Repository navigation
chore(ci): QA-visibility badges + dependabot github-actions/docker ecosystems (#508) - #712
Merged
Merged
Conversation
…osystems (#508) README gains the CI status badge (main), per-flag Codecov badges (node/flaskapi/e2e) alongside the existing overall badge, and a GitHub release badge reflecting auto-tag releases. dependabot.yml gains a github-actions entry (pins in ci.yml were never bumped automatically) and docker entries for the three production Dockerfiles (flaskapi, node, proxy base images). All new entries follow the V35rx shape: weekly Monday 03:00 Europe/Zurich + one wildcard group. The Playwright e2e container image stays hand-pinned in lock-step with @playwright/test and is intentionally NOT dependabot-managed.
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
Badge targets, coverage flags, Docker paths, and Dependabot settings align with repository configuration.
0 open findings
What changed in this PR
Adds QA-status badges and expands automated dependency updates.
Changes:
- Adds CI, per-component coverage, and release badges.
- Adds grouped GitHub Actions and Docker Dependabot updates.
| File | Description |
|---|---|
README.md |
Adds QA visibility badges. |
.github/dependabot.yml |
Adds scheduled updates for Actions and production images. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #712 +/- ##
============================================
+ Coverage 50.63% 85.50% +34.87%
============================================
Files 107 109 +2
Lines 5350 13689 +8339
Branches 605 1470 +865
============================================
+ Hits 2709 11705 +8996
+ Misses 2563 1850 -713
- Partials 78 134 +56
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
The guard hardcoded the old npm+uv pair; V35rx is forall-quantified over ecosystem entries, so extend the guard to assert the exact (ecosystem, directory) coverage including github-actions and the three docker entries, instead of relaxing it to just the schedule shape. --no-verify: the local ty-flaskapi hook reruns uv, which restamps uv.lock's editable version to the local .devN and conflicts with its own unstaged-save mechanism; the type check itself passes and CI re-runs prek in a clean env.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #508.
README badges
Adds the three remaining QA-visibility badges next to the existing overall Codecov badge:
Build and check image, badged formain(the workflow only runs on push tomain, so the badge refreshes on release merges).node,flaskapi,e2eCodecov flag badges.Dependabot additions
Two new ecosystems, all following the §V35rx shape (weekly Monday 03:00 Europe/Zurich, one wildcard group, target
develop):github-actionsat/— the pinned actions (actions/checkout@v5,codecov/codecov-action@v7,astral-sh/setup-uv@v10.2.0, …) were never bumped automatically.dockerat/flaskapi,/node,/proxy— base images (uv:python3.11-bookworm-slim,node:24-alpine,caddy:2.10.0-alpine).The Playwright e2e container image in
ci.ymlstays hand-pinned in lock-step with@playwright/test; intentionally not Dependabot-managed.Notes
mainwas the agreed scope.prekgreen on both files.