Both downstream workflows, IntegrationTest.yml and IntegrationTest_OpenSSL_v1_1.yml, check out JuliaWeb/HTTP.jl with no ref, so they get its default branch. That is HTTP.jl master, currently 2.8.0, whose Project.toml has no OpenSSL dependency any more. Pkg.develop(PackageSpec(path=".")) then adds this package to HTTP.jl's environment as an unused dependency and HTTP.jl's test suite runs without ever loading it. A green "HTTP.jl" check on a PR here says nothing about the PR.
The OpenSSL 1.1 variant is worse off: it fails to resolve (empty intersection between OpenSSL_jll@1.1 and project compatibility 3.5.6 - 3) and takes the "not compatible, no problem" exit, so it is green while testing nothing. Seen on #73, where the HTTP.jl jobs passed on every push including ones that broke the package's own suite.
HTTP.jl 1.x is the line that uses this package (compat OpenSSL = "1.3"). The last 1.x release is v1.11.0, tagged off master before 2.0; the only 1.x maintenance branch is release-1.9 (at 1.9.19). Suggestion: give both actions/checkout steps a ref, v1.11.0 for now, or a release-1.11 branch if HTTP.jl makes one, so the jobs exercise the HTTP.jl that actually depends on OpenSSL.jl:
- name: Clone Downstream
uses: actions/checkout@v6
with:
repository: ${{ matrix.package.user }}/${{ matrix.package.repo }}
ref: ${{ matrix.package.ref }}
path: downstream
with - {user: JuliaWeb, repo: HTTP.jl, ref: v1.11.0} in the matrix. Happy to open the PR.
🤖 Generated with Claude Code
Both downstream workflows,
IntegrationTest.ymlandIntegrationTest_OpenSSL_v1_1.yml, check outJuliaWeb/HTTP.jlwith noref, so they get its default branch. That is HTTP.jlmaster, currently 2.8.0, whoseProject.tomlhas no OpenSSL dependency any more.Pkg.develop(PackageSpec(path="."))then adds this package to HTTP.jl's environment as an unused dependency and HTTP.jl's test suite runs without ever loading it. A green "HTTP.jl" check on a PR here says nothing about the PR.The OpenSSL 1.1 variant is worse off: it fails to resolve (
empty intersection between OpenSSL_jll@1.1 and project compatibility 3.5.6 - 3) and takes the "not compatible, no problem" exit, so it is green while testing nothing. Seen on #73, where the HTTP.jl jobs passed on every push including ones that broke the package's own suite.HTTP.jl 1.x is the line that uses this package (compat
OpenSSL = "1.3"). The last 1.x release isv1.11.0, tagged offmasterbefore 2.0; the only 1.x maintenance branch isrelease-1.9(at 1.9.19). Suggestion: give bothactions/checkoutsteps aref,v1.11.0for now, or arelease-1.11branch if HTTP.jl makes one, so the jobs exercise the HTTP.jl that actually depends on OpenSSL.jl:with
- {user: JuliaWeb, repo: HTTP.jl, ref: v1.11.0}in the matrix. Happy to open the PR.🤖 Generated with Claude Code