You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Assessment: Overall coverage is strong at 91%+ for lines and statements, with branch coverage slightly lower at 84.69%. This indicates good line-level and logical coverage, though some conditional edge cases remain untested.
🛡️ Security-Critical Path Status
File
Statements
Functions
Branches
Status
src/host-iptables-rules.ts
✅ 100.0%
✅ 100.0%
✅ 100.0%
EXCELLENT
src/host-iptables-shared.ts
✅ 100.0%
✅ 100.0%
✅ 100.0%
EXCELLENT
src/docker-manager.ts
✅ 100.0%
✅ 100.0%
—
EXCELLENT
src/domain-patterns.ts
✅ 100.0%
✅ 100.0%
89.47%
GOOD
src/domain-matchers.ts
98.14%
✅ 100.0%
95.0%
EXCELLENT
src/container-lifecycle.ts
96.35%
95.65%
90.0%
GOOD
src/cli.ts
⚠️ 85.71%
✅ 100.0%
50.0%
NEEDS ATTENTION
src/config-writer.ts
89.17%
94.11%
83.21%
ADEQUATE
Key Findings:
Network isolation (host-iptables) is fully covered — excellent for security-critical enforcement
Volume mount subsystem sees frequent changes; coverage is generally good (85%+) but should be monitored.
🔎 Notable Findings
Security Baseline Strong: Host-level network isolation (host-iptables-*.ts) and domain ACL enforcement (domain-*.ts) have excellent coverage, indicating firewall rules are well-tested. ✅
Emerging Components Undertested: The new bounded-execution/ and nvx/ modules (cleanup-registry, finite-cardinality, finite-schema) have critical gaps in coverage (<50%), likely because they are newer or feature-flagged. These manage resource limits and lifecycle hooks and must be prioritized.
Branch Coverage Gap in CLI: The main entry point (cli.ts) has only 50% branch coverage, leaving at least one error-handling or exit-path untested. This is a quality-of-life issue but not a direct security risk.
Disclosure Logic (11% Branches):src/bounded-execution/finite-disclosure.ts has only 11.42% branch coverage, indicating most edge cases and failure modes in credential/secret disclosure prevention are untested. This is a potential security regression vector.
Status: Acceptable but borderline. If this is modified for new features, bring it to 90%+.
Effort: 1 hour per feature addition
Baseline: With 91.29% statement coverage overall and security-critical modules at 95–100%, the codebase demonstrates good test health. However, the three critical CRITICAL modules require immediate remediation to close resource-management and disclosure-prevention gaps before the next release.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-02
Overall Coverage
Assessment: Overall coverage is strong at 91%+ for lines and statements, with branch coverage slightly lower at 84.69%. This indicates good line-level and logical coverage, though some conditional edge cases remain untested.
🛡️ Security-Critical Path Status
src/host-iptables-rules.tssrc/host-iptables-shared.tssrc/docker-manager.tssrc/domain-patterns.tssrc/domain-matchers.tssrc/container-lifecycle.tssrc/cli.tssrc/config-writer.tsKey Findings:
cli.ts(main entry) has only 50% branch coverage and 85.71% statement coverage, with 1 uncovered line📋 Coverage Table
Critical Low-Coverage Modules (< 52% Statements)
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tsMedium-Coverage Modules (< 80% Statements)
src/microvm/network-reservation.tssrc/bounded-execution/finite-disclosure.tssrc/artifact-permissions.tssrc/host-env.tsBranch Coverage Concerns
src/cli.ts: 50% branch coverage (1 of 2 branches untested)src/bounded-execution/finite-disclosure.ts: 11.42% branch coverage (only 4 of 35 branches tested)src/compose-network-conflicts.ts: 85.41% branch coverage (7 untested branches in conflict detection)🔧 Function Audit
Uncovered/Undertested Functions:
src/cloud-hypervisor-runtime-backend.ts: 50% functions covered (3 of 6), but 100% statements (likely utility re-exports)src/container-cleanup.ts: 80% functions (4 of 5), 100% statements (1 cleanup path untested)src/bounded-execution/finite-disclosure.ts: 37.5% functions (3 of 8) — disclosure logic incomplete📅 Recent Source Changes (last 7 days)
Modules Modified:
src/domain-patterns.ts— 100% coverage maintained ✅src/host-env.ts— 95.23% coverage (2 lines uncovered)src/runner-tool-cache.ts— modified, check coveragesrc/services/agent-volumes/*— 10+ files modified, coverage varies 80–100%Volume mount subsystem sees frequent changes; coverage is generally good (85%+) but should be monitored.
🔎 Notable Findings
Security Baseline Strong: Host-level network isolation (
host-iptables-*.ts) and domain ACL enforcement (domain-*.ts) have excellent coverage, indicating firewall rules are well-tested. ✅Emerging Components Undertested: The new
bounded-execution/andnvx/modules (cleanup-registry, finite-cardinality, finite-schema) have critical gaps in coverage (<50%), likely because they are newer or feature-flagged. These manage resource limits and lifecycle hooks and must be prioritized.Branch Coverage Gap in CLI: The main entry point (
cli.ts) has only 50% branch coverage, leaving at least one error-handling or exit-path untested. This is a quality-of-life issue but not a direct security risk.Disclosure Logic (11% Branches):
src/bounded-execution/finite-disclosure.tshas only 11.42% branch coverage, indicating most edge cases and failure modes in credential/secret disclosure prevention are untested. This is a potential security regression vector.🎯 Recommendations
🔴 HIGH — Immediate Action Required
Fix
src/bounded-execution/finite-disclosure.tsbranch coverage (11.42% → 80%+)Raise
src/nvx/cleanup-registry.tsto 70%+ coverage🟡 MEDIUM — Next Sprint
Expand
src/bounded-execution/finite-cardinality.tsandfinite-schema.tsto 75%+ coverageAdd branch coverage to
src/cli.ts(50% → 85%+)⚪ LOW — Backlog
src/config-writer.ts(89.17% statements, 83.21% branches)Baseline: With 91.29% statement coverage overall and security-critical modules at 95–100%, the codebase demonstrates good test health. However, the three critical CRITICAL modules require immediate remediation to close resource-management and disclosure-prevention gaps before the next release.
All reactions