sh-mcp/package.json
Adam Moussa a60a5a5794 Add security-weighted test suite + coverage gate; wire tooling
Add tests for the highest-risk surface (build-plan §5, design.md §7.3):
tool-hiding, server-side scope enforcement (incl. forced hidden calls),
audience binding, input-schema validation, finance redaction on egress, audit
emission with hashed args, prompt-injection regression (tool output is data),
rate limiting, MCP conformance (in-memory transport round-trip), OpenAPI 3.1
validity, and local-auth safety. Add HTTP integration tests (supertest) for both
servers and per-package dev-client tests. 405 tests pass.

Wire the coverage gate into vitest.config.ts: 80% overall, with per-file
thresholds on the auth + dispatch crown jewels; exclude deferred real client
stubs, entrypoints, cdk apps, and aws-only config from the gate (documented).
Extend eslint flat config + add .prettierignore to cover servers/. Commit the
updated package-lock.json.
2026-06-26 12:48:26 -04:00

42 lines
1 KiB
JSON

{
"name": "sh-mcp",
"version": "0.0.1",
"private": true,
"description": "Sea Haven MCP Platform — auth-first task agents backed by trust-tiered MCP servers",
"license": "MIT",
"type": "module",
"workspaces": [
"packages/*",
"servers/*",
"jobs/*",
"auth/*"
],
"scripts": {
"build": "tsc -b",
"test": "vitest run",
"test:watch": "vitest",
"test:coverage": "vitest run --coverage",
"typecheck": "tsc -b",
"lint": "eslint .",
"format:check": "prettier --check .",
"format": "prettier --write .",
"synth": "npm run synth --workspaces --if-present"
},
"devDependencies": {
"@types/node": "22.7.4",
"@typescript-eslint/eslint-plugin": "8.17.0",
"@typescript-eslint/parser": "8.17.0",
"@vitest/coverage-v8": "3.0.2",
"aws-cdk": "2.1128.1",
"aws-cdk-lib": "2.260.0",
"constructs": "10.6.0",
"eslint": "9.14.0",
"prettier": "3.4.2",
"tsx": "4.22.4",
"typescript": "5.6.3",
"vitest": "3.0.2"
},
"engines": {
"node": ">=24.0.0"
}
}