Skip to content

add(tests): Add unit and e2e suite with CI coverage gate and badge - #164

Draft
cx-artur-ribeiro wants to merge 5 commits into
masterfrom
add-test-coverage
Draft

cx-artur-ribeiro wants to merge 5 commits into
masterfrom
add-test-coverage

Conversation

@cx-artur-ribeiro

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes:

  • The action had no automated tests beyond a scan of two sample files, so changes to the PR comment logic, main.js and entrypoint.sh were not verified, and several known bugs went unnoticed.
  • There was no CI step running unit tests and no coverage visibility.

Proposed Changes:

  • Add a node:test suite with no new dependencies:
    • test/unit: PR comment lifecycle, report content and job summary against a fake GitHub API served over real HTTP.
    • test/e2e: main.js run as a workflow would run it, entrypoint.sh against a fake kics, and a contract check between action.yml and the code.
  • Record known bugs as todo tests so they show in every run without failing CI:
  • Add .github/workflows/ci.yml:
    • runs the tests with a coverage gate of 90% lines, 85% branches and 90% functions
    • runs shellcheck on entrypoint.sh
    • on master, publishes the coverage badge JSON to a badges branch
    • actions are pinned by SHA, permissions are read-only except the badge job, and dependencies install through the echohq registry
  • Add the CI and coverage badges and a "Running the tests" section to the README.
  • Current result: 180 tests passing, 20 todo, 100% line coverage and 94.2% branch coverage on src/.

@cx-artur-ribeiro cx-artur-ribeiro self-assigned this Oct 8, 2026
@stepsecurity-app

stepsecurity-app Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 32

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-artur-ribeiro) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

kics-logo

KICS version: v2.1.20

Category Results
CRITICAL CRITICAL 0
HIGH HIGH 1
MEDIUM MEDIUM 3
LOW LOW 1
INFO INFO 0
TRACE TRACE 0
TOTAL TOTAL 5
Metric Values
Files scanned placeholder 2
Files parsed placeholder 2
Files failed to scan placeholder 0
Total executed queries placeholder 1100
Queries failed to execute placeholder 0
Execution time placeholder 24

Queries Results

Query Name Query Id Severity Platform Cwe Risk Score Category Experimental Description File Name Line Issue Type Search Key Expected Value Actual Value Resource Type Resource Name Remediation Remediation Type
Passwords And Secrets - Generic Password 487f4be7-3fd9-4506-a07a-eae252180c08 HIGH Common 798 7.8 Secret Management false Query to find passwords and secrets in infrastructure code. test/samples/positive1.tf 12 RedundantAttribute Hardcoded secret key should not appear in source Hardcoded secret key appears in source
AD Admin Not Configured For SQL Server a3a055d2-9a2e-4cc9-b9fb-12850a1a3a4b MEDIUM Terraform 732 5.9 Insecure Configurations false The Active Directory Administrator is not configured for a SQL server test/samples/positive1.tf 6 MissingAttribute azurerm_sql_server[positive2] A 'azurerm_sql_active_directory_administrator' should be defined for 'azurerm_sql_server[positive2]' A 'azurerm_sql_active_directory_administrator' is not defined for 'azurerm_sql_server[positive2]' azurerm_sql_server mysqlserver1
Admin User Enabled For Container Registry b897dfbf-322c-45a8-b67c-1e698beeaa51 MEDIUM Terraform 732 5.4 Access Control false Admin user is enabled for Container Registry test/samples/positive2.tf 11 IncorrectValue azurerm_container_registry[positive2].admin_enabled 'admin_enabled' equal 'false' 'admin_enabled' equal 'true' azurerm_container_registry containerRegistry1 {"after":"false","before":"true"} replacement
SQL Server Auditing Disabled f7e296b0-6660-4bc5-8f87-22ac4a815edf MEDIUM Terraform 778 6.4 Observability false Make sure that for SQL Servers, 'Auditing' is set to 'On' test/samples/positive1.tf 6 MissingAttribute azurerm_sql_server[positive2] 'azurerm_sql_server.positive2.extended_auditing_policy' should exist 'azurerm_sql_server.positive2.extended_auditing_policy' does not exist azurerm_sql_server mysqlserver1
SQL Server Predictable Active Directory Account Name bcd3fc01-5902-4f2a-b05a-227f9bbf5450 LOW Terraform 522 2.9 Best Practices false Azure SQL Server must avoid using predictable Active Directory Administrator Account names, like 'Admin', which means the attribute 'login' must be set to a name that is not easy to predict test/samples/positive1.tf 18 IncorrectValue azurerm_sql_active_directory_administrator[positive3].login 'azurerm_sql_active_directory_administrator[positive3].login' should not be predictable' 'azurerm_sql_active_directory_administrator[positive3].login' is predictable azurerm_sql_active_directory_administrator positive3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants