Skip to content

chore: bump GAF and adjust acceptance tests - #7274

Open
robertolopezlopez wants to merge 5 commits into
chore/CLI-1859-gaf-toonfrom
feat/CLI-1861
Open

robertolopezlopez wants to merge 5 commits into
chore/CLI-1859-gaf-toonfrom
feat/CLI-1861

Conversation

@robertolopezlopez

@robertolopezlopez robertolopezlopez commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

What does this PR do?

CLI-1861 integration layer: acceptance coverage for default and --full TOON on native test / secrets test, plus legacy fallback behaviour.

Where should the reviewer start?

  • test/jest/acceptance/snyk-test/output-formats/toon.spec.ts
  • test/jest/acceptance/snyk-secrets/snyk-secrets-toon.spec.ts

How should this be manually tested?

make build
TEST_SNYK_COMMAND=./binary-releases/snyk-macos-arm64 npx jest --runInBand --runTestsByPath \
  test/jest/acceptance/snyk-test/output-formats/toon.spec.ts \
  test/jest/acceptance/snyk-secrets/snyk-secrets-toon.spec.ts

What's the product update that needs to be communicated to CLI users?

Native snyk test and snyk secrets test TOON output supports --full for expanded SCA fields (via GAF). No CLI flag wiring added here.

Risk assessment

Low — acceptance tests only; no production CLI logic changes.

Relevant tickets

CLI-1860
CLI-1861


Note

Low Risk
Dependency pin plus Jest acceptance updates only; TOON behavior comes from GAF, with no new CLI wiring in this PR.

Overview
Bumps go-application-framework (pre-release aligned with GAF #767) and cli-extension-dep-graph/v2 in cliv2 and cliv2-private; no CLI source changes in this diff.

Acceptance tests for snyk test and snyk secrets test TOON output are updated to match the new UFM shape (org, sca / secrets tables instead of a results[N]: envelope). They now cover default vs --toon=full (column sets and the “hint: add --toon=full” line), --toon=false, and stdout vs --toon-file-output when full mode also prints TOON to the terminal.

Adds a case where the legacy test route (risk-score feature flags off) ignores TOON flags: human-readable stdout and no TOON file.

Reviewed by Cursor Bugbot for commit 3ff991e. Bugbot is set up for automated code reviews on this repo. Configure here.

@snyk-io

snyk-io Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@robertolopezlopez
robertolopezlopez added this pull request to stack #7272 September 16, 2026 13:31

@octavian-snyk octavian-snyk left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is good to go once GAF version is bumped.

@octavian-snyk

Copy link
Copy Markdown
Contributor

This is good to go into #7267 or #7268. Why is it separate?

Point at go-application-framework@2758ea2 so the CLI stack picks up
--toon=full hint text and the hermetic feature-flag gateway test fix.
Adjust TOON acceptance expectations to match.
@robertolopezlopez
robertolopezlopez force-pushed the feat/CLI-1861 branch 2 times, most recently from 1ab2254 to d314d94 Compare September 17, 2026 10:17
@robertolopezlopez
robertolopezlopez removed this pull request from stack #7272 September 17, 2026 10:21
@robertolopezlopez
robertolopezlopez changed the base branch from feat/CLI-1860 to chore/CLI-1859-gaf-toon September 17, 2026 10:21
@robertolopezlopez
robertolopezlopez added this pull request to stack #7283 September 17, 2026 10:21
@robertolopezlopez
robertolopezlopez force-pushed the feat/CLI-1861 branch 2 times, most recently from 3e26d9e to c07a1ce Compare September 17, 2026 11:08
@robertolopezlopez robertolopezlopez changed the title func: TOON integration feat: integrate UFM TOON output [CLI-1861] Sep 17, 2026
@robertolopezlopez

Copy link
Copy Markdown
Contributor Author

This is good to go into #7267 or #7268. Why is it separate?

@octavian-snyk #7268 was just the gaf pr associated cli pr. This one was for a different task (CLI-1861). Your thought had crossed my head already. Anyway: I have dropped #7268

@robertolopezlopez robertolopezlopez changed the title feat: integrate UFM TOON output [CLI-1861] chore: bump GAF and adjust acceptance tests Sep 17, 2026
@robertolopezlopez
robertolopezlopez marked this pull request as ready for review September 23, 2026 11:28
@robertolopezlopez
robertolopezlopez requested a review from a team as a code owner September 23, 2026 11:28
@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 11 relevant code sections from 7 files (average relevance: 1.00)

🤖 Repository instructions applied (from AGENTS.md)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants