Context
PR #62 skipped lambdas › token-rotator › completes without error (apps/token-rotator/src/main.spec.ts) because it is a live-API test wired to a dead fixture: the committed .env.test authenticated as GitHub App 217830 in the third-party skedrocket org, which no longer exists — the GitHub API returns "Integration not found" unconditionally, so the test failed 100% of the time on every branch (verified on Renovate branches predating that PR).
That skip leaves the entire GitHub-auth → registration-token → SSM-put path with zero test coverage (the only other specs are guard.spec.ts and stringHelpers.spec.ts; libs/github has none). No working coverage was lost, but this must not become permanent.
Restoration options
- Hermetic (preferred): mock the GitHub API (e.g.
nock) so the handler test runs without live credentials — deterministic, no secrets.
- Live: recreate a dedicated test App under the cloudposse org and inject its ID/key via repo secrets (never a committed file).
Hygiene follow-up
.env.test committed the dead App's private key at the repo root; PR #62 replaces it with placeholders, but the key remains in git history — inert (the App is deleted), but worth removing per policy if history-rewrites are ever done.
Refs: #62
Context
PR #62 skipped
lambdas › token-rotator › completes without error(apps/token-rotator/src/main.spec.ts) because it is a live-API test wired to a dead fixture: the committed.env.testauthenticated as GitHub App217830in the third-partyskedrocketorg, which no longer exists — the GitHub API returns "Integration not found" unconditionally, so the test failed 100% of the time on every branch (verified on Renovate branches predating that PR).That skip leaves the entire GitHub-auth → registration-token → SSM-put path with zero test coverage (the only other specs are
guard.spec.tsandstringHelpers.spec.ts;libs/githubhas none). No working coverage was lost, but this must not become permanent.Restoration options
nock) so the handler test runs without live credentials — deterministic, no secrets.Hygiene follow-up
.env.testcommitted the dead App's private key at the repo root; PR #62 replaces it with placeholders, but the key remains in git history — inert (the App is deleted), but worth removing per policy if history-rewrites are ever done.Refs: #62