Skip to content

ci: actually run the test suite - #2

Merged
tiXor-code merged 1 commit into
mainfrom
ci/run-tests
Aug 25, 2026
Merged

tiXor-code merged 1 commit into
mainfrom
ci/run-tests

Conversation

@tiXor-code

Copy link
Copy Markdown
Owner

Why

51 tests exist in this repo. No workflow has ever run any of them.

What

  • tests.yml (new) — pytest on push-to-main and PRs
  • nightly.yml — a smoke-gate step

Two decisions worth reviewing

paths allowlist, not paths-ignore. scrape.yml commits data/ every 15 minutes (~21-28 commits/day). A naive on: push fires on every one and buries real failures in the run history. I used an allowlist rather than paths-ignore: ['data/**'] because a future scraper output directory would silently re-enable that storm under paths-ignore, but stays excluded under an allowlist.

The nightly step runs BEFORE the backfill. This is the load-bearing bit. Once db/termo.db exists, 15 skipif-gated tests un-skip and assert frozen data constants — universe_size == 947, median_pt_days == 22, top slug pt-modul-toporasi. universe_size comes from data/harta.html, which the scraper rewrites from CMTEB's live map. So the day CMTEB adds one PT to that map, a post-backfill pytest would fail the nightly, and since validate/upload/deploy-hook all sit downstream, the site would silently serve stale data indefinitely.

Before the backfill, db/termo.db does not exist, those 15 stay skipped, and the step is a ~10s pure-code gate. Data invariants remain pipeline.validate's job, which already gates the release properly.

Expected CI result

36 passed, 15 skipped — the skips are correct, not a misconfiguration. A run reporting 51 passed would mean a stale local database was present.

Security

  • Actions SHA-pinned (SEC005), matching the convention just landed in termo-site
  • permissions: contents: read — this job never commits, uploads or deploys
  • No ${{ github.event.* }} reaches any run: block

🤖 Generated with Claude Code

This repo has 51 tests and no workflow has ever run them.

Adds tests.yml (push to main + PRs) and a smoke-gate step in nightly.yml.

Two decisions worth recording:

paths allowlist, not paths-ignore. scrape.yml commits data/ every 15 minutes
(~21-28 commits/day). A naive `on: push` fires on all of them and buries real
failures. An allowlist is used because a future scraper output directory would
silently re-enable that storm under paths-ignore but stays excluded here.

The nightly step runs BEFORE the backfill, not after. Once db/termo.db exists,
15 skipif-gated tests un-skip and assert frozen DATA constants
(universe_size == 947, median_pt_days == 22, top slug pt-modul-toporasi).
universe_size is derived from data/harta.html, which the scraper rewrites from
CMTEB's live map - so the day CMTEB adds one PT, a post-backfill pytest would
fail the nightly and leave the site silently serving stale data. Running before
the backfill keeps those 15 skipped and the step a ~10s code gate. Data
invariants stay pipeline.validate's job, which already gates the release.

Actions are pinned to SHAs (SEC005); permissions are contents: read only, since
this job never commits, uploads or deploys.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified: paths-allowlist YAML is valid and matches real directories (pipeline/, scraper/, scripts/, tests/); the new pytest check on this PR already ran and passed in ~10s, self-confirming the trigger and the skip-count reasoning. Nightly gate is correctly placed before backfill so the 15 db-gated tests stay skipped and can't block a release on a legitimate CMTEB universe change. permissions: contents: read is correctly scoped, actions are SHA-pinned, no untrusted input reaches any run: block.

@tiXor-code
tiXor-code merged commit 19f64b4 into main Aug 25, 2026
2 checks passed
@tiXor-code
tiXor-code deleted the ci/run-tests branch August 25, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant