Feature: CI workflow validation As a developer I want to ensure the CI workflow exists and uses nox sessions So that all CI checks run through the same tooling as local development Scenario: CI workflow file exists Given the CI workflow file at ".forgejo/workflows/ci.yml" Then the CI workflow file should exist Scenario: CI workflow references nox for lint Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "lint" And the job "lint" should run "nox -s lint" Scenario: CI workflow references nox for typecheck Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "typecheck" And the job "typecheck" should run "nox -s typecheck" Scenario: CI workflow references nox for unit tests Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "unit_tests" And the job "unit_tests" should run "nox -s unit_tests" Scenario: CI workflow references nox for integration tests Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "integration_tests" And the job "integration_tests" should run "nox -s integration_tests" Scenario: CI workflow references nox for coverage Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "coverage" And the job "coverage" should run "nox -s coverage_report" Scenario: CI workflow references nox for security Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "security" And the job "security" should run "nox -s security_scan" Scenario: CI workflow references nox for build Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "build" And the job "build" should run "nox -s build" Scenario: CI workflow uses Python 3.13 Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow env should set "PYTHON_VERSION" to "3.13" Scenario: CI workflow coverage job depends on lint and typecheck Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "coverage" should depend on "lint" And the job "coverage" should depend on "typecheck" Scenario: All required nox sessions are referenced Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should reference these nox sessions: | session | | lint | | typecheck | | unit_tests | | integration_tests | | coverage_report | | security_scan | | dead_code | | complexity | | build | # --- Release pipeline scenarios --- Scenario: Release workflow file exists Given the CI workflow file at ".forgejo/workflows/release.yml" Then the CI workflow file should exist Scenario: Release workflow YAML is valid Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the workflow YAML should be valid Scenario: Release workflow triggers on version tags Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the workflow should trigger on push tags matching "v*" Scenario: Release workflow has build-wheel job Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the workflow should have a job named "build-wheel" And the job "build-wheel" should run "nox -s build" Scenario: Release workflow has build-docker job Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the workflow should have a job named "build-docker" Scenario: Release workflow has create-release job Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the workflow should have a job named "create-release" Scenario: Release workflow create-release depends on build jobs Given the CI workflow file at ".forgejo/workflows/release.yml" When I parse the CI workflow YAML Then the job "create-release" should depend on "build-wheel" And the job "create-release" should depend on "build-docker" # --- Status-check consolidation job --- Scenario: CI workflow has status-check consolidation job Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "status-check" Scenario: Status-check job depends on all required jobs Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "status-check" should depend on "lint" And the job "status-check" should depend on "typecheck" And the job "status-check" should depend on "security" And the job "status-check" should depend on "unit_tests" And the job "status-check" should depend on "coverage" # --- Coverage threshold --- Scenario: CI coverage threshold is 97% Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the coverage job should enforce a 97% threshold # --- Branch triggers --- Scenario: CI workflow triggers on push to master Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should trigger on push to "master" Scenario: CI workflow triggers on pull requests to master Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should trigger on pull_request to "master" # --- Dependency caching --- Scenario: CI workflow uses dependency caching Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then at least one job should use actions/cache # --- Helm CI job --- Scenario: CI workflow has helm validation job Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the workflow should have a job named "helm" Scenario: Helm job runs helm lint Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "helm" should run "helm lint" Scenario: Helm job runs helm template Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "helm" should run "helm template" Scenario: Helm job validates rendered manifests with kubeconform Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "helm" should run "kubeconform" Scenario: Status-check job depends on helm job Given the CI workflow file at ".forgejo/workflows/ci.yml" When I parse the CI workflow YAML Then the job "status-check" should depend on "helm"