Skip to content

feat: add e2e tests for API - #15760

Draft
lucasfernog wants to merge 24 commits into
devfrom
feat/e2e
Draft

feat: add e2e tests for API#15760
lucasfernog wants to merge 24 commits into
devfrom
feat/e2e

Conversation

@lucasfernog

Copy link
Copy Markdown
Member

No description provided.

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Package Changes Through 4a6372b

There are 14 changes which include tauri with minor, tauri-cli with minor, @tauri-apps/cli with minor, tauri-runtime with minor, tauri-runtime-wry with minor, tauri-utils with minor, tauri-bundler with minor, tauri-build with minor, tauri-macos-sign with minor, tauri-codegen with minor, tauri-macros with minor, tauri-plugin with minor, tauri-driver with minor, @tauri-apps/api with minor

Planned Package Versions

The following package releases are the planned based on the context of changes in this pull request.

package current next
@tauri-apps/api 2.11.1 2.12.0
tauri-utils 2.9.3 2.10.0
tauri-macos-sign 2.3.4 2.4.0
tauri-bundler 2.9.4 2.10.0
tauri-runtime 2.11.3 2.12.0
tauri-runtime-wry 2.11.4 2.12.0
tauri-codegen 2.6.3 2.7.0
tauri-macros 2.6.3 2.7.0
tauri-plugin 2.6.3 2.7.0
tauri-build 2.6.3 2.7.0
tauri 2.11.5 2.12.0
@tauri-apps/cli 2.11.4 2.12.0
tauri-cli 2.11.4 2.12.0
tauri-driver 2.0.6 2.1.0

Add another change file through the GitHub UI by following this link.


Read about change files or the docs at github.com/jbolda/covector

@socket-security

socket-security Bot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @zip.js/zip.js is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/mocha-framework@9.29.1npm/@wdio/local-runner@9.29.1npm/webdriverio@9.29.1npm/@wdio/cli@9.29.1npm/@zip.js/zip.js@2.8.26

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@zip.js/zip.js@2.8.26. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm edgedriver is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/mocha-framework@9.29.1npm/@wdio/local-runner@9.29.1npm/webdriverio@9.29.1npm/@wdio/cli@9.29.1npm/edgedriver@6.3.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/edgedriver@6.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm execa is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/cli@9.29.1npm/execa@9.6.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/execa@9.6.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm spacetrim is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/mocha-framework@9.29.1npm/@wdio/local-runner@9.29.1npm/webdriverio@9.29.1npm/@wdio/cli@9.29.1npm/spacetrim@0.11.59

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/spacetrim@0.11.59. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webdriverio is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/api-e2e/package.jsonnpm/webdriverio@9.29.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webdriverio@9.29.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm workerpool is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/mocha-framework@9.29.1npm/workerpool@6.5.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/workerpool@6.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@wdio/mocha-framework@9.29.1npm/@wdio/local-runner@9.29.1npm/webdriverio@9.29.1npm/@wdio/cli@9.29.1npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Comment thread .github/workflows/test-api-e2e.yml Fixed
Comment on lines +29 to +164
runs-on: ${{ matrix.platform.os }}

strategy:
fail-fast: false
matrix:
platform:
- { name: Linux, os: ubuntu-latest }
- { name: Windows, os: windows-latest }
- { name: macOS, os: macos-latest }

steps:
- uses: actions/checkout@v4

- name: install Rust stable
uses: dtolnay/rust-toolchain@stable

- run: npm i -g --force corepack
- name: setup node
uses: actions/setup-node@v4
with:
node-version: 'lts/*'
cache: 'pnpm'

- name: install Linux dependencies
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y \
libwebkit2gtk-4.1-dev \
webkit2gtk-driver \
libgtk-3-dev \
libayatana-appindicator3-dev \
librsvg2-dev \
xvfb \
fluxbox

# install a matching Microsoft Edge Driver version using msedgedriver-tool
- name: install msedgedriver (Windows)
if: runner.os == 'Windows'
run: |
cargo install --git https://github.com/chippers/msedgedriver-tool
& "$HOME/.cargo/bin/msedgedriver-tool.exe"
$PWD.Path >> $env:GITHUB_PATH

- uses: Swatinem/rust-cache@v2
with:
key: ${{ matrix.platform.os }}

- name: install dependencies
run: pnpm i --frozen-lockfile

- name: build @tauri-apps/api
run: pnpm build:api

- name: build @tauri-apps/cli
run: pnpm build:cli

- name: run e2e tests (Linux)
if: runner.os == 'Linux'
timeout-minutes: 45
# A real window manager (fluxbox) is started so that window-state tests
# (minimize/maximize/fullscreen/position) behave. The tray host is absent
# in this environment, so the tray module is skipped.
run: |
xvfb-run --auto-servernum -- bash -c '
fluxbox >/dev/null 2>&1 &
sleep 1
E2E_SKIP=tray E2E_SPEC_RETRIES=1 pnpm test:api-e2e
'

- name: run e2e tests (Windows)
if: runner.os == 'Windows'
timeout-minutes: 45
shell: pwsh
run: |
$env:E2E_SKIP = "tray"
$env:E2E_SPEC_RETRIES = "1"
pnpm test:api-e2e

- name: run e2e tests (macOS)
if: runner.os == 'macOS' && env.CN_API_KEY != ''
timeout-minutes: 45
# macOS has no native WebDriver for WKWebView, so the app is driven through the
# CrabNebula Webdriver (tauri-plugin-automation + test-runner-backend), which
# authenticates with CN_API_KEY. wdio.conf enables it automatically on darwin and
# builds the `.app` bundle it needs. The tray module is skipped to match the other jobs.
run: E2E_SKIP=tray E2E_SPEC_RETRIES=1 pnpm test:api-e2e
env:
CN_API_KEY: ${{ secrets.TAURI_E2E_CN_API_KEY }}

# The CrabNebula Webdriver proxies every command to a server running *inside* the app
# process, so when the app dies the suite only ever reports `connection refused` — the
# actual cause is never in this log. The app's stdout/stderr is inherited (its `println!`
# output shows up above) and no panic message is printed, which means it goes down on a
# signal. macOS records the reason in a crash report, and that is the only place it
# survives the run.
- name: collect app crash reports (macOS)
if: runner.os == 'macOS' && failure()
run: |
dest="$RUNNER_TEMP/crash-reports"
mkdir -p "$dest"
# ReportCrash writes asynchronously; give the last crash a moment to land.
sleep 5
found=0
for f in "$HOME/Library/Logs/DiagnosticReports"/*.ips \
"$HOME/Library/Logs/DiagnosticReports/Retired"/*.ips; do
[ -e "$f" ] || continue
found=$((found + 1))
cp "$f" "$dest/"
echo "::group::$(basename "$f")"
# An .ips file is a one-line JSON header followed by the JSON report body.
head -n 1 "$f"
tail -n +2 "$f" | jq -r '
"exception: \(.exception // {} | tojson)",
"termination: \(.termination // {} | tojson)",
"asi: \(.asi // {} | tojson)",
"faulting thread \(.faultingThread // 0):",
(. as $r
| $r.threads[$r.faultingThread // 0].frames[]?
| " \($r.usedImages[.imageIndex].name // "?") \(.symbol // "?") +\(.imageOffset)"),
"last ObjC exception:",
(. as $r
| $r.lastExceptionBacktrace[]?
| " \($r.usedImages[.imageIndex].name // "?") \(.symbol // "?") +\(.imageOffset)")
' || cat "$f"
echo "::endgroup::"
done
[ "$found" -gt 0 ] || echo "no crash reports under $HOME/Library/Logs/DiagnosticReports"

- name: upload app crash reports (macOS)
if: runner.os == 'macOS' && failure()
uses: actions/upload-artifact@v4
with:
name: macos-crash-reports
path: ${{ runner.temp }}/crash-reports
if-no-files-found: ignore
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants