You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Coverage Report] Test Coverage Report — 2026-10-06
#9506
Recommendation: Triage coverage for newly added features in these areas, as preview features are not yet production-ready.
🔎 Notable Findings
No security-critical path gaps detected — All core firewall components (docker-manager.ts, host-iptables.ts, squid-config.ts, domain-patterns.ts, cli.ts) maintain excellent coverage.
Preview feature coverage is secondary — The critical gaps are concentrated in new, feature-flagged subsystems (nvx, bounded-execution, microvm) that are intentionally in preview status.
Branch coverage dips in emerging modules — finite-disclosure.ts (11.42% branch) and cleanup-registry.ts (32.11% branch) indicate edge cases and error paths need test attention.
No regression detected — Overall project coverage remains stable at 91.31%; no previously-covered code has regressed.
🎯 Recommendations
High Priority
Expand test cases for src/nvx/cleanup-registry.ts (42.8% → 70%+)
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-06
Overall Coverage
Based on coverage metrics from the latest test run:
✅ Overall project coverage is strong at 91.31% statements, well above the 80% safety threshold for security-critical software.
🛡️ Security-Critical Path Status
Security-critical files (domain filtering, network isolation, container orchestration) all meet or exceed coverage targets:
All security-critical components are well-tested with strong coverage across statements, branches, and functions.
📋 Coverage Table
Files with coverage gaps (< 80% statements):
🔧 Function Audit
Coverage gap analysis by subsystem:
nvx/ (NVX runtime backend, preview feature):
cleanup-registry.ts— artifact registry cleanup with only 42.8% statement coveragecleanup-record.ts— individual record cleanup with low branch coveragebounded-execution/ (resource confinement module):
finite-cardinality.ts— cardinality bounds with 46% coveragefinite-disclosure.ts— disclosure bounds with 11.42% branch coveragefinite-schema.ts— schema validation with 57% coveragemicrovm/ (Cloud Hypervisor backend, preview):
network-reservation.ts— network namespace isolation with 51.5% coverage📅 Recent Source Changes (last 7 days)
The main branch has ongoing development in:
Recommendation: Triage coverage for newly added features in these areas, as preview features are not yet production-ready.
🔎 Notable Findings
docker-manager.ts,host-iptables.ts,squid-config.ts,domain-patterns.ts,cli.ts) maintain excellent coverage.finite-disclosure.ts(11.42% branch) andcleanup-registry.ts(32.11% branch) indicate edge cases and error paths need test attention.🎯 Recommendations
High Priority
src/nvx/cleanup-registry.ts(42.8% → 70%+)Medium Priority
src/bounded-execution/finite-disclosure.ts(11.42% → 50%+)Low Priority
src/microvm/network-reservation.ts(51.5% → 65%+)Generated: 2026-10-06 | Workflow: test-coverage-reporter | Coverage Tool: Jest + istanbuljs
All reactions