Skip to content

ci(quality): add schemathesis API-fuzz nightly (advisory, Fase 8 B.4) - #3956

Merged
diegosouzapw merged 1 commit into
release/v3.8.26from
ci/schemathesis-nightly
Jun 16, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.26from
ci/schemathesis-nightly

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Último item (b) — gate nightly de fuzzing de contrato de API via schemathesis (Fase 8 B.4). Advisory, nightly-only (nunca em PR).

O gate

.github/workflows/nightly-schemathesis.yml: sobe o OmniRoute (mesmo padrão provado do nightly-llm-security — build:cli → node dist/server.js → poll /api/monitoring/health), roda schemathesis run docs/reference/openapi.yaml --url http://localhost:20128 --max-examples 20 --workers 4 --checks all --report junit, sobe o JUnit. Advisory (continue-on-error: true). cron: 23 4 (minuto livre) + workflow_dispatch. timeout-minutes: 30.

  • schemathesis 4.21.7; flags derivadas do --help (v4 usa spec posicional + --url, não o antigo --base-url). Sem secrets-in-job-if; sem input não-confiável.

Validação (smoke end-to-end REAL — auditado por mim)

Subi o OmniRoute local + rodei schemathesis contra ele:

API Operations: Selected 268/268, Tested 268
705 test cases generated → JUnit gerado (269 testcases)

Prova que roda ponta-a-ponta contra o servidor vivo + emite report. Exit 1 (esperado→advisory).

⚠️ Já surfou findings reais (advisory, p/ triagem futura)

O smoke achou: 145 server errors (maioria /v1 sem provider no CI = esperado, mas vale triar os de management), 26 violações de schema, 3 endpoints que aceitam request sem autenticação (potencial — revisar). O nightly vai reportar isso continuamente.

Honesto

  • Validado local: install + spec carrega (268 ops) + flags do --help + smoke end-to-end vivo + JUnit + actionlint pass.
  • CI-only: plumbing GitHub (npm ci/setup-python/upload-artifact) + start do bundle standalone limpo (mesmo padrão do nightly-llm-security que já roda).

Não gera versão.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit 74269a3 into release/v3.8.26 Jun 16, 2026
2 checks passed
diegosouzapw added a commit that referenced this pull request Jun 16, 2026
…drift) (#3962)

The main quality-gate failed on the forward-merge release->main (run 27593205254):
eslintWarnings 3769 > baseline 3760. Measured now on origin/release/v3.8.26
(273ecf7, all cycle merges) via quality:collect = 3769 — identical to CI. The
later gate PRs (#3947/#3949/#3951/#3956/#3961) did not change the count
(scripts/check/*.mjs are eslint-ignored; the new test files added no any/warnings).
The +9 is pre-existing release-wide drift from v3.8.26 feature/other-session merges,
not a product regression. Conscious re-baseline to the real measured value; tighten
via --require-tighten at cycle-end (consistent with prior _eslint_rebaseline notes).

Validated: ratchet passes with the real CI metrics (24 metrics OK, exit 0).
@diegosouzapw
diegosouzapw deleted the ci/schemathesis-nightly branch June 17, 2026 00:54
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…drift) (diegosouzapw#3962)

The main quality-gate failed on the forward-merge release->main (run 27593205254):
eslintWarnings 3769 > baseline 3760. Measured now on origin/release/v3.8.26
(19b37e6, all cycle merges) via quality:collect = 3769 — identical to CI. The
later gate PRs (diegosouzapw#3947/diegosouzapw#3949/diegosouzapw#3951/diegosouzapw#3956/diegosouzapw#3961) did not change the count
(scripts/check/*.mjs are eslint-ignored; the new test files added no any/warnings).
The +9 is pre-existing release-wide drift from v3.8.26 feature/other-session merges,
not a product regression. Conscious re-baseline to the real measured value; tighten
via --require-tighten at cycle-end (consistent with prior _eslint_rebaseline notes).

Validated: ratchet passes with the real CI metrics (24 metrics OK, exit 0).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant