Skip to content

Bring the gates up to the campaign standard - #8

Merged
exploitintel merged 1 commit into
mainfrom
chore/tooling
Aug 19, 2026
Merged

exploitintel merged 1 commit into
mainfrom
chore/tooling

Conversation

@exploitintel

Copy link
Copy Markdown
Owner

Part of the estate-wide campaign in eipv3-quality-campaign.md. Full rationale is in the commit messages, which are written to be read.

Verified locally with every step's exit code checked individually, not chained:

ruff check / ruff format --check / mypy / tests with the coverage gate  all PASS
git diff --check                                                       PASS

claude-code-review.yml is deliberately untouched: workspace AGENTS.md rule 8 says the review job skips itself with a green check when a PR modifies its own workflow file, so pinning it here would ship everything else unreviewed. That pin follows in its own PR, and until it lands "Actions pinned" is not fully true for this repo.

Four gaps against the campaign standard in eipv3-quality-campaign.md. This
repository was already the closest to it: four gates, required-version, the mypy
stale-exemption guard, an ASCII-dash check nothing else has, and every Action
pinned across all three workflows.

The coverage gate was 90 against a measured 93.24 floor, so three points of
slide were allowed. Now 92, in all four places that carry the figure: both the
quality and the release workflow, AGENTS.md, and CONTRIBUTING.md. Raising only
the pull-request gate would have left the path that publishes to PyPI as the lax
one, which is backwards, and CONTRIBUTING.md ships inside the sdist so a stale
figure would have been published with the package.

pytest-cov moves from >=5 to ==7.1.0 and coverage is pinned at ==7.15.4. They
produce the gated number, and coverage.py's statement set is not stable across
its own releases. build gains the <2 cap that both workflows already apply, so a
local build no longer resolves differently from CI.

twine keeps its range, but not for the reason an earlier draft of this message
gave. `twine check` is a hard step in both workflows, so a gate does depend on
its version. Pinning it in requirements-dev.txt would not have helped: the
constraint the gate actually uses is the literal "twine>=6,<7" inside each
workflow, and the strictness comes from the unpinned transitive readme-renderer.

The warn_unused_configs comment claimed an exemption cannot outlive the errors
it was added for. That is false: the flag fires only when an override names a
module mypy never processes, so a module whose errors were fixed keeps its
exemption silently.

AGENTS.md now records that this suite's coverage is terminal-width dependent.
Rich sizes output to the terminal, so a wide one executes render branches a
narrow one does not: 93 percent unset or at 80 columns, 95 at 140. CI has no tty
and sees 93.
@claude

claude Bot commented Aug 19, 2026

Copy link
Copy Markdown

Reviewed against the API-client / hostile-terminal-data boundary checklist (filters/sorts/cursors, page-local re-ranking, exploit-works claims, corpus-text escaping, token handling, archive extraction, JSON-mode integrity, pagination/concurrency bounds, scope creep into acquisition/generation/writes).

This PR only touches CI/tooling config and docs — .github/workflows/quality.yml, .github/workflows/release.yml, AGENTS.md, CONTRIBUTING.md, pyproject.toml (mypy comment only), and requirements-dev.txt (dev dependency pins). No files under src/ are modified, so none of the checklist areas are implicated.

No findings.

@exploitintel
exploitintel merged commit 325e372 into main Aug 19, 2026
4 checks passed
@exploitintel
exploitintel deleted the chore/tooling branch August 19, 2026 09:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant