CI: a push runs the tests, a pull request also builds the firmware
CI / build (push) Successful in 1m6s

Rebuilding both firmwares on every push was more than anyone looked at.
A push now runs the host tests with their coverage (under two minutes);
a pull request adds the release firmware and the Debug Build, and is how
changes reach main; a tag still does everything before it releases.
Pull requests from forks don't run. scripts/ci.sh takes 'tests' or
'builds' for one half; coverage.sh now fails when a test fails.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
This commit is contained in:
2026-10-06 14:19:56 +02:00
co-authored by Claude Opus 5.5
parent 5ecd5d003f
commit 86ddb87f54
5 changed files with 27 additions and 16 deletions
+1 -1
View File
@@ -12,7 +12,7 @@ Until now the tests, the builds, the signing and the flashing all happened on on
| # | Decision |
|---|---|
| Q151 | Every push, to any branch: the host tests and both builds. A tag `v*`: the same, then a release. |
| Q151 | A push, to any branch: the host tests (with their coverage). A pull request: the same and both builds; changes reach `main` through pull requests. A tag `v*`: all of it, then a release. (First: everything on every push, which rebuilt the firmware far more often than anyone looked at it.) |
| Q152 | **CI signs.** The signing key is the repository secret `OTA_SIGNING_KEY`; a tag push makes a complete, signed release with no manual step (ADR 0008). |
| Q153 | The Debug Build is built in CI with a token of the runner's own, to prove it compiles, and **isn't published**: it would hand everyone its Debug Console token. |
| Q154 | Pull requests from forks don't start a run. |