• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / integrity / 34294933689
91%
main: 91%

Build:
Build:
LAST BUILD BRANCH: test/plugin-test-unity-comment
DEFAULT BRANCH: main
Ran 09 Sep 2026 12:30AM UTC
Jobs 1
Files 15
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

09 Sep 2026 12:23AM UTC coverage: 90.628%. First build
34294933689

Pull #71

github

crazeydave
fix: stop WP_DEBUG switching off the HTTPS requirement

The transport check read

    get_option('integrity_require_https', true) && !is_ssl()
        && !(defined('WP_DEBUG') && WP_DEBUG)

so a debugging flag disabled a transport-security control. WP_DEBUG is
routinely left on for a staging site and not rarely on a live one while
something is being chased, and on any such install API keys travelled over
plain HTTP without complaint, with nothing in the admin saying so. The keys
are long-lived and permission-bearing.

INTEGRITY_ALLOW_INSECURE_TRANSPORT replaces it, matching the constants Reach
and Fellowship already carry for exactly this reasoning. Weakening the
control is now a deliberate edit to wp-config.php rather than a side effect
of turning debugging on.

The admin setting is untouched: integrity_require_https stays the supported
way for an administrator to make the decision on purpose. The constant is
the local-development hatch, deliberately kept off the settings screen so
nobody weakens transport security while clicking through options trying to
make a request work.

Anyone who was relying on WP_DEBUG to run Integrity over http locally needs
the new constant in wp-config.php. That is the point of the change rather
than a side effect of it, but it is a change to make on a laptop after
upgrading.

The WP_DEBUG regression is pinned by a test that defines it true and asserts
the request is still refused; both it and the constant's own test run in
separate processes, since define() is permanent and would otherwise leak
into everything that ran afterwards.
Pull Request #71: fix: stop WP_DEBUG switching off the HTTPS requirement

2698 of 2977 relevant lines covered (90.63%)

4.34 hits per line

Jobs
ID Job ID Ran Files Coverage
1 34294933689.1 09 Sep 2026 12:30AM UTC 15
90.63
GitHub Action Run
Source Files on build 34294933689
  • Tree
  • List 15
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #34294933689
  • Pull Request #71
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc