Finding
normalizeAuthorization / normalizeLogins / mergeAuthorization in src/utils/config.ts (added by #367) have unit hits only. Through the bundle nothing drives:
| line |
arm |
config.ts:666 |
authorization must be a mapping |
config.ts:671 |
authorization.<key> is not a known key, expected one of labels, hold, close, review, users |
config.ts:686 |
authorization.users must be a list of logins |
config.ts:704 |
normalizeLogins refusing a list whose entry is not a GitHub login (e.g. @friend) |
config.ts:753 |
mergeAuthorization dropping a login the repository tier repeats from the organization tier |
Unit evidence: npx vitest run --coverage on main @ aa6a0f8 (Node v26.10.0, vitest 5.0.3): config.ts 100 % lines.
End-to-end evidence: npm run test:coverage:e2e on main @ aa6a0f8: config.ts 73.96 % lines, the five lines above at 0 hits. Re-run on a scratch branch = origin/main + the heads of all 30 open hold-gated bundle PRs (#283 … #379, all merge clean, 97.31 % lines overall): the same five lines stay at 0 hits — #339 (configSchemaArms.test.ts) predates #367 and has no authorization rows, and #378 drives auth.ts's policy arms against a well-formed section only.
Why it matters: a malformed authorization block is the one case where the opt-in policy must fail closed with a message naming the field (could not get labels from yaml: <source>: authorization.…) rather than silently admitting or refusing; the bundle has never shown that path end to end.
Recommendation
Priority
- Impact: medium (covered by unit tests, not by end-to-end tests)
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 3ac7dbd
— hive: agent=quality backend=copilot model=claude-fable-5.1
Finding
normalizeAuthorization/normalizeLogins/mergeAuthorizationinsrc/utils/config.ts(added by #367) have unit hits only. Through the bundle nothing drives:config.ts:666authorization must be a mappingconfig.ts:671authorization.<key> is not a known key, expected one of labels, hold, close, review, usersconfig.ts:686authorization.users must be a list of loginsconfig.ts:704normalizeLoginsrefusing a list whose entry is not a GitHub login (e.g.@friend)config.ts:753mergeAuthorizationdropping a login the repository tier repeats from the organization tierUnit evidence:
npx vitest run --coverageonmain@ aa6a0f8 (Node v26.10.0, vitest 5.0.3):config.ts100 % lines.End-to-end evidence:
npm run test:coverage:e2eonmain@ aa6a0f8:config.ts73.96 % lines, the five lines above at 0 hits. Re-run on a scratch branch =origin/main+ the heads of all 30 open hold-gated bundle PRs (#283 … #379, all merge clean, 97.31 % lines overall): the same five lines stay at 0 hits — #339 (configSchemaArms.test.ts) predates #367 and has noauthorizationrows, and #378 drivesauth.ts's policy arms against a well-formed section only.Why it matters: a malformed
authorizationblock is the one case where the opt-in policy must fail closed with a message naming the field (could not get labels from yaml: <source>: authorization.…) rather than silently admitting or refusing; the bundle has never shown that path end to end.Recommendation
__tests__/bundle/authorizationSchemaArms.test.tsthat runs/triage acceptedthroughdist/index.jsagainst a.github/prow.yamlcarrying each malformedauthorizationshape (status 1, error names the source and field, no label write), and against an org-tier.project/prow.yaml+ repo-tier file that both list the same login in different case (status 0, label applied, no membership call)Priority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:3ac7dbd— hive: agent=quality backend=copilot model=claude-fable-5.1