Skip to content

chore: pin actions and drop persisted checkout credentials; raise coverage - #108

Merged
shenxianpeng merged 3 commits into
mainfrom
chore/repo-health-check
Oct 2, 2026
Merged

shenxianpeng merged 3 commits into
mainfrom
chore/repo-health-check

Conversation

@shenxianpeng

@shenxianpeng shenxianpeng commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

This PR has three kinds of change:

  1. SHA pinning. The osv-scanner reusable workflows were the only actions still referenced by tag. They are now pinned to the commit of the same tag (v2.6.0), with the tag in a trailing comment. labeler.yml still calls the org workflow at @main.

  2. No persisted credentials. persist-credentials: false is set on the 9 actions/checkout steps of jobs that never push. The docs deploy job keeps the default, because mkdocs gh-deploy pushes with those credentials.

  3. Coverage.

    • 126 new tests across 22 test files, two of them new (utils/cache_tests.py, utils/rendering_tests.py).
    • lunr is added to the hatch test environment, so prebuild_index: python is tested against the real library.
    • Narrow # pragma: no cover comments mark lines that can't run in the test suite:
      • the docs-only BasePlugin handler stubs, which are deleted at import;
      • the Windows-only colorama setup;
      • the import fallbacks for Markdown < 3.4, Jinja2 < 3.0 and a missing lunr;
      • an unreachable except in get_files().

    Apart from these comments, the source code is unchanged.

Coverage

Line coverage, measured with hatch run test:with-coverage (coverage.py, --source=mkdocs --omit "mkdocs/tests/*", Python 3.14):

Tests Statements Missed Line coverage
Base (main) 780 3865 277 93%
This PR 906 3837 2 99.95%

The two uncovered lines are mkdocs/config/config_options.py 529-530.

Verification

  • hatch run +py=3.14 test:with-coverage and hatch run +py=3.10 test:test pass, in both the default and min-req variants.
  • pre-commit run --all-files passes.
  • actionlint reports no problems.
  • The pinned SHA matches refs/tags/v2.6.0 (git ls-remote).

Checklist

  • New tests added for new behavior (if applicable)
  • Documentation updated (if applicable)
  • Release notes docs/about/release-notes.md updated (if applicable)

@codspeed

codspeed Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 28 untouched benchmarks


Comparing chore/repo-health-check (0873b8a) with main (0e745b4)

Open in CodSpeed

Pin the osv-scanner reusable workflows, the only actions still referenced
by tag, to the commit of the same tag (v2.6.0), like the other actions.
Set `persist-credentials: false` on the checkout steps of jobs that never
push. The docs deploy job keeps the default, because `mkdocs gh-deploy`
pushes with those credentials.
Add tests for code paths that were not exercised yet: config options and
loading, the dev server and serve command, the CLI (get-deps, log
formatting, warnings), gh-deploy, `mkdocs new`, plugins, files, pages,
navigation, search, themes and the utils modules. Line coverage goes from
93% to 99.95%.

Add lunr.py to the hatch test environment so that the search plugin's
`prebuild_index: python` path is tested against the real library, and
always run the "lunr.py is missing" test by patching it out instead of
skipping it.

Lines that cannot run in the test suite are excluded with narrow
`# pragma: no cover` comments (no code changes):
- the doc-only default event handlers of BasePlugin, which are deleted
  right after the class is defined;
- the Windows-only colorama setup at import time;
- import fallbacks for Markdown < 3.4, Jinja2 < 3.0 and a missing lunr;
- an `except ValueError` in get_files() that cannot trigger.
@shenxianpeng
shenxianpeng force-pushed the chore/repo-health-check branch from 5d8a80a to 0873b8a Compare October 2, 2026 19:43
@shenxianpeng shenxianpeng changed the title chore: repository health check (tests, security, deps, CI) ci: pin actions and drop persisted checkout credentials; test: raise coverage to 99.95% Oct 2, 2026
@shenxianpeng shenxianpeng changed the title ci: pin actions and drop persisted checkout credentials; test: raise coverage to 99.95% ci: pin actions and drop persisted checkout credentials; raise coverage Oct 2, 2026
@shenxianpeng shenxianpeng added the maintenance Targets chores, refactors and cleanups label Oct 2, 2026
@shenxianpeng
shenxianpeng marked this pull request as ready for review October 2, 2026 20:00
@shenxianpeng
shenxianpeng merged commit 6a41d5e into main Oct 2, 2026
23 checks passed
@shenxianpeng
shenxianpeng deleted the chore/repo-health-check branch October 2, 2026 20:01
@shenxianpeng shenxianpeng changed the title ci: pin actions and drop persisted checkout credentials; raise coverage chore: pin actions and drop persisted checkout credentials; raise coverage Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Targets chores, refactors and cleanups

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant