Skip to content

ROX-35420: Decouple OCP plugin tests from CVE data - #21633

Merged
dvail merged 1 commit into
masterfrom
dv/ROX-35420-decouple-ocp-plugin-tests-from-data
Jul 13, 2026
Merged

dvail merged 1 commit into
masterfrom
dv/ROX-35420-decouple-ocp-plugin-tests-from-data

Conversation

@dvail

@dvail dvail commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Description

Removes reliance on actual Scanner data for OCP e2e tests. This is in response to increased flakes due to not all data being available by the time the tests run. More concretely - tests are failing due to looking for CVEs in stackrox namespace, when only one or two images have been scanned and have visible results.

Since none of the tests are checking behavior on actual CVE data, instead we mock the responses with fixtures like we recently did for the standalone app tests.

User-facing documentation

Testing and quality

  • the change is production ready: the change is GA, or otherwise the functionality is gated by a feature flag
  • CI results are inspected

Automated testing

  • added unit tests
  • added e2e tests
  • added regression tests
  • added compatibility tests
  • modified existing tests

How I validated my change

Faith in CI

@dvail

dvail commented Jul 8, 2026

Copy link
Copy Markdown
Contributor Author

This change is part of the following stack:

Change managed by git-spice.

@openshift-ci

openshift-ci Bot commented Jul 8, 2026

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@codecov

codecov Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 50.34%. Comparing base (8a7f4fa) to head (864fc7c).
⚠️ Report is 23 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #21633      +/-   ##
==========================================
- Coverage   50.38%   50.34%   -0.04%     
==========================================
  Files        2846     2846              
  Lines      218347   218351       +4     
==========================================
- Hits       110007   109928      -79     
- Misses     100356   100420      +64     
- Partials     7984     8003      +19     
Flag Coverage Δ
go-unit-tests 50.34% <ø> (-0.04%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

A new Cypress route matcher helper for GraphQL operations and a JSON fixture for image resources are added. The cveDetail and imageDetail Cypress test suites are refactored to intercept and assert on GraphQL requests/responses using route matcher maps instead of relying on extracted DOM text.

Changes

GraphQL Interception Migration

Layer / File(s) Summary
Route matcher helper and fixture
ui/apps/platform/cypress/integration-ocp/routes.ts, ui/apps/platform/cypress/fixtures/vulnerabilities/workloadCves/getImageResources.json
Adds getOcpRouteMatcherMapForGraphQL to build POST route matchers keyed by GraphQL operation name, and a new fixture with image/deployment GraphQL response data.
CVE detail test interception flow
ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts
Adds route maps/fixtures for CVE list/detail operations, replaces navigation helpers with interactAndWaitForResponses, and validates project filter header changes and table columns using intercepted requests instead of DOM text.
Image detail test interception flow
ui/apps/platform/cypress/integration-ocp/security/imageDetail.test.ts
Adds route maps/fixtures for image list, image detail, and CVE operations; introduces visitVulnerabilitiesPage/visitImageDetailPage helpers using interactAndWaitForResponses; validates Resources tab columns and namespace headers, and simplifies final assertions to h1 existence.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Test as Cypress Test
  participant CypressRuntime as Cypress
  participant GraphQLAPI as GraphQL Backend

  Test->>CypressRuntime: define route matcher map (getOcpRouteMatcherMapForGraphQL)
  Test->>CypressRuntime: interceptAndWatchRequests / interactAndWaitForResponses
  CypressRuntime->>GraphQLAPI: POST GraphQL operation (e.g. getImagesForCVE, getImageResources)
  GraphQLAPI-->>CypressRuntime: response with acsAuthNamespaceHeader
  CypressRuntime-->>Test: intercepted request/response data
  Test->>Test: assert header value and table column visibility
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and accurately summarizes the main change: decoupling OCP plugin tests from CVE data.
Description check ✅ Passed The description follows the required template and includes the change summary, docs, testing, and validation sections.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dv/ROX-35420-decouple-ocp-plugin-tests-from-data

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts (2)

74-79: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Repeated interception-unwrapping boilerplate.

const request = Array.isArray(interception) ? interception[0] : interception; is duplicated 4 times across this file and imageDetail.test.ts. Consider extracting a small helper (e.g., in helpers/request.js) to unwrap a single interception.

Also applies to: 97-104

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts` around
lines 74 - 79, The interception-unwrapping logic is duplicated in the Cypress
tests, so extract a small reusable helper to normalize the result from
waitForRequests into a single interception object. Add the helper in a shared
location such as helpers/request.js, then update cveDetail.test.ts and
imageDetail.test.ts to use it instead of repeating Array.isArray(interception) ?
interception[0] : interception in each test block.

8-46: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Shared route maps/fixtures/helper duplicated verbatim across test files.

cveListRouteMap, cveListFixtures, and visitVulnerabilitiesPage (Lines 15-46) are byte-for-byte identical to the definitions in imageDetail.test.ts (Lines 14-46). Since routes.ts already centralizes route-matcher logic, extracting these shared constants/helper into it (or a shared spec helper) would avoid drift when GraphQL operation names change.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts` around
lines 8 - 46, The shared cveListRouteMap, cveListFixtures, and
visitVulnerabilitiesPage definitions in cveDetail.test.ts are duplicated
verbatim elsewhere, so move these shared test helpers/constants into a common
location such as routes.ts or a shared spec helper and import them where needed.
Reuse the existing getOcpRouteMatcherMapForGraphQL and interceptRequests-based
setup so only one copy of the GraphQL operation names and fixture mappings
remains to prevent drift across cveDetail.test.ts and imageDetail.test.ts.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts`:
- Around line 74-79: The interception-unwrapping logic is duplicated in the
Cypress tests, so extract a small reusable helper to normalize the result from
waitForRequests into a single interception object. Add the helper in a shared
location such as helpers/request.js, then update cveDetail.test.ts and
imageDetail.test.ts to use it instead of repeating Array.isArray(interception) ?
interception[0] : interception in each test block.
- Around line 8-46: The shared cveListRouteMap, cveListFixtures, and
visitVulnerabilitiesPage definitions in cveDetail.test.ts are duplicated
verbatim elsewhere, so move these shared test helpers/constants into a common
location such as routes.ts or a shared spec helper and import them where needed.
Reuse the existing getOcpRouteMatcherMapForGraphQL and interceptRequests-based
setup so only one copy of the GraphQL operation names and fixture mappings
remains to prevent drift across cveDetail.test.ts and imageDetail.test.ts.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 19f95442-7879-4ec2-8e08-77aff320286f

📥 Commits

Reviewing files that changed from the base of the PR and between e2005f5 and 386a961.

📒 Files selected for processing (4)
  • ui/apps/platform/cypress/fixtures/vulnerabilities/workloadCves/getImageResources.json
  • ui/apps/platform/cypress/integration-ocp/routes.ts
  • ui/apps/platform/cypress/integration-ocp/security/cveDetail.test.ts
  • ui/apps/platform/cypress/integration-ocp/security/imageDetail.test.ts

@github-actions

github-actions Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Build Images Ready

Images are ready for commit f03b532. To use with deploy scripts:

export MAIN_IMAGE_TAG=4.12.x-478-gf03b532130

@dvail
dvail force-pushed the dv/ROX-35420-decouple-ocp-plugin-tests-from-data branch from 386a961 to d18d56b Compare July 9, 2026 19:26
@dvail

dvail commented Jul 9, 2026

Copy link
Copy Markdown
Contributor Author

/test ocp-4-21-ui-e2e-tests

Comment thread ui/apps/platform/cypress/integration-ocp/security/imageDetail.test.ts Outdated
@dvail
dvail force-pushed the dv/ROX-35420-decouple-ocp-plugin-tests-from-data branch from d18d56b to 864fc7c Compare July 10, 2026 20:27
@dvail

dvail commented Jul 10, 2026

Copy link
Copy Markdown
Contributor Author

/test ocp-4-21-ui-e2e-tests

@dvail
dvail marked this pull request as ready for review July 13, 2026 10:51
@dvail
dvail requested a review from a team as a code owner July 13, 2026 10:51

@alwayshooin alwayshooin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm just a few questions in the comments

Comment thread ui/apps/platform/cypress/integration-ocp/routes.ts
@dvail
dvail merged commit f03b532 into master Jul 13, 2026
179 of 202 checks passed
@dvail
dvail deleted the dv/ROX-35420-decouple-ocp-plugin-tests-from-data branch July 13, 2026 18:46
@dvail dvail added backport release-4.10 backport release-4.11 Create a PR to backport this PR to release-4.11 labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ui backport release-4.10 backport release-4.11 Create a PR to backport this PR to release-4.11

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants