Skip to content

ci: Publish prebuilt assets for Pilot - #604

Merged
netchampfaris merged 1 commit into
developfrom
ci/pilot-prebuilt-assets
Oct 5, 2026
Merged

netchampfaris merged 1 commit into
developfrom
ci/pilot-prebuilt-assets

Conversation

@tanmoysrt

@tanmoysrt tanmoysrt commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Build the Gameplan assets in CI and publish them on the release assets-<branch>. Pilot benches download them and skip the asset build, the slowest and most memory-hungry step of an install or update.

What changed

  • Add the Pre-build assets workflow for pushes to develop.

See Prebuilt Assets.

Build the app's assets in CI for each push and publish them on the release assets-<branch>, so Pilot benches download them instead of building on the server.
@greptile-apps

greptile-apps Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[High risk] Adds a CI workflow that calls an external workflow.

The PR has a non-blocking workflow hardening issue.

Reviews (1) · Last reviewed commit: "ci: Publish prebuilt assets for Pilot"

jobs:
assets:
name: Pre-build assets
uses: frappe/pilot/.github/workflows/app-assets.yml@develop

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Mutable workflow has write access The Pilot workflow is loaded from its develop branch, so it can change without a Gameplan change. On the next Gameplan push, that code receives contents: write and could replace published assets or other repository contents. Pin it to a reviewed commit SHA. How this was verified: The called workflow uses a mutable external ref and receives the caller job’s write permission.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/assets.yml
Line: 10

Comment:
**Mutable workflow has write access** The Pilot workflow is loaded from its `develop` branch, so it can change without a Gameplan change. On the next Gameplan push, that code receives `contents: write` and could replace published assets or other repository contents. Pin it to a reviewed commit SHA. **How this was verified:** The called workflow uses a mutable external ref and receives the caller job’s write permission.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Test report

Backend ✅ 1280 passed · 7m 49s

50 modules
Module Tests ✅ ❌ ⏭ ⏱
test_api_endpoints.py 35 35 0 0 17s
test_app_access.py 7 7 0 0 4s
test_app_version.py 5 5 0 0 0s
test_archived_spaces.py 27 27 0 0 15s
test_attachments.py 32 32 0 0 1s
test_bookmarks.py 22 22 0 0 12s
test_collapsible_html.py 9 9 0 0 1s
test_communities.py 36 36 0 0 14s
test_content_access.py 7 7 0 0 3s
test_delete_cascade.py 3 3 0 0 2s
test_demo_fixture.py 7 7 0 0 0s
test_dev_user_switcher.py 8 8 0 0 4s
test_discussions.py 83 83 0 0 43s
test_drafts.py 17 17 0 0 9s
test_email_digest.py 26 26 0 0 17s
test_get_request_transactions.py 9 9 0 0 4s
test_guest_access.py 5 5 0 0 3s
test_guest_participation.py 18 18 0 0 10s
test_guest_structural_actions.py 36 36 0 0 21s
test_html_utils.py 6 6 0 0 0s
test_install.py 2 2 0 0 0s
test_invitations.py 32 32 0 0 17s
test_list_scoping.py 12 12 0 0 6s
test_members.py 9 9 0 0 1s
test_migrations.py 13 13 0 0 2s
test_mutation_ci.py 182 182 0 0 4s
test_mutation_classification.py 34 34 0 0 0s
test_mutation_cli.py 29 29 0 0 0s
test_mutation_mutators.py 27 27 0 0 2s
test_mutation_report.py 30 30 0 0 3s
test_mutation_safety.py 27 27 0 0 0s
test_notifications.py 37 37 0 0 21s
test_pages.py 10 10 0 0 5s
test_per_user_state.py 46 46 0 0 24s
test_permission_defaults.py 9 9 0 0 5s
test_permission_matrix.py 1 1 0 0 1s
test_polls.py 65 65 0 0 35s
test_profile_image_ownership.py 4 4 0 0 0s
test_profiles.py 65 65 0 0 41s
test_reactions.py 43 43 0 0 25s
test_realtime_activity.py 17 17 0 0 9s
test_realtime_events.py 14 14 0 0 6s
test_roles.py 9 9 0 0 0s
test_search.py 20 20 0 0 7s
test_search_isolation.py 8 8 0 0 2s
test_spaces.py 63 63 0 0 32s
test_unread.py 31 31 0 0 19s
test_unsplash.py 19 19 0 0 8s
test_v16_api_compat.py 3 3 0 0 3s
test_visibility.py 21 21 0 0 11s
Total 1280 1280 0 0 7m 49s

Coverage 90.3% (3,632 / 4,020 statements)

Backend coverage by area
Area Covered Statements Coverage
DocTypes 1,846 2,022 91.3%
Permissions 381 393 96.9%
Mixins 335 379 88.4%
HTTP API 271 302 89.7%
Other 238 285 83.5%
Email digest 252 270 93.3%
Search 184 206 89.3%
Utilities 125 163 76.7%
Total 3,632 4,020 90.3%

