CI check to make sure that all libraries have their source code verified#10217
Open
daniellehrner wants to merge 2 commits intobesu-eth:mainfrom
Open
CI check to make sure that all libraries have their source code verified#10217daniellehrner wants to merge 2 commits intobesu-eth:mainfrom
daniellehrner wants to merge 2 commits intobesu-eth:mainfrom
Conversation
…ied as well Signed-off-by: daniellehrner <daniel.lehrner@consensys.net>
Contributor
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Adds a CI gate to ensure Gradle dependency verification metadata includes corresponding source artifact entries for resolved external dependencies, reusing the existing source-resolution logic.
Changes:
- Refactors source-artifact collection/resolution into reusable
extclosures inbuild.gradle. - Adds a new
verifySourceArtifactsGradle task that fails ifgradle/verification-metadata.xmllacks source entries. - Wires the new verification task into the GitHub Actions pre-review workflow as a required job.
Reviewed changes
Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| build.gradle | Extracts shared dependency/source resolution logic and adds verifySourceArtifacts to validate verification metadata coverage. |
| .github/workflows/pre-review.yml | Adds a new CI job that runs ./gradlew verifySourceArtifacts and gates the “unittests-passed” aggregator on it. |
fab-10
approved these changes
Apr 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR description
Adds a new check to the CI that verifies that all libraries that are added to Gradle have their sources verification entries added as well. Reuses logic from the existing resolveSourceArtifacts Gradle task that is adding those sources.
Thanks for sending a pull request! Have you done the following?
doc-change-requiredlabel to this PR if updates are required.Locally, you can run these tests to catch failures early:
./gradlew spotlessApply./gradlew build./gradlew acceptanceTest./gradlew integrationTest./gradlew ethereum:referenceTests:referenceTests