Finding
/meow (src/issueComment/meow.ts) is the one issue_comment command the bundle end-to-end suite never runs. __tests__/bundle/bundle.test.ts drives /kind, /label, /assign, /close, /lgtm, /approve, /retest, /ok-to-test, /remove, /milestone, /hold, /auto-cc, /check-required-labels; the open hold-gated PRs cover /cc /uncc /unassign /retitle /lock /reopen (#238), /test and lgtm cancel (#240) and the cron jobs input (#242). Nothing spawns the committed dist/index.js with prow-commands: /meow.
That matters more for /meow than for the others: it is the only handler that calls out to a third-party origin from the runner (fetch('https://api.thecatapi.com/…') via the global fetch, with redirect: 'manual', AbortSignal.timeout, a 5xx retry loop, an x-api-key header from the cat-api-key input and a host allow-list on the returned url). Whether the ncc bundle preserves that behaviour — global fetch resolution, core.setSecret masking of the key, the "provider outage degrades to a note, only the GitHub write fails the action" contract — is exactly what a unit test with a mocked fetch cannot show.
Evidence
Recommendation
Add a bundle test that spawns dist/index.js on an issue_comment event with prow-commands: /meow against fakeGithub.ts plus a local stand-in for the cat api. The cat api url is hardcoded in meow.ts, so the child needs a preload (NODE_OPTIONS=--require) that rewrites only the https://api.thecatapi.com origin to the stub and leaves headers, redirect and signal untouched. Cases worth asserting end-to-end:
Priority
- Impact: medium — unit-covered; the only handler that reaches a third-party origin has no shipped-bundle evidence
- Effort: low
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: c48bd6d
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
Finding
/meow(src/issueComment/meow.ts) is the oneissue_commentcommand the bundle end-to-end suite never runs.__tests__/bundle/bundle.test.tsdrives/kind,/label,/assign,/close,/lgtm,/approve,/retest,/ok-to-test,/remove,/milestone,/hold,/auto-cc,/check-required-labels; the open hold-gated PRs cover/cc /uncc /unassign /retitle /lock /reopen(#238),/testand lgtm cancel (#240) and the cronjobsinput (#242). Nothing spawns the committeddist/index.jswithprow-commands: /meow.That matters more for
/meowthan for the others: it is the only handler that calls out to a third-party origin from the runner (fetch('https://api.thecatapi.com/…')via the globalfetch, withredirect: 'manual',AbortSignal.timeout, a 5xx retry loop, anx-api-keyheader from thecat-api-keyinput and a host allow-list on the returned url). Whether the ncc bundle preserves that behaviour — globalfetchresolution,core.setSecretmasking of the key, the "provider outage degrades to a note, only the GitHub write fails the action" contract — is exactly what a unit test with a mockedfetchcannot show.Evidence
npx vitest run --coverageonmain@ c48bd6d (Node v26.10.0,@vitest/coverage-v85.0.1):src/issueComment/meow.ts100 % stmts / 97.5 % branch / 100 % lines (__tests__/issueCommentTest/meow.test.ts,fetchmocked in-process).grep -n meow __tests__/bundle/*.ts→ no match onmain@ c48bd6d, and none of test(bundle): opt the node --check spawn out of NODE_V8_COVERAGE so the suite survives coverage.autoAttachSubprocess #236/test(bundle): drive /cc /uncc /unassign /retitle /lock /reopen through dist/index.js #238/test(bundle): drive /test and lgtm cancel (/lgtm cancel, /remove-lgtm) through dist/index.js #240/test(bundle): drive the push event and a blank jobs input through the cron dispatcher in dist/index.js #242 add one. The bundle suite's hits onsrc/are not captured in the coverage report ([quality] the bundle e2e suite's coverage of src/ is never captured — runBundle.ts drops NODE_V8_COVERAGE and dist/ has no source map #235), so this is established from the test inventory, not from a merged profile.Recommendation
Add a bundle test that spawns
dist/index.json anissue_commentevent withprow-commands: /meowagainstfakeGithub.tsplus a local stand-in for the cat api. The cat api url is hardcoded inmeow.ts, so the child needs a preload (NODE_OPTIONS=--require) that rewrites only thehttps://api.thecatapi.comorigin to the stub and leaves headers,redirectandsignaluntouched. Cases worth asserting end-to-end:/meowline postsas the only GitHub call (no authorization read, no post-command sweep)cat-api-keyreaches the provider asx-api-keyand is masked (::add-mask::) in the loghttp:url / foreign host / unparsable url all degrade toThe cat API is unavailable right now.with a::warning::, exit 0/meowin a fenced block,/meowvie,/meow please,can we /meowmake no request to either apiPriority
Filed by quality agent (hold-gated mode)
🐝 Hive Agent:
quality| Instance:hosted-available-lke648397-260827-5q9t| SHA:c48bd6d— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88