aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

feat(ci): structured CI output — pytest JUnit XML + SARIF from eslint/ruff/semgrep (CA-06)

Ouverte
#256 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
ci-cd validation-loop
Langage dominant
TypeScript
Étoiles
146
Forks
46
Merge moyen
3 j 10 h
PR mergées (30 j)
24

Description

> **This is a finding from https://github.com/krokoko/cairn** (action item **CA-06**).

### Component

Tooling / CI

### Describe the feature

Emit **structured CI output** and upload it as artifacts + to GitHub code-scanning:

- **pytest** → JUnit XML (`--junitxml=test-reports/agent.xml`) — currently the agent suite is console-only with no structured artifact.
- **ESLint / ruff / semgrep** → **SARIF**, uploaded to GitHub code-scanning (`github/codeql-action/upload-sarif`).

This makes findings **agent-routable** — every failure carries file / line / rule / suggested-fix, the same property that makes the existing fail-on-mutation `repo.patch` artifact an exemplary agent-consumable signal.

### Use case

The feedback loop is at Level 2 (routable) but several lanes are stuck at Level 1: pytest has no JUnit reporter, and eslint/ruff/semgrep emit console text only. Without structured output, an agent (or the fix-and-repush loop) can't reliably parse *what* to fix and *where*. Structured, machine-routable findings are the prerequisite for closing the loop toward Level 3 (auto re-trigger on failure).

### Proposed solution

1. Add `--junitxml=test-reports/agent.xml` to the pytest invocation; upload via `actions/upload-artifact`.
2. Emit SARIF: `eslint -f @microsoft/sarif`, `ruff --output-format sarif`, semgrep `--sarif`.
3. Upload SARIF to GitHub code-scanning with `github/codeql-action/upload-sarif`.
4. Keep the existing JUnit (`jest-junit`) and lcov/cobertura coverage outputs.

### Acceptance criteria

- [ ] pytest emits JUnit XML uploaded as a CI artifact.
- [ ] ESLint, ruff, and semgrep emit SARIF.
- [ ] SARIF is uploaded to GitHub code-scanning and findings appear in the Security tab.
- [ ] No regression to the existing `jest-junit` / coverage artifacts.

### Other information

Source reports: `verification-report.md` (Feedback Loop Completeness), `verification-strategy.md` (Phase 1 #3; Feedback Loop Improvements), `ai-smells-gates-report.md` (Strengthen existing gates #3). Effort: **S**. Per ADR-003 this issue needs the `approved` label before work begins.

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par localiser les workflows GitHub Actions et leurs appels à pytest, ESLint, ruff, semgrep, jest-junit et coverage. Vérifiez les étapes existantes de téléversement des artefacts, puis assurez-vous que pytest produit l’artefact JUnit demandé, que les trois linters génèrent et téléversent du SARIF vers code scanning, et que les artefacts de test et de coverage existants restent intacts.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
github-actions, python, typescript
Domaine
ci-cd, security, tooling
Type d'issue
Fonctionnalité
Difficulté
4/5
Temps estimé
3-5 jours
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
55/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.