[E00-S04-T05] .env.example contains placeholders only (#404)
CI / Frozen lockfile install (push) Successful in 42s
CI / Secrets not embedded (E00-S02-T08) (push) Successful in 28s
CI / Database-postgres import isolation (E00-S03-T02) (push) Successful in 24s
CI / Migration ledger (E00-S03-T03) (push) Successful in 42s
CI / Migration advisory lock (E00-S03-T04) (push) Successful in 48s
CI / Migration failure diagnostic (E00-S03-T05) (push) Successful in 46s
CI / App readiness after migrations (E00-S03-T06) (push) Successful in 1m4s
CI / Field-specific startup errors (E00-S04-T02) (push) Successful in 1m5s
CI / Secret redaction from logs (E00-S04-T03) (push) Successful in 1m6s
CI / Env adapter owns process.env (E00-S04-T04) (push) Successful in 1m12s
CI / Compose config (E00-S03-T01) (push) Successful in 26s
CI / TypeBox/Ajv config schema (E00-S04-T01) (push) Successful in 1m4s
CI / .env.example placeholders only (E00-S04-T05) (push) Successful in 29s

Co-authored-by: bot-implementer <bot-implementer@fabrika.internal>
This commit was merged in pull request #404.
This commit is contained in:
2026-08-30 05:47:42 +00:00
committed by kpcto
parent 1e0f628651
commit dce6cac05b
8 changed files with 361 additions and 9 deletions
+24
View File
@@ -287,6 +287,30 @@ jobs:
- name: Run config schema test suite
run: node --test tests/config-schema.test.mjs
# E00-S04-T05: the static assertions of tests/env-example.test.mjs gate every
# PR — the suite locks in the committed `.env.example` template: it exists at
# the repo root, is un-ignored in .gitignore (real `.env` files stay ignored
# while the example is tracked), documents every configuration environment
# source (HOST/PORT/DATABASE_URL/EPPP_SESSION_SECRET), and contains
# placeholder values only — no credential URI, no long secret-looking value,
# and no compose default credential — with mutation probes proving the
# assertions are non-vacuous. It also locks the fail-closed EPPP_SESSION_SECRET
# placeholder (shorter than the schema's 32-character minimum), builds the
# secret-shaped probe at runtime so the branch stays gitleaks-clean, and
# masks raw values in assertion messages. The test needs no dependencies, so
# the job only installs Node.
env-example:
name: .env.example placeholders only (E00-S04-T05)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Node.js 24
uses: actions/setup-node@v4
with:
node-version: '24'
- name: Run .env.example test suite
run: node --test tests/env-example.test.mjs
# E00-S03-T01: the static assertions of tests/compose-config.test.mjs (db
# image pinned to postgres:18.6-bookworm, health gate, volume persistence,
# build platforms) gate every PR (the docker-gated real-stack probes inside