-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmutation-guards.json
More file actions
76 lines (76 loc) · 7.55 KB
/
Copy pathmutation-guards.json
File metadata and controls
76 lines (76 loc) · 7.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
{
"not-mutated": [
{
"path": "packages/wiki-write-core/src/frontmatter.ts",
"reason": "Throws on missing/invalid frontmatter, but no gate consumes it: wiki-ingest.ts implements its own local parseFrontmatterDocument/renderFrontmatterDocument instead of importing this module. Only wiki-write-core.test.ts exercises reconstructFrontmatter, and only its happy path."
},
{
"path": "packages/wiki-write-core/src/rendering-policy.ts",
"reason": "validateRenderingPolicy returns unsafe-html findings but no production gate consumes it (only wiki-write-core.test.ts calls it directly). maskCodeContent/maskNonProseContent, the functions the corrections-survival.ts gate does call, are pure content transforms with no rejection path of their own."
},
{
"path": "packages/wiki-write-core/src/wiki-utils.ts",
"reason": "splitFrontmatter's error field is the only rejection-shaped output here, and its sole consumer is wiki-lint.ts, itself not-mutated pending relocation. collectWikiPages/collectWikilinks, consumed by the mutated corrections-survival.ts and wiki-ingest.ts, are non-rejecting collection helpers."
},
{
"path": "packages/wiki-write-core/src/markdown-links.ts",
"reason": "resolveMarkdownLinks' exists signal is consumed only by wiki-lint.ts, itself not-mutated pending relocation; no mutated module reaches this file."
},
{
"path": "packages/wiki-write-core/src/index.ts",
"reason": "Pure re-export barrel with no logic of its own. The core logic lives in the modules it re-exports (corrections.ts, frontmatter.ts, gate-contract.ts, private-leak-adapter.ts, private-leak.ts, rendering-policy.ts, wiki-ingest.ts, wiki-lint.ts), each separately dispositioned in this list or stryker.config.json's mutate set."
},
{
"path": "packages/wiki-write-core/src/gate-contract.ts",
"reason": "Build-time constants only (version + source-tree hash placeholder), no logic to mutate. The module that carries the real check is scripts/build-wiki-write-core.ts (already in mutate), which populates and verifies GATE_SOURCE_TREE_HASH."
},
{
"path": "packages/wiki-write-core/src/wiki-lint.ts",
"reason": "Its real tests are scripts/wiki-lint.test.ts, reaching it through the built dist/ output rather than a same-tree source import. Relocating those tests beside this module flips this entry to mutate."
},
{
"path": "packages/wiki-write-core/src/wiki-ingest.ts",
"reason": "Has a real rejection path (WikiIngestError on INVALID_PAYLOAD/INVALID_FRONTMATTER/INVALID_WIKILINK/CORRECTION_ERODED/PROTECTED_BRANCH) a gate depends on, but its real test is scripts/wiki-ingest.test.ts, which imports the built dist/ output through the scripts/wiki-ingest.ts re-export shell (`export * from '@fro-bot/wiki-write-core/wiki-ingest'`) rather than this source file. A live check:mutation-guards run confirmed 1474/1474 mutants NoCoverage under same-tree pairing. Relocating scripts/wiki-ingest.test.ts beside this module flips this entry to mutate."
},
{
"path": "packages/wiki-write-core/src/wiki-slug.ts",
"reason": "Has a real rejection path (computeRepoSlug throws on an empty sanitized segment) a gate depends on, but its real test is scripts/wiki-slug.test.ts, which imports the built dist/ output through the scripts/wiki-slug.ts re-export shell (`export * from '@fro-bot/wiki-write-core/wiki-slug'`) rather than this source file. A live check:mutation-guards run confirmed only partial coverage attributable to private-leak-adapter.test.ts's direct import, not this dedicated test. Relocating scripts/wiki-slug.test.ts beside this module flips this entry to mutate."
},
{
"path": "packages/wiki-write-core/src/schemas.ts",
"reason": "Has a real rejection path (assertReposFile throws SchemaValidationError) a gate depends on, but its real test is scripts/schemas.test.ts, which imports the built dist/ output through the scripts/schemas.ts re-export shell (`export * from '@fro-bot/wiki-write-core/schemas'`) rather than this source file. A live check:mutation-guards run confirmed only partial coverage attributable to private-leak-adapter.test.ts's indirect exercise of assertReposFile. Relocating scripts/schemas.test.ts beside this module flips this entry to mutate."
},
{
"path": "packages/wiki-write-core/src/correction-text.ts",
"reason": "Pure normalization helper (whitespace collapse) with no rejection path of its own; consumed by the already-mutated corrections-survival.ts gate."
},
{
"path": "packages/wiki-write-core/src/data-branch-bootstrap.ts",
"reason": "GitHub API infra-recovery helper (branch existence check/restore). Its throw paths are network/API failure handling, not content-validation logic a gate depends on."
},
{
"path": "scripts/check-mutation-guards.ts",
"reason": "A directive scanner cannot describe its own grammar in comments without matching it; the classifier and scanner are covered by their fixture tests, not by mutation."
},
{
"path": "packages/wiki-write-core/src/private-leak-adapter.ts",
"reason": "Exported request-time GitHub adapter with no current CI or autonomous-write caller in this repository; only its dedicated tests and the package barrel reference it. Active privacy workflows use scripts/check-private-leak.ts and private-leak.ts directly. Re-promote when a production caller lands. Its test stays in stryker.config.json testFiles regardless: it is private-leak.ts's only same-tree source exerciser (scripts/check-private-leak.ts imports the dist specifier), so mutate=9/testFiles=10 is intentional."
},
{
"path": "scripts/check-repo-onboarded.ts",
"reason": "Survey routing predicate, not an independent write or promotion authority. runCheck fails closed (onboarded:false) on every error path -- missing env, ENOENT, malformed YAML, and schema failure all resolve to false, never true. The deciding predicate, publicRepoEntryExists in scripts/repos-metadata.ts, is not itself in the mutated set, so mutating this wrapper would not exercise the real decision."
},
{
"path": "scripts/check-md-links.ts",
"reason": "Documentation-quality lint for broken relative links. It does not protect a security boundary, autonomous write, persisted trust state, or generated executable artifact; its behavior is adequately covered by conventional tests."
},
{
"path": "scripts/check-solutions-examples.ts",
"reason": "Documentation-quality lint for docs/solutions code examples (parse validity, opt-in symbol/arity checks). It does not protect a security boundary, autonomous write, persisted trust state, or generated executable artifact; its behavior is adequately covered by conventional tests. Whether it belongs in stryker.config.json's mutate set is a separate materiality decision, deliberately left open here."
},
{
"path": "scripts/check-override-floors.ts",
"reason": "Supply-chain lint verifying pnpm-workspace.yaml override floors sit at or above their advisory's patched_versions (see PR #3871). It is a real security-relevant gate, but its rejection paths (fail-closed on unparseable audit output, unparseable ranges, unrecognized severities, and every missing/below-floor case) are enumerated and asserted directly in scripts/check-override-floors.test.ts, including a regression fixture reproducing PR #3871's own pre-fix floors. Whether it belongs in stryker.config.json's mutate set is a separate materiality decision, deliberately left open here, matching scripts/check-solutions-examples.ts's precedent."
}
]
}