Skip to content

test(core): document slice-two evidence and remaining gates - #413

Draft
rowkav09 wants to merge 4 commits into
mainfrom
test/slice2-evidence
Draft

rowkav09 wants to merge 4 commits into
mainfrom
test/slice2-evidence

Conversation

@rowkav09

@rowkav09 rowkav09 commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Scope

Gated evidence inventory, not apply activation. Three granular commits add canonical npm v3 fixture directories, five executable core cases, and a pass/fail table in docs/slice2-evidence-gate.md.

The tests cover a read-only eligible leaf preview; stale source changing the finding key; a source mutation during static overlay causing refusal; .npmrc refusal preserving ordinary scans; and newly observed usage refusing a former preview on the same bytes. The synthetic adapter isolates core semantics rather than claiming real JS adapter or GitHub integration proof.

Validation

  • pnpm --filter @ghostdeps/core test: 487 pass, 0 fail after rebasing onto main
  • pnpm exec eslint packages/core/src/engine/fix-evidence.test.ts
  • pnpm exec prettier --check packages/core/src/engine/fix-evidence.test.ts fixtures/fix-evidence/README.md docs/slice2-evidence-gate.md

Gate result

Partial, not passed for user-facing comment/apply. Real adapter coverage, permission-decline scan-only integration, PR-head CAS, independent App/runner revalidation, M3 stability and ADR-0004 boundary review remain. Do not merge this draft as an activation claim; review the evidence and gaps first. Related: #389 and gated scaffold #405.

Fixture manifests (auto-triage rule 13007)

This PR adds new fixture manifests not yet covered by dependabot auto-triage rule 13007 (exact paths, no globs). Qa: please extend the rule with:

  • fixtures/fix-evidence/declined/package.json
  • fixtures/fix-evidence/declined/package-lock.json
  • fixtures/fix-evidence/eligible/package.json
  • fixtures/fix-evidence/eligible/package-lock.json
  • fixtures/fix-evidence/stale-source/package.json
  • fixtures/fix-evidence/stale-source/package-lock.json
  • fixtures/fix-evidence/usage-revalidated/package.json
  • fixtures/fix-evidence/usage-revalidated/package-lock.json

@rowkav09

Copy link
Copy Markdown
Member Author

GhostDeps independent review - CHANGES REQUESTED at head 58d3dfbc0bcd60647986f307c967b440eee3190e.

The eligible row in docs/slice2-evidence-gate.md claims the fixture asserts two file hashes. The new test at packages/core/src/engine/fix-evidence.test.ts only checks preview.files paths; it does not check beforeSha256 or afterSha256 against the actual before/after bytes. Since this PR is an evidence inventory, please either add those hash assertions to the test or narrow the table claim. The core implementation may produce hashes, but the claimed new assertion is not present.

The other limits are stated accurately: synthetic adapter evidence is not real JS adapter coverage; local .npmrc refusal is not App permission-decline behavior; the source snapshot check is not a GitHub head CAS; no runner proof is present. I merged current main into a disposable worktree and ran core tests (487/487), build, ESLint, Prettier and git diff --check; hosted checks are green. These passes do not close the missing evidence assertion or the wider feature gates. Keep this draft inert and unmerged pending a corrected head and another review. No merge by me.

@rowkav09

Copy link
Copy Markdown
Member Author

GhostDeps independent review - APPROVE the evidence inventory at head e10b625e8c12a2e17e30a25b80cd030d1dd3cdcd. This supersedes my changes request on the prior head, not the feature's release gates.

The eligible case now computes expected manifest and lockfile bytes independently from the fixture, removes the target declaration and node, and checks both before and after SHA-256 digests against the preview output. It also confirms the fixture bytes remain unchanged. This closes the table-versus-test gap I flagged. I reviewed the full PR against current main again; the document still calls the gate PARTIAL and distinguishes synthetic core coverage from real JS adapter, App permission-decline, PR-head CAS, runner and governance evidence.

Disposable merged worktree: core tests 487/487, build, ESLint, Prettier and diff check pass. Hosted Node 22/24 tests were still running at review time; this approves the scoped evidence only. Keep the draft gated and unmerged until its separate prerequisites are resolved. No activation or merge by me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant