Repository navigation
Complete the existing mutation gate with a real sandboxed Stryker.NET runner - #698
Merged
Merged
Conversation
Implements the real .NET mutation seam: StrykerMutationRunner invokes the pinned dotnet-stryker (4.16.0) inside the credential-free audit sandbox, selects owning production projects plus referencing test projects, scopes mutation to validated changed paths, and parses only the machine-readable JSON report. Scoped runs carry no overall score and never move the ratchet; baselines are digest-isolated per engine configuration. Default composition stays inert (NullMutationRunner, gate disabled). Validation: 132 unit tests plus real-tool integration proving the weak-fixture survivor and its death on strengthened tests; solution builds warnings-clean; gitleaks and semgrep (changed files) clean. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> CodeyBox-Prompt-Revision: 1 Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
Route every Stryker console/report-derived string through StrykerPaths.SanitizeForLog before it reaches exceptions, findings, or RawOutput; reject control characters in TryParseMutant and harden tool-version parsing to a strict token charset. Covers probe, discovery, no-report classification, console-tail provenance, survivor details, and auditor failure/enumeration paths. Adds regression tests for hostile mutators, console output, and survivor findings. CodeyBox-Prompt-Revision: 1 Co-Authored-By: CodeyBox <noreply@codeybox.invalid>
Reject any path segment starting with '-' in NormalizeRepoPath and validate every repo-derived Stryker option value at the argv sink, so attacker-influenceable file names can never desynchronize stryker flag parsing. Fail closed with a Tool-kind diagnostic. CodeyBox-Prompt-Revision: 1 Co-Authored-By: CodeyBox <noreply@codeybox.invalid> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated via CodeyBox — work item b2b898c967054c10ad0b9a12e09e21cb
Initiated by CodeyBox operator
Co-Authored-By: CodeyBox noreply@codeybox.invalid
🤖 Generated with CodeyBox