GRM-172: ci: docs fast-path, notify-failure scoping, post-merge queue
Post-merge / detect-and-configure (push) Successful in 1m1s
Post-merge / release-and-maintain (push) Successful in 54s

Co-authored-by: emil User <emil.simeonov@tutanota.com>
This commit was merged in pull request #281.
This commit is contained in:
2026-09-21 20:21:20 +00:00
committed by kireto
parent 96ff368c7c
commit 1b315e0aba
3 changed files with 58 additions and 38 deletions
+25 -12
View File
@@ -32,6 +32,22 @@ jobs:
- uses: actions/checkout@v4
with:
fetch-depth: 0
# Implements: REQ-1 (GRM-172) — docs-only changes skip the heavy
# quality steps. Detection needs only git, so it runs before setup.
- name: Detect docs-only change
id: docs-only
if: github.event_name == 'pull_request'
run: |
HEAD="${{ github.event.pull_request.head.sha || github.sha }}"
DOCS_ONLY=true
while IFS= read -r f; do
case "$f" in
docs/*|*.md|.devin/*) ;;
*) DOCS_ONLY=false; break;;
esac
done < <(git diff --name-only "origin/master...$HEAD")
echo "docs-only=$DOCS_ONLY" >> "$GITHUB_OUTPUT"
echo "docs-only=$DOCS_ONLY"
- name: Set up environment
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
@@ -39,11 +55,13 @@ jobs:
run: make setup-image EXTRAS=ci,lint
# --- quality steps ---
- name: Lint all
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
make lint-all
- name: Unit tests with 100% coverage
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
make pytest-cov
@@ -57,14 +75,17 @@ jobs:
export PATH="$HOME/.local/bin:$PATH"
make devx-docs-check
- name: Translation completeness check
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.ci.check_translations --translations src/grm/translations.json
- name: Check unit test speed
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
python3 -m devx.tools.check_test_speed --max-seconds 4 --max-single-seconds 0.5
- name: Dependency security scan
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
# Install pip in venv if missing (needed by pip-audit)
@@ -72,6 +93,7 @@ jobs:
PIPAPI_PYTHON_LOCATION=$PWD/.venv/bin/python \
pip-audit --desc --skip-editable 2>&1 || true
- name: Workflow dry-run validation
if: steps.docs-only.outputs.docs-only != 'true'
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
@@ -156,18 +178,9 @@ jobs:
--owner "${{ github.repository_owner }}" \
--repo "${{ github.event.repository.name }}" \
--github-output
- name: Notify on failure
if: failure()
env:
CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }}
run: |
. .venv/bin/activate 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
python3 -m devx.ci.notify_failure --auto-login \
--repo "${{ github.repository }}" \
--run-id "${{ github.run_id }}" \
--workflow "ci/validate" \
--commit "${{ github.sha }}"
# Implements: REQ-2 (GRM-172) — no failure-issue step in PR CI;
# auto-created issues are for deploy-pipeline failures only
# (post-merge keeps its notification).
molecule-tests:
needs: [validate]
+3 -1
View File
@@ -25,7 +25,9 @@ on:
concurrency:
group: post-merge-${{ github.ref }}
cancel-in-progress: true
# Implements: REQ-3 (GRM-172) — queue instead of killing an in-flight
# release/publish; a cancelled release can leave tag-without-publish.
cancel-in-progress: false
env:
PIP_BREAK_SYSTEM_PACKAGES: "1"