From 176961247ed2842390f07a28856f40366ff72c56 Mon Sep 17 00:00:00 2001 From: Amr AbuSair Date: Tue, 22 Sep 2026 12:39:35 -0500 Subject: [PATCH] ci(compliance): run the tests when the licence catalogues change MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `data/licenses_all.json` and `data/permissive_names.json` are production data, not fixtures. policy_selector.py fetches them from the mothership over the API, and fetch_mothership_file has no `?ref=`, so it always reads the DEFAULT BRANCH — a change to either file is live across every gated repo the moment it merges, exactly like `scripts/` and `cla/`. The paths filter did not list them, so regenerating a catalogue merged with no test run at all. That was not theoretical. TestOverrideMatchesTheRealCatalogue parses the real data/licenses_all.json and exists specifically to catch the catalogue being regenerated with a different spelling: the allowlist says `LicenseRef-Broadcom_Source_Available` (underscores), the catalogue says `LicenseRef-Broadcom-Source-Available` (hyphens), and only _norm_license_name makes them meet. 48 repos depend on that convergence. The one change the test was written to catch was the one change that could not trigger it. Verified by mutation: rewriting the catalogue's spdx_id to `LicenseRef-BroadcomSourceAvail` fails test_allowlist_and_catalogue_spellings_converge, and the catalogue was restored byte-identical afterwards. Audited the whole suite for the same class of gap by tracing every repo file it opens — `cla/allowlist.yml` and `data/licenses_all.json` are the only two, and both are now covered. 82 tests pass. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/tests.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 49d0dc6..0ca681b 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -15,6 +15,7 @@ on: - 'scripts/**' - 'tests/**' - 'cla/**' + - 'data/**' - '.github/workflows/tests.yml' push: branches: [main] @@ -22,6 +23,7 @@ on: - 'scripts/**' - 'tests/**' - 'cla/**' + - 'data/**' - '.github/workflows/tests.yml' permissions: