Repository navigation
[Coverage Report] Test Coverage Report — 2026-10-04 #9439
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-11T15:53:37.031Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-04
Overall Coverage
Status: ✅ Overall coverage is strong at >85% across all metrics.
🛡️ Security-Critical Path Status
Key Finding: All primary security-critical files are well-covered. The CLI entry point has minor branch coverage gaps but no statement coverage issues.
📋 Coverage Table
Files with < 80% statement coverage:
🔧 Function Audit
Key Security-Critical Export Functions:
host-iptables.ts: Re-export hub with 3 functions (100% coverage)squid-config.ts: Re-export hub with 2 functions (100% coverage)docker-manager.ts: Re-export hub with 15 functions (100% coverage)domain-patterns.ts: 3 exported functions (100% coverage)cli.ts: Minimal exports, 85.71% line coverage (1 branch uncovered)Branch Coverage Notes:
domain-patterns.ts: 89.47% branch coverage (17/19 branches covered)cli.ts: 50% branch coverage (1/2 branches covered) — likely error path or edge caseTest Infrastructure:
📅 Recent Source Changes (last 7 days)
Based on the coverage gaps brief, recent additions include:
These are newer subsystems undergoing active development, which explains the lower coverage.
🔎 Notable Findings
Strong Core Security: All primary security-critical paths (
host-iptables.ts,squid-config.ts,docker-manager.ts) maintain 100% statement coverage. Domain pattern matching (domain-patterns.ts) is 100% covered for statements with 89.47% branch coverage.New Feature Development Gap: The NVX and bounded-execution modules show low coverage (42–59%), reflecting recent feature additions. These modules (cleanup-registry, finite-cardinality, finite-schema) appear to be in active development and need expanded test coverage before production rollout.
CLI Entry Point Edge Case:
src/cli.tshas 85.71% line coverage with only 50% branch coverage — likely one error-handling branch or edge case not exercised in tests.Branch vs Statement Coverage Disparity: Several new modules show reasonable statement coverage but significantly lower branch coverage (e.g.,
bounded-execution/finite-disclosure.ts: 51.78% stmts, 11.42% branch), suggesting conditional logic is undertested.🎯 Recommendations
Priority 1 — HIGH: Test NVX Registry Cleanup (42.8% coverage)
src/nvx/cleanup-registry.tsPriority 2 — MEDIUM: Expand Bounded Execution Branch Coverage (11–43% branches)
src/bounded-execution/*modulesPriority 3 — LOW: Verify CLI Edge Case Coverage (50% branch)
src/cli.tsAll reactions