You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
tracking: re-evaluate coverage reporting / badge after OSS launch #133
The repo previously published a coverage SVG via a badges branch (generated by vladopajic/go-test-coverage's Docker action, plumbed through a workflow_run-triggered workflow) and referenced it from README. That setup was removed in #129 because:
The badge image URL pointed at raw.githubusercontent.com, which requires authentication for private repos. Anonymous viewers saw a broken image.
The badges branch existed solely to side-step the ruleset's block-direct-pushes-to-main rule. Once the badge wasn't serving its purpose, the whole apparatus was overhead.
Coverage data is still computed by make ci and published in the per-run job-summary panel (the "Test Coverage" block). See .github/workflows/ci.yml's "Coverage summary" step and .testcoverage.yml for the threshold spec consumed by scripts/cov.
Decision to make at OSS launch
Two reasonable paths once the repo is public:
Resurrect the old setup. The existing badges-branch publish workflow lives in git history (ci: kill coverage Docker pull on PR runs + tighten claude-review group #129's commit predecessors) — could be cherry-picked back. README badge URL would just start working because raw.githubusercontent.com is unrestricted for public repos. Free, no vendor dep, only as fancy as a static SVG.
Codecov (or similar SaaS). Provides more than a badge: PR-comment coverage diffs ("this PR drops coverage by 2.3%"), sunburst graphs, trends, file-level annotations on the PR diff. Industry standard for public Go projects. Costs: vendor account, workflow integration, one more thing to manage. Free for OSS. Trust caveat: Codecov was the target of a real supply-chain compromise in April 2021 (bash uploader exfiltrated CI secrets for ~2 months); they've hardened since but it's a known incident worth weighing.
Inputs for the decision
How much we end up caring about coverage diff visibility on PRs versus an absolute number on a README. PR-diff is genuinely useful on bigger contributor pools.
Whether we trust the Codecov pipeline post-2021 (they're widely used today, so general industry verdict is "yes, with reasonable precautions").
Whether we want a single dashboard or are fine with per-run summaries.
What this issue should produce
A short ADR (in docs/adr/ or wherever feels right) capturing the chosen approach and the rationale, plus a PR implementing it. Block this issue on the OSS-launch milestone — there's no point deciding this before we have to.
Status: deferred until repo flips public.
What was removed
The repo previously published a coverage SVG via a
badgesbranch (generated byvladopajic/go-test-coverage's Docker action, plumbed through aworkflow_run-triggered workflow) and referenced it from README. That setup was removed in #129 because:raw.githubusercontent.com, which requires authentication for private repos. Anonymous viewers saw a broken image.badgesbranch existed solely to side-step the ruleset's block-direct-pushes-to-main rule. Once the badge wasn't serving its purpose, the whole apparatus was overhead.Coverage data is still computed by
make ciand published in the per-run job-summary panel (the "Test Coverage" block). See.github/workflows/ci.yml's "Coverage summary" step and.testcoverage.ymlfor the threshold spec consumed byscripts/cov.Decision to make at OSS launch
Two reasonable paths once the repo is public:
Resurrect the old setup. The existing badges-branch publish workflow lives in git history (ci: kill coverage Docker pull on PR runs + tighten claude-review group #129's commit predecessors) — could be cherry-picked back. README badge URL would just start working because
raw.githubusercontent.comis unrestricted for public repos. Free, no vendor dep, only as fancy as a static SVG.Codecov (or similar SaaS). Provides more than a badge: PR-comment coverage diffs ("this PR drops coverage by 2.3%"), sunburst graphs, trends, file-level annotations on the PR diff. Industry standard for public Go projects. Costs: vendor account, workflow integration, one more thing to manage. Free for OSS. Trust caveat: Codecov was the target of a real supply-chain compromise in April 2021 (bash uploader exfiltrated CI secrets for ~2 months); they've hardened since but it's a known incident worth weighing.
Inputs for the decision
What this issue should produce
A short ADR (in
docs/adr/or wherever feels right) capturing the chosen approach and the rationale, plus a PR implementing it. Block this issue on the OSS-launch milestone — there's no point deciding this before we have to.Related