• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

dennisdoomen / packageguard / 33877152327
81%

Build:
DEFAULT BRANCH: main
Ran 05 Sep 2026 07:57AM UTC
Jobs 1
Files 83
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

04 Sep 2026 01:16PM UTC coverage: 81.227% (+0.4%) from 80.815%
33877152327

push

github

web-flow
Add risk-report evidence detail and remove Security/Operational double-scoring (#251) (#252)

* Add richer risk-report evidence and remove Security/Operational double-scoring (#251)

- Add detail-list properties to PackageInfo (stale/abandoned/deprecated/
  unmaintained-critical/vulnerable transitive dependency names, versions,
  OSV IDs and release dates), populated by DependencyHealthCountEnricher
  and TransitiveVulnerabilityCountEnricher and rendered inline in risk
  rationale strings (capped at 8 items, 'and N more' beyond that).
- Reword the 'median vulnerability fix time' and 'verified publisher
  signal' rationale lines to explain what they measure.
- Remove genuine double-scoring of StaleTransitiveDependencyCount,
  AbandonedTransitiveDependencyCount and
  UnmaintainedCriticalTransitiveDependencyCount across the Security and
  Operational dimensions: each transitive-health signal is now scored in
  exactly one dimension (stale/deprecated -> Operational, vulnerability-
  driven abandoned/unmaintained-critical -> Security).
- Replace DependencyHealthCounts with DependencyHealthDetails to carry
  both counts and evidence lists.
- Update README.md risk-metrics section to reflect the dimension change
  and document the new evidence detail lines.
- Add/adjust unit tests covering dimension isolation, evidence rendering
  and truncation; validated against a real solution (fluentassertions/
  fluentassertions).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Move dependency detail lists to the Evidence section, not the rationale

The Security/Operational dimension cards (color cards) should only show
scoring rationale with counts; the specific package/vulnerability detail
lists belong in the separate Evidence section instead.

- Revert rationale strings in SecurityRiskEvaluator and
  PackageAdoptionRiskFactor back to plain counts.
- Append the detail-list suffixes to the corresponding Evidence entries in
  RiskHtmlReportWr... (continued)

1975 of 2710 branches covered (72.88%)

Branch coverage included in aggregate %.

118 of 123 new or added lines in 8 files covered. (95.93%)

1 existing line in 1 file now uncovered.

6302 of 7480 relevant lines covered (84.25%)

1707.14 hits per line

Uncovered Changes

Lines Coverage ∆ File
3
87.32
0.94% Src/PackageGuard.Core/Risk/Scoring/SecurityRiskEvaluator.cs
1
95.73
-3.12% Src/PackageGuard.Core/Risk/Enrichment/DependencyHealthCountEnricher.cs
1
69.97
4.11% Src/PackageGuard/RiskHtmlReportWriter.cs

Coverage Regressions

Lines Coverage ∆ File
1
87.32
0.94% Src/PackageGuard.Core/Risk/Scoring/SecurityRiskEvaluator.cs
Jobs
ID Job ID Ran Files Coverage
1 33877152327.1 05 Sep 2026 07:57AM UTC 83
81.23
GitHub Action Run
Source Files on build 33877152327
  • Tree
  • List 83
  • Changed 57
  • Source Changed 7
  • Coverage Changed 57
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #33877152327
  • 29c4f863 on github
  • Prev Build on main (#33750492826)
  • Next Build on main (#33962625979)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc