Ga naar hoofdinhoud

Automated Development Pipeline

Every line of code at Conduction passes through an automated pipeline before it reaches production. The pipeline enforces quality, security, and compliance — no exceptions.

Branch Flow​

feature/* ──┐
bugfix/* ──┼──→ development ──→ beta ──→ main
hotfix/* ──┘

All branches are protected. No direct pushes. Every change flows through a pull request with peer review and CI.

TargetReviews requiredWhat triggers
development1 reviewerQuality CI
beta1 reviewerQuality CI + beta release
main2 reviewersFull CI + stable release

Quality Gates​

Every PR triggers the shared quality pipeline — all applicable gates must pass before merge. The four groups below are the core of it; the full set is 18 job groups, including PHPUnit, Playwright, Newman, axe-core, SBOM and the Hydra gates. See CI/CD and Code Standards for the complete table.

PHP Quality​

CheckTool
Syntaxphp -l
Code stylePHPCS (Conduction standard)
Static analysisPHPStan + Psalm
Mess detectionPHPMD
Code metricsPHPMetrics

Frontend Quality​

CheckTool
JavaScript/VueESLint
CSS/SCSSStylelint

Dependency Checks​

CheckWhat it catches
License complianceCopyleft or restricted licenses in dependencies
Vulnerability scanKnown CVEs in composer and npm packages
SBOM generationCycloneDX bill of materials for audit trail

Security​

CheckWhat it catches
composer auditKnown PHP dependency vulnerabilities
npm auditKnown JS dependency vulnerabilities

Automated Releases​

Releases are fully automated via GitHub Actions:

  • Merge to beta → beta release (nightly channel)
  • Merge to main → stable release

Version numbers are calculated from PR labels:

LabelVersion bump
major1.0.0 → 2.0.0
minor1.0.0 → 1.1.0
patch (default)1.0.0 → 1.0.1

Hydra — Agentic Development Pipeline​

info

Hydra is Conduction's agentic spec-driven development pipeline: it builds applications from structured specifications with government-grade traceability, SBOM generation, and audit trails. Its mechanical quality gates run on every PR in all 18 core apps today (enable-hydra-gates: true) and are published as the open-source composer package conduction/hydra-gates.

Further Reading​