From 43d9c0e1d04f258a4e20c338efe8a02d7a5001b0 Mon Sep 17 00:00:00 2001 From: Hermes Date: Wed, 12 Aug 2026 15:56:53 -0700 Subject: [PATCH] DC-083: claim license-manager.js coverage for Hermes --- DC-PRODUCTION-GRADE-BACKLOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/DC-PRODUCTION-GRADE-BACKLOG.md b/DC-PRODUCTION-GRADE-BACKLOG.md index 6d0c64e..a0c16e2 100644 --- a/DC-PRODUCTION-GRADE-BACKLOG.md +++ b/DC-PRODUCTION-GRADE-BACKLOG.md @@ -145,7 +145,7 @@ - **impact:** Any execSync with interpolation is a potential RCE. This is the same class of bug P0-2 already fixed — finish the job. ### DC-083: 30 source files have zero test coverage -- **status:** partial (coverage 65pct->75pct) +- **status:** in-progress (license-manager.js — revenue path — claimed by hermes 2026-08-12) - **details:** The test gap scan found 30 source files with NO corresponding test file, including critical paths: `license-manager.js` (534 lines, the entire revenue validation path), `config-schema.js`, `middleware.js` (the auth/rate-limit/CORS stack), `startup-validator.js`, all 7 DNS provider modules (`technitium.js`, `cloudflare.js`, `rfc2136.js`, `manual.js`, `base.js`, `registry.js`, `email.js`), `docker-maintenance.js`, `config/migrations.js`, `event-workers.js`, `keychain-manager.js`, `event-store.js`, `host-registry.js`. Fix: prioritize license-manager.js (revenue path) and middleware.js (security stack) first, then work through the rest. Effort: ~8 hr (can be done incrementally, 2-3 files per PR). - **impact:** license-manager.js validates Pro licenses — an untested bug there could silently break activation for every paying customer.