You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The test suite achieved 90.54% statement coverage and 83.54% branch coverage across 368 source files, with 19,067 statements covered out of 21,057 total.
Metric
Coverage
Target
Status
Statements
90.54%
85%+
✅ Exceeds
Branches
83.54%
80%+
✅ Exceeds
Functions
88.88%
85%+
✅ Exceeds
Lines
92.08%
90%+
✅ Exceeds
🛡️ Security-Critical Path Status
Key security modules show strong coverage for core firewall functions:
File
Statements
Branches
Status
domain-patterns.ts
100%
89.47%
✅ Excellent
domain-matchers.ts
98.14%
95%
✅ Excellent
docker-manager.ts
100%
100%
✅ Perfect
domain-utils.ts
100%
100%
✅ Perfect
domain-validation.ts
100%
100%
✅ Perfect
cli-workflow.ts
95.95%
94.11%
✅ Strong
cli.ts
85.71%
50%
⚠️ Attention needed
Note:cli.ts (7 lines) is a thin entry point with limited branching. The 50% branch coverage reflects incomplete coverage of the single conditional branch—recommend adding integration test covering error path.
📋 Coverage Table
High Coverage (95%+) — 156 files
Includes critical modules like cloud-hypervisor, artifact-preservation, container lifecycle, and compose generators. These are production-ready for release.
Good Coverage (85–95%) — 89 files
Represents well-tested modules with minor gaps. Recommend targeted test additions only if indicated by failing integration tests.
Moderate Coverage (70–85%) — 43 files
Includes configuration and specialized execution paths. Some require attention per security guidelines.
Low Coverage (<70%) — 5 CRITICAL files
🔧 Function Audit
Critical Coverage Gaps (Statements < 50%):
Severity
File
Statements
Branches
Issue
🔴 CRITICAL
src/nvx/cleanup-registry.ts
42.8%
32.11%
VM cleanup logic under-tested; affects resource leak risks
🔴 CRITICAL
src/bounded-execution/finite-cardinality.ts
46.03%
35.29%
Execution cardinality bounds—security-critical for denial-of-service prevention
🔴 CRITICAL
src/bounded-execution/finite-schema.ts
49.77%
43.11%
Schema validation for bounded execution; edge cases missing
🟡 MEDIUM
src/microvm/network-reservation.ts
51.5%
54.86%
Network namespace isolation logic; incomplete test paths
preflight.ts: 52.77% function coverage (36 functions, 19 tested)
virtiofsd.ts: 68.75% function coverage (32 functions, 22 tested)
manager-start.ts: 53.84% function coverage (13 functions, 7 tested)
📅 Recent Source Changes (last 7 days)
Recent commits indicate active development in:
Cloud Hypervisor guest and runtime features
NVX/bounded-execution security modules
Container lifecycle and cleanup paths
Recommendation: Prioritize test coverage for recently modified security-critical files (bounded-execution, nvx/cleanup-registry) before merging changes to main branch.
🔎 Notable Findings
Bounded Execution Gap — Both finite-cardinality.ts (46%) and finite-schema.ts (50%) protect against resource exhaustion attacks but lack comprehensive test coverage. These directly impact sandbox isolation guarantees.
Resource Cleanup Risk — nvx/cleanup-registry.ts (43%) manages VM resource lifecycle. Low coverage increases risk of resource leaks in error paths during container teardown.
Enclave Executor Complexity — host-enclave-executor.ts (52% statements, 34% branches) orchestrates multi-service initialization but has 43 uncovered functions. Branch coverage especially weak.
Core Firewall Strength — Domain matching, validation, and Docker orchestration achieve 98–100% coverage, ensuring HTTP/HTTPS filtering and container isolation are production-ready.
🎯 Recommendations
High Priority — Address critical security gaps:
Add unit tests for bounded-execution/finite-cardinality.ts and finite-schema.ts (target: 70%+ statements, 60%+ branches). Focus on boundary conditions, error injection, and recovery scenarios. These modules prevent denial-of-service attacks and require high confidence.
Improve error-path coverage in nvx/cleanup-registry.ts (target: 75%+). Test cleanup failure scenarios, partial cleanup states, and resource reclamation on timeout. Use mock containers and network failures to validate error handling.
