Skip to content

feat: E2E deployment gate with floors, fixtures, SHA pins - #20

Merged
zhongliang02 merged 13 commits into
prodfrom
feat/deployment-gate
Sep 16, 2026
Merged

zhongliang02 merged 13 commits into
prodfrom
feat/deployment-gate

Conversation

@zhongliang02-bot

@zhongliang02-bot zhongliang02-bot Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Test infrastructure only — codeql-config.yml is unchanged, so nothing consumers scan changes on merge. Closes Codex NO-GO findings #1, #7, #10.

What it adds

  • gate/ — derives the scan matrix from the config's own packs: keys, then asserts against this run's SARIF (no baseline filtering): query-count floor (catches query-filters over-excluding) and expected custom rule IDs loaded (catches a pack that installs but skips its queries, or a CLI bump that drops one).
  • No fixtures here. Whether a query is any good is a question about the query — already tested by codeql-pack's unit tests and fixtures. This repo owns the config, so it asserts only that coverage is live.
  • Floors live in gate/config.json — bumping one is a reviewed diff, not a magic number.
  • ci.yml rewired to run those assertions; all uses: SHA-pinned (also in sample-workflow.yml).
  • Tag v1.0.0 created at a4c7e5d — the rollback point.

Evidence

Before you merge

Comment thread gate/fixtures/javascript-typescript/bad/disabled-cert-validation.js Fixed
@zhongliang02
zhongliang02 merged commit 86a4d33 into prod Sep 16, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants