test(backend): cover malformed remediation payload guardrails (#2157) - #2460
Open
Srv99x wants to merge 1 commit into
Open
test(backend): cover malformed remediation payload guardrails (#2157)#2460Srv99x wants to merge 1 commit into
Srv99x wants to merge 1 commit into
Conversation
Author
|
@utksh1 The This PR only modifies backend Python files:
The failure is caused by a pre-existing high-severity npm vulnerability in |
utksh1
approved these changes
Aug 6, 2026
utksh1
left a comment
Owner
There was a problem hiding this comment.
Good defensive guards for malformed remediation payloads. Test coverage looks solid. Backend-only change; frontend failures unrelated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #2157.
Adds a focused regression test suite that exercises every public entry point in
backend/secuscan/remediation.pyagainst malformed and structurally brokeninputs. The tests verify that the safety layer always returns a controlled,
predictable result — never an unhandled exception.
What changed
testing/backend/unit/test_remediation_malformed_payload.py(new)backend/secuscan/remediation.py(patched)Four defensive guardrails added (real bugs exposed by the tests):
parse_remediation_suggestionTypeErroron non-string inputisinstanceguard → returnsNonevalidate_remediationKeyError: 'specifier'on bad graph entryparse_package_lockAttributeErrorwhen JSON root is a listif not isinstance(data, dict): return {}parse_package_lockAttributeErrorwhenpackagesis a stringif not isinstance(packages, dict): packages = {}Acceptance criteria
_assert_controlled_resulthelper)test_remediation_safety.pytests still passTest run
🤖 AI Disclosure
This pull request was developed with the assistance of Antigravity (Google DeepMind), an AI coding assistant.
The AI was used to:
remediation.pyand the existing test file to map the full API surfacetest_remediation_malformed_payload.py)remediation.pyfrom test failures and apply minimal defensive patchesblackandisortformatting on both modified filesAll code was reviewed, verified correct, and confirmed passing locally before this PR was opened.