Skip to content

Add Vulture/CVE CI gates, switch license-scan to push/main - #15

Merged
Wewoc merged 2 commits into
mainfrom
claude/magical-ritchie-807x8r
Sep 30, 2026
Merged

Wewoc merged 2 commits into
mainfrom
claude/magical-ritchie-807x8r

Conversation

@Wewoc

@Wewoc Wewoc commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • vulture-check.yml: gates push/main on check_vulture.py's exit code (dead-code findings after whitelist filtering). Precondition — full triage of the Vulture TODO list — confirmed complete with v1.7.3.3 (vulture_whitelist.py populated, no open findings).
  • cve-check.yml: report-only, mirrors license-scan.yml's pattern (never fails the job — check_cve_whitelist.py always exits 0 by design). Runs on push/main plus a weekly cron, since new CVEs can surface without a code change. Uploads the report as a build artifact.
  • license-scan.yml: trigger switched from workflow_dispatch-only to push/main, matching the other two workflows.
  • windows-test-feasibility.yml: workflow_dispatch-only, experimental. Probes whether run_tests.ps1's pytest-qt suite (test_qt_app.py) can run on a windows-latest runner (no display available). Not wired into any required check — meant to inform a decision on whether a permanent Windows CI test workflow is worth pursuing.

All four follow license-scan.yml's ubuntu-latest + pywin32-filter approach for installing requirements.txt on a Linux runner (where applicable).

Test plan

  • YAML syntax validated locally for all four files
  • Trigger windows-test-feasibility.yml via workflow_dispatch after merge to confirm whether QT_QPA_PLATFORM=offscreen is sufficient for pytest-qt on windows-latest

🤖 Generated with Claude Code

https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g


Generated by Claude Code

Summary by CodeRabbit

  • Chores
    • Added automated checks for dependency vulnerabilities and unused code, with reports saved as workflow artifacts.
    • Added a manually triggered Windows test workflow, including Qt smoke tests and a test run.
    • License scans now run on pushes to the main branch; manual triggering is no longer available.

vulture-check.yml: gates push/main on check_vulture.py's exit code
(dead-code findings after whitelist filtering). Precondition for this
gate — full triage of the Vulture TODO list — was confirmed complete
with v1.7.3.3 (vulture_whitelist.py is populated, no open findings).

cve-check.yml: report-only, mirrors license-scan.yml's pattern (never
fails the job — check_cve_whitelist.py always exits 0 by design). Runs
on push/main plus a weekly cron, since new CVEs can surface without a
code change. Uploads the report as a build artifact for visibility.

Both follow license-scan.yml's ubuntu-latest + pywin32-filter approach
for installing requirements.txt on a Linux runner.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g
…probe

license-scan.yml: trigger changed from workflow_dispatch-only to
push/main, same as the Vulture/CVE workflows — avoids forgetting to
run it manually.

windows-test-feasibility.yml: workflow_dispatch-only, experimental.
Probes whether run_tests.ps1's pytest-qt suite (test_qt_app.py) can
run on a windows-latest runner, which has no display. Runs the Qt
smoke test once without QT_QPA_PLATFORM to capture the raw failure (if
any), once with QT_QPA_PLATFORM=offscreen, then the full run_tests.ps1
under offscreen mode. Not wired into any required check — its result
is meant to inform a decision with Timo on whether a permanent
Windows CI test workflow is worth pursuing, and if so, on which
runner OS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9f1f3ede-7337-4ee3-b4d0-bb7d7367f02a

📥 Commits

Reviewing files that changed from the base of the PR and between 59f1206 and 93cfdb7.

📒 Files selected for processing (4)
  • .github/workflows/cve-check.yml
  • .github/workflows/license-scan.yml
  • .github/workflows/vulture-check.yml
  • .github/workflows/windows-test-feasibility.yml
 ___________________________________________________
< My threat model includes gremlins after midnight. >
 ---------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Wewoc
Wewoc merged commit 8dcc150 into main Sep 30, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants