IQV API Middleware CI
The IQV API Middleware quality pipeline runs on every push and pull request: backend and frontend tests, contract (Swagger) validation, type checking, linting, production builds and a security scan — producing a deterministic quality report.
At a glance
| Topic | Value |
|---|---|
| Environment | GitHub Actions (ubuntu-latest) + Docker |
| Node version | 22 (engines intersection: backend >=20, dashboard >=22 <23) |
| Dependency install | npm ci (deterministic) |
| Phase count | 16 |
| Artifact name | iqv-platform-quality-report |
| Decision authority | ci/scripts/ci-policy.mjs |
Documents
- Architecture — components and data flow
- Pipeline — all 16 phases
- Local run — with and without Docker
- GitHub Actions — workflow, artifact, job summary
- Quality policy — scoring and PASS/FAIL gates
- Troubleshooting
Core principles
- Test counts are never hardcoded; they are computed from real output on every run.
- The existing test infrastructure is reused; no second framework is introduced.
- CI never touches the production database, bucket or SMTP account.
- Reports never contain secret values.