name: regression-first
description: "Use before fixing a bug, starting a refactor, or closing a security finding: write the test that pins the behavior first, watch it fail or hold, then change code."
Regression first
The test is the claim; the fix is the proof.
Bug
Reproduce in a test at the smallest boundary that shows the symptom.
Run it: it must fail for the reported reason, not for a setup error.
Fix. Run again. Green.
The test stays with the name of the symptom, not the fix.
Refactor
Find the tests that already pin the behavior you will touch; run them.
No test pins it → write one against the current behavior before editing.
Refactor. The pinned tests do not change; if one must, the refactor changed behavior: stop and say so.
Security
Encode the boundary as a test: what must never cross (secret in output, path outside root, unauthorized call).
It fails on the vulnerable code, holds after the fix, and stays as the guard.
Rules
RED before GREEN, every time; a test that never failed proves nothing.
One symptom, one test; no drive-by assertions.
Never weaken an existing assertion to make a change pass.
---
name: regression-first
description: "Use before fixing a bug, starting a refactor, or closing a security finding: write the test that pins the behavior first, watch it fail or hold, then change code."
---
# Regression first
The test is the claim; the fix is the proof.
## Bug
1. Reproduce in a test at the smallest boundary that shows the symptom.
2. Run it: it must fail for the reported reason, not for a setup error.
3. Fix. Run again. Green.
4. The test stays with the name of the symptom, not the fix.
## Refactor
1. Find the tests that already pin the behavior you will touch; run them.
2. No test pins it → write one against the current behavior before editing.
3. Refactor. The pinned tests do not change; if one must, the refactor changed behavior: stop and say so.
## Security
1. Encode the boundary as a test: what must never cross (secret in output, path outside root, unauthorized call).
2. It fails on the vulnerable code, holds after the fix, and stays as the guard.
## Rules
- RED before GREEN, every time; a test that never failed proves nothing.
- One symptom, one test; no drive-by assertions.
- Never weaken an existing assertion to make a change pass.