[quality] the bundle e2e suite never drives root-OWNERS authorization on an issue or the OWNERS-based /lgtm refusal on a pull request through dist/index.js
Maintainer thường phản hồi trong vòng 2 ngày
Một pull request liên quan đã được merge.
- #283 của @hivecommons-hive — đã merge
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- github, typescript
- Lĩnh vực
- security, testing-qa
Hướng nghiên cứu
Start with src/utils/auth.ts and the existing bundle tests, especially bundle.test.ts and triggerTestAndLgtmCancel.test.ts. Add tests/bundle/ownersAuth.test.ts using the listed helpers, then run npm run test:coverage:e2e. Done means the three specified issue and pull-request OWNERS authorization cases execute through dist/index.js with the expected comments, label behavior, and API reads.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Finding
src/utils/auth.ts holds the OWNERS-based authorization behind /lgtm, /approve and the /test//retest triggers (assertAuthorizedByOwnersOrMembership, L244). Three of its arms are unit-covered but never run through the committed dist/index.js:
assertRootOwner+retrieveOwnersFile(L271–290, L338–364) — on an issue (not a pull request) the rootOWNERSfile of the default branch is read throughGET …/contents/OWNERS, base64-decoded, parsed, and the commenter is matched against the role. The only bundle route for that path answers404(bundle.test.ts:443, the author-refusal case), so the membership fallback is alldist/ever exercises on issues; no bundle test sends/lgtmto a plain issue at all.assertPullRequestOwner's refusal (L321–322) — on a pull request whose OWNERS files cover the changed files but list neither the commenter as reviewer nor approver,Cannot apply the lgtm label because Error: <login> is not a reviewer or approver for any changed file. Every bundle/lgtmon an OWNERS repository is by a listed reviewer; the OWNERS-less refusal (triggerTestAndLgtmCancel.test.ts:293) goes through the membership arm instead.
Evidence
- Unit:
npx vitest run --coverageonmain@ ec76a3b (vitest 5.0.3,@vitest/coverage-v8) →src/utils/auth.ts100 % lines / 98.43 % branches.__tests__/utils/auth.test.ts:361-387and__tests__/label/lgtm.test.ts:348exercise all three arms with mocked octokit. - End-to-end:
npm run test:coverage:e2e(thevitest.e2e-coverage.config.mjsrecipe from #274: source-mapped bundle built from__tests__/bundle/coverageEntry/, same revision,__tests__/bundleonly) →src/utils/auth.ts63.1 % lines / 53.12 % branches; unreached statement lines include271-290,321-322,338-364(fromcoverage/coverage-final.json). The two runs are reported separately by design (vitest.e2e-coverage.config.mjsheader): their statement maps come from different transforms and do not line-merge.
Unit-covered, not e2e-covered → medium.
Recommendation
- Add
__tests__/bundle/ownersAuth.test.ts(new file, importingcomment,helpersFor,ownersProbe,ownersReads,queueRead,repo,tokenfrom./helpers) with three cases driving/lgtmthroughdist/index.js:- issue, root
OWNERSlists the commenter as reviewer →GET …/contents/OWNERS(200, base64),GET …/labels,POST …/issues/1/labels {labels:['lgtm']}, no/orgs/…/membersor/collaboratorsread, then the post-command config reads; - issue, root
OWNERSdoes not list the commenter → exit 1, one refusal comment naming the login and role, no label write, no membership fallback; - pull request,
OWNERS+sdk/OWNERScoveringsdk/file.go, commenter in neither → exit 1, refusal comment… is not a reviewer or approver for any changed file, nocontents/OWNERSread, no membership read, then the config reads and tide's gate.
- issue, root
Measured with those three cases on the same recipe: auth.ts e2e rises to 79.61 % lines / 70.31 % branches; what remains unreached in the file are throw/catch arms (L22, 42-43, 61, 64, 98, 101, 135-139, 179, 208-222, 279, 311, 348-359) that the unit suite already pins.
Disjoint from the open hold-gated PRs: #230 (vitest.config.mjs), #242 (cronJobsInput.test.ts), #244 (meow.test.ts), #246 (labelCommands.test.ts, helpers.ts repoLabels).
Priority
- Impact: medium — authorization is the gate in front of every label and merge command; the OWNERS branch of it has never been exercised by the shipped bundle
- Effort: low
Filed by quality agent (hold-gated mode)
hive: close-on-merge
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Ngôn ngữ chính
- TypeScript
- Star
- 132
- Fork
- 23
- Merge trung bình
- 1 ngày 20 giờ
- Pull request đã merge (30 ngày)
- 134
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của cncf/prow-github-actions
-
agent/quality hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
cncf/prow-github-actions#393 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
[quality] test.yml never runs on main after a tide merge — github.token merges don't trigger push; add workflow_dispatch + scheduleCó thể đã có người làm @mrbobbytables đã nhận hôm nay. Đang mởagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/failing-test quality testing
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 78/100
cncf/prow-github-actions#329 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
[quality] test.yml runs build-test twice per commit on every PR branch — narrow push to main and add a concurrency groupCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
cncf/prow-github-actions#213 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
[quality] parseOwners's content-shape arms (owners.ts:39/41/83: whitespace-only, non-mapping and non-string-role OWNERS files) have no bundle test through dist/index.jsCó thể đã có người làm @hivecommons-hive đã nhận hôm nay. Đang mởagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing
Độ khó 3/5 Nửa ngày Mức phù hợp với người mới 22/100
cncf/prow-github-actions#405 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t needs-kind quality testing
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 55/100
cncf/prow-github-actions#404 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của cncf/prow-github-actions
Issue tương tự
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
core
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
vectorize-io/hindsight#5457 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
beginner friendly community contributions-welcome good first issue hacktoberfest help wanted testing up-for-grabs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
lukilabs/beautiful-mermaid#160 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
rescript-lang/rescript-lang.org#1420 ·
Maintainer thường phản hồi trong vòng 2 ngày