Skip to content

chore: raise test coverage and stop persisting checkout credentials - #39

Merged
shenxianpeng merged 3 commits into
mainfrom
chore/repo-health-check
Oct 2, 2026
Merged

shenxianpeng merged 3 commits into
mainfrom
chore/repo-health-check

Conversation

@shenxianpeng

@shenxianpeng shenxianpeng commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

This PR contains only three kinds of change:

  • SHA pinning: nothing to change. Every tag ref is already pinned to a full commit SHA, and all seven match their tags. The two same-org reusable workflows stay on @main.
  • No persisted credentials: persist-credentials: false on the four checkouts that lacked it:
    • main.yml: the test and build jobs
    • publish.yml: the build and MCP Registry jobs
  • Coverage: tests only; src/ is unchanged.

Coverage

Measured with pytest-cov on src/commit_check_mcp, against the unmodified source:

Tests Line Branch
main 114 98% (274/279) 101/102
this PR 121 100% (279/279) 102/102

Tests

  • git missing from PATH, both when checking for a repository and when resolving push_refs. These run with an empty PATH rather than a mock.
  • push_refs lines a pre-push hook can receive: abbreviated and upper-case SHAs, a blank line, a deletion, and a revision as the local ref.
  • The upstream fallback against a real upstream on a local bare remote: a branch ahead of it passes, a rewritten one fails.
  • An inline warn list reported alongside the default config sections.
  • tests/test_stdio.py: starts the server the way a client does, as a subprocess on stdio.
  • test_repository_state_include_push_is_unaffected now expects whichever result the installed commit-check gives for a branch without an upstream:
    • skip from 2.18.2 on. CI installs 2.18.2 today, so this test currently fails on main.
    • pass before that, as with the 2.18.0 pinned in uv.lock.

Verification

  • Python 3.12 with src/ unmodified: 121 passed with -W error, at 100% line and branch coverage, in both environments:
    • uv.lock (commit-check 2.18.0, mcp 2.0.0)
    • fresh pip install -e .[dev] (commit-check 2.18.2, mcp 2.2.0)
  • actionlint on the changed workflows: clean.
  • Each pinned SHA checked against its tag with git ls-remote.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d528429b-278b-4d3b-b933-a70af90f386a

📥 Commits

Reviewing files that changed from the base of the PR and between ed82c08 and 1880012.

📒 Files selected for processing (4)
  • .github/workflows/main.yml
  • .github/workflows/publish.yml
  • tests/test_server.py
  • tests/test_stdio.py
 ________________________________________________________________________
< Making the Death Star fully operational, with zero exhaust port flaws. >
 ------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the chore label Oct 1, 2026
@codecov-commenter

codecov-commenter commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (ed82c08) to head (1880012).

Additional details and impacted files
@@             Coverage Diff             @@
##             main       #39      +/-   ##
===========================================
+ Coverage   98.20%   100.00%   +1.79%     
===========================================
  Files           2         2              
  Lines         279       279              
===========================================
+ Hits          274       279       +5     
+ Misses          5         0       -5     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Set persist-credentials: false on the checkouts in the test and build
jobs and in both publish jobs, as the lint job already does. None of them
uses the token after checking out, so it no longer stays in .git/config
for the rest of the job.
commit-check 2.18.2 reports the force-push check as skipped when there
is nothing to compare, where earlier releases reported a pass. CI
installs the newest release the range allows (2.18.2 today), so on main
this test fails with "assert 'skip' == 'pass'", while uv.lock still pins
2.18.0, where it passes.

Expect each release's result, chosen by the installed version, so the
suite passes on both ends of commit-check>=2.18.0,<3.
Brings the server to 100% line and branch coverage without changing it:

- git missing from PATH, when checking for a repository and when
  resolving push_refs, run with an empty PATH rather than a mock;
- push_refs lines a pre-push hook can receive (abbreviated and upper-case
  SHAs, a blank line between refs, a deletion, a revision as local ref);
- the upstream fallback against a real upstream on a local bare remote:
  a branch ahead of it passes, a rewritten one fails;
- an inline warn list reported with the default config sections;
- test_stdio.py starts the server as a client does, a subprocess on
  stdin/stdout, and checks the handshake, the eight tools, structured
  pass and fail results, and a tool error flagged as an error.
@shenxianpeng
shenxianpeng force-pushed the chore/repo-health-check branch from 18dade1 to 1880012 Compare October 2, 2026 19:42
@shenxianpeng shenxianpeng changed the title chore: repository health check (tests, security, deps, CI) chore: raise test coverage to 100% and stop persisting checkout credentials Oct 2, 2026
@shenxianpeng shenxianpeng changed the title chore: raise test coverage to 100% and stop persisting checkout credentials chore: raise test coverage and stop persisting checkout credentials Oct 2, 2026
@shenxianpeng
shenxianpeng marked this pull request as ready for review October 2, 2026 19:55
@shenxianpeng
shenxianpeng merged commit 2f234c6 into main Oct 2, 2026
9 checks passed
@shenxianpeng
shenxianpeng deleted the chore/repo-health-check branch October 2, 2026 19:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants