GRM-132: ci: bump devx to 0.33.0, use devx-check-api-identity-checks
Post-merge / detect-type (push) Successful in 50s
Post-merge / validate-commit-msg (push) Successful in 1m5s
Post-merge / release (push) Successful in 1m11s
Post-merge / vikunja (push) Successful in 1m3s
Post-merge / badges (push) Successful in 1m17s
Post-merge / configure-repo (push) Successful in 1m3s
Post-merge / publish (push) Successful in 1m2s
Post-merge / sync-wiki (push) Successful in 2m38s
Post-merge / detect-type (push) Successful in 50s
Post-merge / validate-commit-msg (push) Successful in 1m5s
Post-merge / release (push) Successful in 1m11s
Post-merge / vikunja (push) Successful in 1m3s
Post-merge / badges (push) Successful in 1m17s
Post-merge / configure-repo (push) Successful in 1m3s
Post-merge / publish (push) Successful in 1m2s
Post-merge / sync-wiki (push) Successful in 2m38s
This commit was merged in pull request #199.
This commit is contained in:
@@ -69,3 +69,24 @@ source activate.zsh # zsh
|
|||||||
```
|
```
|
||||||
|
|
||||||
If `.venv` doesn't exist, run `make setup` first.
|
If `.venv` doesn't exist, run `make setup` first.
|
||||||
|
|
||||||
|
## Common Pitfalls
|
||||||
|
|
||||||
|
### Coverage Verification Before Push
|
||||||
|
|
||||||
|
**Always run `make pytest-cov` before pushing** — CI enforces 100%
|
||||||
|
coverage and will fail the PR if any lines are uncovered. This is the
|
||||||
|
most common cause of CI quality job failures after code changes. The
|
||||||
|
pre-push git hook only validates Vikunja task existence, not tests.
|
||||||
|
|
||||||
|
### API Response Type Checking
|
||||||
|
|
||||||
|
Never use `is True`/`is False` identity checks on API response values.
|
||||||
|
Many APIs return boolean values as strings (`"true"`/`"false"`). Use
|
||||||
|
string comparison or truthy/falsy helpers instead.
|
||||||
|
|
||||||
|
### Time Mocking in Tests
|
||||||
|
|
||||||
|
Always mock `time.sleep` and `time.monotonic` in unit tests using
|
||||||
|
`@patch` decorators. Real sleep calls make tests slow and exceed test
|
||||||
|
speed limits.
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
CI_GITEA_TOKEN: ${{ secrets.CI_GITEA_TOKEN }}
|
CI_GITEA_TOKEN: ${{ secrets.CI_GITEA_TOKEN }}
|
||||||
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
|
CI_GITEA_USERNAME: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
run: make setup-image EXTRAS=lint
|
run: make setup-image EXTRAS=ci,lint
|
||||||
- name: Lint all
|
- name: Lint all
|
||||||
run: |
|
run: |
|
||||||
. .venv/bin/activate 2>/dev/null || true
|
. .venv/bin/activate 2>/dev/null || true
|
||||||
|
|||||||
@@ -433,6 +433,23 @@ Change classification is config-driven via `[tool.devx.classify]` in `pyproject.
|
|||||||
- Secrets are passed via temp JSON files, never on the command line (CWE-214)
|
- Secrets are passed via temp JSON files, never on the command line (CWE-214)
|
||||||
- CI triggers only on `opened` and `synchronize` PR events (not `labeled`)
|
- CI triggers only on `opened` and `synchronize` PR events (not `labeled`)
|
||||||
|
|
||||||
|
### Testing Conventions
|
||||||
|
|
||||||
|
- **Always run `make pytest-cov` before pushing** — CI enforces 100%
|
||||||
|
coverage and will fail the PR if any lines are uncovered. The pre-push
|
||||||
|
hook only validates Vikunja task existence, not tests.
|
||||||
|
- **Never use `is True`/`is False` identity checks on API response
|
||||||
|
values** — many APIs return boolean values as strings (`"true"`/
|
||||||
|
`"false"`). Use string comparison or truthy/falsy helpers instead.
|
||||||
|
- **Always mock `time.sleep` and `time.monotonic` in unit tests** — real
|
||||||
|
sleep calls make tests slow and exceed test speed limits. Use
|
||||||
|
`@patch("time.sleep")` and `@patch("time.monotonic")` decorators.