Test uncovered functions in host-enclave-executor.ts (focus on 23 uncovered functions). Prioritize multi-service handoff logic, API communication, and failure modes. Recommend using integration-test fixtures to exercise full initialization sequence.
Medium Priority — Reduce technical debt:
Add branch-coverage tests to cli.ts error path (target: 100% branch coverage for entry point).
Expand function coverage in preflight.ts (target: ≥75%) and manager-start.ts (target: ≥75%).
Low Priority — Maintain quality baseline:
Keep all security-critical modules (domain-patterns, docker-manager, domain-validation) at ≥95% coverage. Block merges that reduce coverage in these files.
Quarterly audit: re-run npm run test:coverage after each release and track coverage trends.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-02
Overall Coverage
The test suite achieved 90.54% statement coverage and 83.54% branch coverage across 368 source files, with 19,067 statements covered out of 21,057 total.
🛡️ Security-Critical Path Status
Key security modules show strong coverage for core firewall functions:
domain-patterns.tsdomain-matchers.tsdocker-manager.tsdomain-utils.tsdomain-validation.tscli-workflow.tscli.tsNote:
cli.ts(7 lines) is a thin entry point with limited branching. The 50% branch coverage reflects incomplete coverage of the single conditional branch—recommend adding integration test covering error path.📋 Coverage Table
High Coverage (95%+) — 156 files
Includes critical modules like cloud-hypervisor, artifact-preservation, container lifecycle, and compose generators. These are production-ready for release.
Good Coverage (85–95%) — 89 files
Represents well-tested modules with minor gaps. Recommend targeted test additions only if indicated by failing integration tests.
Moderate Coverage (70–85%) — 43 files
Includes configuration and specialized execution paths. Some require attention per security guidelines.
Low Coverage (<70%) — 5 CRITICAL files
🔧 Function Audit
Critical Coverage Gaps (Statements < 50%):
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/cloud-hypervisor/host-enclave-executor.tsFunctions with Low Test Density (<60% coverage):
preflight.ts: 52.77% function coverage (36 functions, 19 tested)virtiofsd.ts: 68.75% function coverage (32 functions, 22 tested)manager-start.ts: 53.84% function coverage (13 functions, 7 tested)📅 Recent Source Changes (last 7 days)
Recent commits indicate active development in:
Recommendation: Prioritize test coverage for recently modified security-critical files (bounded-execution, nvx/cleanup-registry) before merging changes to main branch.
🔎 Notable Findings
Bounded Execution Gap — Both
finite-cardinality.ts(46%) andfinite-schema.ts(50%) protect against resource exhaustion attacks but lack comprehensive test coverage. These directly impact sandbox isolation guarantees.Resource Cleanup Risk —
nvx/cleanup-registry.ts(43%) manages VM resource lifecycle. Low coverage increases risk of resource leaks in error paths during container teardown.Enclave Executor Complexity —
host-enclave-executor.ts(52% statements, 34% branches) orchestrates multi-service initialization but has 43 uncovered functions. Branch coverage especially weak.Core Firewall Strength — Domain matching, validation, and Docker orchestration achieve 98–100% coverage, ensuring HTTP/HTTPS filtering and container isolation are production-ready.
🎯 Recommendations
High Priority — Address critical security gaps:
Add unit tests for
bounded-execution/finite-cardinality.tsandfinite-schema.ts(target: 70%+ statements, 60%+ branches). Focus on boundary conditions, error injection, and recovery scenarios. These modules prevent denial-of-service attacks and require high confidence.Improve error-path coverage in
nvx/cleanup-registry.ts(target: 75%+). Test cleanup failure scenarios, partial cleanup states, and resource reclamation on timeout. Use mock containers and network failures to validate error handling.Test uncovered functions in
host-enclave-executor.ts(focus on 23 uncovered functions). Prioritize multi-service handoff logic, API communication, and failure modes. Recommend using integration-test fixtures to exercise full initialization sequence.Medium Priority — Reduce technical debt:
cli.tserror path (target: 100% branch coverage for entry point).preflight.ts(target: ≥75%) andmanager-start.ts(target: ≥75%).Low Priority — Maintain quality baseline:
npm run test:coverageafter each release and track coverage trends.All reactions