Hermex Output Review

Output Review

28 cases · 1 changed · 0 invariant breach(es)

Reference: ec7ba75 — reused from cache.

Changed

Case Status Proves
comply-all-rule-types-json changed +2 −2 The machine-readable shape of every rule type: fieldPath and actualValue on package-field hits, maxSizeBytes/oversizeFile on max-file-size, installedRange/requiredRange on require-engine-version, matchedFile on codeowners, packageName/worstLevel/scope on release-age. Also where the #95 fix is visible — the two codeowners entries now differ by reason (‘unowned’ vs ‘wrong-owner’), not just matchedFile.

Unchanged (27)

Case Status Proves
scan-human-default unchanged Baseline human output: the sections a repo gets with no output config of its own. Includes both Versus groups — a component pair and a function-only one — which is where #174 is visible: the function-only group reports a real split off files-that-import, where it used to read 0 vs 0 off JSX renders, and the package named by no lockfile entry says so instead of reporting a confident 0%.
scan-human-all-sections unchanged Every human section rendered at once, including details and patterns, which the default config leaves off.
scan-human-charts unchanged The bar-chart renderer: bar scaling and label alignment for packages, components and patterns.
scan-human-minimal unchanged Section toggles actually suppress output — every section off except the summary (#63).
scan-json unchanged The full JSON contract: summary.patternCounts (#80), every owned package in packages[], de-duplicated components (#78, #79), and the compliance block (#55). Also the imported axis (#174): packages[].importingFileCount beside usageCount — lodash and es-toolkit read non-zero on the first and 0 on the second — and versus[].count keyed on it, with present:false marking a configured package the repo does not have.
scan-json-toggles unchanged What output.* toggles do to –format json: today, nothing (#91). The payload below is emitted with every section switched off, yet still carries packages, components, versus and ruleViolations in full. Pair it with scan-human-minimal to see the two formats diverge; when #91 lands, this baseline shrinking is the proof.
comply-human-pass unchanged A repo that satisfies every rule: the clean verdict wording and exit 0.
comply-human-fail unchanged The rules table on a failing repo: row ordering, severity badges, the error/warning tally, and exit 1.
comply-human-warn-only unchanged Warn and info findings are reported but do not fail the build — verdict wording plus exit 0.
comply-json unchanged The compliance block as machine-readable output on a failing repo.
comply-summary-file unchanged The markdown a consumer pastes into a PR comment or job summary — ANSI-free, rules + flagged packages + verdict.
comply-release-age unchanged The flagged-packages table, against a recorded registry: an overdue package with no in-window target (#26), one with a real target, and one merely coming due. rules['release-age'] names two of them at severity error, so the same three packages split across both severity tiers via the implicit ['**'] baseline for everything else — pair it with comply-release-age-unscoped, where the identical repo is checked with nothing enforced.
comply-release-age-unscoped unchanged An authored catch-all at severity warn (no package-specific error entry) enforces nothing, rather than enforcing everything: every installed package is still fetched and reported, every release-age row is advisory, and the exit code comes from rule violations alone. Includes moment — declared, installed, never imported — which release age never even looked up before #171. The only case covering the nothing-enforced path, which is the one path where #171 can move a verdict.
comply-deprecated-packages unchanged Deprecation detection with release-age switched off entirely — the #107 case. Before, deprecation was a by-product of release-age enrichment, so this configuration found nothing at all and this run would have been silently compliant on that axis. Now the registry is consulted for deprecation alone: a no-deprecated-packages row appears in the Rules table carrying npm own notice, and at severity error it fails comply on its own. The only case where the registry is reached without release-age, which is exactly the path that did not exist before.
comply-all-rule-types unchanged Every one of the twelve rule types in one run, at three severities — the only case that renders max-file-size, require-engine-version, codeowners, both package-field shapes, release-age and no-deprecated-packages together. release-age itself never gets a Rules-table row (its display is the Packages table) — that split is what this case pins, along with the only multi-badge Status cell in the fixtures (moment is both forbidden and deprecated).
comply-summary-title unchanged –summary-title replaces the default heading, so a consumer embedding the markdown can name it after the policy rather than the tool.
comply-exit-2 unchanged A pipeline failure (nothing matched includes) exits 2, not 1 — a consumer must be able to tell “could not run” from “not compliant”.
scan-no-files unchanged The same pipeline failure under scan reports the problem and exits 0 — the deliberate asymmetry with comply-exit-2, kept visible so it cannot drift unnoticed.
release-age-root-scope unchanged scope: root enforces only the direct copy, and still surfaces the overdue nested copy as an advisory breach rather than hiding it.
release-age-tree-scope unchanged scope: tree enforces every resolved copy, so the nested version becomes the mandatory failure and the reported installed version follows it.
comply-overrides unchanged Repo-scoped overrides re-scope severities: one rule downgraded to warn, one switched off and gone from the table.
lockfile-npm unchanged package-lock.json produces the same inventory as its siblings.
lockfile-yarn unchanged yarn.lock produces the same inventory as its siblings.
lockfile-pnpm unchanged pnpm-lock.yaml produces the same inventory as its siblings.
parse-errors unchanged The parse-error report, scoped to a repo of nothing but an unparseable file so the block is not buried (#13).
comply-color unchanged The coloured path a developer actually sees in a terminal. Captured raw, so escape sequences are part of the diff.
comply-no-color-flag unchanged –no-color wins over FORCE_COLOR, so the CI-facing output carries no escape sequences even on a colour-capable runner.