
Automatic fixture validation — when tests learn from the database
How Estudos created a system that validates fixtures against the real database schema, preventing tests from passing by deception for nine days.
22 posts

How Estudos created a system that validates fixtures against the real database schema, preventing tests from passing by deception for nine days.

The Resume Tailor is back in the tree, but every tailored résumé is still handcrafted: open the site, describe the job, review, save, send. The plan has had a Phase 5 sketched since August — a semi-automated pipeline that turns a raw job posting into a ready PDF — and it still hasn't left the paper. On the difference between shipping a tool and shipping a habit.

Nine libraries, a test runner major bump and a GitHub action updated in a single day. What it took to merge 11 dependabot pull requests on the Portfolio without breaking the suite — and the one that almost turned into a false alarm.

The reject-post button saved feedback to a file. But a file doesn't open an issue, doesn't notify, and doesn't nag. One day the silent queue swallowed an entire request — and LifeLog learned that rejection without notification is just polite disposal. The story of /api/recusar and the loop that closes itself.

The alarm hunts, the gate blocks, the dog attacks. But there is a fourth layer in my security setup that nobody wrote about: the dependency update queue. On August 31st, the bot delivered five fix proposals. Three days later, all five are still open. The queue became the surface.

After the alarm and the gate, a third guardian was missing: someone who actually attacks the house, in an authorized way, once a week, and delivers an honest penetration report. The agentic red team was born for that — and the first drill proved the sentinel wakes up when someone touches what it shouldn't.

Ten days after automating active hunting, I realized the problem wasn't finding flaws — it was making sure nothing shipped without a security review. The security gate was born not as a tool but as a process rule: before any delivery, the test loop must pass. And the loop includes a dedicated security reviewer.

A Reject button in /ocultos that writes a note, opens a GitHub Issue, saves a file to the repo, and a 15-min cron redoes the post by itself. The story of how human feedback became a pipeline.

Every public site has a front door: the contact form and the resume download. Two endpoints that accept input from strangers on the internet — and I finally treated them as such. Rate limiting, HTML escaping, a contact file for people who find flaws, and a scanner that watches everything in silence.

Every project's AGENTS.md was the official instruction set of the ecosystem, but it lived outside the Yurumi's memory — the ingest only ran when someone remembered to run it. The fix was a signature watcher (mtime+size) that re-ingests only what changed. Along the way: a first_run that ran a full ingest every day, an os.stat that hung when WSL wedged, and the lesson of never trusting a junction.

After mapping the port inventory, the next step was planting bait: fake services, deliberately outdated in appearance, that pose as easy targets. A watcher classifies every touch on the log, and the central dispatcher decides when a detection becomes a notification.

One of the most underestimated layers of security is knowing what is open. The watchdog keeps a living inventory of ports, services and bindings — mapped against what is intentional — so any new port looks abnormal in seconds.

The cover watchdog I built to guarantee good images on the blog found a problem I didn't expect: the AI-generated covers arrived in the wrong format. The browser rejected them, and I only found out because the watchdog itself complained.

The security watchdog stopped feeding a kanban nobody read and started publishing findings where they matter: into persistent memory and the right channel. Less ceremony, more active hunting, zero cards.

Predictive navigation in Arachne: the agent receives a page image, predicts the whole next chain of steps, and executes end-to-end. D→C→B→A fallback cascade, real browser_agent driver, scraping link and WebSocket broadcast on the Cockpit.

The Security Agent cross-references findings from two hunters — the Dogwalk Bug Hunter and the Security Hunter watchdog — and outputs a single deduplicated alarm. A health gate to filter infrastructure false positives, discarded network error patterns, local-state dedup, and the no_agent contract: silence when everything is healthy.

A post that went live with a dark cover made me build a guarantee system: image generation with a two-layer fallback and a silent watchdog that swaps bad covers by itself. The story of how the blog stopped depending on a single path.

After finding 28 hardcoded PT texts scattered across the Portfolio (buttons, aria-labels, modals, tracking), I created an audit test that scans components and fails CI if any Portuguese text appears outside t(). The lesson: old tests were anchored to the bug — they searched for literal PT text instead of the i18n contract.

Automating narrative posts seemed simple: a cron, a script, a preview. On the same day, the pipeline hit 4 real walls — pnpm blocked by the gateway guard, MDX breaking the build with '<', a 0-byte cover and an interrupted session. Each wall became a rule.

Establishing daily posting frequency and solving the AI cover generation pipeline with Cloudflare Workers + FLUX.1 Schnell.

With 3 projects running, the infrastructure needed to be robust. Automated backups, security hardening, and the Hermes Agent as the ecosystem's brain.

How end-to-end tests transformed quality and confidence in Dogwalk's development — the real story of a stack that learned to test itself.