Add Vulture/CVE CI gates, switch license-scan to push/main - #15
Merged
Merged
Conversation
vulture-check.yml: gates push/main on check_vulture.py's exit code (dead-code findings after whitelist filtering). Precondition for this gate — full triage of the Vulture TODO list — was confirmed complete with v1.7.3.3 (vulture_whitelist.py is populated, no open findings). cve-check.yml: report-only, mirrors license-scan.yml's pattern (never fails the job — check_cve_whitelist.py always exits 0 by design). Runs on push/main plus a weekly cron, since new CVEs can surface without a code change. Uploads the report as a build artifact for visibility. Both follow license-scan.yml's ubuntu-latest + pywin32-filter approach for installing requirements.txt on a Linux runner. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g
…probe license-scan.yml: trigger changed from workflow_dispatch-only to push/main, same as the Vulture/CVE workflows — avoids forgetting to run it manually. windows-test-feasibility.yml: workflow_dispatch-only, experimental. Probes whether run_tests.ps1's pytest-qt suite (test_qt_app.py) can run on a windows-latest runner, which has no display. Runs the Qt smoke test once without QT_QPA_PLATFORM to capture the raw failure (if any), once with QT_QPA_PLATFORM=offscreen, then the full run_tests.ps1 under offscreen mode. Not wired into any required check — its result is meant to inform a decision with Timo on whether a permanent Windows CI test workflow is worth pursuing, and if so, on which runner OS. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
1 of 2 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
vulture-check.yml: gates push/main oncheck_vulture.py's exit code (dead-code findings after whitelist filtering). Precondition — full triage of the Vulture TODO list — confirmed complete with v1.7.3.3 (vulture_whitelist.pypopulated, no open findings).cve-check.yml: report-only, mirrorslicense-scan.yml's pattern (never fails the job —check_cve_whitelist.pyalways exits 0 by design). Runs on push/main plus a weekly cron, since new CVEs can surface without a code change. Uploads the report as a build artifact.license-scan.yml: trigger switched fromworkflow_dispatch-only to push/main, matching the other two workflows.windows-test-feasibility.yml:workflow_dispatch-only, experimental. Probes whetherrun_tests.ps1's pytest-qt suite (test_qt_app.py) can run on awindows-latestrunner (no display available). Not wired into any required check — meant to inform a decision on whether a permanent Windows CI test workflow is worth pursuing.All four follow
license-scan.yml's ubuntu-latest + pywin32-filter approach for installingrequirements.txton a Linux runner (where applicable).Test plan
windows-test-feasibility.ymlviaworkflow_dispatchafter merge to confirm whetherQT_QPA_PLATFORM=offscreenis sufficient forpytest-qtonwindows-latest🤖 Generated with Claude Code
https://claude.ai/code/session_01JYLx9STTgfo9KXLC2Gog3g
Generated by Claude Code
Summary by CodeRabbit