<< All versions

Skill v1.0.0

currentAutomated scan100/100
jxoesneon/ciel/jvm-ci-verification
──Details
PublishedSeptember 27, 2026 at 11:59 AM
Content Hashsha256:6cf88ac0457c7f5a...
Git SHA0a73bb6da1f0
──Files
Files (1 file, 1.6 KB)
SKILL.md1.6 KBactive
SKILL.md · 52 lines · 1.6 KB

version: "1.0.0" name: jvm-ci-verification description: The formal verification loop for JVM (Java/Kotlin) projects using Maven or Gradle. license: MIT metadata: ciel-version: 1.0.0 ciel-extension: ciel.yaml


CIEL ADAPTATION: JVM CI Verification (The Gate)

This skill dictates the "Pre-PR" verification protocol for all Java and Kotlin projects. It ensures that only high-quality, verified code enters the shared repository.

The Verification Loop

Phase 1: Clean Build

  • Maven: mvn clean verify -DskipTests (Parallel: -T 4).
  • Gradle: ./gradlew clean assemble -x test.

Phase 2: Quality Analysis

  • Lint: spotless:check or detekt.
  • Static: spotbugs or pmd.
  • Rule: If static analysis fails, the loop terminates immediately.

Phase 3: Tests & Coverage

  • Threshold: Hard gate at 80% line coverage (verified via JaCoCo/Kover).
  • Command: mvn test or ./gradlew koverVerify.

Phase 4: Security Scan

  • Dependencies: org.owasp:dependency-check to find CVEs.
  • Secrets: grep check for sk-, api_key, or password patterns in src/.

Report Generation

The Orchestrator MUST produce a VERIFICATION_REPORT.md before finalizing a branch:

  • Build: PASS/FAIL.
  • Analysis: Tool output summaries.
  • Coverage: % and delta from baseline.
  • Security: CVE count.

Anti-Patterns

  • Test-Skipping: Running mvn install -DskipTests to bypass the quality gate.
  • Local-Only H2: Passing tests on H2 but ignoring production Postgres specificities.
  • Unpinned Analysis: Using "LATEST" versions of static analysis plugins that produce inconsistent results.
All versions