fix(#88): wire Xenon complexity gate into CI#99
Merged
Conversation
- Add blocking Xenon step to security job: --max-average A --max-modules B --max-absolute C - Three files excluded with inline justification comments: - table_detector.py: _detect_text_based_table E/32 — temporary, tracked in #98 - template_detector.py: get_detection_explanation D/22 — stable diagnostic exemption - commands/init.py: init_directories D/26 — stable CLI orchestration exemption - requirements/ci.txt: replace radon==6.0.1 + mccabe==0.7.0 with xenon>=0.9.0 (xenon depends on radon; mccabe was unused) - Gate is blocking from day one — no || true
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Wires a blocking Xenon complexity gate into CI.
radonwas already installed inrequirements/ci.txtbut no CI step enforced any threshold — this closes that gap.Three functions in the codebase currently exceed grade C. Rather than using
|| true(advisory only), the gate is blocking from day one with explicit, documented per-file exclusions for the pre-existing outliers.Changes
.github/workflows/ci.yml: addComplexity gate (Xenon)step to thesecurityjob--max-average A --max-modules B --max-absolute C--excludewith inline justification comments (see below)|| true— gate is hard from day onerequirements/ci.txt: replaceradon==6.0.1+mccabe==0.7.0withxenon>=0.9.0mccabewas installed but unusedExclusions and rationale
analysis/table_detector.py_detect_text_based_tabletemplates/template_detector.pyget_detection_explanationcommands/init.pyinit_directoriesType
Testing
make docker-integrationpassed locally (required when touchingDockerfile,entrypoint.sh,docker-compose.yml, orpackages/parser-core/)Local gate verification:
xenon --max-average A --max-modules B --max-absolute C --exclude "..." packages/parser-core/src→ exit 0Checklist
Downstream impact
bankstatements_core(exported class, function, or exception)