Bug Description
If fetching repositories for an organisation fails, the exploration can
still complete and be marked as a full/complete analysis when a PAT is
present.
In AppContext.jsx, repository fetching uses Promise.allSettled():
await Promise.allSettled(validOrgs.map(async org => {
reposPerOrg[org.login] = await fetchRepos(org.login, org.public_repos, pat)
}))
The settled results are not inspected. If fetchRepos() rejects, no
entry is added to reposPerOrg for that organisation. buildAnalyticalModel()
then falls back to an empty repository list:
const repos = reposPerOrg[org.login] || []
However, after building the model, the exploration sets:
Therefore, when a PAT is present, an exploration can be marked complete
even though an organisation's repository data was never fetched. The
rejection is absorbed entirely by allSettled and never reaches the
outer try/catch, so no error is ever shown to the user.
Related: #81 documents the same category of silent-partial-completion,
for the Governance audit specifically, and states that explore()
correctly surfaces rate-limit errors. That's no longer accurate against
the current runFullExplore() implementation — it discards fetchRepos()
rejections via this same unchecked Promise.allSettled() pattern. This
suggests the underlying issue may be systemic across the codebase rather
than isolated to one function, and could be worth an audit of other
allSettled() call sites.
Steps to Reproduce
-
Add a valid GitHub PAT in OrgExplorer.
-
Temporarily make fetchRepos() fail for an organisation:
if (org === 'AOSSIE-Org') {
throw new Error('TEST_REPO_FAILURE')
}
-
Go to the Home page.
-
Enter AOSSIE-Org.
-
Click EXPLORE.
Expected behaviour:
If repository fetching fails for an organisation, the application
should not silently treat that organisation as having zero repositories
and mark the overall analysis as complete. The failure should at least
be surfaced to the user and the analysis should be represented as
incomplete/partial. For multi-organisation analysis, it would also be
useful to identify which organisation(s) failed.
Actual behavior:
The application navigates to the Overview page without showing a
repository-fetch error. The resulting analysis shows:
- Total repos: 0
- Total stars: 0
- Total forks: 0
- Active repos: 0
The Contributors page also shows:
- 0 contributors found
- Bus Factor: 0 / UNKNOWN
- Freshness: 0/10
The PAT is present, so the analysis is still treated as complete.
Logs and Screenshots
Environment Details
- OS: macOS
- Browser: Google Chrome
- Project: AOSSIE-Org/OrgExplorer
- Repository version: current
main branch
- Authentication: GitHub Personal Access Token configured
- Runtime: Vite development server
- Reproduction: local development environment
Impact
Medium - Feature works but has issues
Code of Conduct
Bug Description
If fetching repositories for an organisation fails, the exploration can
still complete and be marked as a full/complete analysis when a PAT is
present.
In
AppContext.jsx, repository fetching usesPromise.allSettled():The settled results are not inspected. If
fetchRepos()rejects, noentry is added to
reposPerOrgfor that organisation.buildAnalyticalModel()then falls back to an empty repository list:
However, after building the model, the exploration sets:
Therefore, when a PAT is present, an exploration can be marked complete
even though an organisation's repository data was never fetched. The
rejection is absorbed entirely by
allSettledand never reaches theouter try/catch, so no error is ever shown to the user.
Related: #81 documents the same category of silent-partial-completion,
for the Governance audit specifically, and states that
explore()correctly surfaces rate-limit errors. That's no longer accurate against
the current
runFullExplore()implementation — it discardsfetchRepos()rejections via this same unchecked
Promise.allSettled()pattern. Thissuggests the underlying issue may be systemic across the codebase rather
than isolated to one function, and could be worth an audit of other
allSettled()call sites.Steps to Reproduce
Add a valid GitHub PAT in OrgExplorer.
Temporarily make
fetchRepos()fail for an organisation:Go to the Home page.
Enter
AOSSIE-Org.Click EXPLORE.
Expected behaviour:
If repository fetching fails for an organisation, the application
should not silently treat that organisation as having zero repositories
and mark the overall analysis as complete. The failure should at least
be surfaced to the user and the analysis should be represented as
incomplete/partial. For multi-organisation analysis, it would also be
useful to identify which organisation(s) failed.
Actual behavior:
The application navigates to the Overview page without showing a
repository-fetch error. The resulting analysis shows:
The Contributors page also shows:
The PAT is present, so the analysis is still treated as complete.
Logs and Screenshots
Environment Details
mainbranchImpact
Medium - Feature works but has issues
Code of Conduct