Hub rules-vitest

rules-vitest

v3 public Verified

Vitest

Vitest is a Vite-native unit test framework. These rules govern test suite reliability, hook usage, and best practices for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-vitest →
Severity
3 error 4 warn 0 info
demo.cast
Vitest is a Vite-native unit test framework. These rules govern test suite reliability, hook usage, and best practices for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

vitest

vitest-deny-eval-in-mock error block

RISK: eval() inside vi.fn()/vi.mock() executes arbitrary code strings — if the mock is seeded from any external data it becomes a code-injection vector. FIX: replace eval with explicit function implementations or use vi.importMock() with a static factory.

Rule source requires an active Pro or Enterprise subscription.
vitest-deny-globalsetup-exec error block

RISK: globalSetup scripts that spawn child processes can start live infrastructure (databases, servers) that outlive the test run and expose ports to the host. FIX: use in-process test doubles (vi.mock) or explicitly track and teardown any spawned processes in the corresponding globalTeardown.

Rule source requires an active Pro or Enterprise subscription.
vitest-deny-hardcoded-secret-fixture error block

RISK: Hardcoded credentials in test fixtures or spec files are committed to version control and can be scraped by automated secret-scanning bots (CWE-798). FIX: use placeholder strings like 'test-secret-placeholder' or read from process.env / a .env.test file that is gitignored.

Rule source requires an active Pro or Enterprise subscription.
vitest-deny-real-network-in-unit-test warning log

RISK: Unit/integration tests that make real HTTP calls over the network are non-deterministic, slow, and may inadvertently mutate production data. FIX: intercept with msw (Mock Service Worker) or vi.mock, or move these to a dedicated e2e suite gated behind an explicit environment flag.

Rule source requires an active Pro or Enterprise subscription.
vitest-warn-coverage-disabled-threshold warning log

ADVISORY: A 0% coverage threshold in vitest configuration provides no quality gate — CI will pass regardless of how little code is covered. Set meaningful thresholds (e.g. lines: 80) so regressions in coverage cause a failed build.

Rule source requires an active Pro or Enterprise subscription.
vitest-warn-mock-clear warning log

If mockReset is false, mocked modules might leak state between tests. Ensure tests do not have cross-dependencies due to shared mock state.

Rule source requires an active Pro or Enterprise subscription.
vitest-warn-test-timeout warning log

A very large testTimeout is detected. This could indicate inefficient tests or tests that are prone to hanging (e.g. unclosed connections, infinite loops).

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
8121b9ce1358e12b74a112717f035b377d5f099b3db725d25094d3e9d44c8aa6
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-vitest/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-vitest. The published version only bumps when a maintainer resyncs.

No commit history available.