Skip to content

👷 ci: setup github actions and dependabot - #36

Merged
chriskyfung merged 22 commits into
masterfrom
ci/setup-github-actions-and-dependabot
Aug 10, 2026
Merged

👷 ci: setup github actions and dependabot#36
chriskyfung merged 22 commits into
masterfrom
ci/setup-github-actions-and-dependabot

Conversation

@chriskyfung

Copy link
Copy Markdown
Owner
  • Add CI workflow for linting and testing
  • Configure multi-platform PowerShell matrix
  • Implement CodeQL security analysis
  • Add dependency review for pull requests
  • Setup weekly Dependabot updates

- Add CI workflow for linting and testing
- Configure multi-platform PowerShell matrix
- Implement CodeQL security analysis
- Add dependency review for pull requests
- Setup weekly Dependabot updates
@chriskyfung chriskyfung self-assigned this Aug 7, 2026
@chriskyfung chriskyfung moved this to 🏗 In progress in PowerShell projects Aug 7, 2026
- Split lint-and-test into PS 5.1 and PS 7 jobs
- Simplify module installation logic
- Remove redundant artifact upload steps
- Standardize environment setup across jobs
- Add PowerShellExecutable parameter to Build.ps1
- Force specific PS engines in CI workflows
- Replace CodeQL with PSScriptAnalyzer SARIF upload
- Update Build.ps1 version and documentation
- Skip integration tests in CI to prevent network disruption
- Add DesktopOnly tags for PowerShell Core compatibility
- Fix variable scoping in theBrain test files
- Prevent destructive tests from running on CI runners
- Extract module installation to composite action
- Update CI branch trigger to master
- Improve error handling in Build.ps1 using throw
- Adjust runner and permissions for CI jobs
- Prevent errors when temp directory is missing
- ensure SARIF results are uploaded even if violations are found
- Move $script:SkipAll outside BeforeAll blocks
- Ensure Pester Discovery evaluates skips correctly
- Fix CI failures for specific theBrain tests
- Simplify Mock implementations in theBrain tests
The ampersand character caused issues in CI; replaced with "and" for compatibility.
- Mock data directory path to simulate failure
- Ensure tests use temporary path via Pester v5 mock
- Prevent tests from accessing actual brain data dirs
…s and adding UTF-8 BOM

Windows PowerShell 5.1 incorrectly parsed the UTF-8 encoded script, rendering the non-ASCII ✓ checkmark as garbled '✓' text. Added a UTF-8 byte order mark (BOM) to the start of the script to ensure correct encoding detection in PS 5.1, and replaced all non-ASCII ✓ host output markers with ASCII [OK] strings to eliminate display issues.
- Mock TheBrainMeta.db path to remove local dependency
- Ensure tests run without a local TheBrain install
- Standardize Invoke-SqliteQuery mocks across tests
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Update test expectations and README example to use "and" instead of "&"
in the VS Code Profile and Extension Export header text for consistency.
- Allow manual specification of brain data folder
- Bypass PSSQLite dependency when path is provided
- Update scripts to support optional directory input
- Refactor tests to remove unnecessary database mocks
- Add PSEdition Desktop requirement to tests
- Skip Windows-specific tests when running on Core
- Prevent CI failures in non-Windows environments
- Fix admin check skip logic in disk tests
- Remove CI-specific skip for CSV injection test
- Group GitHub Actions updates to reduce PR noise
- Add custom commit message prefix for updates
- Improve configuration with documentation comments
@chriskyfung
chriskyfung force-pushed the ci/setup-github-actions-and-dependabot branch from 7f2a5c3 to 7cae3e9 Compare August 10, 2026 09:22
@chriskyfung

Copy link
Copy Markdown
Owner Author

Summary

This PR introduces a full CI pipeline and automated dependency management for the repository, along with the Pester v5 fixes needed to make the test suite reliable across both PowerShell 5.1 and PowerShell 7.

🆕 What's new

  • GitHub Actions CI workflow (.github/workflows/ci.yml) running on push/PR to master:
    • Lint & test job on Windows PowerShell 5.1
    • Lint & test matrix job on PowerShell 7 (windows-2022 / windows-2025)
    • PSScriptAnalyzer job that generates and uploads SARIF results to GitHub Code Scanning
    • Dependency Review job (PR-only) checking for vulnerable/incompatible-license dependencies
  • Reusable composite action (.github/actions/setup-powershell-modules) to install pinned Pester (5.7.1) and PSScriptAnalyzer (1.25.0) versions consistently across jobs
  • Dependabot config (.github/dependabot.yml) for weekly GitHub Actions version updates
  • Build.ps1 v1.2.0: new -PowerShellExecutable parameter (auto/pwsh/powershell) to explicitly control which engine runs isolated Pester tests in CI

🐛 Fixes

  • Corrected Pester v5 discovery-phase scoping bug: $script:SkipAll-style skip flags are now assigned at top-level script scope (not inside BeforeAll), so -Skip: expressions evaluate correctly during Discovery across all affected test files
  • Added Desktop-only skip guards to test suites for scripts requiring #Requires -PSEdition Desktop (TheBrain scripts, Get-DiskReliabilityCounter, Optimize-DockerDesktopVHD, Optimize-WslDistroVHD, Export-VSCodeProfiles) so they no longer fail on PowerShell 7 runners
  • Mocked TheBrain's metadata database precondition (Test-Path on TheBrainMeta.db) so tests don't depend on a real local TheBrain installation
  • Fixed PSScriptAnalyzer SARIF generation by piping results through ConvertTo-Sarif (the previous -Save parameter doesn't exist on Invoke-ScriptAnalyzer)
  • Fixed encoding issue in Export-VSCodeExtensionList.ps1 that broke parsing under Windows PowerShell 5.1 due to a non-ASCII checkmark character

🧪 Tests

  • Updated test files across theBrain, Bluestacks, OneNote, VSCode, and Windows directories with corrected skip logic and CI-safe mocking
  • All 6 CI checks now pass on both PS 5.1 and PS 7

Status: All checks passing, no merge conflicts, ready to merge.

@chriskyfung
chriskyfung merged commit a5f3a7f into master Aug 10, 2026
7 checks passed
@github-project-automation github-project-automation Bot moved this from 🏗 In progress to ✅ Done in PowerShell projects Aug 10, 2026
@chriskyfung
chriskyfung deleted the ci/setup-github-actions-and-dependabot branch August 10, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

2 participants