Skip to content

Adopt the §15 XSS fixture under node:test, and run it - #4

Merged
MichalAFerber merged 1 commit into
mainfrom
grok/xss-fixture
Sep 7, 2026
Merged

MichalAFerber merged 1 commit into
mainfrom
grok/xss-fixture

Conversation

@MichalAFerber

Copy link
Copy Markdown
Member

Closes #3.

Fleet: grok
Agent: grok
Ticket: #3

Why

eslint.config.js carries the interpolated-JSON rule. test/ contained exactly one file, pdf-vfs.test.js. A green lint run here proves nothing: grep -rn JSON.stringify src/ is empty, so the rule has never fired. §15 is explicit that an unproven control is not coverage.

The runner decision

The vitest kit cannot be adopted byte-identical: this repo's suite is node:test. Adding vitest for one file would be a second runner that only the kit uses. MichalAFerber/gh-office already made this call — same kit, same runner. The specimen is byte-identical; the test is the adapter.

file identity
test/fixtures/xss-lint-fixture.js sha256 ff94e2e464c960086ca47940a1300ef6171b35972c9ea190126fff59988cd4ed — matches tgwab-standards templates/xss-lint-fixture.js at origin/main
test/xss-lint-fixture.test.js node:test adapter (gh-office shape) plus the current kit's named-covers assertion
test/fixtures/xss-lint-covers.json src/exporters/html.js, src/core.js, src/common.js. Not build/build.mjs

The test script is load-bearing

origin/main pins "test": "node … --test test/pdf-vfs.test.js". Dropping the fixture files in without widening that glob leaves the control unexecuted — the exact failure mode this ticket exists to close. Measured:

  • old script: 4/4, xss tests never run
  • this head: 7/7 (the original 4 plus 3), lint clean
  • coverage line: the rule resolves for 9 of 9 linted files; 3 named as product source

Draft. DevOps marks ready; Michal merges.

The rule was wired; the specimen was not. A green lint run is not
evidence it fires. Vendor templates/xss-lint-fixture.js byte-identical
(sha256 ff94e2e4…). The test is the node:test adapter — this repo's
suite is node:test, and adding vitest for one file would be a second
runner that only the kit uses.

covers.json names src/exporters/html.js, src/core.js, src/common.js.
The test script pinned test/pdf-vfs.test.js; widening to test/*.test.js
is what makes the fixture a measurement rather than decoration.

Closes #3
@MichalAFerber
MichalAFerber marked this pull request as ready for review September 7, 2026 00:49
@MichalAFerber
MichalAFerber merged commit 4504ff2 into main Sep 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

§15 half-adopted: the XSS rule is wired but ships no fixture, so a green lint run is not evidence it fires

1 participant