Expect and Findings

Check a condition

expect takes a condition, an optional message, and optional severity. Use backticks when the message includes values.

input endpoint: url
response = http.get(endpoint, timeout=3s)
expect response.status == 200, `Unexpected status: ${response.status}`
expect response.status != 500, "Server returned 500", severity="low"

When the condition is false:

  • Without severity, the check is recorded as a step failure.
  • With severity, it creates a finding at that severity instead.

A false check does not stop execution. assert currently has the same behavior as expect; do not use it as a hard stop. If later work depends on a condition, guard that work with if or use return to exit. Errors while evaluating a check still follow normal error handling.

Report directly

Use finding when you have already identified an issue rather than testing a condition:

finding(
    "Unauthenticated access to an internal report",
    severity=high,
    repro=here(),
    detail={ path: "/internal/report", status: 200 }
)

Severity is info, low, medium, high, or critical; finding defaults to info. A finding requires a title. Optional fields include detail for context, evidence for an artifact or list of artifacts, and repro=here() to associate the report with this point in the program.

Include enough context to reproduce the issue, and remove secrets or unrelated personal data from anything you attach. Use vex_help in your environment for the full signature.

Improve team velocity with
better security and privacy.