Skip to content

fix: drift ワークフローの実体にソース由来の経路検知を入れる - #1919

Merged
mhaya merged 2 commits into
develop_v2.1.0from
fix/api-inventory-drift-detect-routes
Sep 27, 2026
Merged

mhaya merged 2 commits into
develop_v2.1.0from
fix/api-inventory-drift-detect-routes

Conversation

@mhaya

@mhaya mhaya commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

変更内容

  • .github/workflows/api-inventory-drift.yml を原本(tools/api-inventory/ci/)に揃える。実体から抜けていた detect_routes.py --cross-check --gate(ソース ↔ 台帳の突き合わせ)の段が入る
  • 原本と実体の一致を見る tools/api-inventory/tests/test_workflows.py を追加
  • 実体だけを触った変更でもそのテストが走るよう、api-inventory-tests.yml(原本・実体)の paths に drift の実体を追加

目的

原本にだけ検知段があり、CI では一度も走っていなかった。config で無効・プラグイン未導入の経路が台帳から落ちても気付けない状態だったため。

動作確認

  • develop_v2.1.0 上で同じ引数で detect_routes.py を実行: 検知 733 件すべてが台帳と対応し、未収載 0 でゲートを通過(出力は件数のみ)
  • cd tools/api-inventory && python3 -m pytest 全件パス
  • 実体をわざとずらすと test_workflows.py が落ちることを確認
  • drift ワークフローそのものはマージ後に workflow_dispatch で確認する

🤖 Generated with Claude Code

Summary by Sourcery

Add source-based route coverage checks to API inventory drift detection and keep the workflow implementation synchronized with its canonical definition.

New Features:

  • Add source-derived route detection to the API inventory drift workflow and include its results in drift artifacts and pull request comments.

Bug Fixes:

  • Ensure routes hidden by configuration or unavailable plugins are checked against the API inventory during CI.

Enhancements:

  • Add tests that verify workflow originals and deployed GitHub Actions workflows remain identical.

CI:

  • Trigger API inventory tests when the drift workflow changes in both workflow path configurations.

Tests:

  • Add workflow consistency tests for the API inventory CI configuration.

mhaya and others added 2 commits September 26, 2026 01:44
原本(tools/api-inventory/ci/)には detect_routes.py --cross-check --gate の段が
あったが、GitHub Actions が動かす .github/workflows/ 側に反映されておらず、
config で無効な経路が台帳から落ちても CI で気付けない状態だった。

- 原本を実体にコピーする
- 原本と実体の一致を見る test_workflows.py を足す
- 実体だけを触った変更でもそのテストが走るよう、tests ワークフローの
  paths に drift の実体を足す

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@sourcery-ai

sourcery-ai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

API inventory drift にソース(AST)由来の経路検知を追加し、実機由来の照合では見逃す config 無効・未導入経路もゲート対象にする。併せて原本と実体のワークフロー一致テストを導入し、drift ワークフロー変更時にそのテストが実行されるよう paths を更新している。

Sequence diagram for dual API inventory drift detection

sequenceDiagram
    participant Workflow as DriftWorkflow
    participant Reconcile as reconcile.py
    participant Detect as detect_routes.py
    participant Gate as InventoryGate
    participant Report as DriftReport

    Workflow->>Reconcile: reconcile.py --summary-only --gate
    Reconcile->>Gate: compare url_map with inventory
    Gate-->>Reconcile: pass or fail
    Workflow->>Detect: detect_routes.py --cross-check --summary-only --gate
    Detect->>Gate: compare source routes with inventory
    Gate-->>Detect: pass or fail
    Workflow->>Report: upload /tmp/reconcile.md and /tmp/detect.md
    Workflow->>Report: Comment on PR
Loading

File-Level Changes

Change Details Files
ソース由来の経路検知を実体の drift ワークフローに追加し、既存の実機ベース照合と併せて二段階で台帳網羅性を検証する。
  • detect_routes.py --cross-check --gate を実行し、ソースと台帳の未収載経路を検出する
  • 検知結果をアーティファクトおよび PR コメントに追加する
  • 検知対象のワークフロー処理を説明するコメントを追加する
.github/workflows/api-inventory-drift.yml
ワークフロー原本と GitHub Actions の実体の同期を自動テストで保証する。
  • tools/api-inventory/ci/ の各 YAML に対応する実体の存在と内容一致を検証する
  • ツール単体環境ではリポジトリ側のワークフロー比較をスキップする
tools/api-inventory/tests/test_workflows.py
drift ワークフローの実体変更時にも API インベントリーテストを起動する。
  • 原本と実体の両方のテストワークフローで drift ワークフローを paths 対象に追加する
.github/workflows/api-inventory-tests.yml
tools/api-inventory/ci/api-inventory-tests.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: ad68b2ee-46e6-4597-b4f6-f2f815a8797d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@github-actions

Copy link
Copy Markdown

API インベントリ差分(件数のみ)

台帳ブランチ: develop_v2.1.0

明細は公開できないため件数のみ表示しています。該当箇所はプライベートリポジトリ側の台帳・レポートで確認してください。

ベースラインとの差分

API インベントリ差分レポート

  • 旧: b572c442d v2.0.4-577-gb572c442d (profile=default) endpoints=933 (外部ライブラリ由来 359)
  • 新: d634df26e v2.0.4-606-gd634df26e (profile=default) endpoints=933 (外部ライブラリ由来 359)

判定: ✅ PASS (FAIL 0 / WARN 0)

サマリ

分類 件数
ADDED 0
REMOVED 0
RULE_CHANGED 0
METHODS_CHANGED 0
AUTH_CHANGED 0
IMPL_CHANGED 0
ATTRS_UNKNOWN_NEW 0
ModelView 追加 0
ModelView 削除 0
ModelView フラグ変化 0
config 変化 0
コメントアウト認証の増加 0
依存パッケージの版変化 0

変化はありません。


台帳との突き合わせ

スナップショット ↔ インベントリ 突き合わせ

  • リビジョン: d634df26e v2.0.4-606-gd634df26e 経路URI=913
  • 台帳: 行=1053 URI=924

件数のみ。詳細はプライベートリポジトリ側の完全版レポートを参照。

判定: ✅ 一致 (0件)

検出 件数
A. インベントリ未収載(抽出漏れ) 0
B. 実機に無い(未説明) 0
B'. 実機に無い(既知・許容) 11
C. メソッド不一致 0
D. app列の不一致 0
E. endpoint 未収載 0
E'. endpoint が実機に無い(参考) 1

ソース由来の経路検知

ソース由来の経路検知

  • 解析対象: /home/runner/work/weko/weko
検知源 件数
route 286
expose 206
add_url_rule 75
rest_config 28
modelview 23
entry_point 115
計 733

判定: ✅ 全検知が台帳に対応 (0件)

検知源 検知 台帳に対応 未収載 既知・許容
route 286 286 0 0
expose 206 206 0 0
add_url_rule 75 71 0 0
rest_config 28 26 0 2
modelview 23 23 0 0
entry_point 115 115 0 0

add_url_rule(**rule) 形式の config 駆動一括登録が 4 箇所。個々の経路は rest_config 側で検知する。

参考: 静的検知と結びつかなかった台帳行

  • 全体: 170 / 1053 行
  • うち実ファイルを持つ行: 24(pip・framework・ModelView 総称表記を除いた数)

@mhaya
mhaya merged commit 26466c3 into develop_v2.1.0 Sep 27, 2026
159 of 161 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant