Skip to content
37 changes: 37 additions & 0 deletions .github/workflows/static-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,9 @@ jobs:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Need the PR base (or push before SHA) so the E2E wait_for_timeout
# guard can diff only *new* call sites (#189).
fetch-depth: 0
persist-credentials: false

- name: Set up Python
Expand All @@ -46,6 +49,40 @@ jobs:
- name: Enforce PRKS engineering invariants
run: python scripts/check_invariants.py

- name: Fail on new E2E page.wait_for_timeout
# Diff-aware (#189): historical sleeps under tests/e2e/ do not fail
# unrelated PRs. Only newly added / newly-unexempted call sites fail.
# PR base is the immutable event SHA (not the live base-branch tip).
# Zero-before pushes (new/recreated branch) use the empty tree so the
# full tip is scanned — do not merge-base with origin/master after a
# master push (that ref can equal HEAD and skip newly pushed history).
# workflow_dispatch compares against HEAD so grandfathered historical
# waits stay grandfathered (empty tree would fail the whole corpus).
shell: bash
env:
PRKS_PR_BASE_SHA: ${{ github.event.pull_request.base.sha }}
PRKS_PUSH_BEFORE: ${{ github.event.before }}
run: |
set -euo pipefail
empty_tree="4b825dc642cb6eb9a060e54bf8d6927f8d2765b5"
zero_sha="0000000000000000000000000000000000000000"
if [[ "${{ github.event_name }}" == "pull_request" ]]; then
base="${PRKS_PR_BASE_SHA:?missing pull_request.base.sha}"
git fetch --no-tags --depth=1 origin "$base"
elif [[ "${{ github.event_name }}" == "push" ]]; then
if [[ -n "${PRKS_PUSH_BEFORE:-}" && "${PRKS_PUSH_BEFORE}" != "$zero_sha" ]]; then
base="$(git rev-parse --verify --end-of-options "${PRKS_PUSH_BEFORE}")"
else
# Parentless / new-branch push: scan full tip vs empty tree.
base="$empty_tree"
fi
else
# workflow_dispatch (and any other non-PR/non-push event): no-new-
# change baseline so historical E2E waits remain grandfathered.
base="$(git rev-parse --verify --end-of-options HEAD)"
fi
python scripts/check_e2e_wait_for_timeout.py --base "$base"

pyright:
permissions:
contents: read
Expand Down
Loading
Loading