Security and data
TestDetta runs in your CI and on your machines. Your source code, coverage maps and test results never leave them. This page lists everything it stores and every network call it makes.
What stays in your CI
- The analysis of your diff and source code.
- Coverage maps: which test class ran which method, and how long each class took. They name your types, methods and test classes, so treat them like build artifacts.
- Test runs and their results.
- The count of active committers. Author emails are read from git history to count them, on your machine; no names or emails are sent anywhere.
Where it keeps files
| Path | Contents |
|---|---|
.testdetta/coverage/ | Coverage maps of the current commit, one per test project |
.testdetta/cache/ | A cache of the evaluated project graph |
.testdetta/license.json | Optional: extra bot accounts to leave out of the committer count |
~/.testdetta/license | A license installed with td license install, or renewed automatically |
~/.testdetta/license-refresh | When the last renewal was attempted |
--maps-dir folder | Maps of earlier commits, one folder per commit, kept where you choose |
On GitHub Actions, maps are stored in your repository's Actions cache. .testdetta/coverage/ and .testdetta/cache/ are generated; keep them out of version control.
The one network call
With a subscription license, TestDetta asks the license service for a renewed license at most once a day, so that renewals reach CI without anyone updating a secret.
- It sends the license itself, nothing else: no repository name, code, paths or counts.
- It runs next to the analysis and waits at most 6 seconds. A failure that may pass is tried again after an hour; if the service cannot be reached, the current license keeps working.
HTTPS_PROXYis honoured.TESTDETTA_LICENSE_REFRESH=offturns it off. Offline and enterprise licenses never call home.
Public repositories need no license and make no call.
How the license is checked
A license is a signed string, verified on your machine with a public key built into TestDetta. It names the repositories it covers, matched against the origin remote with any credentials removed first. A license problem never fails a build: every test runs instead, as before TestDetta. More about licenses.
What we keep
For a subscription: the licensee name, the repositories it covers, the number of seats and its period. The payment and the email address it is sent to are handled by Polar Software, Inc., our merchant of record. See the privacy policy.
Reporting a vulnerability
Email support@testdetta.com. Please give us time to fix it before you publish.