fix(ci): make main deployable again — coverage, CVEs, and the image job
ci / e2e (pull_request) Blocked by required conditions
ci / shared (pull_request) Failing after 13s
ci / test (pull_request) Successful in 10m18s
ci / image (pull_request) Skipped

Found while preparing the tenant-registry enforcement flip: the deployed
portal image is from June 10, so the service-token code merged in #21
never shipped — flipping tenant-registry would have broken every portal
page. Three independent defects:

1. The image job's job-level hashFiles('Dockerfile') condition evaluates
   BEFORE checkout against an empty workspace — always false, job
   silently skipped on every main push. Same bug just fixed in
   tenant-registry (#16).

2. The test job was red on #21's merge: this repo pins 100%
   function/branch coverage and my local run skipped --coverage. Closed
   for real, not lowered: two dead json() arrows removed from mocks the
   code never reads (it throws on !ok before touching the body), and a
   new test exercising the expires_in ?? 300 default-lifetime branch.
   80 tests, 100/100/100/100.

3. The shared job's trivy gate was red on 14 real findings (3 CRITICAL):
   @auth/core 0.37.2 -> 0.41.3 (CVE-2026-73420, Unicode-normalization
   email homoglyph bypass — in the auth library this rollout depends on),
   next 16.2.6 -> 16.2.11, nanoid + postcss via pnpm overrides.
   next-auth 5.0.0-beta.25 -> beta.30; typecheck, lint and build clean
   on the new versions.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Sharang Parnerkar
2026-08-30 23:16:10 +02:00
co-authored by Claude Fable 5
parent f2f9ab74c8
commit 55b42d7dbe
4 changed files with 121 additions and 102 deletions
+4 -1
View File
@@ -122,7 +122,10 @@ jobs:
# --service breakpilot-portal --branch main
# ) accepts unsigned payloads — orca matches on repo + branch.
needs: [shared, test]
if: github.event_name == 'push' && github.ref == 'refs/heads/main' && hashFiles('Dockerfile') != ''
# NOTE: no hashFiles() here — at job level it evaluates BEFORE checkout
# against an empty workspace, so the old condition was always false and
# this job silently never ran (deployment sat on a June-10 image).
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: docker
steps:
- uses: actions/checkout@v4