Skip to content

refactor(fail-on): share the gate-class labels between the two scan paths - #1288

Open
Souptik96 wants to merge 1 commit into
OWASP:mainfrom
Souptik96:feature/issue-1274-shared-gate-labels
Open

Souptik96 wants to merge 1 commit into
OWASP:mainfrom
Souptik96:feature/issue-1274-shared-gate-labels

Conversation

@Souptik96

Copy link
Copy Markdown

What changed and why

The single- and multi-folder scan paths each typed the three --fail-on gate-class labels as string literals. One path's wording could change without any test noticing.

  • src/utils/severity.ts: export GATE_CLASS_LABELS next to failingGateSummary.
  • src/scan/single-scan.ts and src/scan/multi-folder-scan.ts: both call sites now build their gate input from it.
  • Tests:
    • tests/cli-integration.test.ts (single-folder) and tests/multi-folder-scan.test.ts (multi-folder) each get a test that trips all three classes. Each asserts the printed gate line against GATE_CLASS_LABELS, not a hand-typed copy. The single-folder test needed a detectDM001 module mock in that file. Its default returns [], so no existing test changes behaviour.
    • tests/utils/failon-gate-summary.test.ts pins the wording itself, once.

Gate behaviour, exit codes and printed text are unchanged.

The check from the issue. I replaced each label at each call site with a literal, one at a time (6 mutations: 3 classes × 2 paths). Every mutation fails exactly one of the new tests. Changing the shared constant fails the pinning test.

Verification. npm ci, npm run lint:tests, npm run build, node dist/index.js advisories sync and npm test were run on Windows (Node 22).

  • On unmodified main, the suite has 64 failures.
  • On this branch it has the same 64, plus 3 new passing tests.
  • The 64 are Windows-specific and unrelated to this change. One example: an e2e test saves a temp caCert path into the real ~/.cve-lite-cli/config.json, and later e2e runs then fail on it. I can file that separately if it's useful.

Closes #1274

@Souptik96
Souptik96 requested a review from sonukapoor as a code owner October 4, 2026 05:57
@prx-my

prx-my commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Heads-up: this branch is currently behind main, which blocks the merge. Could you update it?

  • Click Update branch on this PR, or
  • Rebase locally:
    git fetch upstream
    git rebase upstream/main
    git push --force-with-lease
    

Once updated, CI will re-run. Thanks!

…aths

The single- and multi-folder scan paths each typed out the three --fail-on
gate-class labels as string literals, so the wording for one class could
change on one path without any test noticing.

Export GATE_CLASS_LABELS next to failingGateSummary and build both call
sites' gate input from it. Each path now has a test that trips all three
classes and asserts the gate line against the shared labels, and a unit
test pins the wording itself. No change to gate behaviour, exit codes or
printed text.

Closes OWASP#1274
@Souptik96
Souptik96 force-pushed the feature/issue-1274-shared-gate-labels branch from da4b923 to 1c5e893 Compare October 10, 2026 06:17
@Souptik96

Copy link
Copy Markdown
Author

Rebased onto current main (1c5e893, no conflicts). The --fail-on gate tests and the new label tests pass locally. Thanks for the heads-up.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

refactor: share the --fail-on gate-class labels between the two scan paths

2 participants