test-go — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited test-go (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Examples below use two placeholders. They are not literal - substitute the actual names from the project being worked on, matching the case of the surrounding context:
{PROJECT} - the project's identifier (e.g. env-var prefix, repo name). In env vars: MYAPP_…. In prose: MyApp or myapp.{integration} - an external system or adapter name (e.g. jira, stripe, claude). In paths: internal/tracker/jira/. In env vars: JIRA_…. In type names: JiraAdapter..go files in assets/ use concrete-looking sample names (Adapter, MYAPP_INTEGRATION_TEST, etc.) so the templates stay syntactically valid Go; comments inside each template tell you what to rename.
Before writing any test, determine which category it belongs to:
| Category | Characteristics | Run condition |
|---|---|---|
| Unit | Deterministic, no I/O, no network | Always (make test) |
| Unit with fixtures | Reads testdata/ files, uses t.TempDir() | Always |
| Unit with httptest | Spins up httptest.NewServer, tests HTTP adapters | Always |
| Integration | Talks to real external service | Env-gated by per-adapter variable: {PROJECT}_{INTEGRATION}_TEST=1 |
Pick the lightest category that validates the behavior.
Every test file in this project follows this skeleton. Internalize it - do not deviate.
package pkg // or pkg_test for black-box
import (
"testing"
// stdlib, then project imports, then third-party
)
// --- Test helpers (file-scoped, before test functions) ---
func helperName(t *testing.T, args ...) ReturnType {
t.Helper()
// setup or assertion logic
// use t.Cleanup() for teardown, never defer in helpers
}
// --- Tests ---
func TestFunctionName(t *testing.T) {
t.Parallel()
// ...
}Key rules this project enforces:
t.Helper() is the first statement in every helper - no exceptions.t.Cleanup() for teardown in helpers; defer only in test functions themselves.t.Parallel() at both test and subtest level for independent cases.t.TempDir() for filesystem isolation - never write to fixed paths.t.Setenv() for environment variable isolation in tests.errors.As() / errors.Is() - never string comparison.Use when multiple cases share identical execution logic. This is the dominant pattern in this project.
func TestSanitizeKey(t *testing.T) {
t.Parallel()
tests := []struct {
name string
input string
want string
wantErr bool
}{
{"simple key", "ABC-123", "ABC-123", false},
{"empty input", "", "", true},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
t.Parallel()
got, err := SanitizeKey(tt.input)
if tt.wantErr {
if err == nil {
t.Fatalf("SanitizeKey(%q) = %q, want error", tt.input, got)
}
return
}
if err != nil {
t.Fatalf("SanitizeKey(%q) unexpected error: %v", tt.input, err)
}
if got != tt.want {
t.Errorf("SanitizeKey(%q) = %q, want %q", tt.input, got, tt.want)
}
})
}
}When NOT to use tables: cases needing different setup, conditional mocking, or complex branching. Write separate t.Run blocks or separate test functions instead.
Table struct conventions:
name string as the first fieldwantErr bool for error presence; add wantKind field for typed error checkingFuncName(%v) = %v, want %vThis project uses custom typed errors extensively. Test error semantics, never strings.
// Domain error types: TrackerError, ConfigError, PathError, TemplateError
// Each has a Kind or Field for categorization
// Pattern: typed error assertion helper
func assertTrackerErrorKind(t *testing.T, err error, want domain.TrackerErrorKind) {
t.Helper()
if err == nil {
t.Fatalf("expected error with kind %q, got nil", want)
}
var te *domain.TrackerError
if !errors.As(err, &te) {
t.Fatalf("error type = %T, want *domain.TrackerError", err)
}
if te.Kind != want {
t.Errorf("TrackerError.Kind = %q, want %q", te.Kind, want)
}
}Error testing rules:
errors.As() for type assertion - validates the error chain, not just the toperrors.Is() for sentinel comparisonKind/Field/Op of typed errors, not .Error() stringst.Fatal when nil-error means subsequent assertions will panic; t.Error otherwiseHelpers belong at the top of the test file, before test functions. Each adapter package defines its own helpers - do not create a shared testutil package.
Common helper patterns in this project:
// Factory helper - creates a valid test subject or fails.
// Rename Adapter / NewAdapter to the concrete adapter type from your package.
