Skip to content

fix(ci): restore the API install and verification baseline - #588

Merged
dDevAhmed merged 3 commits into
mainfrom
stabilization/api-ci-baseline-584
Oct 7, 2026
Merged

dDevAhmed merged 3 commits into
mainfrom
stabilization/api-ci-baseline-584

Conversation

@dDevAhmed

@dDevAhmed dDevAhmed commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Addresses the first Gate B tranche of #584.

Repairs

  • pins TypeScript 6.0.3, within the supported range of the current Nest/TypeScript tooling;
  • updates the npm lock entry deterministically;
  • makes lint verification non-mutating by removing --fix;
  • checks out history before dorny/paths-filter evaluates sensitive changes.

Evidence required

All API checks must execute at this exact head. Remaining source, test, container, or security failures stay visible and will be handled as focused follow-ups rather than being bypassed.

Out of scope

Summary by CodeRabbit

  • Chores
    • Linting now reports issues without automatically fixing them.
    • Pinned the TypeScript development dependency to a specific version.
    • Updated repository checkout settings for the sensitive-change review workflow.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: DigiNodes/truthbounty-api/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 852f9887-f2bd-4b00-9831-81067b776862
📥 Commits

Reviewing files that changed from the base of the PR and between 5fa48e6 and 2759d9e.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The sensitive-changes workflow now checks out the full Git history. The package configuration removes ESLint automatic fixes and pins the TypeScript development dependency to version 6.0.3.

Changes

Sensitive changes workflow

Layer / File(s) Summary
Full-history checkout
.github/workflows/ci.yml
The sensitive-changes-protection job checks out the repository with fetch-depth: 0 before the existing filter and enforcement steps.

Package tooling settings

Layer / File(s) Summary
Lint and TypeScript settings
package.json
The lint script runs ESLint without automatic fixes. The TypeScript development dependency is pinned to 6.0.3.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: ykargeee-bit

Merge Risk: ⚪ Minimal · up to 2759d

The sensitive-change check now has full history, lint verification does not rewrite files, and TypeScript is pinned consistently. No merge-blocking risk is evident; the change appears ready subject to normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description summarizes the changes and scope, but it omits most required template sections and checklist information. Complete the template. Identify exactly one active V2-BE issue and provide the full reviewed head SHA. Address the scope and assignment checks, all architecture and security checks, and each validation check. Mark each checklist item or exp…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the API installation and verification baseline changes, including the lint and CI updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Resolution

Complete the template. Identify exactly one active V2-BE issue and provide the full reviewed head SHA. Address the scope and assignment checks, all architecture and security checks, and each validation check. Mark each checklist item or explain why it does not apply.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dDevAhmed
dDevAhmed merged commit 70efcca into main Oct 7, 2026
2 of 9 checks passed

Copy link
Copy Markdown
Contributor Author

@dDevAhmed post-merge hold for reviewed head 2759d9e1ee5c6a05d32763d5dcbe44a450984a54.

This CI-baseline tranche merged while required evidence was still red and without an approving human review:

  • Backend CI Security and Quality Gates
    • Build, TypeCheck, Lint, and Test — failed at Install dependencies
    • Security Scans — failed at Install dependencies; audit/SBOM/secret/CodeQL steps did not run, and the evidence uploads also failed
    • Container Vulnerability Scan — failed at Build Docker image; Trivy did not run
    • Sensitive Changes Protection — cancelled
  • Container Smoke Build — failed at Build the image from a clean checkout
  • PR Guardian Report — failed/cancelled

Do not treat Gate B as restored or deploy from this merge. Keep #584 open. Open an immediate focused remediation PR from current main, reproduce with npm ci and docker build ., reconcile the package/lockfile and Docker install inputs without --force or --legacy-peer-deps, then require the full backend, security, container-smoke, policy/guardian matrix plus an explicit human maintainer approval on the remediation head before merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant