pkgwatch/Makefile.toml
Austin Schaefer 13a1381bdf
All checks were successful
CI / build (push) Successful in 13m17s
CI / test (push) Successful in 3m59s
CI / coverage (push) Successful in 9m22s
CI / audit (push) Successful in 16s
Add shift-left quality gates: cognitive complexity, coverage, dependency fix
Adds two new gates to the existing format/lint/test/audit pipeline
(Makefile.toml `cargo make ci`, .forgejo/workflows/ci.yml):

- Cognitive complexity via clippy's nursery cognitive_complexity lint
  (clippy.toml, threshold 15), scoped to --bins so test code's naturally
  higher branch count doesn't get gated. Went with this over the closest
  real cyclomatic-complexity tool (rust-code-analysis-cli) because that
  crate hasn't shipped a release since Jan 2023.
- Test coverage via cargo-llvm-cov, chosen over cargo-tarpaulin for
  friendlier behavior in containerized/dind CI (no ptrace). Report-only
  for now (no --fail-under-lines) since a real threshold needs real usage
  data first — see below. main.rs is excluded: it's orchestration glue
  exercised by the real end-to-end `cargo run`, not unit tests.

Getting both gates running required writing pkgwatch's first tests
(previously zero). To make the GitHub-facing modules unit-testable
without hitting real github.com/api.github.com, added `GithubEndpoints`
(src/github.rs) so checker/fetcher/verifier take injectable base URLs,
and added mockito + tempfile as dev-dependencies. Result: 27 tests,
94% region / 96% line coverage excluding main.rs.

Also: cargo audit (now wired into `cargo make ci`) immediately caught a
real, currently-open advisory (RUSTSEC-2026-0285, published days ago) in
the transitive rustls dependency — bumped 0.23.44 -> 0.23.45 to clear it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 09:16:14 +02:00

57 lines
1.6 KiB
TOML

[config]
default_to_workspace = false
[tasks.format]
command = "cargo"
args = ["fmt"]
[tasks.format-check]
command = "cargo"
args = ["fmt", "--check"]
[tasks.lint]
command = "cargo"
args = ["clippy", "--all-targets", "--", "-D", "warnings"]
# Cognitive complexity (clippy's nursery lint, not literal cyclomatic
# complexity — see clippy.toml for why) on the bin target only: run without
# --all-targets so #[cfg(test)] code, which naturally reads as more
# "complex" without being a maintainability signal, isn't gated on this.
[tasks.complexity]
command = "cargo"
args = ["clippy", "--bins", "--", "-D", "warnings", "-W", "clippy::cognitive_complexity"]
[tasks.test]
command = "cargo"
args = ["test"]
# Named coverage-report, not coverage: cargo-make reserves "coverage" for
# its own built-in tarpaulin/kcov-routing composite task, which clobbers a
# same-named custom one.
#
# Reports coverage only; not gated on a threshold yet — main.rs is thin
# orchestration glue exercised by the real end-to-end `cargo run`, not unit
# tests, so it's excluded here rather than dragging the number down for
# reasons unrelated to test quality.
[tasks.coverage-report]
command = "cargo"
args = ["llvm-cov", "--ignore-filename-regex", "main\\.rs", "--summary-only"]
[tasks.audit]
command = "cargo"
args = ["audit"]
[tasks.build]
command = "cargo"
args = ["build", "--release"]
[tasks.install-hooks]
description = "One-time setup: point git at the tracked hooks in .githooks/"
command = "git"
args = ["config", "core.hooksPath", ".githooks"]
[tasks.ci]
dependencies = ["format-check", "lint", "complexity", "test", "coverage-report", "audit"]
[tasks.default]
alias = "ci"