// e.g. {Integration}Adapter / New{Integration}Adapter.
func mustAdapter(t *testing.T, config map[string]any) *Adapter {
t.Helper()
a, err := NewAdapter(config)
if err != nil {
t.Fatalf("NewAdapter: %v", err)
}
return a.(*Adapter)
}
// Fixture loader - reads testdata/ files
func loadFixture(t *testing.T, name string) []byte {
t.Helper()
data, err := os.ReadFile("testdata/" + name)
if err != nil {
t.Fatalf("reading fixture %s: %v", name, err)
}
return data
}
// Config builder - returns valid baseline config for modification
func validConfig(endpoint string) map[string]any {
return map[string]any{
"endpoint": endpoint,
"api_key": "[email protected]:api_token_123",
"project": "PROJ",
}
}
// Resource cleanup helper
func closeStore(t *testing.T, s *Store) {
t.Helper()
if err := s.Close(); err != nil {
t.Errorf("Close: %v", err)
}
}Naming conventions:
mustX - creates X or fatals (setup that cannot fail gracefully)validX / defaultX - returns baseline config/params for test customizationloadFixture - reads from testdata/assertX / requireX - assertion helpers (require fatals, assert errors)Adapter tests use httptest.NewServer with handler functions that return fixture data. Never mock the http.Client itself.
func TestFetchIssues(t *testing.T) {
t.Parallel()
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// Verify request details
if got := r.Header.Get("Authorization"); got == "" {
t.Error("missing Authorization header")
}
// Return fixture response
w.Header().Set("Content-Type", "application/json")
w.Write(loadFixture(t, "search_single_page.json"))
}))
defer srv.Close()
adapter := mustAdapter(t, validConfig(srv.URL))
issues, err := adapter.FetchIssuesByStates(context.Background(), []string{"To Do"})
if err != nil {
t.Fatalf("FetchIssuesByStates: %v", err)
}
// Assert on normalized domain objects, not raw JSON
}Rules for httptest usage:
testdata/ - do not inline large JSON stringsatomic counters when verifying call counts across concurrent requestsIntegration tests talk to real external services. They MUST be gated by environment variables and skip cleanly when disabled.
Read references/integration-tests.md for the full integration testing protocol including skip helpers, required env vars, and CI configuration.
Quick reference:
// Replace MYAPP with the project's env-var prefix and INTEGRATION
// with the adapter name (e.g. STRIPE, GITHUB).
func skipUnlessIntegration(t *testing.T) {
t.Helper()
if os.Getenv("MYAPP_INTEGRATION_TEST") != "1" {
t.Skip("skipping integration test: set MYAPP_INTEGRATION_TEST=1 to enable")
}
}integration_test.go (separate from unit tests)t.Skip, not silent pass - skipped tests are visible in outputEvery adapter (tracker or agent) must prove it satisfies the domain interface. Use compile-time interface checks and conformance test suites.
// Compile-time interface satisfaction - place in test file.
// Replace Adapter with the concrete adapter type from your package.
var _ domain.TrackerAdapter = (*Adapter)(nil)
var _ domain.AgentAdapter = (*mockAgentAdapter)(nil)What conformance tests must cover (per architecture Section 17):
This project uses three kinds of test doubles - pick the lightest one that works.
| Double | Purpose | Example |
|---|---|---|
| Stub | Returns fixed data | validConfig() returning a map |
| Fake | Simplified working implementation | internal/agent/mock package, internal/tracker/file adapter |
| Spy | Records interactions for later assertion | httptest handler with atomic counters |
Registered fakes (when this project provides them, e.g. internal/agent/mock/, internal/tracker/file/) are first-class adapters in the registry. Use them for orchestrator-level tests that need controllable adapter behavior - check the project layout for the actual package paths.
Mock struct pattern:
type mockTrackerAdapter struct{}
var _ domain.TrackerAdapter = (*mockTrackerAdapter)(nil)
func (m *mockTrackerAdapter) FetchIssuesByStates(ctx context.Context, states []string) ([]domain.Issue, error) {
return nil, nil
}
// ... implement all interface methodsStore test data in testdata/ within the package directory. Go tooling ignores this directory during builds.
internal/tracker/{integration}/testdata/
search_single_page.json
search_multi_page_1.json
search_multi_page_2.json
issue_detail.json
comments.jsonRules:
testdata/ directory per package that needs fixturessearch_empty.json, malformed.json, comments_multi_page_1.jsonloadFixture(t, name) helper - never hardcode paths in test functionsEvery assertion must produce a message diagnosable without reading the test source.
Format: FuncName(inputs) = got, want expected// Correct - includes function, input, got, want
t.Errorf("SanitizeKey(%q) = %q, want %q", tt.input, got, tt.want)
t.Errorf("TrackerError.Kind = %q, want %q", te.Kind, want)
// Incorrect - missing context
t.Errorf("got %q, want %q", got, tt.want)
t.Error("wrong result")got before want in message ordering%q for strings (shows quotes and escapes), %v for general values%d for integers, %f for floats - match the typeAfter writing or modifying tests, verify:
make test passes with -race (the default)t.Parallel() where appropriatet.Helper() as first statementerrors.As() / errors.Is(), not string comparisoncmp.Diff if needed)testdata/ and are loaded via helpert.TempDir() used for any filesystem operations~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.