Pipelines: Remove CodeClimate, integrate ESLint with CQ
What does this MR do?
- Do the same thing with ESLint that was done in gitlab!172592 (merged): in CI, configure it to output a Code Quality report.
- Remove the deprecated CodeClimate scanning engine from CI. CodeClimate was previously running an old version of ESLint, alongside some very basic "maintainability" metrics (# of lines allowed in a single function, # of parameters for a function declaration, etc.).
Screenshots or screen recordings
Violations work properly
Here's an example job where there are violations (since I messed with the ESLint config). It successfully executes and creates a report. https://gitlab.com/gitlab-org/gitlab-ui/-/jobs/8405659183
gl-code-quality-report__11_.json
This testing was done in a separate MR: !4834 (closed).
CodeClimate is removed
This MR demonstrates what happens when CodeClimate is removed. The MR widget is reporting a few hundred resolved findings. These are very basic "maintainability" metrics (# of lines allowed in a single function, # of parameters for a function declaration, etc.) which empirically we do not seem to care about.
Integration merge requests
No integration required—this is a CI change only.
-
GitLab: mr_url -
CustomersDot: mr_url -
Status Page: mr_url
Does this MR meet the acceptance criteria?
This checklist encourages the authors, reviewers, and maintainers of merge requests (MRs) to confirm changes were analyzed for conformity with the project's guidelines, security and accessibility.
Toggle the acceptance checklist
Conformity
-
Code review guidelines. -
GitLab UI's contributing guidelines. -
If it changes a Pajamas-compliant component's look & feel, the MR has been reviewed by a UX designer. -
If it changes GitLab UI's documentation guidelines, the MR has been reviewed by a Technical Writer. -
If the MR changes a component's API, integration MR(s) have been opened (see integration merge requests above). -
Added the ~"component:*"
label(s) if applicable.
Security
If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:
-
Label as security and @ mention @gitlab-com/gl-security/appsec
-
Security reports checked/validated by a reviewer from the AppSec team
Accessibility
If this MR adds or modifies a component, take a few moments to review the following:
-
All actions and functionality can be done with a keyboard. -
Links, buttons, and controls have a visible focus state. -
All content is presented in text or with a text equivalent. For example, alt text for SVG, or aria-label
for icons that have meaning or perform actions. -
Changes in a component’s state are announced by a screen reader. For example, changing aria-expanded="false"
toaria-expanded="true"
when an accordion is expanded. -
Color combinations have sufficient contrast.