aws-samples / aws-samples/sample-autonomous-cloud-coding-agents
feat(ci): structured CI output — pytest JUnit XML + SARIF from eslint/ruff/semgrep (CA-06)
- Langage dominant
- TypeScript
- Étoiles
- 146
- Forks
- 46
- Merge moyen
- 3 j 10 h
- PR mergées (30 j)
- 24
Description
> **This is a finding from https://github.com/krokoko/cairn** (action item **CA-06**).
### Component
Tooling / CI
### Describe the feature
Emit **structured CI output** and upload it as artifacts + to GitHub code-scanning:
- **pytest** → JUnit XML (`--junitxml=test-reports/agent.xml`) — currently the agent suite is console-only with no structured artifact.
- **ESLint / ruff / semgrep** → **SARIF**, uploaded to GitHub code-scanning (`github/codeql-action/upload-sarif`).
This makes findings **agent-routable** — every failure carries file / line / rule / suggested-fix, the same property that makes the existing fail-on-mutation `repo.patch` artifact an exemplary agent-consumable signal.
### Use case
The feedback loop is at Level 2 (routable) but several lanes are stuck at Level 1: pytest has no JUnit reporter, and eslint/ruff/semgrep emit console text only. Without structured output, an agent (or the fix-and-repush loop) can't reliably parse *what* to fix and *where*. Structured, machine-routable findings are the prerequisite for closing the loop toward Level 3 (auto re-trigger on failure).
### Proposed solution
1. Add `--junitxml=test-reports/agent.xml` to the pytest invocation; upload via `actions/upload-artifact`.
2. Emit SARIF: `eslint -f @microsoft/sarif`, `ruff --output-format sarif`, semgrep `--sarif`.
3. Upload SARIF to GitHub code-scanning with `github/codeql-action/upload-sarif`.
4. Keep the existing JUnit (`jest-junit`) and lcov/cobertura coverage outputs.
### Acceptance criteria
- [ ] pytest emits JUnit XML uploaded as a CI artifact.
- [ ] ESLint, ruff, and semgrep emit SARIF.
- [ ] SARIF is uploaded to GitHub code-scanning and findings appear in the Security tab.
- [ ] No regression to the existing `jest-junit` / coverage artifacts.
### Other information
Source reports: `verification-report.md` (Feedback Loop Completeness), `verification-strategy.md` (Phase 1 #3; Feedback Loop Improvements), `ai-smells-gates-report.md` (Strengthen existing gates #3). Effort: **S**. Per ADR-003 this issue needs the `approved` label before work begins.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par localiser les workflows GitHub Actions et leurs appels à pytest, ESLint, ruff, semgrep, jest-junit et coverage. Vérifiez les étapes existantes de téléversement des artefacts, puis assurez-vous que pytest produit l’artefact JUnit demandé, que les trois linters génèrent et téléversent du SARIF vers code scanning, et que les artefacts de test et de coverage existants restent intacts.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- github-actions, python, typescript
- Domaine
- ci-cd, security, tooling
- Type d'issue
- Fonctionnalité
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 55/100