Skip to content

docs: describe WebKit security coverage accurately - #731

Open
2160039878-cyber wants to merge 1 commit into
libredb:mainfrom
2160039878-cyber:docs/playwright-browser-scope-669
Open

docs: describe WebKit security coverage accurately#731
2160039878-cyber wants to merge 1 commit into
libredb:mainfrom
2160039878-cyber:docs/playwright-browser-scope-669

Conversation

@2160039878-cyber

@2160039878-cyber 2160039878-cyber commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Description

Three README passages imply CI only runs Chromium. Correct all three to describe the Chromium suite and the WebKit security-headers spec, naming webkit-security and preserving the remaining real-device limitations.

Type of Change

  • Documentation update

Related Issue

Closes #669

Changes Made

Compared all three passages with playwright.config.ts and the CI browser-install step. The configuration still scopes webkit-security to security-headers.spec.ts; no broader WebKit coverage is claimed. bun run readme:check passed. Documentation only; no workflow or test configuration changes, and the issue explicitly excludes a new duplication guard.

Testing

  • Local: bun run readme:check passed.
  • Linux CI on the exact PR commit b4f571c: 14,713 tests passed, all 391 isolated core files and 34 component groups passed; 46324/46324 lines covered (100%). Ran the unfiltered bun run test:coverage and bun run coverage:check scripts.
  • The same run passed formatting, lint, typecheck, knip, README/chart/channel/security guards, application and library builds, Helm lint, and Node 24/26 engine smoke tests.
  • Playwright: 64 passed / 2 flaky (passed on retry) / 6 skipped under the existing configuration, plus 1 subpath, 1 PostgreSQL functional smoke, 3 tarball, and 3 npx tests passed.
  • Secret Scan passed after fetching all fork branch history, including this commit; no leaks found.

I did not complete bun run test / full coverage, the Helm checks, and E2E locally on Windows: the existing SQLite cleanup hits EBUSY, and Docker Desktop is unavailable. The unchanged upstream workflow ran the complete coverage/test layers and the other checks above on Linux instead. SonarCloud is the sole failed job in that fork run: access to the upstream project returns 401 / Not authorized or project not found. Upstream CI already skips SonarCloud for external fork PRs; no workflow or coverage gate was changed.

Test Environment

LibreDB Studio 0.15.0; Windows local / Ubuntu CI; Bun 1.4.2; Node 24 (plus Node 26 smoke); Chromium and WebKit; PostgreSQL functional smoke.

Checklist

  • Claimed the linked issue before editing; branch starts from main.
  • Reviewed the diff and followed the existing style.
  • Documentation only: the issue explicitly requires no new test.
  • All executable test/build jobs pass on the exact commit in Linux CI.

Additional Notes

AI-assisted implementation and validation using Codex, disclosed in the issue claim. Only documentation changes. No provider code changes, so the provider code/doc/test triad is not applicable. No dependent changes or screenshots are needed.

CI follow-up

The fork-run SonarCloud 401 is tracked in #732 and fixed by #733. The inherited condition admitted fork-owned pushes and fork-local PRs to the canonical SonarCloud project. The dedicated CI fix run now succeeds: all nine executable test/build jobs pass, and SonarCloud is scoped to the canonical repository. That run tests CI fix commit 80a318b; this PR's exact-head verification remains the original run linked above, whose nine executable jobs passed. Upstream Actions still await maintainer approval.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant