Repository navigation
ci: add advisory ImpactGate reports #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Change impact | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: impact-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| impact: | |
| name: Change impact (advisory) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| defaults: | |
| run: | |
| shell: bash | |
| env: | |
| BASE_REF: refs/remotes/origin/${{ github.base_ref || github.ref_name }} | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6 | |
| with: | |
| python-version: '3.12' | |
| - name: Install analysis tools | |
| run: python -m pip install -r .github/impact-gate/requirements.txt | |
| - name: Check reporting behavior with the real CLI | |
| run: python -m unittest discover -s scripts/tests -p test_impact_gate.py -v | |
| - name: Pin and identify target branch | |
| id: target | |
| env: | |
| TARGET_BRANCH: ${{ github.base_ref || github.ref_name }} | |
| BASE_SHA: ${{ github.event.pull_request.base.sha || github.sha }} | |
| run: | | |
| # Keep one logical target ref across push/PR events, pinned to the | |
| # event's commit even if the remote branch advances while queued. | |
| git update-ref "$BASE_REF" "$BASE_SHA" | |
| echo "BASELINE_DIR=$RUNNER_TEMP/impact-baseline" >> "$GITHUB_ENV" | |
| python - <<'PY' | |
| import hashlib | |
| import os | |
| with open(os.environ['GITHUB_OUTPUT'], 'a') as output: | |
| key = hashlib.sha256(os.environ['TARGET_BRANCH'].encode()).hexdigest() | |
| output.write(f'key={key}\n') | |
| PY | |
| # The fallback stays within one tool/policy AND target branch. Never use a | |
| # repository-wide fallback: another release branch has different history. | |
| - name: Restore baselines | |
| id: restore | |
| uses: actions/cache/restore@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 | |
| with: | |
| path: ${{ env.BASELINE_DIR }} | |
| key: impact-${{ hashFiles('.github/impact-gate/**', 'scripts/impact-gate.py', '.github/workflows/impact.yml') }}-${{ steps.target.outputs.key }}-${{ github.event.pull_request.base.sha || github.sha }} | |
| restore-keys: impact-${{ hashFiles('.github/impact-gate/**', 'scripts/impact-gate.py', '.github/workflows/impact.yml') }}-${{ steps.target.outputs.key }}- | |
| - name: Validate or build baselines | |
| id: prepare | |
| env: | |
| REFRESH: ${{ github.event_name == 'push' && steps.restore.outputs.cache-hit != 'true' }} | |
| run: | | |
| args=() | |
| if [[ "$REFRESH" == 'true' ]]; then args+=(--refresh); fi | |
| python scripts/impact-gate.py prepare --base "$BASE_REF" --cache-dir "$BASELINE_DIR" "${args[@]}" | |
| - name: Save main baselines | |
| if: github.event_name == 'push' && steps.prepare.outputs.rebuilt == 'true' | |
| uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 | |
| with: | |
| path: ${{ env.BASELINE_DIR }} | |
| key: ${{ steps.restore.outputs.cache-primary-key }} | |
| - name: Report pull request impact | |
| if: github.event_name == 'pull_request' | |
| run: python scripts/impact-gate.py report --base "$BASE_REF" --cache-dir "$BASELINE_DIR" |