[quality] e2e coverage report's repository-escape guard has no test
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 89/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- javascript, node.js, playwright
- Domain
- security, testing-qa, tooling
Research direction
Read tests/tools/e2e-coverage-report.mjs:196-200 and the related cases at tests/e2e-coverage-report.test.mjs:709 and :848. Build the described fixture with src as a symlink outside the fixture root, then run node --test tests/e2e-coverage-report.test.mjs. Done means the test asserts /source map source escapes repository/ and the guard lines are covered.
Written by the indexing model from the issue text.
Description
Finding
tests/tools/e2e-coverage-report.mjs is the tool that converts Playwright V8 coverage
into src/** line attribution. It contains three layered containment guards that stop a
malicious or malformed source map from pulling file contents in from outside the
repository. One of them — the repository-escape guard — has no test:
tests/tools/e2e-coverage-report.mjs:196-200
if (!isInside(rootPath, resolvedSource)) {
throw new Error(
`source map source escapes repository: ${sourceFile.relative}`,
);
}
Its two siblings are already pinned: tests/e2e-coverage-report.test.mjs:709
(rejects symlinked maps, bundles, and sources) and :848
(rejects a nominal src symlink to an unrelated repo file) both assert
/source map source escapes src directory/. Nothing asserts
/source map source escapes repository/.
The guard is reachable, not dead code. It fires when src itself is the symlink:
srcRootPath = await realpath(srcRoot) then resolves to the outside directory, so the
isInside(srcRootPath, resolvedSource) check at :185-189 is satisfied and only the
repository check at :196 sees the escape. Untested, a refactor can delete it silently
and the tool will happily read and embed file contents from outside the checkout into a
published coverage artifact.
Evidence
Unit evidence — npm run test:unit:coverage (node --test coverage, TZ=UTC,
node v26.8.1) run locally on 2026-10-02 at 0c87310:
tests/tools/e2e-coverage-report.mjs | 97.32 | 89.49 | 133-134 180-183 197-200 598-602 | ...
Lines 197-200 are the guard body. Adding one test moves the file to
98.03 | 89.83 and leaves 197-200 covered.
End-to-end evidence — not applicable. This file is build tooling executed by the
End-to-end coverage (non-gating) CI job; it is never loaded in the browser, so it
cannot appear in the Playwright V8 coverage artifact. Confirmed against the
e2e-coverage artifact (id 11211344262) of run
https://github.com/cncf/endusers/actions/runs/36972418667 (report.txt, run
36972418667-1, status passed), whose file list is src/** only. This is therefore
a unit-only gap and carries no e2e dimension.
Why this matters now
Repository region coverage is 94.90% against the --check-regions 94 floor enforced by
npm run test:unit:coverage:check. tests/tools/e2e-coverage-report.mjs at 89.49%
regions is the single largest drag on that margin.
Recommendation
Add one test to tests/e2e-coverage-report.test.mjs that builds a fixture whose src
is a symlink to a directory outside the fixture root, and assert
collectE2ECoverage rejects with /source map source escapes repository/.
Completion criteria
- a test asserts
/source map source escapes repository/ -
node --test tests/e2e-coverage-report.test.mjspasses -
tests/tools/e2e-coverage-report.mjslines196-200are covered
Priority
- Impact: medium
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5n31 | SHA: 0c87310
— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88
- Dominant language
- JavaScript
- Stars
- 0
- Forks
- 2
- Avg merge
- 20h 41m
- Merged PRs (30d)
- 468
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from cncf/endusers
-
agent/scanner bug hive/hosted-available-lke648397-260827-5n31
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
agent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
Difficulty 2/5 1-3 hours Newbie friendliness 58/100
Maintainers usually reply within 1 day
-
[quality] no test runs a validator over a merged e2e data overlay, so a fixture's invalidity cannot be told from driftPossibly taken @hivecommons-hive claimed this today. Openagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5n31 quality testing
Difficulty 4/5 3-5 days Newbie friendliness 20/100
Maintainers usually reply within 1 day
-
[quality] no e2e case ever selects the contributor membership filterPossibly taken @hivecommons-hive claimed this today. Openagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5n31 quality testing
Difficulty 2/5 1-3 hours Newbie friendliness 35/100
Maintainers usually reply within 1 day
-
[sec-check] rewriteImages() promotes a javascript:// image destination into a live link instead of reducing it to alt textPossibly taken @hivecommons-hive claimed this today. Openagent/sec-check hive/covered-by-pr hive/hosted-available-lke648397-260827-5n31 security
Difficulty 2/5 1-3 hours Newbie friendliness 25/100
Maintainers usually reply within 1 day
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
capricorn86/happy-dom#2485 ·
Maintainers usually reply within 2 days
-
area:space-accuracy good first issue track:data
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Sara-Managed-Projects/space-radar#904 ·
Maintainers usually reply within 1 day