Skip to content

feat(TU-47260): add turbo-cache and per-package coverage PR comment to frontend-pr-workflow - #271

Merged
sh-waqar merged 1 commit into
mainfrom
feat/turbo-cache-coverage-comment
Sep 28, 2026
Merged

sh-waqar merged 1 commit into
mainfrom
feat/turbo-cache-coverage-comment

Conversation

@sh-waqar

@sh-waqar sh-waqar commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Three opt-in inputs for frontend-pr-workflow. The defaults keep today's behaviour.

Input What it does
turbo-cache: true Turbo remote cache backed by the GitHub Actions cache (rharkor/caching-for-turbo, pinned by SHA), in the build and unit-test jobs. Unchanged packages replay their cached outputs, including coverage/, instead of re-running.
coverage-path Replaces the hardcoded coverage/ upload path. Accepts newline-separated globs for monorepos, e.g. packages/*/coverage.
coverage-report: off | always | on-failure Sticky PR comment with one row per coverage-summary.json. on-failure creates the comment only when unit tests fail, then keeps it updated so a fix shows ✅.

Why

  • Nothing shared replaced SonarCloud after it was removed from the shared workflows (PLT-3524), so teams have been adding their own:
    • admin-home adds a job of its own that downloads this workflow's coverage-${run_id} artifact and posts it with MishaKav/jest-coverage-comment@main, on every PR.
    • in-app-notifications (TU-46981) posts lcov.info with romeovs/lcov-reporter-action, only when coverage falls below its threshold.
    • Both could move to coverage-report: always and on-failure respectively.
  • Coverage didn't work for monorepos. The coverage path was fixed to a root coverage/, so per-package coverage in a monorepo was never uploaded.
  • Turbo monorepos started every run with an empty cache.

Design notes

  • Commenting happens in its own coverage-comment job with pull-requests: write. The workflow-level permissions (id-token, contents) narrow every job's token, and unit-tests shouldn't need more. This follows the existing deep-purple job.
  • Reporting never fails the build. Thresholds stay in the test tool's own config (Vitest or Jest).
  • The comment rows are labelled with each package's directory, e.g. packages/hooks.
  • A single-app repo keeps the default coverage/ and gets a one-row table.

Verified on frontend-packages (pnpm + Turbo, 2 packages and 1 app)

Current head 589296c, in #33 (coverage-report: on-failure, default runner)

Run What changed Result
1 first run, no existing comment ✅ green; no comment posted; Build and Unit Tests jobs created from the default runner
2 hooks line threshold raised from 85% to 95% (actual 90%) ❌ Unit Tests failed (Coverage for lines (90%) does not meet global threshold (95%)); ❌ comment created; password-validation replayed from the cache (1/2 cached); Record PR verification skipped
3 threshold change reverted ✅ green; the same comment was updated to ✅ (no new comment); test:coverage 2/2 cached

Turbo cache, in #32 (earlier commits of this PR; the cache step is unchanged since)

Run What changed Result
1 first run cache miss for every task; entries saved; comment posted
2 only pr.yml FULL TURBO: lint and build 3/3 cached, test:coverage 2/2 cached (178 ms, vs about 8 s when it ran)
3 one package's src only @typeform/hooks missed on lint, build and test; every task for the other packages replayed

Local check: the comment logic was run against every combination of mode × passed/failed × existing comment, using a stubbed GitHub client.

Secret scan: the status line is an if/else rather than a ternary, because passed ? '…' : '…' tripped the gitleaks credentials-yaml-quoted rule in ci-standard-checks.

One question for reviewers: is it OK to run rharkor/caching-for-turbo inside the shared workflow? It's pinned by SHA and opt-in. The first-party alternative is actions/cache on .turbo/cache, which is simpler but never prunes old entries.

🤖 Generated with Claude Code

https://claude.ai/code/session_019tUHRKTe2YrU4YwTbKzXPH

@sh-waqar
sh-waqar force-pushed the feat/turbo-cache-coverage-comment branch from 0127472 to d1f0249 Compare September 28, 2026 11:56
@sh-waqar
sh-waqar changed the base branch from fix/reusable-workflow-secrets-and-runner-defaults to main September 28, 2026 11:56
…o frontend-pr-workflow

All opt-in; defaults keep today's behaviour.

- turbo-cache: Turbo remote cache backed by the GitHub Actions cache
  (rharkor/caching-for-turbo, pinned by SHA) in the build and unit-test jobs.
  Unchanged packages replay their outputs (e.g. coverage/) instead of re-running.
- coverage-path: configurable coverage upload path (was hardcoded coverage/),
  newline-separated globs for monorepos, e.g. packages/*/coverage.
- coverage-report: off | always | on-failure. unit-tests builds a sticky comment
  with one row per coverage-summary.json; a separate coverage-comment job posts
  it, so only that job gets pull-requests: write (the workflow-level permissions
  narrow every other job's token). on-failure creates the comment only when unit
  tests fail and keeps an existing one updated, so a fix flips it to passing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019tUHRKTe2YrU4YwTbKzXPH
@sh-waqar
sh-waqar force-pushed the feat/turbo-cache-coverage-comment branch from d1f0249 to 589296c Compare September 28, 2026 12:16
@sh-waqar
sh-waqar marked this pull request as ready for review September 28, 2026 13:24
@sh-waqar
sh-waqar requested a review from a team as a code owner September 28, 2026 13:24
@pr-auditor

pr-auditor Bot commented Sep 28, 2026

Copy link
Copy Markdown

✅ Security Analysis Results

No security issues found. 2 files reviewed.


@pr-auditor rescan to re-run · Powered by Claude Sonnet 5 · Docs · #security-engineering-team

@sh-waqar
sh-waqar merged commit 33a0a19 into main Sep 28, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants