Files
sanderling/pkg/spec
pj 66fd5bce5d fix(runner): a secure field's value does not reach state.lastAction either
folio extracts lastAction, and extractor values are persisted as
extractor_changes, so the password still reached the run directory
through the spec after the three render sites were closed.

The wrap sits in the runner rather than in lastActionFields because the
hosts hold the next step's tree, not the one the action was chosen
against: a field that stops being secure between the two would publish
what the trace withheld. Live and replay now agree byte for byte.
2026-08-18 17:32:28 +05:30
..

@sanderling/spec

TypeScript spec API for sanderling, a property-based UI fuzzer for Android, iOS and web apps.

A spec exports properties (what the app must always or eventually do), extractors (structured state read off the UI), and action generators (what sanderling is allowed to do). The sanderling CLI evaluates the spec against a running app once per step.

npm install --save-dev @sanderling/spec

Getting started installs the CLI and runs a first spec. The spec language reference lists every primitive, and the case study walks a complete spec end to end.

The CLI bundles this package's TypeScript sources at run time, so keep the CLI and the package on the same release.