You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[quality] the bundle e2e suite never drives the dry-run and config action inputs through dist/index.js #247
`tests/bundle/bundle.test.ts` (the end-to-end suite, spawning `dist/index.js` against `fakeGithub`) drives every event route and nearly every `/command`, but two of the seven inputs declared in `action.yml` are never set in any `runBundle` call:
`dry-run` — `src/cronJobs/labelSync.ts:44,67,80,85`: the plan-only path that skips every `POST`/`PATCH` and logs `label-sync (dry-run): would create …`.
`config` — `src/utils/config.ts:176-180,232-262` (`loadExplicitTier`): the explicit `owner/repo:path[@ref]` source read at `?ref=` in place of the `.project`/`.github` lookup, and the `http://` rejection arm.
Why it matters: these are the two inputs a caller sets by hand in the reusable workflow (`with: dry-run`, `with: config`); the unit tests mock `core.getInput`, so nothing verifies that the ncc bundle actually reads `INPUT_DRY-RUN`/`INPUT_CONFIG`, that octokit encodes the explicit path and `ref` as expected on the wire, or that the failure is surfaced as `::error::` with exit 1.
Recommendation
Add three cases to the existing `workflow_dispatch label-sync job` block of `tests/bundle/bundle.test.ts`:
`dry-run: 'true'` — same routes as the writing case; assert exit 0, the `label-sync (dry-run): would create N […], would update 1 [kind/bug (color)], unchanged 0` log line, zero `POST`/`PATCH`/`DELETE`, and exactly the config reads + labels read.
`config: 'Codertocat/shared-config:labels/prow.yaml@v1'` — assert the single read is `GET /repos/Codertocat/shared-config/contents/labels%2Fprow.yaml?ref=v1`, no `.project`/`.github` read, the repo tier still probed, and the labels created from the explicit source.
`config: 'http://…'` — assert exit 1, `::error::TypeError: error handling issue comment: Error: config: http:// sources are not allowed, use https://`, and no writes.
The `https://` form is not covered here: `fetchUrl` uses global `fetch` and the fake listens on plain HTTP, which the loader rejects by design; driving it needs a TLS fake and is a separate deliverable.
Priority
Impact: medium — covered by unit tests, not end-to-end
Finding
`tests/bundle/bundle.test.ts` (the end-to-end suite, spawning `dist/index.js` against `fakeGithub`) drives every event route and nearly every `/command`, but two of the seven inputs declared in `action.yml` are never set in any `runBundle` call:
Evidence, `origin/main` @ c48bd6d:
Why it matters: these are the two inputs a caller sets by hand in the reusable workflow (`with: dry-run`, `with: config`); the unit tests mock `core.getInput`, so nothing verifies that the ncc bundle actually reads `INPUT_DRY-RUN`/`INPUT_CONFIG`, that octokit encodes the explicit path and `ref` as expected on the wire, or that the failure is surfaced as `::error::` with exit 1.
Recommendation
Add three cases to the existing `workflow_dispatch label-sync job` block of `tests/bundle/bundle.test.ts`:
The `https://` form is not covered here: `fetchUrl` uses global `fetch` and the fake listens on plain HTTP, which the loader rejects by design; driving it needs a TLS fake and is a separate deliverable.
Priority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:c48bd6d— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88