Hermex Output Review

Output Review

27 cases · 14 changed · 0 invariant breach(es)

Reference: 78a9e27 — reused from cache.

Changed

Case Status Proves
scan-human-default changed +0 −2 Baseline human output: the sections a repo gets with no output config of its own.
scan-human-all-sections changed +0 −2 Every human section rendered at once, including details and patterns, which the default config leaves off.
scan-json changed +3 −8 The full JSON contract: summary.patternCounts (#80), every owned package in packages[], de-duplicated components (#78, #79), and the compliance block (#55).
scan-json-toggles changed +3 −8 What output.* toggles do to –format json: today, nothing (#91). The payload below is emitted with every section switched off, yet still carries packages, components, versus and ruleViolations in full. Pair it with scan-human-minimal to see the two formats diverge; when #91 lands, this baseline shrinking is the proof.
comply-json changed +3 −8 The compliance block as machine-readable output on a failing repo.
comply-release-age changed +1 −1 The flagged-packages table, against a recorded registry: an overdue package with no in-window target (#26), one with a real target, and one merely coming due. rules['release-age'] names two of them at severity error, so the same three packages split across both severity tiers via the implicit ['**'] baseline for everything else — pair it with comply-release-age-unscoped, where the identical repo is checked with nothing enforced.
comply-release-age-unscoped changed +1 −1 An authored catch-all at severity warn (no package-specific error entry) enforces nothing, rather than enforcing everything: every installed package is still fetched and reported, every release-age row is advisory, and the exit code comes from rule violations alone. Includes moment — declared, installed, never imported — which release age never even looked up before #171. The only case covering the nothing-enforced path, which is the one path where #171 can move a verdict.
comply-all-rule-types changed +15 −2 Every one of the eleven rule types in one run, at three severities — the only case that renders max-file-size, require-engine-version, codeowners, both package-field shapes, and release-age together. release-age itself never gets a Rules-table row (its display is the Packages table) — that split is what this case pins.
comply-all-rule-types-json changed +126 −32 The machine-readable shape of every rule type: fieldPath and actualValue on package-field hits, maxSizeBytes/oversizeFile on max-file-size, installedRange/requiredRange on require-engine-version, matchedFile on codeowners, packageName/worstLevel/scope on release-age. Also where the #95 fix is visible — the two codeowners entries now differ by reason (‘unowned’ vs ‘wrong-owner’), not just matchedFile.
release-age-root-scope changed +1 −1 scope: root enforces only the direct copy, and still surfaces the overdue nested copy as an advisory breach rather than hiding it.
release-age-tree-scope changed +1 −1 scope: tree enforces every resolved copy, so the nested version becomes the mandatory failure and the reported installed version follows it.
lockfile-npm changed +0 −1 package-lock.json produces the same inventory as its siblings.
lockfile-yarn changed +0 −1 yarn.lock produces the same inventory as its siblings.
lockfile-pnpm changed +0 −1 pnpm-lock.yaml produces the same inventory as its siblings.

Unchanged (13)

Case Status Proves
scan-human-charts unchanged The bar-chart renderer: bar scaling and label alignment for packages, components and patterns.
scan-human-minimal unchanged Section toggles actually suppress output — every section off except the summary (#63).
comply-human-pass unchanged A repo that satisfies every rule: the clean verdict wording and exit 0.
comply-human-fail unchanged The rules table on a failing repo: row ordering, severity badges, the error/warning tally, and exit 1.
comply-human-warn-only unchanged Warn and info findings are reported but do not fail the build — verdict wording plus exit 0.
comply-summary-file unchanged The markdown a consumer pastes into a PR comment or job summary — ANSI-free, rules + flagged packages + verdict.
comply-summary-title unchanged –summary-title replaces the default heading, so a consumer embedding the markdown can name it after the policy rather than the tool.
comply-exit-2 unchanged A pipeline failure (nothing matched includes) exits 2, not 1 — a consumer must be able to tell “could not run” from “not compliant”.
scan-no-files unchanged The same pipeline failure under scan reports the problem and exits 0 — the deliberate asymmetry with comply-exit-2, kept visible so it cannot drift unnoticed.
comply-overrides unchanged Repo-scoped overrides re-scope severities: one rule downgraded to warn, one switched off and gone from the table.
parse-errors unchanged The parse-error report, scoped to a repo of nothing but an unparseable file so the block is not buried (#13).
comply-color unchanged The coloured path a developer actually sees in a terminal. Captured raw, so escape sequences are part of the diff.
comply-no-color-flag unchanged –no-color wins over FORCE_COLOR, so the CI-facing output carries no escape sequences even on a colour-capable runner.