Skip to content

Testing and Security

Thomas Maerz edited this page Oct 4, 2026 · 1 revision

Testing and Security

Automated evidence

The repository test suite covers:

  • workspace parsing, validation, and secret handling;
  • Slackdump command planning, retries, failures, and redaction;
  • global lock contention and timeout behavior;
  • SQLite backup snapshots;
  • canonical schema, upserts, continuity, and validation;
  • attachment reconciliation;
  • compaction equivalence and checkpoint rebasing;
  • Prometheus exposition and Pushgateway requests;
  • Dagster assets, checks, jobs, schedules, sensors, and concurrency;
  • Compose and deployment contracts.

Run:

uv sync --all-extras
uv run pytest -q

Secret boundaries

Never publish:

  • Slack tokens or cookies;
  • exported messages or channel inventories;
  • raw SQLite archives, attachments, or canonical DuckDB files;
  • Dagster/PostgreSQL credentials;
  • private topology, host paths, or operational run identifiers.

Subprocess output is redacted, but operators should still avoid attaching raw logs to public issues without review.

Threat model

Slackpipe assumes the host and configured secret/storage mounts are trusted. It does not turn Dagster or Pushgateway into internet-safe public services. Network authentication and TLS belong at the deployment boundary.

Evidence boundary

Tests establish structural, transactional, and operational behavior. They do not prove Slack API completeness, continued access to deleted/retained content, or the correctness of credentials supplied by an operator.

Clone this wiki locally