Conversation
vringar
force-pushed
the
ci/per-commit-checks
branch
from
June 15, 2026 22:14
f361334 to
1041f4f
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1190 +/- ##
=======================================
Coverage 62.34% 62.34%
=======================================
Files 40 40
Lines 3930 3930
=======================================
Hits 2450 2450
Misses 1480 1480 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
vringar
marked this pull request as ready for review
June 19, 2026 23:03
vringar
force-pushed
the
ci/per-commit-checks
branch
from
June 19, 2026 23:04
1041f4f to
24076a0
Compare
There was a problem hiding this comment.
Pull request overview
Adds a new GitHub Actions workflow to gate rebase-and-merge PRs by running a fast static-check suite on every individual commit in the PR (and in merge-queue merge_group candidates), preventing “broken intermediate commits” from landing on master.
Changes:
- Introduces
per-commit-checks.yaml, triggered onpull_requestandmerge_group. - Computes a commit range and iterates commit-by-commit, running
pre-commit(changed-files), conditional Extension build,import openwpm, andpytest --collect-only. - Aggregates failures across commits (doesn’t stop at first failure) and fails the job at the end if any commit failed.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
vringar
force-pushed
the
ci/per-commit-checks
branch
from
July 20, 2026 22:54
c4533be to
4183b69
Compare
vringar
force-pushed
the
ci/per-commit-checks
branch
7 times, most recently
from
September 6, 2026 20:35
ce797fb to
81f4d2c
Compare
The commit-msg hook has never linted anything. commitlint.config.js extends @commitlint/config-conventional, which is a devDependency of the root package.json, so the hook fails with MODULE_NOT_FOUND for anyone who has not run `npm install` at the repo root — and nothing installs root node_modules in CI. For a developer who has, rev v9.11.0 bundles commitlint 18 while the root manifest provides config-conventional 21, so the preset loads with no rules and commitlint errors out with "Please add rules to your commitlint.config.js". Bump the hook to v9.26.0, which bundles commitlint 21, and declare the preset as an additional_dependency so the hook no longer depends on root node_modules. With the hook working, `release: vX.Y.Z` is rejected, as release is not one of the conventional commit types (it was not one under commitlint 18 either, the hook was simply never running). Note the `chore(release):` form in the release checklist instead.
…er rebase-merge) Add a lightweight CI job that runs the fast static checks on every commit in a PR / merge-queue candidate, not just the tip. Because the project uses rebase-and-merge, every commit lands on master individually, but the existing tests job only validates the tip — a commit that is broken in isolation can reach master. This gate closes that gap cheaply: per commit it runs the pre-commit hooks (black/isort/mypy/actionlint) over the whole tree, checks the commit message with the commit-msg hooks, rebuilds the extension when its sources changed, imports the package, and collects the test suite. It intentionally does not run the browser test suite — runtime and browser-behavior regressions stay covered by the tests job on the tip plus the merge queue. The logic lives in scripts/per_commit_checks.py rather than inline in the workflow, so it is readable, reviewable and runnable locally (`python scripts/per_commit_checks.py --base master --head HEAD`) instead of being a shell loop embedded in YAML. The workflow is reduced to checkout, setup and one call. The script reads the commit range from the GitHub event payload, so no untrusted event data is interpolated into a shell command. A failed conda env rebuild ends the walk rather than blaming every later commit, as install.sh removes the environment before re-creating it and leaves nothing behind to check the remaining commits against.
vringar
force-pushed
the
ci/per-commit-checks
branch
from
September 6, 2026 21:44
81f4d2c to
f0c19f8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebase-and-merge lands every PR commit on master individually, but CI only
tests the tip, so a commit that is broken on its own can still ship. This runs
the fast checks on each commit in the range:
pre-commit run --all-files, thecommit-msg hooks,
import openwpm,pytest --collect-only, plusnpm ci/npm run buildif it touchedExtension/and./install.shif it changedenvironment.yaml. No browser suite — that stays on the tip and the mergequeue.
The logic is in
scripts/per_commit_checks.pyrather than inline in the YAML,so it can be linted and run locally:
It reads the range from the event payload, so nothing event-controlled reaches
a command line. Every commit is visited and every failure reported before the
non-zero exit. A failed conda rebuild is the exception and ends the walk, since
install.shremoves the env before re-creating it.Only gates once it's a required status check in branch protection.
First commit: the commitlint hook was dead
It never linted anything.
commitlint.config.jsextends@commitlint/config-conventional, a rootpackage.jsondevDependency thatnothing installs in CI (
MODULE_NOT_FOUND); and for anyone who has run rootnpm install,rev: v9.11.0bundles commitlint 18 against config-conventional21, which loads no rules. Bumped to
v9.26.0with the preset as anadditional_dependency.Consequence:
release: vX.Y.Zis rejected,releasenot being a conventionaltype. Not from the bump — it fails identically under 18. 5 of the last 40
master messages would fail, 4 of them
release:. Release checklist now sayschore(release):.