🌱 e2e/fuzz: Account for Scorecard API repo migration - #5253
Merged
justaugustus merged 1 commit intoSep 28, 2026
Merged
Conversation
The e2e Fuzzing check test against ossf/scorecard-webapp expected 3 info messages (1 for OSS-Fuzz integration, 2 for native Go fuzz functions). The native fuzz functions (FuzzVerifyWorkflow, FuzzExtractCertInfo) have since moved to ossf/scorecard-infra, so the check now correctly reports only the OSS-Fuzz integration signal. Note: OSS-Fuzz's status.json does not yet track ossf/scorecard-infra as a project (see google/oss-fuzz#16140, unmerged), so this expected value may need to change again once that lands. Assisted-by: LLM Signed-off-by: Stephen Augustus <foo@auggie.dev>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #5253 +/- ##
==========================================
+ Coverage 66.80% 75.52% +8.72%
==========================================
Files 230 252 +22
Lines 16602 13967 -2635
==========================================
- Hits 11091 10549 -542
+ Misses 4808 3417 -1391
+ Partials 703 1 -702 🚀 New features to boost your workflow:
|
justaugustus
marked this pull request as ready for review
September 28, 2026 02:15
justaugustus
requested review from
spencerschrock
and removed request for
a team
September 28, 2026 02:15
justaugustus
enabled auto-merge (squash)
September 28, 2026 02:15
jeffmendoza
approved these changes
Sep 28, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce?
test fix
What is the current behavior?
The e2e Fuzzing check test against
ossf/scorecard-webappexpects 3 infomessages (1 for OSS-Fuzz integration, 2 for native Go fuzz functions). The
native fuzz functions (
FuzzVerifyWorkflow,FuzzExtractCertInfo) have sincemoved to
ossf/scorecard-infra, so the check now correctly returns only 1info message, and the e2e test fails (e.g. #5231's
integration-trustedjob).What is the new behavior (if this is a feature change)?
The expected info count is corrected to 1, similar to the fix in #5159.
Which issue(s) this PR fixes
NONE
Special notes for your reviewer
OSS-Fuzz's
status.jsonstill tracksossf/scorecard-webappas themain_repofor itsscorecard-webproject, so the OSS-Fuzz integrationsignal (1) is still accurate today. There's an open, unmerged
google/oss-fuzz#16140 that
repoints that project to
ossf/scorecard-infra; once it merges, thisexpectation will likely need a follow-up change.
Does this PR introduce a user-facing change?
For user-facing changes, please add a concise, human-readable release note to
the
release-note(In particular, describe what changes users might need to make in their
application as a result of this pull request.)