|
||||||
|
- **Extract complex inline shell from workflows to tested Python tools**
|
||||||
|
— SSH loops, curl polling, docker exec chains, and multi-line
|
||||||
|
if/then/else shell blocks should be Python scripts in `scripts/`
|
||||||
|
with unit tests. Simple variable checks and venv activation are fine
|
||||||
|
as inline shell.
|
||||||
|
|
||||||
### Container-Level Fix Verification (Mandatory)
|
### Container-Level Fix Verification (Mandatory)
|
||||||
|
|
||||||
**Rule:** Before pushing any fix that modifies container state (CA certs,
|
**Rule:** Before pushing any fix that modifies container state (CA certs,
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.PHONY: all setup setup-ci setup-quality setup-molecule setup-release setup-image install update lint ansible-lint makefile-lint lint-all lint-ruff lint-format lint-bandit lint-deps typecheck checkmake install-hooks test test-unit pytest-cov molecule molecule-all test-all clean workflow-lint workflow-dryrun workflow-check install-tools
|
.PHONY: all setup setup-ci setup-quality setup-molecule setup-release setup-image install update lint ansible-lint makefile-lint lint-all lint-ruff lint-format lint-bandit lint-deps typecheck checkmake install-hooks test test-unit pytest-cov molecule molecule-all test-all clean workflow-lint workflow-dryrun workflow-check install-tools check-api-identity-checks
|
||||||
.PHONY: configure-gitea-pypi
|
.PHONY: configure-gitea-pypi
|
||||||
.PHONY: create-task create-pr push-with-pr git-push
|
.PHONY: create-task create-pr push-with-pr git-push
|
||||||
|
|
||||||
@@ -173,7 +173,10 @@ makefile-lint:
|
|||||||
echo "checkmake not found, skipping Makefile lint"; \
|
echo "checkmake not found, skipping Makefile lint"; \
|
||||||
fi
|
fi
|
||||||
|
|
||||||
lint-all: lint ansible-lint makefile-lint workflow-lint
|
lint-all: lint ansible-lint makefile-lint workflow-lint check-api-identity-checks
|
||||||
|
|
||||||
|
check-api-identity-checks:
|
||||||
|
@$(BIN)/python -m devx.tools.check_api_identity_checks
|
||||||
|
|
||||||
test-integration:
|
test-integration:
|
||||||
$(BIN)/pytest tests/integration/ -v --no-cov
|
$(BIN)/pytest tests/integration/ -v --no-cov
|
||||||
|
|||||||
+2
-2
@@ -34,7 +34,7 @@ ci = [
|
|||||||
"build==1.5.0",
|
"build==1.5.0",
|
||||||
"twine==6.2.0",
|
"twine==6.2.0",
|
||||||
# Reusable CI/CD and dev tools (auto-merge, pr-review, pre-push checks, etc.)
|
# Reusable CI/CD and dev tools (auto-merge, pr-review, pre-push checks, etc.)
|
||||||
"devx==0.32.0",
|
"devx==0.33.1",
|
||||||
]
|
]
|
||||||
# Lint and type-checking tools (quality job)
|
# Lint and type-checking tools (quality job)
|
||||||
lint = [
|
lint = [
|
||||||
@@ -54,7 +54,7 @@ molecule = [
|
|||||||
dev = [
|
dev = [
|
||||||
"gitea-runner-manager[ci,lint,molecule]",
|
"gitea-runner-manager[ci,lint,molecule]",
|
||||||
# Reusable CI/CD and dev tools (pre-push hooks, create-task, create-pr)
|
# Reusable CI/CD and dev tools (pre-push hooks, create-task, create-pr)
|
||||||
"devx==0.32.0",
|
"devx==0.33.1",
|
||||||
# Non-Python dev dependency: checkmake (Makefile linter)
|
# Non-Python dev dependency: checkmake (Makefile linter)
|
||||||
# Install via: go install github.com/checkmake/checkmake/cmd/checkmake@latest
|
# Install via: go install github.com/checkmake/checkmake/cmd/checkmake@latest
|
||||||
]
|
]
|
||||||
|
|||||||
Reference in New Issue
Block a user