Skip to content

test(#4594): add threshold validation tests for scorecard constants - #4595

Open
fullsend-ai-coder[bot] wants to merge 1 commit into
mainfrom
agent/4594-threshold-validation-tests
Open

test(#4594): add threshold validation tests for scorecard constants#4595
fullsend-ai-coder[bot] wants to merge 1 commit into
mainfrom
agent/4594-threshold-validation-tests

Conversation

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor

Add unit tests that call validateThresholdNumberIntervals for each built-in ThresholdConfig to assert their correctness at test time, preventing invalid threshold definitions from breaking the scorecard plugin at startup.

Tests added for:

  • PERCENTAGE_THRESHOLDS (code-coverage)
  • DEPENDABOT_THRESHOLDS (dependabot)
  • OPENSSF_THRESHOLDS (openssf)
  • SONARQUBE_NUMBER_THRESHOLDS (sonarqube, all 11 metrics)
  • DEFAULT_NUMBER_THRESHOLDS (scorecard-common, in scorecard-node)

Export PERCENTAGE_THRESHOLDS from CodeCoverageMetricProvider.ts so the test file can import it directly. This is not re-exported from the package public API.


Closes #4594

Post-script verification

  • Branch is not main/master (agent/4594-threshold-validation-tests)
  • Secret scan passed (gitleaks — 9b57fa7595438dfd9f603e842d6d8fd4706498f5..HEAD)
  • Pre-commit hooks passed (authoritative run on runner)
  • Tests ran inside sandbox

Add unit tests that call validateThresholdNumberIntervals for each
built-in ThresholdConfig to assert their correctness at test time,
preventing invalid threshold definitions from breaking the scorecard
plugin at startup.

Tests added for:
- PERCENTAGE_THRESHOLDS (code-coverage)
- DEPENDABOT_THRESHOLDS (dependabot)
- OPENSSF_THRESHOLDS (openssf)
- SONARQUBE_NUMBER_THRESHOLDS (sonarqube, all 11 metrics)
- DEFAULT_NUMBER_THRESHOLDS (scorecard-common, in scorecard-node)

Export PERCENTAGE_THRESHOLDS from CodeCoverageMetricProvider.ts so
the test file can import it directly. This is not re-exported from
the package public API.

Closes #4594
@fullsend-ai-coder fullsend-ai-coder Bot added the ready-for-review Agent PR ready for human review label Sep 6, 2026
@rhdh-gh-app

rhdh-gh-app Bot commented Sep 6, 2026

Copy link
Copy Markdown

Missing Changesets

The following package(s) are changed by this PR but do not have a changeset:

  • @red-hat-developer-hub/backstage-plugin-scorecard-backend-module-code-coverage

See CONTRIBUTING.md for more information about how to add changesets.

Changed Packages

Package Name Package Path Changeset Bump Current Version
@red-hat-developer-hub/backstage-plugin-scorecard-backend-module-code-coverage workspaces/scorecard/plugins/scorecard-backend-module-code-coverage none v0.0.0

@sonarqubecloud

sonarqubecloud Bot commented Sep 6, 2026

Copy link
Copy Markdown

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 6, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:48 AM UTC · Completed 6:56 AM UTC

