The "--fail-on via policy.json" block wrote a policy.json into a tmp root it never scanned and passed --fail-on on the CLI, so ci.failOn / ci.compact had no test at all. The rewrite scans a copy of grade-a-project as the process's own working tree (the only place policy.json is honored since v8.1.0): WARNING with 0 critical exits 1 by default, and exits 0 only if `ci.failOn: 'critical'` is read from the policy. Measured: each branch of main() mutated away turns exactly its own test red (fail 1), real code 4/4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| e2e | ||
| fixtures | ||
| golden | ||
| helpers | ||
| hooks | ||
| lib | ||
| scanners | ||
| av-surface.test.mjs | ||