From f606405cf39c9da66a251766eea351a202f7ea95 Mon Sep 17 00:00:00 2001 From: bgard68 <30295154+bgard68@users.noreply.github.com> Date: Thu, 10 Sep 2026 21:16:33 -0500 Subject: [PATCH] test: clear the two CodeQL quality alerts in the test projects Alert #59 (cs/local-not-disposed): the StreamReader over the response body was created inline and never disposed. Bind it to a `using` local instead. Nothing reads Response.Body after this point, so letting the reader close the stream is fine. Alert #60 (cs/linq/missed-where): the theory-data loop filtered with an `if` inside the body. Move the predicate to `.Where(...)` on the source sequence. The case list is still built here rather than filtered inside the test, so the doc comment above it still holds. Co-Authored-By: Claude Opus 5 --- .../ApiExceptionHandlerTests.cs | 3 ++- .../AcknowledgementTests.cs | 8 +++----- 2 files changed, 5 insertions(+), 6 deletions(-) diff --git a/tests/DevSecOpsSentinel.Api.Integration.Tests/ApiExceptionHandlerTests.cs b/tests/DevSecOpsSentinel.Api.Integration.Tests/ApiExceptionHandlerTests.cs index 329ef8c..93763b2 100644 --- a/tests/DevSecOpsSentinel.Api.Integration.Tests/ApiExceptionHandlerTests.cs +++ b/tests/DevSecOpsSentinel.Api.Integration.Tests/ApiExceptionHandlerTests.cs @@ -172,7 +172,8 @@ public async Task TryHandleAsync_ProblemDetailsServiceDeclinesToWrite_WritesTheP // Assert context.Response.Body.Seek(0, SeekOrigin.Begin); - string body = await new StreamReader(context.Response.Body, Encoding.UTF8).ReadToEndAsync(); + using StreamReader reader = new(context.Response.Body, Encoding.UTF8); + string body = await reader.ReadToEndAsync(); using JsonDocument document = JsonDocument.Parse(body); diff --git a/tests/DevSecOpsSentinel.Infrastructure.Tests/AcknowledgementTests.cs b/tests/DevSecOpsSentinel.Infrastructure.Tests/AcknowledgementTests.cs index fd88ee7..53010fa 100644 --- a/tests/DevSecOpsSentinel.Infrastructure.Tests/AcknowledgementTests.cs +++ b/tests/DevSecOpsSentinel.Infrastructure.Tests/AcknowledgementTests.cs @@ -119,12 +119,10 @@ public void Analyze_CheckoutThatIsReported_IsNotAlsoAcknowledged() public static TheoryData RulesThatAcknowledgeNothing() { TheoryData data = []; - foreach (IWorkflowSecurityRule rule in RuleCatalogue.All()) + foreach (IWorkflowSecurityRule rule in RuleCatalogue.All() + .Where(rule => rule is not (ExcessivePermissionsRule or PersistedCredentialsRule))) { - if (rule is not (ExcessivePermissionsRule or PersistedCredentialsRule)) - { - data.Add(rule.RuleId); - } + data.Add(rule.RuleId); } return data;