chore: pin actions and drop persisted checkout credentials; raise coverage - #108
Merged
Merged
Conversation
Contributor
Pin the osv-scanner reusable workflows, the only actions still referenced by tag, to the commit of the same tag (v2.6.0), like the other actions.
Set `persist-credentials: false` on the checkout steps of jobs that never push. The docs deploy job keeps the default, because `mkdocs gh-deploy` pushes with those credentials.
Add tests for code paths that were not exercised yet: config options and loading, the dev server and serve command, the CLI (get-deps, log formatting, warnings), gh-deploy, `mkdocs new`, plugins, files, pages, navigation, search, themes and the utils modules. Line coverage goes from 93% to 99.95%. Add lunr.py to the hatch test environment so that the search plugin's `prebuild_index: python` path is tested against the real library, and always run the "lunr.py is missing" test by patching it out instead of skipping it. Lines that cannot run in the test suite are excluded with narrow `# pragma: no cover` comments (no code changes): - the doc-only default event handlers of BasePlugin, which are deleted right after the class is defined; - the Windows-only colorama setup at import time; - import fallbacks for Markdown < 3.4, Jinja2 < 3.0 and a missing lunr; - an `except ValueError` in get_files() that cannot trigger.
shenxianpeng
force-pushed
the
chore/repo-health-check
branch
from
October 2, 2026 19:43
5d8a80a to
0873b8a
Compare
shenxianpeng
marked this pull request as ready for review
October 2, 2026 20:00
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR has three kinds of change:
SHA pinning. The osv-scanner reusable workflows were the only actions still referenced by tag. They are now pinned to the commit of the same tag (
v2.6.0), with the tag in a trailing comment.labeler.ymlstill calls the org workflow at@main.No persisted credentials.
persist-credentials: falseis set on the 9actions/checkoutsteps of jobs that never push. The docsdeployjob keeps the default, becausemkdocs gh-deploypushes with those credentials.Coverage.
utils/cache_tests.py,utils/rendering_tests.py).lunris added to the hatchtestenvironment, soprebuild_index: pythonis tested against the real library.# pragma: no covercomments mark lines that can't run in the test suite:BasePluginhandler stubs, which are deleted at import;coloramasetup;exceptinget_files().Apart from these comments, the source code is unchanged.
Coverage
Line coverage, measured with
hatch run test:with-coverage(coverage.py,--source=mkdocs --omit "mkdocs/tests/*", Python 3.14):main)The two uncovered lines are
mkdocs/config/config_options.py529-530.Verification
hatch run +py=3.14 test:with-coverageandhatch run +py=3.10 test:testpass, in both the default and min-req variants.pre-commit run --all-filespasses.actionlintreports no problems.refs/tags/v2.6.0(git ls-remote).Checklist
docs/about/release-notes.mdupdated (if applicable)