Files
accounted/.github/workflows/test-pg-real.yml
T
Jakob WennbergandClaude Opus 4.8 bc61862e76 feat(agent): telemetry + CI-gate quick wins from the "AI systems that ship" audit (#677)
* feat(agent): telemetry completeness + durability, CI gates, commit_method provenance

Quick wins from the "Building AI systems that ship" audit:

- mcp.tool_called gains errorMessage (message_sv, truncated 500 chars) on
  all failure exits; new mcp.skill_loaded event on every gnubok_load_skill
  (all tiers) so atom usage is finally measurable
- event_log: (event_type, created_at) index; cleanup cron keeps
  mcp.*/agent.* telemetry 180 days (delivery events stay 30)
- CI: lint ratchet (npm run check:lint — 60 legacy errors baselined,
  fails only on NEW errors) and a pg-real coverage gate (migrations
  touching trigger/RPC/RLS/DEFERRABLE require a *.pg.test.ts change;
  escape hatch: -- pg-test: covered-by/skip)
- journal_entries.commit_method CHECK widened with 'api_key'/'agent';
  the MCP approve path records 'api_key' truthfully instead of
  'user_accept' (agent_first_vision §8 P0-1). 'agent' is reserved — ALL
  MCP traffic (incl. claude.ai OAuth, whose access_token is a minted
  API key) authenticates as api_key today

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* feat(import): derive opening balances from prior-year #UB when SIE lacks #IB (#675)

SIE files exported without #IB 0 rows (only #UB -1) previously imported
with zero opening balances. getEffectiveOpeningBalances() now derives IB
from prior-year UB for balance-sheet accounts when explicit #IB is
absent, surfaces the derivation as an info issue in the import preview,
and excludes share-capital vouchers from opening-balance detection.
Detection regexes are shared between parser and importer so the two
checks cannot drift. 507 lib/import tests pass.

(Authored in a parallel session in this checkout; included per request.)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(review): address PR #677 bot findings — RoPA entry, execFileSync, gate scope note

Triage of the compliance-swarm + Greptile findings:

Applied:
- .compliance/ropa.yaml: new mcp.telemetry processing activity declaring
  the 180-day mcp.*/agent.* retention, lawful basis, data categories, and
  the no-args/no-results minimisation (ISO A.8.10, GDPR Art.5(1)(c) —
  the retention split is now formally documented, referenced from the cron)
- check-pg-test-coverage.mjs: execFileSync with argv array — no shell, so
  a hostile base-ref can't inject (ASVS V13.2.1); verified an injection
  attempt exits 2 without executing
- check-pg-test-coverage.mjs: documented the PR-level (not per-migration)
  scope of the gate so reviewers know to check coverage per migration when
  a PR carries several risky migrations (Greptile P2)

Acknowledged, no change:
- errorMessage PII risk: messages are domain-mapped strings; event_log
  already persists far richer delivery payloads under the same RLS; now
  declared in ropa.yaml
- cron error envelope: errorResponse maps to the canonical safe envelope
  and the endpoint is CRON_SECRET-gated
- two-pass delete "partial state": TTL deletes are idempotent — the next
  daily run sweeps whatever a failed pass left behind
- skill_loaded actorLabel/sessionId: mirrors the pre-existing
  mcp.tool_called payload; sessionId is the join key the analytics exist for

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 15:47:13 +02:00

86 lines
2.6 KiB
YAML

name: pg-real tests
on: [pull_request]
concurrency:
group: pg-real-${{ github.ref }}
cancel-in-progress: true
jobs:
coverage-gate:
# Enforces the database.md rule: a migration touching a trigger/RPC/RLS/
# DEFERRABLE must come with a *.pg.test.ts change. Previously instruction-
# only. Escape hatch: `-- pg-test: covered-by <path>` / `-- pg-test: skip
# (<reason>)` comments inside the migration.
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# Full history so the merge-base with the PR base branch exists.
fetch-depth: 0
- uses: actions/setup-node@v4
with:
node-version: 20
- name: Require pg-real coverage for trigger/RPC/RLS migrations
env:
PG_GATE_BASE: origin/${{ github.base_ref }}
run: node scripts/check-pg-test-coverage.mjs
pg-real:
runs-on: ubuntu-latest
services:
postgres:
# Supabase image ships the auth schema, auth.uid(), and the extensions
# (uuid-ossp, pg_cron, btree_gist, vector) this repo's migrations need.
# Plain postgres:15 would require manual bootstrap SQL.
image: supabase/postgres:15.8.1.060
env:
POSTGRES_PASSWORD: postgres
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U postgres"
--health-interval 5s
--health-timeout 5s
--health-retries 20
env:
DATABASE_URL: postgresql://postgres:postgres@localhost:5432/postgres
PGPASSWORD: postgres
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- name: Install psql client
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends postgresql-client
- name: Bootstrap storage schema
# The supabase/postgres image ships a partial storage schema; the rest
# is provisioned by the storage-api service at runtime, which we do
# not run in CI. This aligns the schema with what migrations expect.
run: psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -q -f tests/pg/bootstrap.sql
- name: Apply migrations
run: |
set -euo pipefail
shopt -s nullglob
files=(supabase/migrations/*.sql)
if [ ${#files[@]} -eq 0 ]; then
echo "No migration files found"
exit 1
fi
for f in "${files[@]}"; do
echo "Applying $f"
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -q -f "$f"
done
- run: npm run test:pg