CI Quality Report
On every push to main, every pull request, and every manual (workflow_dispatch) trigger, the quality-report job in .github/workflows/ci.yml (display name: CI / Quality Report) runs and produces an IQV Platform CI Quality Result report.
What it does
The quality-report job depends (needs) on the six required jobs that run before it, and runs with if: always() even if any of them fails:
- CI / Lint
- CI / Production TypeScript
- CI / Test TypeScript
- CI / Tests and Coverage
- CI / Production Build
- CI / Dependency Audit
The job reads the needs.<job>.result values and (if available) the coverage/test metrics from the iqv-platform-ci-metrics temporary artifact produced by the CI / Tests and Coverage job, then runs scripts/generate-ci-quality-report.mjs.
Outputs
- A summary report titled
IQV Platform CI Quality Resultis shown on GitHub's "Job Summary" screen. - A downloadable artifact named
iqv-platform-ci-quality-reportis produced, retained for 14 days. This artifact has the following structure:
iqv-platform-ci-quality-report/
├── REPORT.md
├── REPORT.json
├── iqv-platform-ci-report.md
├── iqv-platform-ci-report.json
├── mkdocs.yml
└── docs/
├── index.md
├── ci-quality-report.md
└── development.md
Scoring
The total score is 100:
- A) Required CI job results — 50 points: Lint (8), Production TypeScript (8), Test TypeScript (8), Tests and Coverage (12), Production Build (9), Dependency Audit policy (5).
- B) Test and coverage quality — 20 points: all suites passing (5), all tests passing (5), statements/branches/functions/lines above threshold (2+2+2+2), a bonus for comfortably exceeding thresholds (2).
- C) Workflow security and deterministic structure — 15 points: least-privilege permissions,
npm ci+package-lock.json, Node version via.nvmrc, concurrency, timeouts, no secret logging, no deploy step. - D) Repository and documentation quality — 15 points: presence of
mkdocs.ymlanddocs/*.mdfiles, the report being produced as both Markdown and JSON, the artifact being prepared successfully.
Result levels
| Score | Result |
|---|---|
| 95–100 | PASSED — Excellent |
| 90–94 | PASSED WITH WARNINGS — Good |
| 80–89 | NEEDS IMPROVEMENT |
| 0–79 | FAILED |
Important: If any required job fails, or a critical dependency vulnerability is detected, the overall result is always reported as FAILED, regardless of how high the numeric score is. The report script never fabricates values; if a data source (coverage, test details) is unavailable, the corresponding field is marked "Unavailable" and no points are awarded for it.
Known limitations
- The
CI / Dependency Auditjob only turns red on critical-severity findings (npm audit --audit-level=critical, blocking); high/moderate findings are reported in a separate, non-blocking step. Because of this, the report shows the "Accepted/Documented Risk" status for high/moderate findings rather than their exact count. - Coverage and test details depend on the
iqv-platform-ci-metricsartifact produced by theCI / Tests and Coveragejob. If that artifact is not produced for any reason (e.g. the job fails at thenpm cistep before reaching the coverage step), the report does not crash — the corresponding fields are simply marked "Unavailable".