Hermex Output Review

Output Review

27 cases · 3 changed · 0 invariant breach(es)

Changed

Case Status Proves
comply-release-age-unscoped changed +14 −14 An empty enforceOn names no mandatory packages and so enforces none, rather than enforcing everything: every installed package is still fetched and reported, every release-age row is advisory, and the exit code comes from rule violations alone. Includes moment — declared, installed, never imported — which release age never even looked up before #171. The only case covering the empty-enforceOn path, which is the one path where #171 can move a verdict.
release-age-root-scope changed +7 −7 scope: root enforces only the direct copy, and still surfaces the overdue nested copy as an advisory breach rather than hiding it.
release-age-tree-scope changed +7 −7 scope: tree enforces every resolved copy, so the nested version becomes the mandatory failure and the reported installed version follows it.

All cases

Case Status Proves
scan-human-default unchanged Baseline human output: the sections a repo gets with no output config of its own.
scan-human-all-sections unchanged Every human section rendered at once, including details and patterns, which the default config leaves off.
scan-human-charts unchanged The bar-chart renderer: bar scaling and label alignment for packages, components and patterns.
scan-human-minimal unchanged Section toggles actually suppress output — every section off except the summary (#63).
scan-json unchanged The full JSON contract: summary.patternCounts (#80), every owned package in packages[], de-duplicated components (#78, #79), and the compliance block (#55).
scan-json-toggles unchanged What output.* toggles do to –format json: today, nothing (#91). The payload below is emitted with every section switched off, yet still carries packages, components, versus and ruleViolations in full. Pair it with scan-human-minimal to see the two formats diverge; when #91 lands, this baseline shrinking is the proof.
comply-human-pass unchanged A repo that satisfies every rule: the clean verdict wording and exit 0.
comply-human-fail unchanged The rules table on a failing repo: row ordering, severity badges, the error/warning tally, and exit 1.
comply-human-warn-only unchanged Warn and info findings are reported but do not fail the build — verdict wording plus exit 0.
comply-json unchanged The compliance block as machine-readable output on a failing repo.
comply-summary-file unchanged The markdown a consumer pastes into a PR comment or job summary — ANSI-free, rules + flagged packages + verdict.
comply-release-age unchanged The flagged-packages table, against a recorded registry: an overdue package with no in-window target (#26), one with a real target, and one merely coming due. enforceOn names two of them, so the same three packages split across both severity tiers — pair it with comply-release-age-unscoped, where the identical repo is checked with nothing enforced.
comply-release-age-unscoped changed +14 −14 An empty enforceOn names no mandatory packages and so enforces none, rather than enforcing everything: every installed package is still fetched and reported, every release-age row is advisory, and the exit code comes from rule violations alone. Includes moment — declared, installed, never imported — which release age never even looked up before #171. The only case covering the empty-enforceOn path, which is the one path where #171 can move a verdict.
comply-all-rule-types unchanged Every one of the nine rule types in one table, at three severities — the only case that renders require-engine-version, codeowners and both package-field shapes.
comply-all-rule-types-json unchanged The machine-readable shape of every rule type: fieldPath and actualValue on package-field hits, installedRange/requiredRange on require-engine-version, matchedFiles on codeowners. Also where #95 is visible — the two codeowners entries are byte-identical apart from matchedFiles.
comply-summary-title unchanged –summary-title replaces the default heading, so a consumer embedding the markdown can name it after the policy rather than the tool.
comply-exit-2 unchanged A pipeline failure (nothing matched includes) exits 2, not 1 — a consumer must be able to tell “could not run” from “not compliant”.
scan-no-files unchanged The same pipeline failure under scan reports the problem and exits 0 — the deliberate asymmetry with comply-exit-2, kept visible so it cannot drift unnoticed.
release-age-root-scope changed +7 −7 scope: root enforces only the direct copy, and still surfaces the overdue nested copy as an advisory breach rather than hiding it.
release-age-tree-scope changed +7 −7 scope: tree enforces every resolved copy, so the nested version becomes the mandatory failure and the reported installed version follows it.
comply-overrides unchanged Repo-scoped overrides re-scope severities: one rule downgraded to warn, one switched off and gone from the table.
lockfile-npm unchanged package-lock.json produces the same inventory as its siblings.
lockfile-yarn unchanged yarn.lock produces the same inventory as its siblings.
lockfile-pnpm unchanged pnpm-lock.yaml produces the same inventory as its siblings.
parse-errors unchanged The parse-error report, scoped to a repo of nothing but an unparseable file so the block is not buried (#13).
comply-color unchanged The coloured path a developer actually sees in a terminal. Captured raw, so escape sequences are part of the diff.
comply-no-color-flag unchanged –no-color wins over FORCE_COLOR, so the CI-facing output carries no escape sequences even on a colour-capable runner.