Skip to content

CI: add Sobelow and a Compile · Format job - #40

Merged
bbangert merged 2 commits into
mainfrom
claude/serene-curie-xrjxef-sobelow
Oct 4, 2026
Merged

bbangert merged 2 commits into
mainfrom
claude/serene-curie-xrjxef-sobelow

Conversation

@bbangert

@bbangert bbangert commented Oct 4, 2026

Copy link
Copy Markdown
Owner

What changed

Adds the two CI jobs every repo is required to have, both running in parallel with the existing jobs. This PR targets main directly; it is not stacked on another PR.

Jobs before: Test (deps.get, compile --warnings-as-errors, mix test), Credo, Dialyzer, Hex audit, Argus

Jobs after: Test (mix test only), Compile · Format (new), Credo, Dialyzer, Sobelow (new), Hex audit, Argus

  • Compile · Format (compile-format): runs mix compile --warnings-as-errors and then mix format --check-formatted. The compile step moved here from the Test job. Before this PR, CI did not check formatting at all. The job uses the same setup-beam/cache action versions and the same MIX_ENV: test as Test, with its own cache key mix-compile-*.
  • Sobelow (sobelow): runs mix sobelow --skip --exit --threshold medium, with its own cache key mix-sobelow-*. mix.exs gains {:sobelow, "~> 0.14", only: [:dev, :test], runtime: false} next to credo and dialyxir. Only mix deps.get changed mix.lock (it added sobelow 0.16.0).

What Sobelow reported

There were no findings, at any threshold (I also ran it with no --threshold). espex is not a Phoenix app, so Sobelow prints a "cannot find the router" warning and skips the router-based checks. It also prints harmless warnings while parsing mix.lock. No --ignore flags or # sobelow_skip comments were needed.

Validation (run locally on this branch)

  • The workflow YAML parses, with 7 jobs.
  • mix deps.get --check-locked: ok
  • mix compile --warnings-as-errors --force (MIX_ENV=test): ok
  • mix format --check-formatted: ok
  • mix sobelow --skip --exit --threshold medium: exit 0, no findings
  • mix credo --strict: no issues
  • mix dialyzer: passed
  • mix hex.audit: no retired or security-advisory packages
  • mix deps.unlock --check-unused: ok
  • mix argus --fail-above 0: 0 findings
  • mix test: 4 doctests, 420 tests, 0 failures

🤖 Generated with Claude Code

https://claude.ai/code/session_01UmkxCtMk3Y8vf2b42ZyVTu


Generated by Claude Code

Move compile --warnings-as-errors out of the Test job into a parallel
Compile · Format job that also checks formatting, and add a Sobelow
job (medium threshold) with sobelow as a dev/test dep.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UmkxCtMk3Y8vf2b42ZyVTu

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The dependency and workflow changes are consistent, scoped, and correctly implement the stated CI checks.

Review effort: Balanced
Findings: None

What changed in this PR

Adds required Sobelow security scanning and compile/format validation to CI.

Changes:

  • Adds a parallel Compile · Format job.
  • Adds Sobelow dependency and CI job.
  • Moves warnings-as-errors compilation out of Test.
File Description
.github/​workflows/​ci.yml Adds Compile · Format and Sobelow jobs.
mix.exs Adds Sobelow as a development/test dependency.
mix.lock Locks Sobelow 0.16.0.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Without --private, Sobelow calls out to a version service on every run,
adding latency and making the security job depend on that service's
availability.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UmkxCtMk3Y8vf2b42ZyVTu

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The CI jobs and dependency changes are consistent, scoped, and correctly configured.

Review effort: Balanced
Findings: None

@bbangert
bbangert merged commit adba0f7 into main Oct 4, 2026
8 checks passed
@bbangert
bbangert deleted the claude/serene-curie-xrjxef-sobelow branch October 4, 2026 23:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants