Repository navigation
[Fleet Monitor] petry-projects/google-app-scripts β .github/workflows/nodejs-tests.ymlΒ #388
Description
Activity
- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 15, 2026 Dev-Lead Implementation Plan
Issue: #388 β [Fleet Monitor] petry-projects/google-app-scripts β .github/workflows/nodejs-tests.yml
Root-cause analysis
- The 12 runs the monitor counts as failures all have conclusion
action_requiredwith zero jobs executed β they are PR runs gated behind GitHub's "approve workflow run" setting, not test failures. There are 0failureconclusions in the window (68 success,12 action_required). Approval-gating is a repository Actions setting and cannot be changed from a workflow file. - However,
nodejs-tests.ymlhas a genuine reliability/correctness defect: the "Discover packages" step only finds top-level directories containing atests/subdir (deploy,gas-installer) and then runsnpx jest "<pkg>/tests"with a loose path-regex. As a result CI executes only 87 of 301 tests β thecalendar-to-briefing-doc,calendar-to-sheets, andgmail-to-drive-by-labelspackages are never run in CI. The discovery also depends onfs.readdirSyncordering, making it non-deterministic. coverage.ymlalready runs the full suite deterministically withnpm test -- --coverage, confirming the brittle discovery here is unnecessary.
Scope
Make
nodejs-tests.ymlrun the full Jest suite deterministically (matching the project'snpm testentry point) and drop the unused elevatedactions: writepermission.Implementation Checklist
- Replace the brittle "Discover packages" + per-package loop in
.github/workflows/nodejs-tests.ymlwith a single deterministicnpm testinvocation - Remove the unused
actions: writejob permission (least privilege; matchescoverage.yml)
Tests to Write
-
tests/workflows/nodejs-tests-workflow.test.jsβ assert the workflow runs the full suite vianpm test, does not use the brittle top-level discovery pattern, and does not grantactions: write
Test Command
npm test- The 12 runs the monitor counts as failures all have conclusion
Dev-Lead: Implementation Complete
Root cause
The 12 runs the Fleet Monitor counts as failures all have conclusion
action_requiredwith zero jobs executed β they are PR runs gated behind GitHub's "approve workflow run" setting (a repository Actions setting), not test failures. The window has 0failureconclusions (68 success, 12 action_required). That gating cannot be changed from a workflow file.Separately,
nodejs-tests.ymlhad a real reliability/correctness defect: the "Discover packages" step only found top-level directories containing atests/subdir (deploy,gas-installer) and rannpx jest "<pkg>/tests"with a loose path-regex. Net effect: CI executed only 87 of 301 tests βcalendar-to-briefing-doc,calendar-to-sheets, andgmail-to-drive-by-labelswere never run in CI β and discovery depended on non-deterministicfs.readdirSyncordering.coverage.ymlalready runs the full suite deterministically vianpm test, confirming the brittle discovery was unnecessary.Plan Execution
- Replaced the brittle "Discover packages" + per-package loop with a single deterministic
npm test -- --colors(runs all packages via JesttestMatch) - Removed the unused
actions: writejob permission (least privilege; matchescoverage.yml) - Added a regression test guarding the workflow against the brittle pattern
Test Results
> jest --runInBand Test Suites: 13 passed, 13 total Tests: 304 passed, 304 total Snapshots: 0 total Time: 1.691 s, estimated 4 s Ran all test suites.- Coverage: statements 98.91%, branches 90.00%, functions 98.00%, lines 100% β all thresholds met (
node scripts/check-coverage.js). npm run check(prettier + eslint): 0 errors.
Files Changed
.github/workflows/nodejs-tests.yml: replaced FS-order-dependent discovery + loop (which silently skipped 3 of 5 test packages) with deterministicnpm test -- --colors; dropped unusedactions: writepermission.tests/workflows/nodejs-tests-workflow.test.js: new test asserting the workflow runs the full suite vianpm test, avoids the brittle top-level discovery, and grants noactions: write.
Notes
- The monitor's "failure" signal is GitHub's
action_requiredapproval gate on PR runs β a repository setting outside any workflow file's control. The change here fixes the genuine workflow defects (non-deterministic, partial-coverage test execution) that left CI unable to actually validate most of the codebase. .dev-lead/scripts/dev-lead-lint.shreports pre-existing SC2043 shellcheck warnings inscripts/apply-repo-settings.shandscripts/setup-code-quality-ruleset.sh. These files are unrelated to this issue and unchanged vsmain; left untouched per the "do not modify unrelated files" constraint.
- Replaced the brittle "Discover packages" + per-package loop with a single deterministic
Dev-Lead: Lint Check Failed
The implementation for issue #388 contained lint errors. The commit was aborted to prevent a CI failure.
[lint] shellcheck on 4 file(s)... In scripts/apply-repo-settings.sh line 40: for cmd in gh; do ^-- SC2043 (warning): This loop will only ever run once. Bad quoting or missing glob/expansion? In scripts/setup-code-quality-ruleset.sh line 39: for cmd in gh; do ^-- SC2043 (warning): This loop will only ever run once. Bad quoting or missing glob/expansion? For more information: https://www.shellcheck.net/wiki/SC2043 -- This loop will only ever run once...To retry: fix the lint errors locally (or re-apply the
dev-leadlabel β the agent will try again).β Auto-resolved by Fleet Monitor. This workflow's failure rate has been below the 10% threshold (or the workflow was removed) since 2026-06-15 (30 days) β the monitor stopped flagging it. Closing. It will reopen automatically if the workflow crosses the threshold again.
π DEGRADED:
petry-projects/google-app-scripts/.github/workflows/nodejs-tests.ymlWorkflow:
.github/workflows/nodejs-tests.yml