Skip to content

chore: merge develop to main (CI/CD optimizations) - #115

Merged
overwrite00 merged 11 commits into
mainfrom
develop
Jun 22, 2026
Merged

chore: merge develop to main (CI/CD optimizations)#115
overwrite00 merged 11 commits into
mainfrom
develop

Conversation

@overwrite00

Copy link
Copy Markdown
Owner

Synchronize main branch with develop CI/CD improvements.

Changes Included

GitHub Actions Optimization

  • ✅ Remove claude.yml (unnecessary, causes log noise)
  • ✅ Optimize codeql.yml (remove weekly schedule, add fail-fast)
  • ✅ Optimize tests.yml (add node_modules caching)
  • ✅ Add test coverage reporting with coverage.py

Coverage Reporting

  • Coverage tracking for all Python versions (3.11, 3.12, 3.13)
  • XML report generation and upload
  • Coverage summary in build logs
  • 30-day retention of coverage artifacts

Files Modified

  • .github/workflows/claude.yml (DELETED)
  • .github/workflows/codeql.yml (OPTIMIZED)
  • .github/workflows/tests.yml (OPTIMIZED + Coverage)
  • backend/requirements.txt (added coverage==7.6.1)

Benefits

  • Reduced workflow runs (no unnecessary Claude reviews)
  • Faster test execution (node_modules caching)
  • Better test quality visibility (coverage reports)
  • Improved security scanning (fail-fast, no redundant scheduling)

dependabot Bot and others added 11 commits June 15, 2026 10:31
Bumps the minor-and-patch group in /frontend with 1 update: [axios](https://github.com/axios/axios).


Updates `axios` from 1.17.0 to 1.18.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.17.0...v1.18.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…0.5.3

Bumps the development-updates group in /frontend with 1 update: [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh).


Updates `eslint-plugin-react-refresh` from 0.5.2 to 0.5.3
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.5.2...v0.5.3)

---
updated-dependencies:
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Updates:
- fastapi 0.136.3 → 0.137.0
- pydantic 2.13.4 → 2.14.3 (compatible with pydantic-core 2.47.x)
- pydantic-settings 2.13.1 → 2.14.1
- uvicorn 0.42.0 → 0.49.0
- mail-parser 4.1.4 → 4.4.0
- beautifulsoup4 4.13.5 → 4.15.0
- sqlalchemy 2.0.48 → 2.0.50
- pytest 9.0.3 → 9.1.0
- pytest-asyncio 1.3.0 → 1.4.0

Removed explicit pydantic-core pinning (transitive dependency, resolved by pip).
All 119 tests passing.
Updates (all tested and verified):
- fastapi: 0.137.0 → 0.138.0
- pydantic-settings: 2.14.1 → 2.14.2 (SECURITY PATCH)
- sqlalchemy: 2.0.50 → 2.0.51
- pytest: 9.1.0 → 9.1.1

Maintained:
- beautifulsoup4: 4.13.5 (for extract-msg 0.55.0 compatibility)

All 119 tests passing. Zero regressions detected.
Bumps the minor-and-patch group in /frontend with 2 updates: [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) and [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom).


Updates `lucide-react` from 1.18.0 to 1.21.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.21.0/packages/lucide-react)

Updates `react-router-dom` from 7.17.0 to 7.18.0
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/react-router-dom@7.18.0/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.0/packages/react-router-dom)

---
updated-dependencies:
- dependency-name: lucide-react
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: react-router-dom
  dependency-version: 7.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Resolve 2 Dependabot security alerts by enforcing secure versions via npm overrides:
- Alert #44: @babel/core 7.29.0 → 7.29.6 (fixes sourceMappingURL arbitrary read)
- Alert #45: js-yaml 4.1.1 → 4.2.0 (fixes quadratic DoS in merge key handling)

Also upgraded form-data from 4.0.5 → 4.0.6 to fix CRLF injection vulnerability.

All 119 backend tests passing, frontend build successful, ESLint checks passed.
Conflicts resolved by selecting develop versions (newer and tested):
- fastapi: 0.137.0 → 0.138.0
- pydantic-settings: 2.14.1 → 2.14.2 (security update)
- sqlalchemy: 2.0.50 → 2.0.51
- pytest: 9.1.0 → 9.1.1
- lucide-react: 1.18.0 → 1.21.0

All versions tested and validated on develop branch.
Removed and optimized workflows:
- Remove claude.yml: Not necessary for automated CI/CD, causes log noise
- Optimize codeql.yml:
  * Remove weekly schedule (redundant with PR/push analysis)
  * Set fail-fast: true (stop early on errors)
- Optimize tests.yml:
  * Add node_modules caching for faster frontend test runs
  * Cache key based on package-lock.json hash

Impact:
- Reduced unnecessary workflow runs
- Improved test execution time
- Cleaner log history
Added coverage tracking and reporting:
- Add coverage.py (7.6.1) to dev dependencies
- Track code coverage during pytest runs
- Generate coverage.xml report (standard format)
- Display coverage summary in build logs
- Upload coverage artifact for download (30 day retention)

Coverage reports:
- Uploaded to: Artifacts → coverage-report → coverage.xml
- Shows which code lines are/aren't tested
- Helps identify untested code paths
- Baseline: monitor coverage trends over time

Note: Coverage tracking runs on all Python versions,
but artifact upload only happens on Python 3.13 (once per run)
Kept develop version (claude.yml removed) as it's the optimized state.
This removes the unnecessary Claude Code Review workflow from main.
@overwrite00
overwrite00 merged commit f7b2eed into main Jun 22, 2026
8 checks passed
@overwrite00 overwrite00 self-assigned this Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant