Skip to content

Fix/federation form and dependency refresh - #19

Merged
KFilippopolitis merged 5 commits into
masterfrom
fix/federation-form-and-dependency-refresh
Sep 15, 2026
Merged

KFilippopolitis merged 5 commits into
masterfrom
fix/federation-form-and-dependency-refresh

Conversation

@KFilippopolitis

Copy link
Copy Markdown
Contributor

No description provided.

- Spring Boot 4.1.1 with Tomcat 11.0.25 override (GHSA-9xv2-5v5q-p794),
  springdoc 3.1.1, Flyway 12.11.0, gson 2.14.0, JUnit 6.1.3
- Angular 22.1.6 plus Material/CDK, Angular CLI 22.1.8, TypeScript 6.0.3,
  fontawesome 7.3.1, and refreshed npm overrides
- data_quality_tool: pandas 3, gunicorn 26, pytest 9.1.1, black 26.5.1,
  Poetry 2.4.3 and Python 3.12 images
- Pin base images (Maven 3.9.16, Corretto 21.0.12-alpine3.24,
  Node 24.21.0, Nginx 1.31.5, dockerize v0.15.1) and PostgreSQL 18.6 in
  compose.yaml and the Helm values together
- Pin GitHub Actions to immutable versions and document the Angular 22
  and postgres 18.6 changes; ignore generated frontend/dist
…age NgModule

Serve add/update through loadComponent routes at /federations/add and
/federations/update, removing the now-unused FederationsPage NgModule,
routing module, and list component (the landing page embeds the cards).

The form is self-contained: it reads the isUpdate route data and the
federationCode query param, unsubscribes on destroy, reports a missing
federation code, coerces institutions/records to integers, marks invalid
fields on submit, and surfaces create/update failures (with a distinct
403 message) instead of only logging them.

Landing page shows the add-federation card to admins only, including the
empty state, and navigates to /federations/add.

Tests cover the new routes, form validation/payload/error handling, and
admin-only visibility of the add card.
DataModelRepository is keyed by UUID, so passing the stringified ids to
findAllById made every create/update federation lookup come up empty and
reject otherwise valid dataModelIds. Type the repository id as UUID and
share one resolveReleasedDataModels helper between create and update,
treating a missing dataModelIds list as empty.

Adds a regression test that updateFederation queries by UUID and attaches
the resolved data models.
Codecov now rejects tokenless uploads from GitHub Actions ("Token
required - not valid tokenless upload"), so the coverage step fails the
whole Converter CI job. Pass CODECOV_TOKEN to the action and skip the
upload while the repository secret is missing, so the build stays green
and coverage still reports once the token is configured.
@KFilippopolitis

Copy link
Copy Markdown
Contributor Author

CI status: green

Converter CI was failing only at Upload Coverage to Codecov (build + tests passed). Codecov now rejects tokenless uploads from GitHub Actions:

error -- Upload queued for processing failed: {"message":"Token required - not valid tokenless upload"}

codecov/codecov-action was bumped v1.0.5 -> v7.1.0 in this PR and runs with fail_ci_if_error: true, so the missing token failed the whole job. The legacy v1 uploader would fail the same way today (Codecov returns 400 Your CI provider is not compatible with tokenless uploads for this repo).

Changes in 1f5d2fe:

  • pass token: ${{ secrets.CODECOV_TOKEN }} to the action,
  • skip the step while that repository secret is missing (if: ${{ env.CODECOV_TOKEN != '' }}), so the gate is explicit instead of silently dropped.

All checks now pass (2x build, CodeQL, Analyze (actions|java-kotlin|javascript-typescript|python)). Coverage reporting resumes automatically once a maintainer adds the secret:

gh secret set CODECOV_TOKEN --repo Medical-Informatics-Platform/datacatalog

Merge is still BLOCKED on REVIEW_REQUIRED, not on checks.

Comment thread .github/workflows/data_quality_tool.yml Outdated

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7.0.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add only the major version? Why be specific?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point — full pins bought nothing here and turned every minor/patch release into a Dependabot PR. Switched the uses: refs back to their floating major tag in a5e3000 (actions/checkout@v7, actions/setup-python@v7, codecov/codecov-action@v7, docker/*-action@v4|v7, wei/git-sync@v3), so ebrains.yml is now identical to master again. Verified each major tag exists upstream.

Still specific in two places, deliberately:

  • poetry==2.4.3 — poetry.lock is generated by that Poetry version, so the lockfile and CI have to agree on it.
  • the OSV_SCANNER_VERSION / TRIVY_VERSION downloads in the audit workflow — those are checksum-verified curl fetches rather than action refs, so they need an immutable release.

One exception worth knowing about: actions/dependency-review-action stopped publishing floating major tags after v3 (only v5.0.0 exists), so that one stays on the full tag.

Keep only the major version in `uses:` refs so minor and patch releases are
picked up by the action maintainers instead of a per-release Dependabot PR.
@KFilippopolitis
KFilippopolitis merged commit 6110c6b into master Sep 15, 2026
7 checks passed
@KFilippopolitis
KFilippopolitis deleted the fix/federation-form-and-dependency-refresh branch September 15, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants