Conversation
After the Check manifestShield step, the workflow runs git status --porcelain limited to app/manifestShield and app/dependencies and requires that output to be empty. Any untracked or modified file under those paths fails the job. Fixes Moop-App#337
Member
|
Thanks for taking the time to put this together. This is a personal project and I don't accept outside contributions, so I'm closing this PR. I'll take care of #337 on my side. Thanks again for your interest! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
After the Check manifestShield step, the workflow runs git status --porcelain limited to app/manifestShield and app/dependencies and requires that output to be empty. Any untracked or modified file under those paths fails the job.
CI reports success for the manifestShield and dependencyGuard checks when the baseline files they compare against are absent from the commit. Each run writes a fresh baseline in the job workspace and exits successfully, so a configuration change that should have shipped an updated baseline still looks green. The workflow treated a zero exit from the guard tasks as a finished check. Those tasks create a baseline when none is present and succeed, and the job never looked at git status for app/manifestShield or app/dependencies, so the files written during the run did not fail the build.
Fixes #337