Quality Policy
The score is not decorative. The same input always produces the same score;
the rules live in ci/scripts/ci-policy.mjs as the single source of truth.
Weights (total 100)
| Category | Weight | Covered phases |
|---|---|---|
| Backend Tests | 18 | Backend Unit |
| Backend Integration | 15 | Backend Integration |
| Frontend Tests | 18 | Frontend Unit/Component/Service |
| API Contracts | 12 | Swagger + Node-RED regression |
| Security | 15 | secret scan |
| Build | 12 | backend + frontend production build |
| Code Quality | 6 | 3× typecheck + ESLint |
| Maintainability | 4 | audit logs + reminder mail + API Middleware |
| Total | 100 |
How a category is scored
- No executed phase in the category → 0 points. No evidence, no credit.
- Phases reporting test counts:
passed / (passed + failed)× weight. - Phases without test counts (build, typecheck): ratio of passing phases.
- Environment-blocked phases are removed from the denominator — a missing environment is not a penalty, but it does produce a separate warning finding.
Score labels
| Range | Label |
|---|---|
| 95–100 | Mükemmel (Excellent) |
| 90–94 | Çok İyi (Very Good) |
| 80–89 | İyi (Good) |
| 70–79 | İyileştirilmeli (Needs Improvement) |
| < 70 | Yetersiz (Insufficient) |
PASS / FAIL gates
CI never decides by score alone. If any of the following holds, the
result is FAILED:
criticalfinding count > 0- Backend unit test failures > 0
- Backend integration test failures > 0
- Frontend test failures > 0
- Node-RED regression failures > 0
- Swagger / OpenAPI contract failures > 0
- Audit log test failures > 0
- Reminder mail test failures > 0
- API Middleware backend test failures > 0
- TypeScript compile error (backend, frontend or frontend-test)
- Production build error (backend or frontend)
- Hardcoded secret in source (
HARDCODED_SECRET_FOUND) - A mandatory phase never ran (partial run) — an incomplete run cannot look green without producing evidence
Non-blocking (warnings only)
- ESLint errors — style/lint violations do not block a release; reported as
Öncelikli İyileştirme(priority improvement). - Missing environment (MongoDB/MinIO/SMTP/Docker unreachable) —
Normal İyileştirme. - Skipped tests — coverage gap,
Normal İyileştirme.
Action levels
| Level | Meaning |
|---|---|
| Acil Aksiyon (Urgent) | Blocks the release; fix immediately. |
| Öncelikli İyileştirme (Priority) | Does not block; close in the next iteration. |
| Normal İyileştirme (Normal) | Planned improvement; scope/maturity topic. |
Never allowed
To produce a green result, the following are never done:
- deleting a failing test
- relaxing an assertion
- adding
test.skip - dismissing a real failure as a "timeout"
- changing production code just to make a test pass
- making a mock differ from real behaviour
If a test is genuinely red, it is reported red.