name: ‘step-03-configure-quality-gates’ description: ‘Configure burn-in, quality gates, and notifications’ nextStepFile: ‘{skill-root}/steps-c/step-04-validate-and-summary.md’ knowledgeIndex: ‘./resources/tea-index.csv’
Configure burn-in loops, quality thresholds, and notification hooks.
{communication_language}CRITICAL: Follow this sequence exactly. Do not skip, reorder, or improvise.
Use {knowledgeIndex} to load ci-burn-in.md guidance:
Stack-conditional burn-in:
test_stack_type is frontend or fullstack): Enable burn-in by default. Burn-in targets UI flakiness (race conditions, selector instability, timing issues).test_stack_type is backend): Skip burn-in by default. Backend tests (unit, integration, API) are deterministic and rarely exhibit UI-related flakiness. If the user explicitly requests burn-in for backend, honor that override.Security: Script injection prevention for reusable burn-in workflows:
When burn-in is extracted into a reusable workflow (on: workflow_call), all ${{ inputs.* }} values MUST be passed through env: intermediaries and referenced as quoted "$ENV_VAR". Never interpolate them directly.
Inputs must be DATA, not COMMANDS. Do not accept command-shaped inputs (e.g., inputs.install-command, inputs.test-command) that get executed as shell code — even through env:, running $CMD is still command injection. Use fixed commands (e.g., npm ci, npx playwright test) and pass inputs only as data arguments.
# ✅ SAFE — fixed commands with data-only inputs
- name: Install dependencies
run: npm ci
- name: Run burn-in loop
env:
TEST_GREP: ${{ inputs.test-grep }}
BURN_IN_COUNT: ${{ inputs.burn-in-count }}
BASE_REF: ${{ inputs.base-ref }}
run: |
# Security: inputs passed through env: to prevent script injection
for i in $(seq 1 "$BURN_IN_COUNT"); do
echo "Burn-in iteration $i/$BURN_IN_COUNT"
npx playwright test --grep "$TEST_GREP" || exit 1
done
Define:
Contract testing gate (if tea_use_pactjs_utils is enabled):
Use {knowledgeIndex} to load:
pact-consumer-framework-setup.md — determinism gate (check-pact-determinism.sh), jq -S publish normalization, 1:1 local/CI paritypactjs-utils-consumer-helpers.md — one-interaction-per-it() determinism rulepactjs-utils-provider-verifier.md — buildVerifierOptions, broker config, breaking change patterns, vitest pool: 'forks' + singleFork (same rule applies to consumer AND provider)pactjs-utils-request-filter.md — createRequestFilter auth injection patterns for CI pipeline auth setuppact-broker-webhooks.md — webhook auth pattern, PAT rotation runbook, staleness monitoring (webhook failures silently break can-i-deploy)
Determinism gate must pass (consumer side): npm run test:pact:consumer runs the suite N times and fails on byte-different pact JSON before any publish is attempted. This is a non-negotiable pre-publish gate.
can-i-deploy must pass before any deployment to staging or production
Block the deployment pipeline if contract verification fails
Treat consumer pact publishing failures as CI failures (contracts must stay up-to-date)
Provider verification must pass for all consumer pacts before merge
Staleness alert: scheduled job asserts recent verifications exist — a missing signal indicates a silently-broken webhook (usually an expired GitHub PAT on the PactFlow secret; see pact-broker-webhooks.md rotation runbook).
Configure:
Save this step’s accumulated work to {outputFile}.
{outputFile} does not exist (first save), create it with YAML frontmatter: ---
stepsCompleted: ['step-03-configure-quality-gates']
lastStep: 'step-03-configure-quality-gates'
lastSaved: '{date}'
---
Then write this step’s output below the frontmatter.
{outputFile} already exists, update:
'step-03-configure-quality-gates' to stepsCompleted array (only if not already present)lastStep: 'step-03-configure-quality-gates'lastSaved: '{date}'Load next step: {nextStepFile}