pj 8b4c300ad2 fix(sidecar): state on android whether a field is a secure entry
maestro's tree mapper copies a fixed attribute list off the device's XML and
password is not on it, so no android element ever reported the fact and the
conservative rule downstream redacted every typed value in the trace, the
prompt and the log. The XML still carries it: re-read it once per settled
snapshot and state the fact on the text fields it matches. A field it cannot
match stays unstated, which still reads as a credential.
2026-08-19 18:46:57 +05:30
2026-06-09 20:13:54 +05:30

sanderling

Autonomous property-based testing for mobile and web apps.

You write rules that must always hold about your app. sanderling explores the app on its own for minutes or hours, performing thousands of taps, swipes, and inputs, and records every step where a rule breaks. No scripted test paths. One TypeScript spec runs against Android, iOS, and web builds of the same app.

import { extract, always } from "@sanderling/spec";
import { defaultActions } from "@sanderling/spec/defaults";
import { noUncaughtExceptions } from "@sanderling/spec/defaults/properties";

const balance = extract("balance", s =>
  parseInt(s.ax.find({ testTag: "Balance" })?.text ?? "0", 10));

export const properties = {
  noUncaughtExceptions,
  balanceNeverNegative: always(() => balance.current >= 0),
};

export const actionsRoot = defaultActions;

Every run produces a trace: one JSON line and one screenshot per step. sanderling replay opens it in a web UI for stepping through actions, screenshots, property timelines, and violations.

Alpha. Android, iOS, and web (Chrome driver only). Full scope in the v0.1.0 roadmap.

Docs


sanderling

sanderling, a wading bird that probes the shoreline for bugs that lie beneath.

S
Description
No description provided
Readme Apache-2.0
51 MiB
0 Stars 1 Watchers 0 Forks
Languages
Go 74.6%
TypeScript 15.2%
Kotlin 5.5%
Shell 2.7%
Swift 1%
Other 0.9%