How to Add Quality Gates to a GitHub Actions Pipeline (Step by Step)
Most CI pipelines run tests. Far fewer pipelines actually stop bad code from reaching production. The difference is a quality gate : a check that must pass before the pipeline is allowed to move to the next stage. In this tutorial, you'll build a GitHub Actions pipeline with four gates: Lint: code style and obvious errors Unit tests + coverage threshold: fail if coverage drops below a minimum API…
Quality gates enhance CI pipelines by ensuring that only code meeting specific standards progresses through the development process. This tutorial demonstrates how to build a GitHub Actions pipeline with four quality gates: linting, unit tests with a coverage threshold, API tests, and manual approval. The gates are structured in order of increasing cost and complexity, allowing for early detection of issues while minimizing delays.
To set up the pipeline, create a workflow file named `.github/workflows/pipeline.yml`. The first job, named "lint," runs on an Ubuntu environment and checks for code style issues and syntax errors using the Ruff linter. Subsequent jobs include unit tests with a 80% coverage threshold, API tests against the running service, and a manual approval step before deployment to the production environment.
It's crucial to measure the current coverage of the codebase and begin with a reasonable threshold, gradually increasing it over time to avoid creating gates that always fail. Before deploying to production, an API test suite runs against the service to ensure integration and contract compliance. Lastly, the pipeline requires manual approval for deployment to the production branch, ensuring that human oversight is part of the process.
By implementing these gates, the pipeline effectively catches style issues, logic bugs, and integration problems early in the development cycle, reducing the likelihood of failures reaching production. Once the main branch is protected with a branch protection rule, requiring status checks to pass before merging, the gates provide a robust safeguard against subpar code entering the production environment.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.