Skip to content

Restore handler test coverage for the token-rotation path #63

Description

Context

PR #62 skipped lambdas › token-rotator › completes without error (apps/token-rotator/src/main.spec.ts) because it is a live-API test wired to a dead fixture: the committed .env.test authenticated as GitHub App 217830 in the third-party skedrocket org, which no longer exists — the GitHub API returns "Integration not found" unconditionally, so the test failed 100% of the time on every branch (verified on Renovate branches predating that PR).

That skip leaves the entire GitHub-auth → registration-token → SSM-put path with zero test coverage (the only other specs are guard.spec.ts and stringHelpers.spec.ts; libs/github has none). No working coverage was lost, but this must not become permanent.

Restoration options

  1. Hermetic (preferred): mock the GitHub API (e.g. nock) so the handler test runs without live credentials — deterministic, no secrets.
  2. Live: recreate a dedicated test App under the cloudposse org and inject its ID/key via repo secrets (never a committed file).

Hygiene follow-up

.env.test committed the dead App's private key at the repo root; PR #62 replaces it with placeholders, but the key remains in git history — inert (the App is deleted), but worth removing per policy if history-rewrites are ever done.

Refs: #62

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions