Skip to content

fix(ci): security advisory + Playwright + 20 TEST artifacts + STPA update#71

Merged
avrabe merged 1 commit intomainfrom
feat/ci-fixes-test-coverage-stpa
Mar 22, 2026
Merged

fix(ci): security advisory + Playwright + 20 TEST artifacts + STPA update#71
avrabe merged 1 commit intomainfrom
feat/ci-fixes-test-coverage-stpa

Conversation

@avrabe
Copy link
Copy Markdown
Contributor

@avrabe avrabe commented Mar 22, 2026

  • rustls-webpki RUSTSEC-2026-0049 fix
  • Playwright strict mode violations from sr-only captions
  • 20 new TEST artifacts (19% → 44% FEAT coverage)
  • STPA hazards/constraints/UCAs/scenarios for LSP + WebView

479 artifacts, PASS. 🤖

… STPA update

CI fixes:
- rustls-webpki 0.103.9 → 0.103.10 (RUSTSEC-2026-0049 CRL matching)
- stpa.spec.ts: use getByRole("heading") to avoid sr-only caption clash
- aadl.spec.ts: handle contains + allocated-from links in ARCH-SYS-001

TEST coverage (19% → 44%):
- TEST-016 through TEST-035 covering dashboard, commits, cross-repo,
  conditional rules, impact, sphinx-needs, test scanner, build-system,
  salsa, CLI mutations, markdown, HTML export, CI, Playwright, LSP,
  Gherkin, AADL, STPA-Sec, SCORE

STPA update for v0.2.0 features:
- H-19 (LSP stale validation), H-20 (WebView postMessage)
- SC-21 (500ms re-validate SLA), SC-22 (WebView sandbox)
- UCA-C-26/27, CC-C-26/27, LS-L-4/5 for LSP + WebView
- SH-7 + SSC-7 (STPA-Sec: LSP non-project file injection)

479 artifacts, PASS, 0 warnings.

Fixes: FEAT-001
Refs: REQ-014

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@avrabe avrabe merged commit d468440 into main Mar 22, 2026
@avrabe avrabe deleted the feat/ci-fixes-test-coverage-stpa branch March 22, 2026 05:03
@codecov
Copy link
Copy Markdown

codecov Bot commented Mar 22, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Copy link
Copy Markdown

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Performance Alert ⚠️

Possible performance regression was detected for benchmark 'Rivet Criterion Benchmarks'.
Benchmark result of this commit is worse than the previous benchmark result exceeding threshold 1.20.

Benchmark suite Current: 52e5db8 Previous: 5ee0838 Ratio
store_lookup/100 2219 ns/iter (± 8) 1663 ns/iter (± 5) 1.33
store_lookup/1000 25968 ns/iter (± 185) 19376 ns/iter (± 108) 1.34
traceability_matrix/1000 59807 ns/iter (± 425) 40249 ns/iter (± 177) 1.49
query/100 773 ns/iter (± 2) 611 ns/iter (± 1) 1.27
query/1000 7262 ns/iter (± 75) 5135 ns/iter (± 50) 1.41

This comment was automatically generated by workflow using github-action-benchmark.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant