zscripts-token-savers/.github/workflows/tests.yml
KellyMichels 3a8eb9ec13 fix(ci): the push trigger names master, which is this repo's default branch
The workflow was written with `branches: [main]` like the other two added
the same day, but evo.zscripts' default branch is master, so the push
trigger could never fire here - the PR trigger ran and passed, the merge
to master ran nothing, and the "tests" badge would have stayed at the
PR's result forever. Caught when the post-merge run was looked for and
did not exist.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-09 18:04:43 -05:00

81 lines
3.5 KiB
YAML

# The Pester suite, on every push to master and every PR.
#
# This repo is one of the twelve on the fleet board
# (evomedia.net/testsuites.html) and was one of three with no CI at all, so the
# only thing ever running these tests was a workstation at 04:00. That is a
# poor place for the only copy of a check to live.
#
# windows-latest, not ubuntu, even though Pester runs on Linux: these scripts
# deploy from a Windows workstation and the suite reads like it - paths,
# executables, the shell itself. Proving them on Linux would be proving
# something nobody runs. Windows minutes bill at double, which this suite's
# size affords.
name: tests
on:
push:
branches: [master]
pull_request:
# Read-only: this job builds nothing and publishes nothing, so the default
# write-capable token is more than it needs.
permissions:
contents: read
concurrency:
group: tests-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: windows-latest
timeout-minutes: 15
steps:
# Actions pinned to a commit, not a moving tag: a tag can be repointed
# by whoever owns it, and this token, read-only though it is, still sees
# the repository.
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
# Pester pinned to 5.x: the suite is written against the v5 configuration
# API (New-PesterConfiguration), and Windows images still carry a v3 in
# the module path that would be picked ahead of it. PSScriptAnalyzer is
# the PowerShell linter; there is no typecheck for PowerShell, so the
# analyzer is the whole of that half.
- name: Install Pester 5 and PSScriptAnalyzer
shell: powershell
run: |
Set-PSRepository -Name PSGallery -InstallationPolicy Trusted
Install-Module Pester -MinimumVersion 5.5.0 -MaximumVersion 5.99.99 `
-Force -SkipPublisherCheck -Scope CurrentUser
Install-Module PSScriptAnalyzer -Force -Scope CurrentUser
Import-Module Pester -MinimumVersion 5.5.0
'Pester ' + (Get-Module Pester).Version + ', PSScriptAnalyzer ' + (Get-Module -ListAvailable PSScriptAnalyzer | Select-Object -First 1).Version
# Errors fail the job; warnings are printed and do not. The repo was
# written without the analyzer, and turning every style warning into a
# red build on day one would make the gate something to disable rather
# than something to keep. PSAvoidUsingWriteHost is excluded outright:
# these are command-line tools whose Write-Host output IS the interface.
- name: Lint (PSScriptAnalyzer)
shell: powershell
run: |
$r = Invoke-ScriptAnalyzer -Path . -Recurse -ExcludeRule PSAvoidUsingWriteHost
$warn = @($r | Where-Object Severity -eq Warning)
$err = @($r | Where-Object Severity -eq Error)
if ($warn) {
Write-Host ("{0} warning(s), not failing the build:" -f $warn.Count)
$warn | Format-Table RuleName, ScriptName, Line -AutoSize | Out-String | Write-Host
}
if ($err) {
$err | Format-Table RuleName, ScriptName, Line, Message -AutoSize -Wrap | Out-String | Write-Host
throw ("PSScriptAnalyzer: {0} error(s)" -f $err.Count)
}
Write-Host "no errors"
# -CI sets the exit code from the result, which is the whole point here:
# Invoke-Pester on its own reports failures and still exits 0, so the
# job would go green with a red suite.
- name: Tests
shell: powershell
run: Invoke-Pester -Path tests -CI