Finding
.github/workflows/ci.yml:28 measures unit coverage and then throws the result away as far as the build is concerned:
- name: Run unit tests with coverage
run: npm run test:unit:coverage | tee coverage-summary.txt
shell: bash -o pipefail {0}
npm run test:unit:coverage invokes tests/tools/coverage-report.mjs with no --check, so the reporter prints a total and exits 0 regardless of what that total is. The summary is published to $GITHUB_STEP_SUMMARY and uploaded as the coverage-summary artifact, but nothing compares it to anything. Coverage can collapse from 98.94% to 40% and the Validate repository check stays green.
The reporter has supported a gate since it was written — --check <minLinePercent> exits 1 below the threshold — so this is one line away from being enforced.
Measured at rev a994a2e in a fresh clone after npm ci: npm run -s test:unit:coverage on node v26.8.2 reports all files | 98.94. Latest green CI run: 36009167129.
Recommendation
Once the test:unit:coverage:check script exists, replace the step body in .github/workflows/ci.yml. Exact replacement — the step keeps its name, its tee, its pipefail shell and its position, and only the npm script changes:
- name: Run unit tests with coverage
run: npm run test:unit:coverage:check | tee coverage-summary.txt
shell: bash -o pipefail {0}
The Publish coverage summary and Upload coverage report steps that follow are already if: always(), so the summary and the artifact are still produced when the gate fails — which is exactly when someone wants to read them.
This needs a human to land
The change is confined to .github/workflows/ci.yml. The quality agent's GitHub App token is minted at the contributor tier, which does not carry the Workflows permission, so GitHub rejects any push whose diff touches .github/workflows/** server-side. This is a hard ceiling, not a judgement call: no PR this agent can open is capable of containing the change. It needs a human maintainer, or an agent whose token carries workflows.
The replacement text above is given in full so applying it is mechanical.
Priority
- Impact: high — the repository believes it has a coverage gate and does not have one
- Effort: low — one line, already written above
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown
— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88
Finding
.github/workflows/ci.yml:28measures unit coverage and then throws the result away as far as the build is concerned:npm run test:unit:coverageinvokestests/tools/coverage-report.mjswith no--check, so the reporter prints a total and exits 0 regardless of what that total is. The summary is published to$GITHUB_STEP_SUMMARYand uploaded as thecoverage-summaryartifact, but nothing compares it to anything. Coverage can collapse from 98.94% to 40% and theValidate repositorycheck stays green.The reporter has supported a gate since it was written —
--check <minLinePercent>exits 1 below the threshold — so this is one line away from being enforced.Measured at rev
a994a2ein a fresh clone afternpm ci:npm run -s test:unit:coverageon node v26.8.2 reportsall files | 98.94. Latest green CI run: 36009167129.Recommendation
Once the
test:unit:coverage:checkscript exists, replace the step body in.github/workflows/ci.yml. Exact replacement — the step keeps its name, itstee, itspipefailshell and its position, and only the npm script changes:The
Publish coverage summaryandUpload coverage reportsteps that follow are alreadyif: always(), so the summary and the artifact are still produced when the gate fails — which is exactly when someone wants to read them..github/workflows/ci.ymlrunstest:unit:coverage:checkValidate repositoryThis needs a human to land
The change is confined to
.github/workflows/ci.yml. The quality agent's GitHub App token is minted at thecontributortier, which does not carry the Workflows permission, so GitHub rejects any push whose diff touches.github/workflows/**server-side. This is a hard ceiling, not a judgement call: no PR this agent can open is capable of containing the change. It needs a human maintainer, or an agent whose token carriesworkflows.The replacement text above is given in full so applying it is mechanical.
Priority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5n31| SHA:unknown— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88