Fix/federation form and dependency refresh - #19
Conversation
- Spring Boot 4.1.1 with Tomcat 11.0.25 override (GHSA-9xv2-5v5q-p794), springdoc 3.1.1, Flyway 12.11.0, gson 2.14.0, JUnit 6.1.3 - Angular 22.1.6 plus Material/CDK, Angular CLI 22.1.8, TypeScript 6.0.3, fontawesome 7.3.1, and refreshed npm overrides - data_quality_tool: pandas 3, gunicorn 26, pytest 9.1.1, black 26.5.1, Poetry 2.4.3 and Python 3.12 images - Pin base images (Maven 3.9.16, Corretto 21.0.12-alpine3.24, Node 24.21.0, Nginx 1.31.5, dockerize v0.15.1) and PostgreSQL 18.6 in compose.yaml and the Helm values together - Pin GitHub Actions to immutable versions and document the Angular 22 and postgres 18.6 changes; ignore generated frontend/dist
…age NgModule Serve add/update through loadComponent routes at /federations/add and /federations/update, removing the now-unused FederationsPage NgModule, routing module, and list component (the landing page embeds the cards). The form is self-contained: it reads the isUpdate route data and the federationCode query param, unsubscribes on destroy, reports a missing federation code, coerces institutions/records to integers, marks invalid fields on submit, and surfaces create/update failures (with a distinct 403 message) instead of only logging them. Landing page shows the add-federation card to admins only, including the empty state, and navigates to /federations/add. Tests cover the new routes, form validation/payload/error handling, and admin-only visibility of the add card.
DataModelRepository is keyed by UUID, so passing the stringified ids to findAllById made every create/update federation lookup come up empty and reject otherwise valid dataModelIds. Type the repository id as UUID and share one resolveReleasedDataModels helper between create and update, treating a missing dataModelIds list as empty. Adds a regression test that updateFederation queries by UUID and attaches the resolved data models.
Codecov now rejects tokenless uploads from GitHub Actions ("Token
required - not valid tokenless upload"), so the coverage step fails the
whole Converter CI job. Pass CODECOV_TOKEN to the action and skip the
upload while the repository secret is missing, so the build stays green
and coverage still reports once the token is configured.
CI status: green
Changes in 1f5d2fe:
All checks now pass (2x Merge is still |
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7.0.1 |
There was a problem hiding this comment.
Add only the major version? Why be specific?
There was a problem hiding this comment.
Good point — full pins bought nothing here and turned every minor/patch release into a Dependabot PR. Switched the uses: refs back to their floating major tag in a5e3000 (actions/checkout@v7, actions/setup-python@v7, codecov/codecov-action@v7, docker/*-action@v4|v7, wei/git-sync@v3), so ebrains.yml is now identical to master again. Verified each major tag exists upstream.
Still specific in two places, deliberately:
poetry==2.4.3—poetry.lockis generated by that Poetry version, so the lockfile and CI have to agree on it.- the
OSV_SCANNER_VERSION/TRIVY_VERSIONdownloads in the audit workflow — those are checksum-verifiedcurlfetches rather than action refs, so they need an immutable release.
One exception worth knowing about: actions/dependency-review-action stopped publishing floating major tags after v3 (only v5.0.0 exists), so that one stays on the full tag.
Keep only the major version in `uses:` refs so minor and patch releases are picked up by the action maintainers instead of a per-release Dependabot PR.
No description provided.