--- name: regression-first description: "Use before fixing a bug, starting a refactor, or closing a security finding: write the test that pins the behavior first, watch it fail or hold, then change code." --- # Regression first The test is the claim; the fix is the proof. ## Bug 1. Reproduce in a test at the smallest boundary that shows the symptom. 2. Run it: it must fail for the reported reason, not for a setup error. 3. Fix. Run again. Green. 4. The test stays with the name of the symptom, not the fix. ## Refactor 1. Find the tests that already pin the behavior you will touch; run them. 2. No test pins it → write one against the current behavior before editing. 3. Refactor. The pinned tests do not change; if one must, the refactor changed behavior: stop and say so. ## Security 1. Encode the boundary as a test: what must never cross (secret in output, path outside root, unauthorized call). 2. It fails on the vulnerable code, holds after the fix, and stays as the guard. ## Rules - RED before GREEN, every time; a test that never failed proves nothing. - One symptom, one test; no drive-by assertions. - Never weaken an existing assertion to make a change pass.