Skip to content

refactor(ci): extract shared quality-gate reusable workflow for 2 of 8 duplicated files - #1683

Merged
seonghobae merged 6 commits into
mainfrom
claude/zealous-pare-876b64
Sep 2, 2026
Merged

seonghobae merged 6 commits into
mainfrom
claude/zealous-pare-876b64

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

An audit flagged 8 .github/workflows/*-quality-ci.yml files as sharing a
near-identical bootstrap template. This PR does the real work of figuring out
which parts of that duplication are safe to templatize and which aren't, and
acts only on the safe part.

  • Verified job-name safety first. Neither caller's job name
    (exact-head-coverage-contract, exact-head-policy) appears in this
    repo's branch-protection required status checks (gh api repos/ContextualWisdomLab/.github/branches/main/protection) or in the
    org's required-workflow ruleset (which per docs/CWL-MASTER-CONTEXT.md
    only governs Strix/OpenCode Review/the PR Review Merge Scheduler) — so
    restructuring these two files can't silently break a required check,
    here or in a sibling repo.
  • Extracted the one genuinely duplicate pair.
    javascript-coverage-quality-ci.yml
    and
    organization-commercial-readiness-loop-quality-ci.yml
    had byte-for-byte identical logic (same pinned six-package requirements
    heredoc, same coverage run --branch -m pytest --import-mode=importlib +
    coverage report --fail-under=100 + compileall + git diff --exit-code
    shape) differing only in timeout-minutes, the pytest target, and the
    coverage --include path. Extracted that shape into a new
    workflow_call-only
    exact-head-coverage-quality-gate.yml
    reusable workflow (4 required inputs: timeout_minutes, pytest_target,
    coverage_include, compileall_targets) and turned both callers into
    thin uses:/with: wrappers, following this repo's existing
    workflow_call convention (deploy-pages.yml, pr-review-fix-scheduler.yml).
  • Left the other 6 files alone. agent-mention-router-quality-ci.yml,
    exact-artifact-sbom-attestation-quality.yml,
    noema-token-lifetime-quality-ci.yml,
    opencode-rust-coverage-toolchain-quality-ci.yml,
    strix-changed-path-quality-ci.yml, and
    trusted-uv-materializer-quality-ci.yml look similar at a glance but each
    enforces a genuinely different policy: harden-runner presence, a
    docstring/interrogate gate, different exact-head-verification mechanics
    (noema has no ref: pin at all), multi-Python-version matrices with
    non-shared extra logic (a tomli-fallback exercise, a compile-only Python
    3.10 contract), or (strix) no coverage --fail-under step at all —
    delegating instead to a bash gate script. Forcing these into one template
    would either weaken what they individually enforce or need enough
    per-caller toggles to defeat the point of sharing. This mirrors the
    precedent already documented in this repo for ruling out consolidating
    the agent-mention dispatch pair and the noema/opencode/strix
    "cancel superseded runs" jobs.

Contract tests updated

  • tests/test_organization_commercial_readiness_loop_policy.py and
    tests/test_organization_commercial_readiness_loop_import_contract.py now
    check the coverage/exact-head mechanics against the shared gate file and
    the subsystem wiring (coverage_include, fixtures path) against the
    caller, instead of the old inline text.
  • Added tests/test_exact_head_coverage_quality_gate_contract.py to pin the
    new gate's workflow_call-only contract, its required/typed inputs, and
    both callers' distinct input wiring.
  • javascript-coverage-quality-ci.yml had no dedicated contract test before
    this change; behavior is now covered indirectly through the new gate test
    plus the org-loop tests exercising the same shared file.

Test plan

  • PYTHONPATH=. coverage run -m pytest tests -q — 2603 passed, 1 skipped
  • coverage report --show-missing — 100% branch coverage on scripts/ci
  • interrogate — 100% docstrings
  • actionlint on the 3 changed workflow files — clean

🤖 Generated with Claude Code


Devin Review

…8 duplicated files

An audit of the 8 .github/workflows/*-quality-ci.yml files that share a
bootstrap-templated skeleton found only one pair -- javascript-coverage-quality-ci.yml
and organization-commercial-readiness-loop-quality-ci.yml -- where the shared shape
(exact-head checkout, an identical pinned six-package requirements heredoc, coverage
run --branch + --fail-under=100, compileall, git diff --exit-code) was genuinely the
same logic, differing only in timeout, pytest target, and coverage --include path.
Extract that into a new workflow_call-only exact-head-coverage-quality-gate.yml and
turn both callers into thin uses:/with: wrappers.

Verified first that no branch-protection required status check or the org's
required-workflow ruleset references either caller's job name, so restructuring them
is safe. Updated the contract tests that pinned the old inline text and added one for
the new gate's own contract and both callers' input wiring.

The other 6 files each encode a genuinely different policy (harden-runner presence, a
docstring gate, exact-head-verification mechanics, multi-Python-version matrices with
non-shared extra logic, or no coverage --fail-under step at all) so templatizing them
would weaken what they individually enforce. Left untouched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 4 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 7c4e30f3-c75b-4958-9485-b7dae692749c

📥 Commits

Reviewing files that changed from the base of the PR and between 9330d41 and 1a6d38b.

📒 Files selected for processing (7)
  • .github/workflows/exact-head-coverage-quality-gate.yml
  • .github/workflows/javascript-coverage-quality-ci.yml
  • .github/workflows/organization-commercial-readiness-loop-quality-ci.yml
  • CHANGELOG.md
  • tests/test_exact_head_coverage_quality_gate_contract.py
  • tests/test_organization_commercial_readiness_loop_import_contract.py
  • tests/test_organization_commercial_readiness_loop_policy.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 3 potential issues.

Devin Review

- name: Checkout exact source revision
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Exact-head context survives delegation

Reusable calls retain the caller’s pull-request context. github.event.pull_request.head.sha therefore still binds checkout and verification to the exact head.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +75 to +80
python -m coverage run --branch -m pytest --import-mode=importlib ${{ inputs.pytest_target }} -q
python -m coverage report \
--include='${{ inputs.coverage_include }}' \
--show-missing \
--fail-under=100
python -m compileall -q ${{ inputs.compileall_targets }}

@devin-ai-integration devin-ai-integration Bot Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Caller arguments preserve command behavior

Folded inputs become space-separated shell words. The organization globs still expand into the same pytest and compileall arguments as before.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread .github/workflows/exact-head-coverage-quality-gate.yml Outdated
Resolve CHANGELOG.md conflict by keeping both this PR's quality-CI
consolidation entry and main's hourly-review-repair-callers entry
(#1673), newest first.

Also fold in a fix for a Devin Review finding on the new
exact-head-coverage-quality-gate.yml reusable workflow: route
pytest_target/coverage_include/compileall_targets through step-level
env vars instead of interpolating ${{ inputs.* }} directly into the
run: script, matching this repo's own established convention
(test_verifier_is_data_only_and_workflow_never_executes_downloaded_evidence
in test_exact_artifact_sbom_attestation_contract.py already enforces
this for exact-artifact-sbom-attestation.yml). Verified glob/word-split
behavior for the two callers is unchanged.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@seonghobae seonghobae added priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep labels Sep 2, 2026 — with ChatGPT Codex Connector
seonghobae and others added 2 commits September 2, 2026 18:40
Resolve CHANGELOG.md conflict by keeping both this PR's quality-CI
consolidation entry and main's active_workflow_runs caching entry
(ADR-0022), newest first. Full suite after merge: 2591 passed, 1
skipped, 100% branch coverage, 100% docstrings, actionlint clean on
the workflow files this PR touches.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Resolve CHANGELOG.md conflict by keeping both this PR's quality-CI
consolidation entry and main's fail-closed stale-workflow-cancellation
entry, newest first. Full suite after merge: 2625 passed, 1 skipped,
100% branch coverage, 100% docstrings.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
devin-ai-integration[bot]

This comment was marked as resolved.

seonghobae and others added 2 commits September 2, 2026 19:13
javascript-coverage-quality-ci.yml's pytest_target is the whole tests
directory, so it already executes
tests/test_exact_head_coverage_quality_gate_contract.py -- but that
file was missing from the workflow's own path trigger, so an edit
scoped only to that test could merge without the gate that runs it
ever firing (Devin Review finding on PR #1683). Added the file to the
JS caller's path list, not the org-loop caller's: org-loop's
pytest_target is a narrower glob that never matches this filename, so
adding it there would trigger a job that doesn't actually exercise the
test. Pinned this with a new contract test.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copy link
Copy Markdown
Contributor Author

A sibling session here — this PR was behind main (base at 67998ec, main had moved 10 commits ahead) and its owning session appeared idle, so I merged current main in (non-destructive merge commit 1a6d38b, no rebase/force-push) to keep it current per the standing directive's stacked-PR guidance. Clean merge, no conflicts. Verified: full suite 2630 passed, 1 skipped, 21 subtests on the merged head. No functional changes of my own — this PR's own diff/intent is untouched.


Generated by Claude Code


Generated by Claude Code

@seonghobae
seonghobae merged commit c2bb59e into main Sep 2, 2026
13 of 33 checks passed
@seonghobae
seonghobae deleted the claude/zealous-pare-876b64 branch September 2, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants