Skip to content

[quality] config.ts:305 — the explicit config source's not found arm is never driven through dist/index.js #422

Description

@hivecommons-hive

Finding

loadExplicitConfig (src/utils/config.ts:297-308) resolves the config input owner/repo:path[@ref]. fetchRepoFile swallows a 404 into undefined (:321-323), and the loader then throws its own message:

if (text === undefined) {
  throw new Error(`could not load prow config from ${input}: not found`)   // config.ts:305
}

That is the message a user sees when the path or ref in their config: input does not exist — the most likely misconfiguration of that input. __tests__/bundle/explicitConfigSource.test.ts already drives the sibling arms through dist/index.js (a directory → is not a file, a bare file name → pattern refusal, a 500 on the organization and repository tiers), but no bundle test issues a 404 against the explicit source, so the not found arm is reached only by the unit suite.

Evidence (main @ d0b1d87, Node v26.10.0, vitest 5.0.3):

  • Unit: npx vitest run --coverage → 100 % lines (142 files / 2073 tests); config.ts:305 is covered.
  • End-to-end: npm run test:coverage:e2e (63 files / 436 tests) → 98.14 % statements of src/; config.ts residual is 220,305,428. :220 (resetProwConfigCache) and :428 (normalizeSections, remapped) are not user-visible paths; :305 is.
  • Reachability: __tests__/bundle/fakeGithub.ts:100 answers every unrouted path with 404 Not Found (fake), so kind('cncf/prow-config:configs/prow.yaml@v2') with no route reaches the arm and also passes a non-empty @ref through to GET …/contents/configs%2Fprow.yaml?ref=v2.

Recommendation

  • add one case to __tests__/bundle/explicitConfigSource.test.ts: an explicit source with an @ref and no route, asserting could not load prow config from cncf/prow-config:configs/prow.yaml@v2: not found and that the single GET carried ?ref=v2

Priority

  • Impact: medium (the error text a misconfigured config: input produces)
  • Effort: low

🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: d0b1d87

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Activity

  1. added
    qualityCreated by Hive for agent-filed issue provenance
    testingCreated by Hive for agent-filed issue provenance
    agent/qualityCreated by Hive for agent-filed issue provenance
    on Oct 9, 2026
  2. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    Please add a kind label with /kind failing-test or /kind cleanup.

  3. added
    hive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmed
    on Oct 9, 2026
  4. hivecommons-hive commented on Oct 10, 2026

    @hivecommons-hive
    ContributorAuthor

    Folded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.

    [quality] push-repacked-dist cannot mint its App token: Dependabot secrets REPACK_APP_ID / REPACK_APP_PRIVATE_KEY are not configured, so bundled-dep dependabot PRs still fail the dist/ gate (#440)

    Finding

    #390 (merged as 15802ac) added the repack-dist / push-repacked-dist job pair to .github/workflows/test.yml so dependabot bumps of ncc-bundled dependencies no longer die on the "Verify committed dist/ matches source" gate. Its description ends with Maintainer setup required: store the App id/key as the Dependabot secrets REPACK_APP_ID / REPACK_APP_PRIVATE_KEY.

    That step has not happened. #440 (js-yaml 5.4.2 → 5.4.3, a runtime dependency since #411, so it is bundled into dist/index.js) is the first bundled bump since #390 landed, and its run shows the job pair working exactly up to the missing secret:

    • run 38068101038
      • repack-dist → success, changed=true, artifact repacked-dist-<sha> uploaded
      • push-repacked-dist → failure at the very first step, actions/create-github-app-token:
        Error: The 'client-id' (or deprecated 'app-id') input must be set to a non-empty string. If using a secret or variable, ensure it is available in this workflow context.
        The job header confirms Secret source: Dependabot, i.e. only Dependabot secrets are visible and REPACK_APP_ID resolves to empty.
      • build-test → failure on Verify committed dist/ matches source (the pre-ci: repack dist/ on dependabot branches without exposing a write token #390 symptom, unchanged because no repack was pushed).

    The other three dependabot PRs in the same batch (#441 dev-deps, #442 setup-node, #443 upload-artifact) are green: none of them touch a bundled runtime dependency, so repack-dist reports changed=false and push-repacked-dist is skipped.

    Recommendation

    This is configuration, not code — nothing in the repository can fix it, and no agent token can write repository secrets:

    • A maintainer creates (or reuses) a GitHub App with contents: write, installs it on this repository, and adds REPACK_APP_ID and REPACK_APP_PRIVATE_KEY under Settings → Secrets and variables → Dependabot (not Actions secrets — dependabot-triggered runs only see Dependabot secrets)
    • Re-run workflow 38068101038 (or @dependabot rebase chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440) and confirm push-repacked-dist pushes chore: repack dist/ for dependency bump and the re-triggered build-test goes green

    Until then every bundled-dependency dependabot PR needs the same hand repack that #188 got (7e70949), and #440 should be treated as blocked on this issue rather than on its diff.

    Priority

    • Impact: medium (every runtime-dependency bump stays red; the push-repacked-dist failure also makes the PR's build-test status look like a code fault)
    • Effort: low (a few minutes of repository settings; needs a human with admin on the repo)

    Filed by quality agent (hold-gated mode)


    🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: d0b1d87

    — hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

  5. hivecommons-hive commented on Oct 10, 2026

    @hivecommons-hive
    ContributorAuthor

    Folded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.

    [quality] test.yml never runs test:coverage:e2e — the bundle's src/ coverage is only ever measured locally, never summarised or archived in CI

    Finding

    npm run test:coverage:e2e (added by #274 to close #235) is the only measurement of what the shipped bundle actually exercises in src/, but nothing in CI runs it. .github/workflows/test.yml build-test runs npm run test:coverage (unit), writes its coverage-summary.json to the job summary and uploads coverage/ as coverage-${{ github.sha }}; the e2e figure is never produced, summarised, or archived (grep -n e2e .github/workflows/*.yml → no match).

    Consequences:

    Evidence (main @ d0b1d87, Node v26.10.0):

    • Unit (npx vitest run --coverage): 100 % lines (2457/2457), 99.82 % branches.
    • E2E (npm run test:coverage:e2e -- --coverage.reportsDirectory=coverage-e2e): 63 files / 436 tests pass, 98.33 % lines (2421/2462) of src/, wall time 3 m 52 s. Writes coverage-e2e/{coverage-summary.json,lcov.info}; coverage/ from the unit run is left untouched. Without the reportsDirectory override both runs write to coverage/ and the second overwrites the first — which is why the step below redirects it.

    Recommendation

    One deliverable, one mechanical edit to .github/workflows/test.yml. Insert after the Coverage summary step (currently line ~49, before the upload-artifact step) and extend the artifact path:

          - run: npm run test:coverage:e2e -- --coverage.reportsDirectory=coverage-e2e
          - name: E2E coverage summary
            if: always()
            run: |
              [ -f coverage-e2e/coverage-summary.json ] || exit 0
              # shellcheck disable=SC2016
              node -e '
                const t = require("./coverage-e2e/coverage-summary.json").total;
                const row = k => `| ${k} | ${t[k].pct}% | ${t[k].covered}/${t[k].total} |`;
                console.log("### E2E coverage of src/ (`npm run test:coverage:e2e`)\n\n| Metric | % | Covered |\n|---|---|---|");
                for (const k of ["statements","branches","functions","lines"]) console.log(row(k));
              ' >> "$GITHUB_STEP_SUMMARY"

    and change the existing upload-artifact step's path: from

              path: coverage/

    to

              path: |
                coverage/
                coverage-e2e/
    • test.yml: add the two steps and widen the artifact path as above

    Notes for the reviewer: test:coverage:e2e runs pack:coverage into the git-ignored .coverage-bundle/, so the later "Verify committed dist/ matches source" step (npm run pack → dist/) is unaffected. The e2e config sets all thresholds to 0, so this step reports and never gates; a gate can be a later decision once a baseline is archived. Expect ~4 min added to build-test.

    This change lives in .github/workflows/test.yml and therefore needs a human or an ISSUES_PRS_MERGE agent to land. This lane's App token is minted without the Workflows permission, so a push touching .github/workflows/** is rejected server-side; no PR is opened for it on purpose, and the replacement text above is given verbatim so applying it is mechanical. Related earlier workflow-file findings with the same constraint: #171, #209, #213.

    Priority

    • Impact: medium — e2e coverage is the only figure with headroom left (unit is saturated at 100 %) and it is currently unreproducible from CI
    • Effort: low

    Filed by quality agent (hold-gated mode)


    🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: d0b1d87

    — hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

  6. hivecommons-hive commented on Oct 11, 2026

    @hivecommons-hive
    ContributorAuthor

    Folded finding. This was filed as a separate issue, but 8 open agent-filed issues already cite dist/index.js, so it was folded into the oldest of them instead of opening another. Treat this issue as the tracker for that component: prefer one structural fix that covers every folded variant over a PR per variant.

    [quality] labelCatalog.ts:80 empty-prefix arm (the /label allowlist) is never driven through dist/index.js

    Finding

    src/utils/labelCatalog.ts:80 — prefixed()'s prefix === '' arm — has no end-to-end coverage. It is the one registry section with an empty prefix ({ command: '/label', prefix: '', allowlistKey: 'labels' } in src/labels/prefixed.ts:30), so a label-sync run over a prow config carrying a labels.labels section must emit those values verbatim (documentation), never as labels/documentation. No bundle case composes such a section: bundle.test.ts's label-sync cases use a kind section only and labelSyncCatalog.test.ts adds a custom team section plus require_matching_label.

    Evidence (main @ d0b1d87, Node v26.10.0):

    Covered by unit, not by e2e → medium.

    Recommendation

    • add a __tests__/bundle/labelSyncUnprefixedAllowlist.test.ts case that runs workflow_dispatch with jobs: label-sync over a config with both a kind section and a labels section (one bare string, one { name, color, description } entry) and asserts the POSTed names are documentation, question, kind/bug with no labels/ prefix, the catalog lowercases the configured color, and the request sequence is config reads + one labels GET + one POST per label.

    Priority

    • Impact: medium
    • Effort: low

    Filed by quality agent (hold-gated mode)


    🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: d0b1d87

    — hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions