ci: add vulture dead code detection to validate job
CI/CD Pipeline / Deploy Production (pull_request) Failing after 1560h21m48s
CI/CD Pipeline / Build Production Runtime Images (pull_request) Failing after 1560h21m50s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Failing after 33s
CI/CD Pipeline / Unit Tests (pull_request) Failing after 33s
CI/CD Pipeline / Integration Tests (pull_request) Failing after 24s
CI/CD Pipeline / Frontend Lint (pull_request) Has been skipped
CI/CD Pipeline / Build & Push Staging (Watchtower auto-deploy) (pull_request) Failing after 1559h50m15s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 1559h50m13s
CI/CD Pipeline / Production Browser E2E (pull_request) Failing after 1559h50m11s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 1559h50m13s

- Add vulture dead code scan step (P2 - advisory mode)
- Confidence threshold: 80%
- Whitelist for framework code (FastAPI, SQLAlchemy, Celery, etc.)
- Exclude tests, migrations, scripts, docs
- Advisory only, does not block CI
This commit is contained in:
2026-07-13 15:20:52 +08:00
parent 7b2acc75ed
commit 9d69c71d77
+33
View File
@@ -112,6 +112,39 @@ jobs:
set -eu
bandit -r apps packages -q -ll
- name: Dead code detection (vulture)
shell: sh
run: |
set -eu
echo "=== Installing vulture ==="
python3 -m pip install -q vulture
vulture --version
echo ""
echo "=== Running vulture dead code scan ==="
echo "Confidence threshold: 80%"
echo "Mode: advisory (not blocking CI)"
echo ""
# 运行 vulture,使用配置文件和白名单
set +e
vulture --config vulture.conf --min-confidence 80 --sort-by-size > /tmp/vulture-report.txt
VULTURE_EXIT=$?
set -e
# 显示结果
cat /tmp/vulture-report.txt
echo ""
# 统计
DEAD_CODE_COUNT=$(grep -c ':' /tmp/vulture-report.txt 2>/dev/null || echo 0)
echo "=== Summary ==="
echo "Total findings: $DEAD_CODE_COUNT"
echo ""
# 告警模式,不阻断
echo "vulture scan completed (advisory mode - not blocking CI)"
if [ "$VULTURE_EXIT" != "0" ]; then
echo "WARNING: Dead code detected. Review the report above."
echo "This is currently advisory only."
fi
exit 0
- name: Validate release scripts syntax
shell: sh
run: |