
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
taskbounty-coverage-gate
Advanced tools
Zero-dependency coverage gate: read your existing LCOV or json-summary report, show the gap to a target (default 80%) and the lowest-covered files, and fail CI when below target.
A zero-dependency coverage gate for JavaScript and TypeScript projects. It reads
the coverage report your test run already produced (LCOV or Istanbul
json-summary), prints your current line coverage, the gap to a target (default
80%), and your lowest-covered files, and fails CI when you are below target.
No network calls, no account, no dependencies. It works with jest, vitest, nyc,
and c8, anything that can emit lcov.info or coverage-summary.json.
npm install -g taskbounty-coverage-gate
Or run it without installing via npx (shown below).
# after running your tests with coverage
npx taskbounty-coverage-gate --min 80
It auto-detects coverage/lcov.info, coverage/coverage-summary.json,
coverage-summary.json, or lcov.info. Point it explicitly with --report:
npx taskbounty-coverage-gate --report coverage/lcov.info --min 80
Options:
| Flag | Default | Meaning |
|---|---|---|
--report <path> | auto | Path to the LCOV or json-summary report |
--min <pct> | 80 | Target line coverage |
--top <n> | 5 | How many lowest-covered files to list |
--no-fail | off | Report only, always exit 0 |
Example output:
Coverage gate (report: coverage/lcov.info)
Line coverage 62.4% ███████████████░░░░░░░░░
Target 80.0%
Result BELOW target by 17.6 points
Lowest-covered files:
0% src/api/webhooks.ts
31% src/billing/invoices.ts
44% src/auth/session.ts
Exit code is 1 when below target (so it gates CI), 0 otherwise or with
--no-fail.
- name: Test with coverage
run: npm test -- --coverage
- name: Coverage gate
uses: task-bounty/coverage-gate@v1
with:
report: coverage/lcov.info
min: 80
# fail-under: false # report only, do not fail the job
lcov.info): line coverage summed from LF/LH per file.coverage-summary.json): repo total plus per-file
line percentages.Below 80% and want to get there without the grind? TaskBounty takes a repo to 80% line coverage and delivers it as a sandbox-verified pull request, refunded if it misses. Free coverage check for any repo: https://www.task-bounty.com/coverage-check
MIT
FAQs
Zero-dependency coverage gate: read your existing LCOV or json-summary report, show the gap to a target (default 80%) and the lowest-covered files, and fail CI when below target.
The npm package taskbounty-coverage-gate receives a total of 3 weekly downloads. As such, taskbounty-coverage-gate popularity was classified as not popular.
We found that taskbounty-coverage-gate demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.