Repository navigation
[quality] config.ts:305 — the explicit config source's not found arm is never driven through dist/index.js #422
Description
Activity
- addedqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenanceagent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
on Oct 9, 2026 Please add a kind label with
/kind failing-testor/kind cleanup.- addedhive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedHive verified that an open PR references or claims this issue; still actionable until confirmed
on Oct 9, 2026 hivecommons-hive commented
on Oct 10, 2026 ContributorAuthorMore actionsFolded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite
dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.[quality] push-repacked-dist cannot mint its App token: Dependabot secrets REPACK_APP_ID / REPACK_APP_PRIVATE_KEY are not configured, so bundled-dep dependabot PRs still fail the dist/ gate (#440)
Finding
#390 (merged as 15802ac) added the
repack-dist/push-repacked-distjob pair to.github/workflows/test.ymlso dependabot bumps ofncc-bundled dependencies no longer die on the "Verify committed dist/ matches source" gate. Its description ends with Maintainer setup required: store the App id/key as the Dependabot secretsREPACK_APP_ID/REPACK_APP_PRIVATE_KEY.That step has not happened. #440 (js-yaml 5.4.2 → 5.4.3, a runtime dependency since #411, so it is bundled into
dist/index.js) is the first bundled bump since #390 landed, and its run shows the job pair working exactly up to the missing secret:- run 38068101038
repack-dist→ success,changed=true, artifactrepacked-dist-<sha>uploadedpush-repacked-dist→ failure at the very first step,actions/create-github-app-token:
Error: The 'client-id' (or deprecated 'app-id') input must be set to a non-empty string. If using a secret or variable, ensure it is available in this workflow context.
The job header confirmsSecret source: Dependabot, i.e. only Dependabot secrets are visible andREPACK_APP_IDresolves to empty.build-test→ failure onVerify committed dist/ matches source(the pre-ci: repack dist/ on dependabot branches without exposing a write token #390 symptom, unchanged because no repack was pushed).
The other three dependabot PRs in the same batch (#441 dev-deps, #442 setup-node, #443 upload-artifact) are green: none of them touch a bundled runtime dependency, so
repack-distreportschanged=falseandpush-repacked-distis skipped.Recommendation
This is configuration, not code — nothing in the repository can fix it, and no agent token can write repository secrets:
- A maintainer creates (or reuses) a GitHub App with
contents: write, installs it on this repository, and addsREPACK_APP_IDandREPACK_APP_PRIVATE_KEYunder Settings → Secrets and variables → Dependabot (not Actions secrets — dependabot-triggered runs only see Dependabot secrets) - Re-run workflow 38068101038 (or
@dependabot rebasechore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440) and confirmpush-repacked-distpusheschore: repack dist/ for dependency bumpand the re-triggeredbuild-testgoes green
Until then every bundled-dependency dependabot PR needs the same hand repack that #188 got (7e70949), and #440 should be treated as blocked on this issue rather than on its diff.
Priority
- Impact: medium (every runtime-dependency bump stays red; the
push-repacked-distfailure also makes the PR'sbuild-teststatus look like a code fault) - Effort: low (a few minutes of repository settings; needs a human with admin on the repo)
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:d0b1d87— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- run 38068101038
hivecommons-hive commented
on Oct 10, 2026 ContributorAuthorMore actionsFolded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite
dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.[quality] test.yml never runs test:coverage:e2e — the bundle's src/ coverage is only ever measured locally, never summarised or archived in CI
Finding
npm run test:coverage:e2e(added by #274 to close #235) is the only measurement of what the shipped bundle actually exercises insrc/, but nothing in CI runs it..github/workflows/test.ymlbuild-testrunsnpm run test:coverage(unit), writes itscoverage-summary.jsonto the job summary and uploadscoverage/ascoverage-${{ github.sha }}; the e2e figure is never produced, summarised, or archived (grep -n e2e .github/workflows/*.yml→ no match).Consequences:
- Every end-to-end coverage figure quoted on this repository's
coverage-gapissues ([quality] 14 commenter-auth catch arms (10 commands + auth.ts:181/210/217/224) are unreachable — only module mocks in unit tests keep them covered #386, [quality] getArgumentLabels and anyLabelMatches have no production caller — only their unit tests keep them covered #366, the bundle-test PRs test(bundle): drive root-OWNERS authorization on an issue and the OWNERS-based /lgtm refusal through dist/index.js #283…test(bundle): drive checkOrgMember's missing payload.repository guard (auth.ts:43-45) through dist/index.js #447) comes from an agent's local scratch run. There is no CI run URL or artifact a reader can reproduce it from, and no record of the figure at any givenmainSHA. - A regression in e2e coverage (a handler that stops being reached through
dist/index.js) is invisible; the unit run is at 100 % lines and cannot move. docs/contributing.md:48documents the script as a first-class suite but CI treats it as optional.
Evidence (
main@ d0b1d87, Node v26.10.0):- Unit (
npx vitest run --coverage): 100 % lines (2457/2457), 99.82 % branches. - E2E (
npm run test:coverage:e2e -- --coverage.reportsDirectory=coverage-e2e): 63 files / 436 tests pass, 98.33 % lines (2421/2462) ofsrc/, wall time 3 m 52 s. Writescoverage-e2e/{coverage-summary.json,lcov.info};coverage/from the unit run is left untouched. Without thereportsDirectoryoverride both runs write tocoverage/and the second overwrites the first — which is why the step below redirects it.
