GitHub Actions
Workflow: .github/workflows/ci-quality.yml
Triggers
| Event | Scope |
|---|---|
push |
main, develop |
pull_request |
all pull requests |
workflow_dispatch |
manual run |
Older runs on the same ref are cancelled via concurrency.
Job timeout: 60 minutes. Permissions: contents: read only.
Services
| Service | Image | Purpose |
|---|---|---|
mongo-ci |
mongo:7 |
real MongoDB integration tests (iqvizyon_ci_test) |
minio-ci |
bitnami/minio |
object storage tests (iqv-platform-ci bucket) |
mailpit-ci |
axllent/mailpit |
SMTP sink — no mail reaches a real recipient |
The production
iqvizyondatabase, theiqv-platform-notlarbucket and the real Office365 account are not used in CI. The realSMTP_PASSWORDnever enters CI; Mailpit requires no authentication.
Job Summary
generate-ci-report.mjs appends iqv-platform-ci-report.md to
$GITHUB_STEP_SUMMARY. The Actions run page shows:
# IQV Platform Quality Result
**Project:** IQV Platform
**Version:** 1.0.0
**Result:** PASSED
**Score:** 96/100 (Mükemmel)
**Critical:** 0
**Error:** 0
**Warning:** 4
The numbers above are illustrative; every run recomputes them from real output.
Artifact
Name: iqv-platform-quality-report — uploaded even when the pipeline is red
(if: always()), retained for 30 days.
| File | Content |
|---|---|
iqv-platform-ci-report.json |
short machine-readable summary |
iqv-platform-ci-report.md |
same short Markdown as the job summary |
REPORT.json |
detailed machine-readable report |
REPORT.md |
18-section detailed human report |
results.json, raw/ |
raw phase results and full logs |
Secrets
This workflow requires no GitHub secrets. All credentials are CI-only, ephemeral, container-local constants. Production secrets are never moved into the repository or into CI.