Least covered

File Coverage
gameplan/command_palette.py 13.6% (3/22)
gameplan/mixins/manage_members.py 25.0% (5/20)
gameplan/utils/sanitizer.py 52.6% (20/38)
gameplan/www/g.py 69.1% (56/81)
gameplan/mixins/tags.py 73.2% (52/71)
gameplan/utils/utils.py 83.7% (103/123)
gameplan/gameplan/doctype/gp_user_profile/gp_user_profile.py 84.9% (338/398)
gameplan/unsplash.py 87.0% (94/108)
gameplan/gameplan/doctype/gp_unread_record/gp_unread_record.py 89.1% (180/202)
gameplan/search_sqlite.py 89.3% (184/206)

Measured over product code only. Excluded: test suite (gameplan/tests/), Cypress seed API (gameplan/ui_test_helpers.py), demo data generator (gameplan/demo/), one-off Discourse importer (gameplan/migrate_from_discourse/), migration patches (gameplan/patches/), desk config stubs (gameplan/config/). Coverage is informational — no minimum threshold is enforced.

Cypress ✅ 157 passed · 9m 38s

45 specs
Spec Tests ✅ ❌ ⏭ ⏱
accept-invitation.cy.ts 2 2 0 0 5s
add-members.cy.ts 4 4 0 0 12s
archived-content.cy.ts 2 2 0 0 8s
bookmarks.cy.ts 1 1 0 0 8s
command-palette.cy.ts 5 5 0 0 12s
comment-actions.cy.ts 2 2 0 0 17s
comment-drafts.cy.ts 3 3 0 0 18s
community-home.cy.ts 3 3 0 0 6s
community-routing.cy.ts 3 3 0 0 7s
community-shell.cy.ts 3 3 0 0 6s
community-switching.cy.ts 3 3 0 0 8s
composer.cy.ts 3 3 0 0 10s
create-discussion.cy.ts 1 1 0 0 7s
create-page.cy.ts 1 1 0 0 7s
discussion-actions.cy.ts 8 8 0 0 28s
feeds.cy.ts 3 3 0 0 10s
guest-access.cy.ts 2 2 0 0 9s
join-leave.cy.ts 7 7 0 0 13s
member-management.cy.ts 3 3 0 0 9s
membership.cy.ts 4 4 0 0 14s
mention-prefixes.cy.ts 3 3 0 0 9s
merge-url-healing.cy.ts 1 1 0 0 7s
more-pages.cy.ts 4 4 0 0 10s
move-and-archive.cy.ts 2 2 0 0 12s
new-discussion.cy.ts 7 7 0 0 45s
notifications.cy.ts 2 2 0 0 9s
onboarding.cy.ts 1 1 0 0 4s
pinned-author-row.cy.ts 1 1 0 0 4s
poll-lifecycle.cy.ts 4 4 0 0 22s
profile-bento-cards.cy.ts 6 6 0 0 14s
profile-card-editing.cy.ts 7 7 0 0 15s
profile-customize.cy.ts 28 28 0 0 1m 2s
profile-settings.cy.ts 1 1 0 0 16s
profile-unsplash-cover.cy.ts 7 7 0 0 18s
quote-backlink-badge.cy.ts 1 1 0 0 6s
reactions.cy.ts 1 1 0 0 9s
realtime-activity.cy.ts 1 1 0 0 5s
scoped-links.cy.ts 3 3 0 0 7s
search-page.cy.ts 1 1 0 0 10s
search-privacy.cy.ts 1 1 0 0 5s
settings-menu.cy.ts 3 3 0 0 7s
shared-draft.cy.ts 4 4 0 0 25s
space-creation-guardrails.cy.ts 2 2 0 0 5s
task-actions.cy.ts 1 1 0 0 8s
task-comment-draft.cy.ts 2 2 0 0 33s
Total 157 157 0 0 9m 38s

Coverage 73.1% (6,343 / 8,677 statements)

Frontend coverage by area
Area Covered Statements Coverage
Components 3,712 5,113 72.6%
Pages 1,559 2,119 73.6%
Data layer 616 767 80.3%
Other 251 344 73.0%
Utilities 177 237 74.7%
Composables 17 81 21.0%
Directives 11 16 68.8%
Total 6,343 8,677 73.1%

Least covered

File Coverage
src/components/Settings/NotificationsSettings.vue 6.1% (6/99)
src/components/AvatarCropper.vue 6.6% (6/91)
src/components/ProfileImageEditor.vue 7.3% (3/41)
src/composables/usePointerSortableSections.ts 10.3% (7/68)
src/components/Settings/CustomEmojiSettings.vue 25.7% (18/70)
src/components/editor/collapsible/collapsible-extension.ts 26.9% (21/78)
src/components/NewDiscussionSpaceDialog.vue 28.1% (9/32)
src/pages/Configure/CommunityGuestsList.vue 33.9% (21/62)
src/components/Settings/QuickReactionsEditor.vue 34.9% (29/83)
src/pages/Configure/CommunityOptions.vue 35.0% (7/20)

Collected by Cypress against an istanbul-instrumented build, so it marks lines that ran, not lines a spec asserted on — read it to find untouched areas, not as a quality score against the backend number. Excluded: generated doctype types (src/types/). Coverage is informational — no minimum threshold is enforced.

Updated for commit 73633ca.

@netchampfaris
netchampfaris merged commit 2612c7e into develop Oct 5, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants