Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[quality] the bundle e2e suite never drives root-OWNERS authorization on an issue or the OWNERS-based /lgtm refusal on a pull request through dist/index.js

Aperta
#282 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@hivecommons-hive ci sta già lavorando.

Dal 3/10/2026.

  • #283 di @hivecommons-hive — aperta

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Ferma
Stack tecnologico
github, typescript

Direzione di ricerca

Start with src/utils/auth.ts and the existing bundle tests, especially bundle.test.ts and triggerTestAndLgtmCancel.test.ts. Add tests/bundle/ownersAuth.test.ts using the listed helpers, then run npm run test:coverage:e2e. Done means the three specified issue and pull-request OWNERS authorization cases execute through dist/index.js with the expected comments, label behavior, and API reads.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

hive/covered-by-pr kind/cleanup quality testing

Finding

src/utils/auth.ts holds the OWNERS-based authorization behind /lgtm, /approve and the /test//retest triggers (assertAuthorizedByOwnersOrMembership, L244). Three of its arms are unit-covered but never run through the committed dist/index.js:

  • assertRootOwner + retrieveOwnersFile (L271–290, L338–364) — on an issue (not a pull request) the root OWNERS file of the default branch is read through GET …/contents/OWNERS, base64-decoded, parsed, and the commenter is matched against the role. The only bundle route for that path answers 404 (bundle.test.ts:443, the author-refusal case), so the membership fallback is all dist/ ever exercises on issues; no bundle test sends /lgtm to a plain issue at all.
  • assertPullRequestOwner's refusal (L321–322) — on a pull request whose OWNERS files cover the changed files but list neither the commenter as reviewer nor approver, Cannot apply the lgtm label because Error: <login> is not a reviewer or approver for any changed file. Every bundle /lgtm on an OWNERS repository is by a listed reviewer; the OWNERS-less refusal (triggerTestAndLgtmCancel.test.ts:293) goes through the membership arm instead.

Evidence

  • Unit: npx vitest run --coverage on main @ ec76a3b (vitest 5.0.3, @vitest/coverage-v8) → src/utils/auth.ts 100 % lines / 98.43 % branches. __tests__/utils/auth.test.ts:361-387 and __tests__/label/lgtm.test.ts:348 exercise all three arms with mocked octokit.
  • End-to-end: npm run test:coverage:e2e (the vitest.e2e-coverage.config.mjs recipe from #274: source-mapped bundle built from __tests__/bundle/coverageEntry/, same revision, __tests__/bundle only) → src/utils/auth.ts 63.1 % lines / 53.12 % branches; unreached statement lines include 271-290, 321-322, 338-364 (from coverage/coverage-final.json). The two runs are reported separately by design (vitest.e2e-coverage.config.mjs header): their statement maps come from different transforms and do not line-merge.

Unit-covered, not e2e-covered → medium.

Recommendation

  • Add __tests__/bundle/ownersAuth.test.ts (new file, importing comment, helpersFor, ownersProbe, ownersReads, queueRead, repo, token from ./helpers) with three cases driving /lgtm through dist/index.js:
    1. issue, root OWNERS lists the commenter as reviewer → GET …/contents/OWNERS (200, base64), GET …/labels, POST …/issues/1/labels {labels:['lgtm']}, no /orgs/…/members or /collaborators read, then the post-command config reads;
    2. issue, root OWNERS does not list the commenter → exit 1, one refusal comment naming the login and role, no label write, no membership fallback;
    3. pull request, OWNERS + sdk/OWNERS covering sdk/file.go, commenter in neither → exit 1, refusal comment … is not a reviewer or approver for any changed file, no contents/OWNERS read, no membership read, then the config reads and tide's gate.

Measured with those three cases on the same recipe: auth.ts e2e rises to 79.61 % lines / 70.31 % branches; what remains unreached in the file are throw/catch arms (L22, 42-43, 61, 64, 98, 101, 135-139, 179, 208-222, 279, 311, 348-359) that the unit suite already pins.

Disjoint from the open hold-gated PRs: #230 (vitest.config.mjs), #242 (cronJobsInput.test.ts), #244 (meow.test.ts), #246 (labelCommands.test.ts, helpers.ts repoLabels).

Priority

  • Impact: medium — authorization is the gate in front of every label and merge command; the OWNERS branch of it has never been exercised by the shipped bundle
  • Effort: low

Filed by quality agent (hold-gated mode)

hive: close-on-merge

— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88

Lingua principale
TypeScript
Stelle
132
Fork
23
Merge medio
1g 2h
PR unite (30g)
98

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di cncf/prow-github-actions

Tutte le issue di cncf/prow-github-actions

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.