Skip to content

ci: run the test suite on pull requests - #122

Merged
nimrodkor merged 2 commits into
baz-scm:mainfrom
benglewis:ci/run-tests-in-pr
Aug 25, 2026
Merged

nimrodkor merged 2 commits into
baz-scm:mainfrom
benglewis:ci/run-tests-in-pr

Conversation

@benglewis

Copy link
Copy Markdown
Contributor

Problem

The build-test job in .github/workflows/pr.yml installs, builds, packs, installs the tarball and runs baz -h — but never runs a test. Nothing under src/**/*.spec.* gates a merge today, so a regression test can go red while CI stays green.

Split out of #120, where a new regression test would not have been run by CI.

Change

  • pr.yml: add a Run tests step to build-test, before the build so it fails fast.
  • vitest.config.ts: scope collection to include: ["src/**/*.spec.{ts,tsx}"].

The Vitest scoping is needed for the CI step to be meaningful. tsc copies every spec into dist/, and stale builds and git worktrees leave further copies around, so an unscoped run collects the same test two or three times — and fails outright on copies whose source no longer exists (a dist/components/ScrollableViewport.spec.js with no counterpart in src/ currently does exactly that locally).

Verification

On this branch: npx vitest run collects 2 files / 60 tests from src/ only (was 12 files / 264, mostly duplicates of the same specs). npm run lint and npm run format:check pass.

Note: tsc still emits the specs into dist/, so they ship in the package. Excluding them from the build would also stop type-checking them, so I left that alone — worth a separate look if the packaged size matters.

🤖 Generated with Claude Code

The `build-test` job built and smoke-tested the packed CLI but never ran
a test, so nothing in `src/**/*.spec.*` gated a merge — a regression test
could go red and CI would stay green.

Scope Vitest to the sources first. `tsc` copies every spec into `dist/`,
and stale builds and git worktrees leave further copies behind, so an
unscoped run collects the same test two or three times and fails on
copies whose source no longer exists.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@baz-reviewer

baz-reviewer Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Generated description

Run the Vitest suite in the build-test workflow before building, and restrict vitest.config.ts test discovery to source specs. Harden GitHub Actions checkouts by disabling persisted credentials for jobs that execute pull request code.

Topics
TopicDetails
Checkout security Harden workflow checkouts by setting persist-credentials: false before running untrusted pull request code.
Modified files (1)
  • .github/workflows/pr.yml
Latest Contributors(0)
UserCommitDate
CI test coverage Gate pull requests on npm test and prevent duplicate or stale spec collection by limiting Vitest to src/**/*.spec.{ts,tsx}.
Modified files (2)
  • .github/workflows/pr.yml
  • vitest.config.ts
Latest Contributors(0)
UserCommitDate

Review this PR on Baz | Customize your next review

@baz-reviewer

baz-reviewer Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

⚠️ Advanced Security cannot run on this PR.

Your organization's Advanced Security usage limit has been reached. To continue using Advanced Security reviews, please upgrade your plan or increase your usage limits in your account settings.

Comment thread .github/workflows/pr.yml
actions/checkout stores the job token as an extraheader in .git/config by
default. Both jobs then run code from the pull request - npm lifecycle
scripts, the test suite, knip and the packaged CLI - which can read that
config and use or exfiltrate the token.

Neither job performs an authenticated Git operation, so the credential is
not needed at all.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@nimrodkor
nimrodkor merged commit eada4fd into baz-scm:main Aug 25, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants