Skip to content

Fail CI when dependencyGuard or manifestShield baselines are uncommitted - #354

Closed
mvanhorn wants to merge 1 commit into
Moop-App:developfrom
mvanhorn:fix/337-ci-baseline-committed-check
Closed

mvanhorn wants to merge 1 commit into
Moop-App:developfrom
mvanhorn:fix/337-ci-baseline-committed-check

Conversation

@mvanhorn

@mvanhorn mvanhorn commented Oct 4, 2026

Copy link
Copy Markdown

Summary

After the Check manifestShield step, the workflow runs git status --porcelain limited to app/manifestShield and app/dependencies and requires that output to be empty. Any untracked or modified file under those paths fails the job.

CI reports success for the manifestShield and dependencyGuard checks when the baseline files they compare against are absent from the commit. Each run writes a fresh baseline in the job workspace and exits successfully, so a configuration change that should have shipped an updated baseline still looks green. The workflow treated a zero exit from the guard tasks as a finished check. Those tasks create a baseline when none is present and succeed, and the job never looked at git status for app/manifestShield or app/dependencies, so the files written during the run did not fail the build.

Fixes #337

After the Check manifestShield step, the workflow runs git status
--porcelain limited to app/manifestShield and app/dependencies and
requires that output to be empty. Any untracked or modified file under
those paths fails the job.

Fixes Moop-App#337
@fornewid

fornewid commented Oct 4, 2026

Copy link
Copy Markdown
Member

Thanks for taking the time to put this together.

This is a personal project and I don't accept outside contributions, so I'm closing this PR. I'll take care of #337 on my side.

Thanks again for your interest!

@fornewid fornewid closed this Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants