-
Notifications
You must be signed in to change notification settings - Fork 24
[quality] action.yml inputs are not contract-tested against the core.getInput names src/ reads #231
Copy link
Copy link
Open
Labels
agent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
Description
Activity
Metadata
Metadata
Assignees
Labels
agent/qualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedHive verified that an open PR references or claims this issue; still actionable until confirmedhive/hosted-available-lke648397-260827-5q9tCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenanceneeds-kindqualityCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenancetestingCreated by Hive for agent-filed issue provenanceCreated by Hive for agent-filed issue provenance
Finding
__tests__/workflows.test.tscontract-testsaction.ymlagainst the reusable workflow (.github/workflows/prow.yml), the starter templates and the dogfood workflow, so an input cannot drift between those files. Nothing, however, tiesaction.ymlto the code that consumes it: no test asserts that the seven declared inputs (github-token,prow-commands,jobs,dry-run,merge-method,config,cat-api-key) are exactly the namessrc/reads throughcore.getInput/core.getBooleanInput.Consequence: a misspelt name (
getInput('dry-runn')), or a newgetInputadded insrc/without a matchingaction.ymlentry, compiles, passes the whole suite (every unit test mockscore.getInput) and reads''at runtime. The reverse — anaction.ymlinput no code reads — documents a knob that does nothing.Evidence,
main@ c48bd6d:npx vitest run --coverage→ 99.83% statements, so this is a contract gap, not a line-coverage gap; the remaining uncovered lines are all claimed by open hold-gated PRs. Theprow / prowdogfood check emits no coverage data (#209), so there is no end-to-end evidence to cite either way. Today the two sets do match (7 = 7), verified by grep.Recommendation
Add a
describe('action.yml mirrors the inputs src/ reads')block to__tests__/workflows.test.tsthat walkssrc/**/*.ts, collects every string-literal argument ofget(Boolean|Multiline)?Input(...), and asserts set equality withObject.keys(action.yml.inputs)— with a per-input failure message naming the reading file. Verified locally that the test goes red whendry-runis misspelt insrc/cronJobs/labelSync.ts.Test-only change in
__tests__/workflows.test.ts; no open hold-gated PR touches that file.Priority
action.ymlcontractFiled by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:c48bd6d— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88