Recommendation
One deliverable, one mechanical edit to
.github/workflows/test.yml. Insert after theCoverage summarystep (currently line ~49, before theupload-artifactstep) and extend the artifact path:- run: npm run test:coverage:e2e -- --coverage.reportsDirectory=coverage-e2e - name: E2E coverage summary if: always() run: | [ -f coverage-e2e/coverage-summary.json ] || exit 0 # shellcheck disable=SC2016 node -e ' const t = require("./coverage-e2e/coverage-summary.json").total; const row = k => `| ${k} | ${t[k].pct}% | ${t[k].covered}/${t[k].total} |`; console.log("### E2E coverage of src/ (`npm run test:coverage:e2e`)\n\n| Metric | % | Covered |\n|---|---|---|"); for (const k of ["statements","branches","functions","lines"]) console.log(row(k)); ' >> "$GITHUB_STEP_SUMMARY"
and change the existing
upload-artifactstep'spath:frompath: coverage/
to
path: | coverage/ coverage-e2e/
-
test.yml: add the two steps and widen the artifact path as above
Notes for the reviewer:
test:coverage:e2erunspack:coverageinto the git-ignored.coverage-bundle/, so the later "Verify committed dist/ matches source" step (npm run pack→dist/) is unaffected. The e2e config sets all thresholds to 0, so this step reports and never gates; a gate can be a later decision once a baseline is archived. Expect ~4 min added tobuild-test.This change lives in
.github/workflows/test.ymland therefore needs a human or an ISSUES_PRS_MERGE agent to land. This lane's App token is minted without the Workflows permission, so a push touching.github/workflows/**is rejected server-side; no PR is opened for it on purpose, and the replacement text above is given verbatim so applying it is mechanical. Related earlier workflow-file findings with the same constraint: #171, #209, #213.Priority
- Impact: medium — e2e coverage is the only figure with headroom left (unit is saturated at 100 %) and it is currently unreproducible from CI
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:d0b1d87— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Every end-to-end coverage figure quoted on this repository's
hivecommons-hive commented
on Oct 11, 2026 ContributorAuthorMore actionsFolded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite
dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.[quality] labelCatalog.ts:80 empty-prefix arm (the /label allowlist) is never driven through dist/index.js
Finding
src/utils/labelCatalog.ts:80—prefixed()'sprefix === ''arm — has no end-to-end coverage. It is the one registry section with an empty prefix ({ command: '/label', prefix: '', allowlistKey: 'labels' }insrc/labels/prefixed.ts:30), so alabel-syncrun over a prow config carrying alabels.labelssection must emit those values verbatim (documentation), never aslabels/documentation. No bundle case composes such a section:bundle.test.ts's label-sync cases use akindsection only andlabelSyncCatalog.test.tsadds a customteamsection plusrequire_matching_label.Evidence (
main@ d0b1d87, Node v26.10.0):- Unit:
npx vitest run --coverage→ 100 % lines (142 files / 2073 tests). The arm is green via__tests__/utils/labelCatalog.test.ts:52-58("applies the /label allowlist verbatim"). - End-to-end:
npm run test:coverage:e2eon a scratch branch =origin/main+ the heads of the 11 open hold-gated bundle PRs (test(bundle): drive loadExplicitConfig's not-found arm (config.ts:305) through dist/index.js #423 … test(bundle): drive checkOrgMember's missing payload.repository guard (auth.ts:43-45) through dist/index.js #447, all merge clean; 71 files / 451 tests pass) → 98.73 % lines ofsrc/;labelCatalog.tsbranch 95 %, line 80 listed with 0 hits. - Overlap check: test(bundle): drive getCurrentLabels' bare-string label arm (labeling.ts:148) through dist/index.js #433 (
stringLabelArm.test.ts) and test(bundle): drive labelSync's null label description arm (labelSync.ts:133) through dist/index.js #435 (labelSyncNullDescription.test.ts) touch label sync but neither composes alabels.labelssection.
Covered by unit, not by e2e → medium.
Recommendation
- add a
__tests__/bundle/labelSyncUnprefixedAllowlist.test.tscase that runsworkflow_dispatchwithjobs: label-syncover a config with both akindsection and alabelssection (one bare string, one{ name, color, description }entry) and asserts the POSTed names aredocumentation,question,kind/bugwith nolabels/prefix, the catalog lowercases the configured color, and the request sequence is config reads + one labels GET + one POST per label.
Priority
- Impact: medium
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:d0b1d87— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Unit:
Finding
loadExplicitConfig(src/utils/config.ts:297-308) resolves theconfiginputowner/repo:path[@ref].fetchRepoFileswallows a 404 intoundefined(:321-323), and the loader then throws its own message:That is the message a user sees when the path or ref in their
config:input does not exist — the most likely misconfiguration of that input.__tests__/bundle/explicitConfigSource.test.tsalready drives the sibling arms throughdist/index.js(a directory →is not a file, a bare file name → pattern refusal, a 500 on the organization and repository tiers), but no bundle test issues a 404 against the explicit source, so thenot foundarm is reached only by the unit suite.Evidence (
main@ d0b1d87, Node v26.10.0, vitest 5.0.3):npx vitest run --coverage→ 100 % lines (142 files / 2073 tests);config.ts:305is covered.npm run test:coverage:e2e(63 files / 436 tests) → 98.14 % statements ofsrc/;config.tsresidual is220,305,428.:220(resetProwConfigCache) and:428(normalizeSections, remapped) are not user-visible paths;:305is.__tests__/bundle/fakeGithub.ts:100answers every unrouted path with404 Not Found (fake), sokind('cncf/prow-config:configs/prow.yaml@v2')with no route reaches the arm and also passes a non-empty@refthrough toGET …/contents/configs%2Fprow.yaml?ref=v2.Recommendation
__tests__/bundle/explicitConfigSource.test.ts: an explicit source with an@refand no route, assertingcould not load prow config from cncf/prow-config:configs/prow.yaml@v2: not foundand that the single GET carried?ref=v2Priority
config:input produces)🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:d0b1d87— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88