← All finding types

missing_error_tests

Missing Error Tests — a PullGuard finding type. Findings of this type appear in the PR comment, Step Summary, SARIF (GitHub Security tab / IDE viewers), and the HTML report, each with severity, location, and the remediation guidance below.

How to fix

Add test cases for error paths low effort

it('throws on invalid input', () => {
  expect(() => process(null)).toThrow('Input required');
});

it('returns error for unauthorized access', async () => {
  const res = await request(app).get('/admin').set('Authorization', 'invalid');
  expect(res.status).toBe(401);
});

Triage

Suppress a confirmed non-issue with a committed .pullguardignore entry (pullguard ignore locally, or comment /pullguard ignore <fingerprint> <reason> on the PR — the fingerprint is printed in the PR comment’s Triage section). Entries support expiresAt for time-boxed snoozes.

Security findings at major or critical severity — and any critical finding — always surface: .pullguardignore cannot hide them. The reviewed paths that keep them visible are acknowledged (reviewed, stays in reports) and, for a confirmed false positive, a reasoned false_positive entry — visible and audited, excluded only from the merge block.