Skip to content

CI Quality Report

On every push to main, every pull request, and every manual (workflow_dispatch) trigger, the quality-report job in .github/workflows/ci.yml (display name: CI / Quality Report) runs and produces an IQV Platform CI Quality Result report.

What it does

The quality-report job depends (needs) on the six required jobs that run before it, and runs with if: always() even if any of them fails:

  • CI / Lint
  • CI / Production TypeScript
  • CI / Test TypeScript
  • CI / Tests and Coverage
  • CI / Production Build
  • CI / Dependency Audit

The job reads the needs.<job>.result values and (if available) the coverage/test metrics from the iqv-platform-ci-metrics temporary artifact produced by the CI / Tests and Coverage job, then runs scripts/generate-ci-quality-report.mjs.

Outputs

  1. A summary report titled IQV Platform CI Quality Result is shown on GitHub's "Job Summary" screen.
  2. A downloadable artifact named iqv-platform-ci-quality-report is produced, retained for 14 days. This artifact has the following structure:
iqv-platform-ci-quality-report/
├── REPORT.md
├── REPORT.json
├── iqv-platform-ci-report.md
├── iqv-platform-ci-report.json
├── mkdocs.yml
└── docs/
    ├── index.md
    ├── ci-quality-report.md
    └── development.md

Scoring

The total score is 100:

  • A) Required CI job results — 50 points: Lint (8), Production TypeScript (8), Test TypeScript (8), Tests and Coverage (12), Production Build (9), Dependency Audit policy (5).
  • B) Test and coverage quality — 20 points: all suites passing (5), all tests passing (5), statements/branches/functions/lines above threshold (2+2+2+2), a bonus for comfortably exceeding thresholds (2).
  • C) Workflow security and deterministic structure — 15 points: least-privilege permissions, npm ci + package-lock.json, Node version via .nvmrc, concurrency, timeouts, no secret logging, no deploy step.
  • D) Repository and documentation quality — 15 points: presence of mkdocs.yml and docs/*.md files, the report being produced as both Markdown and JSON, the artifact being prepared successfully.

Result levels

Score Result
95–100 PASSED — Excellent
90–94 PASSED WITH WARNINGS — Good
80–89 NEEDS IMPROVEMENT
0–79 FAILED

Important: If any required job fails, or a critical dependency vulnerability is detected, the overall result is always reported as FAILED, regardless of how high the numeric score is. The report script never fabricates values; if a data source (coverage, test details) is unavailable, the corresponding field is marked "Unavailable" and no points are awarded for it.

Known limitations

  • The CI / Dependency Audit job only turns red on critical-severity findings (npm audit --audit-level=critical, blocking); high/moderate findings are reported in a separate, non-blocking step. Because of this, the report shows the "Accepted/Documented Risk" status for high/moderate findings rather than their exact count.
  • Coverage and test details depend on the iqv-platform-ci-metrics artifact produced by the CI / Tests and Coverage job. If that artifact is not produced for any reason (e.g. the job fails at the npm ci step before reaching the coverage step), the report does not crash — the corresponding fields are simply marked "Unavailable".