Commit: af58aa9 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Cost: $2.18

@codecov

codecov Bot commented Sep 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 62.38%. Comparing base (9b57fa7) to head (af58aa9).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4595   +/-   ##
=======================================
  Coverage   62.38%   62.38%           
=======================================
  Files        2607     2607           
  Lines      104756   104756           
  Branches    29438    29436    -2     
=======================================
  Hits        65347    65347           
  Misses      37580    37580           
  Partials     1829     1829           
Flag Coverage Δ *Carryforward flag
adoption-insights 84.77% <ø> (ø) Carriedforward from 9b57fa7
ai-integrations 78.80% <ø> (ø) Carriedforward from 9b57fa7
app-defaults 56.22% <ø> (ø) Carriedforward from 9b57fa7
augment 46.67% <ø> (ø) Carriedforward from 9b57fa7
boost 80.51% <ø> (ø) Carriedforward from 9b57fa7
bulk-import 73.12% <ø> (ø) Carriedforward from 9b57fa7
cost-management 13.35% <ø> (ø) Carriedforward from 9b57fa7
dcm 73.47% <ø> (ø) Carriedforward from 9b57fa7
e2e-adoption-insights 60.00% <ø> (ø) Carriedforward from 9b57fa7
e2e-extensions 62.31% <ø> (ø) Carriedforward from 9b57fa7
e2e-global-header 50.35% <ø> (ø) Carriedforward from 9b57fa7
e2e-homepage 61.11% <ø> (ø) Carriedforward from 9b57fa7
e2e-intelligent-assistant 47.04% <ø> (ø) Carriedforward from 9b57fa7
e2e-orchestrator 49.52% <ø> (ø) Carriedforward from 9b57fa7
e2e-orchestrator-plugin 49.51% <ø> (ø) Carriedforward from 9b57fa7
e2e-quickstart 55.21% <ø> (ø) Carriedforward from 9b57fa7
e2e-scorecard 50.21% <ø> (ø) Carriedforward from 9b57fa7
e2e-theme 16.36% <ø> (ø) Carriedforward from 9b57fa7
extensions 57.37% <ø> (ø) Carriedforward from 9b57fa7
global-floating-action-button 71.18% <ø> (ø) Carriedforward from 9b57fa7
global-header 68.09% <ø> (ø) Carriedforward from 9b57fa7
homepage 48.48% <ø> (ø) Carriedforward from 9b57fa7
install-dynamic-plugins 71.31% <ø> (ø) Carriedforward from 9b57fa7
intelligent-assistant 76.43% <ø> (ø) Carriedforward from 9b57fa7
konflux 91.98% <ø> (ø) Carriedforward from 9b57fa7
lightspeed 69.02% <ø> (ø) Carriedforward from 9b57fa7
mcp-integrations 84.14% <ø> (ø) Carriedforward from 9b57fa7
orchestrator 71.13% <ø> (ø) Carriedforward from 9b57fa7
quickstart 63.74% <ø> (ø) Carriedforward from 9b57fa7
sandbox 79.56% <ø> (ø) Carriedforward from 9b57fa7
scorecard 87.96% <100.00%> (ø)
theme 87.91% <ø> (ø) Carriedforward from 9b57fa7
translations 5.12% <ø> (ø) Carriedforward from 9b57fa7
x2a 77.10% <ø> (ø) Carriedforward from 9b57fa7

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 9b57fa7...af58aa9. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@fullsend-ai-review

Copy link
Copy Markdown

Review — ✅ Approve

PR: #4595test(#4594): add threshold validation tests for scorecard constants
Author: fullsend-ai-coder[bot]
Scope: workspaces/scorecard (6 files, +104 −1)

Summary

This PR adds unit tests that call validateThresholdNumberIntervals for each built-in ThresholdConfig constant, exactly matching the scope authorized by issue #4594. All five threshold configs are covered:

Constant Test location
PERCENTAGE_THRESHOLDS CodeCoverageConfig.test.ts (new)
DEPENDABOT_THRESHOLDS DependabotConfig.test.ts (new)
OPENSSF_THRESHOLDS OpenSSFConfig.test.ts (new)
SONARQUBE_NUMBER_THRESHOLDS SonarQubeConfig.test.ts (extended)
DEFAULT_NUMBER_THRESHOLDS validateThresholdNumberIntervals.test.ts (extended)

Review dimensions

Dimension Result
Correctness ✅ Tests call validateThresholdNumberIntervals(config.rules, 'number') with correct arguments matching the function signature (rules: ThresholdRule[], expectedMetricType: MetricType). No existing tests weakened or removed — all changes are purely additive.
Security ✅ No secrets, injection patterns, permission changes, or prompt injection detected. The constexport const change for PERCENTAGE_THRESHOLDS does not expand the public API surface (not re-exported from src/index.ts).
Intent & coherence ✅ PR matches issue #4594 authorization exactly. All 5 threshold configs listed in the issue are covered. No scope creep — every changed file directly serves the stated goal. The export change is justified: it was the only constant not already exported.
Style & conventions ✅ All new test files include the Apache 2.0 license header, follow *.test.ts naming, use standard describe/it structure, and match existing test patterns in the scorecard workspace.
Documentation ✅ No documentation updates needed — test-only change with no public API additions.
Cross-repo contracts ⏭ Skipped — the export change is internal to the package (not re-exported from the public API barrel).

Production change assessment

The sole production change (constexport const for PERCENTAGE_THRESHOLDS in CodeCoverageMetricProvider.ts) is safe:

  • No behavioral change at runtime
  • The symbol is consumed only by the new test file
  • The package's src/index.ts only exports scorecardModuleCodeCoveragePERCENTAGE_THRESHOLDS remains internal

No blocking findings. The change is well-scoped, correctly implemented, and safe to merge.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge ready-for-review Agent PR ready for human review workspace/scorecard

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scorecard: Assert correctness of threshold constants in unit tests

0 participants