Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[quality] e2e coverage report's repository-escape guard has no test

Closed Beginner friendly
#970 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
89/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
javascript, node.js, playwright

Research direction

Read tests/tools/e2e-coverage-report.mjs:196-200 and the related cases at tests/e2e-coverage-report.test.mjs:709 and :848. Build the described fixture with src as a symlink outside the fixture root, then run node --test tests/e2e-coverage-report.test.mjs. Done means the test asserts /source map source escapes repository/ and the guard lines are covered.

Written by the indexing model from the issue text.

Description

agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5n31 quality testing

Finding

tests/tools/e2e-coverage-report.mjs is the tool that converts Playwright V8 coverage
into src/** line attribution. It contains three layered containment guards that stop a
malicious or malformed source map from pulling file contents in from outside the
repository. One of them — the repository-escape guard — has no test:

tests/tools/e2e-coverage-report.mjs:196-200

if (!isInside(rootPath, resolvedSource)) {
  throw new Error(
    `source map source escapes repository: ${sourceFile.relative}`,
  );
}

Its two siblings are already pinned: tests/e2e-coverage-report.test.mjs:709
(rejects symlinked maps, bundles, and sources) and :848
(rejects a nominal src symlink to an unrelated repo file) both assert
/source map source escapes src directory/. Nothing asserts
/source map source escapes repository/.

The guard is reachable, not dead code. It fires when src itself is the symlink:
srcRootPath = await realpath(srcRoot) then resolves to the outside directory, so the
isInside(srcRootPath, resolvedSource) check at :185-189 is satisfied and only the
repository check at :196 sees the escape. Untested, a refactor can delete it silently
and the tool will happily read and embed file contents from outside the checkout into a
published coverage artifact.

Evidence

Unit evidence — npm run test:unit:coverage (node --test coverage, TZ=UTC,
node v26.8.1) run locally on 2026-10-02 at 0c87310:

tests/tools/e2e-coverage-report.mjs | 97.32 | 89.49 | 133-134 180-183 197-200 598-602 | ...

Lines 197-200 are the guard body. Adding one test moves the file to
98.03 | 89.83 and leaves 197-200 covered.

End-to-end evidence — not applicable. This file is build tooling executed by the
End-to-end coverage (non-gating) CI job; it is never loaded in the browser, so it
cannot appear in the Playwright V8 coverage artifact. Confirmed against the
e2e-coverage artifact (id 11211344262) of run
https://github.com/cncf/endusers/actions/runs/36972418667 (report.txt, run
36972418667-1, status passed), whose file list is src/** only. This is therefore
a unit-only gap and carries no e2e dimension.

Why this matters now

Repository region coverage is 94.90% against the --check-regions 94 floor enforced by
npm run test:unit:coverage:check. tests/tools/e2e-coverage-report.mjs at 89.49%
regions is the single largest drag on that margin.

Recommendation

Add one test to tests/e2e-coverage-report.test.mjs that builds a fixture whose src
is a symlink to a directory outside the fixture root, and assert
collectE2ECoverage rejects with /source map source escapes repository/.

Completion criteria

  • a test asserts /source map source escapes repository/
  • node --test tests/e2e-coverage-report.test.mjs passes
  • tests/tools/e2e-coverage-report.mjs lines 196-200 are covered

Priority

  • Impact: medium
  • Effort: low

Filed by quality agent (hold-gated mode)


🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5n31 | SHA: 0c87310

— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88

Dominant language
JavaScript
Stars
0
Forks
2
Avg merge
20h 41m
Merged PRs (30d)
468

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from cncf/endusers

All issues in cncf/endusers

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.