud expectation
seonghobae 45e1fdc
test(browser): prove secure-id failure is fail-closed
seonghobae 4d39ff6
test(coverage): reproduce remaining browser trust boundaries
seonghobae 5cf6e91
fix(browser): close exact coverage gaps at causal boundaries
seonghobae df0a648
fix(stack): restore complete browser planner after coverage repair at…
seonghobae e250878
fix(browser): validate file-picker handles before sync
seonghobae 1a33ef7
chore(browser): remove unapplied file-picker adapter
seonghobae 9add5ca
fix(stack): reconcile exact-head controls with protected dependency bump
seonghobae da14bb4
fix(stack): reconcile billing root with current develop
seonghobae 07e93b2
test(browser): prove failed file writes do not retain sync authority
seonghobae 958387a
fix(sync): commit JSON file authority only after durable write
seonghobae f49fc33
test(browser): cover invalid file picker shapes
seonghobae 124a6da
test(browser): cover exact-head interaction residuals
seonghobae b37abec
test(browser): cover stale insertion anchor recovery
seonghobae 196227d
test(ci): require CodeQL on stacked pull requests
seonghobae eb05b38
fix(ci): run CodeQL on stacked pull requests
seonghobae 058c2cd
test(ci): tolerate trigger rationale comments
seonghobae c183216
docs(ci): reconcile exact-head evidence authority
seonghobae e0319de
docs(changelog): correct CodeQL stacked-PR evidence
seonghobae 0ffb077
test(ci): exercise browser defensive fallback contracts
seonghobae 6eacc1a
fix(ci): remove unreachable browser coverage fallbacks
seonghobae b80d502
fix(stack): reconcile billing root with Playwright develop update
seonghobae 3a426cf
fix(stack): inherit protected Playwright 1.62.1 in exact-head controls
seonghobae 8dc44d6
test(ci): fix CodeQL contract success marker
seonghobae 63110a3
test(ci): cover remaining browser production paths
seonghobae 36a4c91
test(ci): isolate browser coverage server ports
seonghobae 1a4e55b
test(e2e): target stable root-task control
seonghobae f55f3b1
test(coverage): reject omitted production modules
seonghobae b148e66
fix(coverage): include every production runtime module
seonghobae e4fa739
merge(billing): carry trusted checkout repair into exact coverage
seonghobae e4c471b
test(ci): require direct browser coverage dependencies
seonghobae a220d8d
fix(ci): declare browser coverage tool dependencies
seonghobae 3f4b590
fix(ci): lock browser coverage tool dependencies
seonghobae a371e06
fix(ci): preserve reviewed dependency lock metadata
seonghobae 39a48bf
fix(stack): remove unrelated billing slice from CI controls
seonghobae fce3925
test(ci): reproduce product guard regressions in coverage branch
seonghobae 54bb312
fix(ci): preserve shipped defensive product guards
seonghobae 4d9a916
fix(ci): keep server coverage behavior-neutral
seonghobae 1f6531c
chore(ci): remove overlapping buyer-surface changes
seonghobae d295fc3
test(ci): reproduce uncovered server entrypoint
seonghobae 096d225
test(ci): register server entrypoint regression
seonghobae 0782f6f
fix(ci): execute and close the server entrypoint under coverage
seonghobae 107cd45
test(server): reject whitespace-only port configuration
seonghobae 106bda4
fix(server): fail closed on whitespace-only port values
seonghobae bc41066
test(ci): require OSV introduced findings to fail closed
seonghobae 2371285
fix(ci): fail OSV on introduced vulnerabilities
seonghobae d908ce3
test(ci): isolate OSV evidence from PR-controlled paths
seonghobae ebe1c97
fix(ci): isolate OSV evidence from PR-controlled symlinks
seonghobae 6c897fd
test(ci): fail closed on incomplete OSV scans
seonghobae cbcad7e
fix(ci): fail closed when OSV scans abort
seonghobae 863bdba
test(ci): require OSV SARIF upload after finding failure
seonghobae 1c96b92
fix(ci): upload OSV SARIF on vulnerability findings
seonghobae d1fdd01
fix(ci): repair balanced-match lock integrity
seonghobae 740e98a
fix(ci): preserve package lock metadata
seonghobae fb8408c
test(ci): guard package lock registry metadata
seonghobae 75ff15a
test(ci): run package lock metadata regression
seonghobae 8c4cb4c
fix(ci): restore canonical lock registry metadata
seonghobae f6d9877
test(ci): reject corrupted lock license metadata
seonghobae c684ff0
fix(ci): restore yargs-parser lock license metadata
seonghobae 9e84f48
test(ci): require non-publishing CodeQL database mode
seonghobae 9c05326
fix(ci): disable required CodeQL database uploads
seonghobae a401e0c
test(ci): reject duplicate CodeQL required check names
seonghobae acc09f8
fix(ci): disambiguate CodeQL protected checks
seonghobae 431f010
test(ci): require coverage from every Playwright page
seonghobae 89ad7f9
fix(ci): capture coverage from secondary Playwright pages
seonghobae 4cba725
test(ci): reject stale advanced CodeQL publisher
seonghobae c14ac41
fix(ci): retire disabled advanced CodeQL publisher
seonghobae bcad2b6
test(ci): make stacked CodeQL contract single-authority
seonghobae 9c5d7e1
test(ci): reject unused CodeQL write permission
seonghobae 19140bb
fix(ci): drop unused CodeQL write authority
seonghobae 273674e
docs(ci): make CodeQL authority code-current
seonghobae ee8bb7e
docs(ci): make CodeQL changelog single-authority
seonghobae 96af111
test(ci): reject ambiguous failed OSV scan evidence
seonghobae c3e631b
fix(ci): fail closed on ambiguous OSV scan failures
seonghobae e7adced
test(ci): require complete coverage failure diagnostics
seonghobae 5e4f57a
fix(ci): continue coverage failure diagnostics
seonghobae 7f2b24b
test(ci): run coverage diagnostics workflow contract
seonghobae 4b96b14
test(ci): keep OSV out of CodeQL code-scanning ownership
seonghobae 83de84c
fix(ci): keep OSV evidence out of CodeQL scanning
seonghobae 355d85b
test(ci): align OSV contract with CodeQL-only ownership
seonghobae 9c12035
test(ci): require clean OSV contributor scan tree
seonghobae 6dcec94
fix(ci): sanitize OSV contributor scan tree
seonghobae 2304fb6
fix(ui): keep non-Gantt modal controls reachable
seonghobae b737ad9
test(ci): require exact-head dependency review evidence
seonghobae 6f86462
test(ci): register dependency review evidence contract
seonghobae 95a15bc
fix(ci): bind dependency review to exact live revisions
seonghobae 12a0c11
test(server): cover nullable audit and live billing boundaries
seonghobae c20fff8
fix(server): make strict coverage reflect reachable contracts
seonghobae 728a891
test(api): normalize sqlite row prototype in audit assertion
seonghobae e83add7
fix(web): preload production modules
seonghobae bd1ce35
fix(ui): preserve delegated modal close targets
seonghobae cd11b25
fix(sync): commit file handle only after durable write
seonghobae 18bc414
revert: preserve existing app commentary before focused autosave repair
seonghobae 92468f0
fix(sync): retain autosave authority only after successful write
seonghobae b44c238
test: exercise browser analytics coverage boundaries
seonghobae 88b025b
test: cover demo billing checkout boundary
seonghobae 5b469e8
test(ci): reproduce browser coverage failure masking
seonghobae 00a614e
test(ci): run browser failure precedence regression
seonghobae 44abe3d
fix(ci): preserve browser test failure authority
seonghobae e76f259
fix(ci): keep Playwright failure primary in coverage collector
seonghobae 081ef40
test(ci): bind coverage contract to failure precedence guard
seonghobae 541bbfb
test(ci): cover exact analytics browser boundaries
seonghobae 2cf753a
test(ci): retain checkout redirect coverage on failed navigation
seonghobae 112a017
test(ci): cover corrupt persisted date recovery
seonghobae ddc48f4
test(coverage): exercise browser invariant boundaries
seonghobae c86a9a7
test(ci): reject stale live-base dependency evidence
seonghobae 165d6fd
fix(ci): reject diverged dependency baselines
seonghobae 94a8d16
test(coverage): exercise module-private invariant branches
seonghobae b806e77
test(e2e): bind helper coverage to exact app breakpoint
seonghobae 7066fcd
test(e2e): avoid debugger pause race in coverage probe
seonghobae 1f44e23
test(e2e): cover editor fallback through real events
seonghobae 37901a0
fix(browser): remove unreachable window guard
seonghobae 18b7b7b
test(e2e): restore module-scoped invariant coverage
seonghobae 535dd31
test(ci): reject duplicate unit and API execution
seonghobae 9e72573
fix(ci): avoid duplicate unit and API suites
seonghobae a73e8be
fix(ci): bound manual fuzz iteration input
seonghobae c3a326a
test(ci): require CodeQL v4.37.8 pin
seonghobae 365f092
ci: preserve CodeQL v4.37.8 on exact-head workflow
seonghobae 0d50f4e
test(ci): align exact-head CodeQL contract with v4.37.8
seonghobae 55520ec
test(ci): require OSV v2.5.1 pin
seonghobae 9744fdb
ci: preserve OSV v2.5.1 on exact-head scan
seonghobae 180ad6c
test(ci): require singular live-base resolution
seonghobae ca81000
ci: enforce singular live-base resolution
seonghobae adcaedb
test(ci): require exact-head OSV code-scanning evidence
seonghobae 166f129
test(ci): align OSV exact-head code-scanning contract
seonghobae 18a4ef3
fix(ci): restore exact-head OSV code-scanning evidence
seonghobae 9d3784a
test(ci): reject OSV code-scanning publication
seonghobae 7e13a54
fix(ci): keep OSV SARIF out of CodeQL-only analysis
seonghobae e57f8b6
test(ci): align OSV exact-head contract with CodeQL-only policy
seonghobae 70358e8
test(ci): require complete browser suite in protected gate
seonghobae f949e00
fix(ci): run complete browser suite in required gate
seonghobae 135117e
test(e2e): stabilize invariant probe outside coverage lane
seonghobae 85c99c8
test(ci): pin OSV analysis configuration identity
seonghobae 09be4ae
test(ci): execute OSV configuration identity regression
seonghobae 1a230a0
test(ci): align OSV contract with protected configuration identity
seonghobae 7779ed2
fix(ci): preserve OSV analysis configuration identity
seonghobae e08dbb3
test(ci): require substantive exact-head OSV analysis identity
seonghobae 42614e1
fix(ci): restore exact-head OSV code-scanning identity
seonghobae 7cb8b09
test(ci): align OSV exact-head workflow contract with GHAS
seonghobae 79a0488
test(ci): align OSV fail-closed contract with exact-head GHAS
seonghobae c6b782a
test(ci): restore CodeQL-only OSV ownership regression
seonghobae e28b5ca
fix(ci): keep OSV read-only under CodeQL-only scanning
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,56 @@ | ||
| name: CodeQL Required | ||
|
|
||
| on: | ||
| # No base-branch filter: stacked PRs target feature branches, and their | ||
| # exact contributor heads still require CodeQL evidence before integration. | ||
| pull_request: | ||
| push: | ||
| branches: ["develop", "master"] | ||
| schedule: | ||
| - cron: "15 2 * * 6" | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: codeql-required-${{ github.event.pull_request.number || github.ref }} | ||
| cancel-in-progress: true | ||
|
|
||
| jobs: | ||
| analyze: | ||
| name: Analyze (${{ matrix.language }}) | ||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| contents: read | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| language: | ||
| - javascript-typescript | ||
| - python | ||
| steps: | ||
| - name: Checkout exact revision | ||
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| persist-credentials: false | ||
|
|
||
| - name: Verify exact checkout | ||
| env: | ||
| EXPECTED_CHECKOUT_SHA: ${{ github.event.pull_request.head.sha || github.sha }} | ||
| run: | | ||
| set -euo pipefail | ||
| actual_sha="$(git rev-parse HEAD)" | ||
| test "$actual_sha" = "$EXPECTED_CHECKOUT_SHA" | ||
|
|
||
| - name: Initialize CodeQL | ||
| uses: github/codeql-action/init@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 | ||
| with: | ||
| languages: ${{ matrix.language }} | ||
|
|
||
| - name: Perform CodeQL analysis | ||
| uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 | ||
| with: | ||
| category: "/language:${{ matrix.language }}" | ||
| upload: never | ||
| upload-database: false | ||
This file was deleted.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.