Finding
scripts/import-architecture-issue.mjs landed hours ago in #805 and is the only file in the repository with uncovered source lines. On main@be53bd1:
$ npm run test:unit:coverage
scripts/import-architecture-issue.mjs | 96.03 | 78.95 | 76-79 116-117 162-163 193-194
...
src files | 99.84 | 98.46 | 6329/6339 lines
Every other source file is at 100% lines. These ten lines are the whole of the shortfall.
All four uncovered regions are load-bearing, and three of them only ever execute in the workflow — never in a local run:
| Lines |
Branch |
Why it matters |
| 76-79 |
neither --issue-json nor GITHUB_EVENT_PATH |
the "I have no payload" guard |
| 116-117 |
a required: true body section is unanswered |
the fail-closed gate on incomplete submissions |
| 162-163 |
GITHUB_OUTPUT → id=<id> |
the workflow names the generated PR from this value |
| 193-194 |
a template field heading is absent from the body |
catches a body that did not come from the current issue template |
The GITHUB_OUTPUT line is the sharpest of these. .github/workflows/architecture-submission.yml reads the step output to title the pull request it opens, so a renamed or unwritten key degrades the PR title silently — and nothing currently asserts the key name.
Worth noting that the un-exercised path is also the normal one: the workflow passes no --issue-json at all and relies on GITHUB_EVENT_PATH, which no test covers. Every existing test uses the --issue-json path instead.
A latent hazard in the test sandbox
tests/helpers-import-issue-sandbox.mjs spreads process.env into the child. Inside GitHub Actions both GITHUB_EVENT_PATH and GITHUB_OUTPUT are really set, so today the unit suite would:
- take a different branch in CI than it does locally (an ambient
GITHUB_EVENT_PATH masks the 76-79 guard entirely), and
- append
id=acme-corp to the live workflow's output file via line 163.
That is environment bleed from a test into its own CI run. Since ci.yml is what runs the suite, the sandbox has to scrub both variables and let tests opt back in explicitly.
Coverage evidence
- Unit:
npm run test:unit:coverage (tests/tools/coverage-report.mjs, node v26.8.2, TZ=UTC), run locally 2026-09-28 at rev be53bd1 — figures above.
- End-to-end:
.github/workflows/ci.yml:117 runs npm run test:e2e. That suite is Playwright browser specs against the served site (tests/e2e/*.spec.js); grep -rl import-architecture-issue tests/e2e/ returns no matches. This is a CLI invoked by a workflow and is never loaded by the site, so it is structurally outside end-to-end reach — not merely unobserved.
Covered by neither unit nor end-to-end → priority 1.
Recommendation
Priority
- Impact: high — brand-new automation, and the only uncovered source lines in the repo
- Effort: low — the sandbox already exists; this is fixtures plus two new options
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5n31 | SHA: be53bd1
— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88
Finding
scripts/import-architecture-issue.mjslanded hours ago in #805 and is the only file in the repository with uncovered source lines. Onmain@be53bd1:Every other source file is at 100% lines. These ten lines are the whole of the shortfall.
All four uncovered regions are load-bearing, and three of them only ever execute in the workflow — never in a local run:
--issue-jsonnorGITHUB_EVENT_PATHrequired: truebody section is unansweredGITHUB_OUTPUT→id=<id>The
GITHUB_OUTPUTline is the sharpest of these..github/workflows/architecture-submission.ymlreads the step output to title the pull request it opens, so a renamed or unwritten key degrades the PR title silently — and nothing currently asserts the key name.Worth noting that the un-exercised path is also the normal one: the workflow passes no
--issue-jsonat all and relies onGITHUB_EVENT_PATH, which no test covers. Every existing test uses the--issue-jsonpath instead.A latent hazard in the test sandbox
tests/helpers-import-issue-sandbox.mjsspreadsprocess.envinto the child. Inside GitHub Actions bothGITHUB_EVENT_PATHandGITHUB_OUTPUTare really set, so today the unit suite would:GITHUB_EVENT_PATHmasks the 76-79 guard entirely), andid=acme-corpto the live workflow's output file via line 163.That is environment bleed from a test into its own CI run. Since
ci.ymlis what runs the suite, the sandbox has to scrub both variables and let tests opt back in explicitly.Coverage evidence
npm run test:unit:coverage(tests/tools/coverage-report.mjs, node v26.8.2,TZ=UTC), run locally 2026-09-28 at revbe53bd1— figures above..github/workflows/ci.yml:117runsnpm run test:e2e. That suite is Playwright browser specs against the served site (tests/e2e/*.spec.js);grep -rl import-architecture-issue tests/e2e/returns no matches. This is a CLI invoked by a workflow and is never loaded by the site, so it is structurally outside end-to-end reach — not merely unobserved.Covered by neither unit nor end-to-end → priority 1.
Recommendation
GITHUB_EVENT_PATHandGITHUB_OUTPUTfrom the sandbox's inherited environment; addenvandpassIssueJsonoptions so tests can supply them deliberatelyGITHUB_EVENT_PATHfallback — the way the workflow actually invokes the scriptid=<id>line written toGITHUB_OUTPUTPriority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5n31| SHA:be53bd1— hive: agent=quality backend=copilot model=claude-opus-5 copilot=1.0.88