test: add NotApplicable aggregation regression tests - #819
Merged
yvonnedevlinrh merged 1 commit intoAug 24, 2026
Merged
yvonnedevlinrh merged 1 commit into
yvonnedevlinrh merged 1 commit into
Conversation
yvonnedevlinrh
force-pushed
the
chore/go-gemara-aggregation-tests
branch
from
August 18, 2026 16:34
ffd667c to
f8587ab
Compare
yvonnedevlinrh
requested review from
em-redhat and
trevor-vaughan
and removed request for
cdaniels255 and
sedonnel
August 20, 2026 13:04
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
yvonnedevlinrh
force-pushed
the
chore/go-gemara-aggregation-tests
branch
from
August 20, 2026 13:44
f8587ab to
ef8d084
Compare
em-redhat
approved these changes
Aug 20, 2026
em-redhat
left a comment
Contributor
There was a problem hiding this comment.
PR #819 Review: test: add NotApplicable aggregation regression tests
Verdict: APPROVE
Summary
This PR adds regression test coverage for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (pulled in via #813). The tests lock down the corrected NotApplicable semantics and fix a stale comment. CHANGELOG entries document the behavioral change and a CVE fix. Clean, focused, well-structured.
What Changed (3 files, +43/-3)
| File | Change |
|---|---|
CHANGELOG.md |
Added ### Fixed (NotApplicable aggregation) and ### Security (CVE-2026-50163) under ## Unreleased |
internal/output/evaluator_test.go |
2 new table-driven cases + 1 standalone multi-control test |
internal/output/scan_summary_test.go |
Fixed stale comment (was "aggregates to Passed", now "preserves NotApplicable") |
Convention Compliance
| Check | Status |
|---|---|
| TC-001 (success + edge cases) | PASS |
| TC-003 (meaningful assertions) | PASS |
| TC-006 (regression test for bug fix) | PASS |
| TC-007 (descriptive test names) | PASS |
| CR-001 (testify assert/require) | PASS |
| CR-002 (assert for non-fatal) | PASS |
| SPDX headers | PASS |
| Conventional Commits | PASS |
| Signed-off-by trailer | PASS |
| Spec requirement | N/A (test-only, exempt) |
Source Verification
Verified against vendored UpdateAggregateResult in go-gemara@v0.9.1 (vendor/github.com/gemaraproj/go-gemara/enums.go:994-1026). All three test scenarios match the actual switch logic:
NotApplicable + NotApplicable->NotApplicable(line 1025)Passed + NotApplicable->Passed(line 1022)NotRun-> returns previous unchanged (line 999)
CI
All 29 checks PASS (or NEUTRAL/SKIPPED). Zero failures.
Issues Found
None. No findings at any severity level.
Notes
- The
llm_assistedlabel andAssisted-by: OpenCodetrailer are appropriately present. - No website issue needed (test-only change, exempt per AGENTS.md).
- CHANGELOG entries are correctly placed and well-formatted.
trevor-vaughan
approved these changes
Aug 22, 2026
em-redhat
pushed a commit
to em-redhat/complyctl
that referenced
this pull request
Sep 1, 2026
Add regression test coverage and documentation for the UpdateAggregateResult behavioral change introduced in go-gemara v0.9.0 (merged via complytime#813, originally proposed in complytime#801). - New tests in evaluator_test.go: - All-skipped steps yields NotApplicable (was Passed pre-v0.9.0) - Mixed passed and skipped yields Passed (dominance preserved) - Multi-control all-skipped yields overall NotApplicable - Fix stale comment in scan_summary_test.go describing pre-v0.9.0 aggregation behavior - CHANGELOG entries for behavioral change and CVE-2026-50163 Assisted-by: OpenCode (claude-opus-4-6) Signed-off-by: Yvonne Devlin <ydevlin@redhat.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds regression test coverage and documentation for the
UpdateAggregateResultbehavioral change introduced ingo-gemara v0.9.0 (merged via #813, originally proposed in #801).
Changes
evaluator_test.go:NotApplicable(wasPassedpre-v0.9.0)Passed(dominance preserved)NotApplicablescan_summary_test.go:300-302Context
The go-gemara v0.9.0+
UpdateAggregateResultfix correctly returnsNotApplicableinstead ofPassedwhen all inputs areNotApplicable. This affectsevaluator.go:91,106andsarif.go:61. These tests lock down the new semantics toprevent silent regressions if upstream behavior changes again.