Skip to content

Add CI coverage reporting for backend and frontend - #1315

Open
dgee2 wants to merge 4 commits into
mainfrom
codex/issue-1158-coverage
Open

dgee2 wants to merge 4 commits into
mainfrom
codex/issue-1158-coverage

Conversation

@dgee2

@dgee2 dgee2 commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Collect backend and frontend test coverage in CI, publish Actions step summaries, and update one coverage comment on pull requests, including fork and Dependabot PRs.

Closes #1158

Changes

  • Add MTP CodeCoverage to all three backend test projects and collect Cobertura reports.
  • Collect Vitest v8 coverage with LCOV and JSON summaries.
  • Publish backend and frontend step summaries and upload coverage data as short-lived artifacts.
  • Add a default-branch workflow_run reporter that reads coverage data without executing PR code and posts a sticky PR comment using the built-in GitHub token.
  • Pin the third-party reporting actions to commit SHAs.

Verification

  • .NET Release solution build passed; 163 MenuApi unit, 16 MenuDB unit, and 53 Aspire integration tests passed with Cobertura output before the frontend-only upstream changes were rebased in.
  • After rebasing onto current main: frozen pnpm install, OpenAPI type generation, production build and typecheck passed.
  • Frontend lint passed with 0 errors and 16 warnings in existing test files.
  • Full Vitest and Storybook coverage run passed: 40 files, 281 tests, with LCOV and JSON output.
  • Coverage comment generation was checked locally with complete and empty report sets, then with the actual ZIP artifacts from CI. An oversized compressed entry was rejected without extraction; git diff --check passed.
  • On commit eba4920e, the Build workflow passed: both backend jobs, frontend validation, all three E2E shards, and the merged E2E report. The backend unit, backend integration, and frontend coverage artifacts were uploaded.
  • CodeQL, SonarCloud, GitGuardian, dependency review, and dependency submission passed. The fork-only E2E placeholder was skipped as designed. Dependency review annotated the pinned ReportGenerator action's OpenSSF score (2.1, below its threshold of 3) without failing the job.
  • The workflow_run reporter can run only after its workflow exists on the default branch, so the PR comment path is locally verified but not yet exercised by GitHub Actions.

Co-authored-by: Codex <codex@openai.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:39
Comment thread .github/workflows/coverage-report.yml Fixed
Co-authored-by: Codex <codex@openai.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Untrusted coverage archives are decompressed in a privileged workflow without bounded extraction.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds backend and frontend coverage collection, summaries, artifacts, and sticky pull-request reporting.

Changes:

  • Adds MTP Cobertura coverage to all backend test projects.
  • Adds Vitest V8 coverage with LCOV and JSON reports.
  • Adds CI summaries, artifacts, and a default-branch PR comment workflow.
File Description
.github/​scripts/​coverage-comment.py Builds coverage comments from reports.
.github/​workflows/​coverage-report.yml Downloads artifacts and updates PR comments.
.github/​workflows/​main.yml Collects and publishes CI coverage.
.gitignore Ignores backend coverage outputs.
backend/​MenuApi.Integration.Tests/​MenuApi.Integration.Tests.csproj Adds MTP coverage dependency.
backend/​MenuApi.Tests/​MenuApi.Tests.csproj Adds MTP coverage dependency.
backend/​MenuDB.Tests/​MenuDB.Tests.csproj Adds MTP coverage dependency.
docs/​ci-path-filters.md Documents coverage reporting and workflow filters.
ui/​menu-website/​.gitignore Ignores frontend coverage outputs.
ui/​menu-website/​package.json Adds the frontend coverage command.
ui/​menu-website/​vitest.config.ts Configures V8 coverage reports.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/coverage-report.yml Outdated
dgee2 and others added 2 commits October 6, 2026 21:49
Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Codex <codex@openai.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@dgee2
dgee2 marked this pull request as ready for review October 6, 2026 21:32
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T21:36:56.306659Z eba4920 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eba4920e63

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +27 to +29
number=$(gh api "repos/$GITHUB_REPOSITORY/pulls?state=open&per_page=100" --paginate |
jq -sr --arg sha "$HEAD_SHA" --arg repo "$HEAD_REPOSITORY" \
'[.[][] | select(.head.sha == $sha and .head.repo.full_name == $repo) | .number] | first // empty')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Disambiguate PRs that share a head commit

🤖 This comment was written by Codex.

When two open PRs share the same commit—such as separate branches pointing at one SHA or one head targeting different accepted base branches—this query matches both and arbitrarily selects first. Both completed runs can consequently update the same sticky comment while the other PR receives none. Resolve from workflow_run.pull_requests when available and make the fork fallback reject or disambiguate multiple matches.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: Add code coverage reporting to GitHub Actions

3 participants