Skip to content

[quality] the bundle e2e suite never drives the dry-run and config action inputs through dist/index.js #247

Description

@hivecommons-hive

Finding

`tests/bundle/bundle.test.ts` (the end-to-end suite, spawning `dist/index.js` against `fakeGithub`) drives every event route and nearly every `/command`, but two of the seven inputs declared in `action.yml` are never set in any `runBundle` call:

  • `dry-run` — `src/cronJobs/labelSync.ts:44,67,80,85`: the plan-only path that skips every `POST`/`PATCH` and logs `label-sync (dry-run): would create …`.
  • `config` — `src/utils/config.ts:176-180,232-262` (`loadExplicitTier`): the explicit `owner/repo:path[@ref]` source read at `?ref=` in place of the `.project`/`.github` lookup, and the `http://` rejection arm.

Evidence, `origin/main` @ c48bd6d:

Why it matters: these are the two inputs a caller sets by hand in the reusable workflow (`with: dry-run`, `with: config`); the unit tests mock `core.getInput`, so nothing verifies that the ncc bundle actually reads `INPUT_DRY-RUN`/`INPUT_CONFIG`, that octokit encodes the explicit path and `ref` as expected on the wire, or that the failure is surfaced as `::error::` with exit 1.

Recommendation

Add three cases to the existing `workflow_dispatch label-sync job` block of `tests/bundle/bundle.test.ts`:

  • `dry-run: 'true'` — same routes as the writing case; assert exit 0, the `label-sync (dry-run): would create N […], would update 1 [kind/bug (color)], unchanged 0` log line, zero `POST`/`PATCH`/`DELETE`, and exactly the config reads + labels read.
  • `config: 'Codertocat/shared-config:labels/prow.yaml@v1'` — assert the single read is `GET /repos/Codertocat/shared-config/contents/labels%2Fprow.yaml?ref=v1`, no `.project`/`.github` read, the repo tier still probed, and the labels created from the explicit source.
  • `config: 'http://…'` — assert exit 1, `::error::TypeError: error handling issue comment: Error: config: http:// sources are not allowed, use https://`, and no writes.

The `https://` form is not covered here: `fetchUrl` uses global `fetch` and the fake listens on plain HTTP, which the loader rejects by design; driving it needs a TLS fake and is a separate deliverable.

Priority

  • Impact: medium — covered by unit tests, not end-to-end
  • Effort: low

Filed by quality agent (hold-gated mode)


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: c48bd6d

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenancehive/likely-doneHive verified that a merged PR references or claims this issue; pending confirmationneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions