Cypress automation framework (Page Object Model, 50+ custom commands) for the Customer Lifecycle Platform — E2E, component, API, mobile, and visual regression in a single TypeScript codebase. Test plans in Zephyr Scale, visual validation against Figma specs. Component tests run in 7s vs 52s on full E2E, enabling fast feedback loops across 30+ sprints.
Load testing suite for OAA onboarding (100 VUs, 10 min sustained, P95 < 2000ms, error rate < 1%). Covers critical compliance endpoints: PEP checks and tax residency across 3 jurisdictions. Observability validated with Datadog on GCP during runs.
Evolution of the QA Metrics undergrad thesis (open source) at Questrade: Dockerized platform with GitHub Actions — Newman integrates SonarCloud, Jira and Google Sheets via API → InfluxDB → real-time Grafana dashboards, replacing manual spreadsheet extraction and giving the team, manager and PO visibility into rework hotspots and root cause analysis.
QA coverage for mobile MFA and IDV flows not covered by the existing Detox setup — inspecting payloads via Android Studio in debug mode. Cross-device regression on BrowserStack and physical devices, validating selfie and document approval/rejection via Mitek SDK; backend checks in SQL Server and MongoDB.
Three-layer coverage: Postman/Newman (800+ tests) for KYC, onboarding and lifecycle flows; Cypress component testing integrated into CI/CD; Playwright for MFA with OAuth2/PKCE, TOTP and multi-tenant isolation (8+ services) in SIT/UAT.
API collections also ran headless in GitLab CI (not only in the Postman desktop app): official Newman Alpine image, HTML artifact plus JUnit so failures surface on the merge request pipeline.
stages:
- test
postman_tests:
stage: test
image:
name: postman/newman_alpine33
entrypoint: [""]
script:
- newman --version
- npm install -g newman-reporter-html
- newman run collection.json --reporters cli,html,junit \
--reporter-html-export report.html \
--reporter-junit-export report.xml
artifacts:
when: always
paths:
- report.html
reports:
junit: report.xml
Beyond status codes: tests assert response shape with JSON Schema (pm.response.to.have.jsonSchema), locking required fields and rejecting unexpected properties, aligned with Swagger/OpenAPI contracts.
const schema = {
type: "object",
properties: {
code: { type: "string" },
error: {
type: "object",
properties: { message: { type: "string" } },
required: ["message"]
},
tags: {
type: "array",
minItems: 1,
maxItems: 3,
items: { type: "string" }
}
},
required: ["code", "error"],
additionalProperties: false
};
pm.test("Validate schema", () => {
pm.response.to.have.jsonSchema(schema);
});
Collections also ran inside the official Newman image with the working directory mounted as a volume, plus CSV --iteration-data for file-upload cases. For a fuller local stack, Jenkins was started in Docker with Postman/Newman support (UTF-8 JVM, persistent jenkins_home).
# Run collection inside Newman container
docker run -v "$PWD:/etc/newman" -t postman/newman \
run collection.json --iteration-data data.csv
# data.csv (file upload iterations)
# fileName,statusCode
# file1.txt,200
# file2.txt,400
# Local Jenkins + Postman/Newman image
docker run -p 8080:8080 -p 50000:50000 --restart=on-failure \
-v jenkins_home:/var/jenkins_home \
--env JAVA_OPTS="-Dfile.encoding=UTF8" \
vdespa/jenkins-postman
Viewport library built from the product's own design system breakpoints (360–599 mobile / 600–839 tablet / 840+ desktop) — not a generic device library. Key insight: three pairs of Responsive Viewer profiles at exactly 1px apart to catch boundary regressions: modal layout shift (519/520px), submenu visibility (1019/1020px), and action button swap (1279/1280px). Boundary Value Analysis applied to responsive design.
Exportable profile library with mobile, tablet, desktop and BREAKPOINTS tabs (BVA pairs at 1px). Import via Responsive Viewer extension → Load JSON.
BVA — Boundary Value Analysis. Classic test technique: exercise values immediately before and after a threshold where behavior changes. Pairs here differ by 1px to catch off-by-one regressions in media queries and layout rules.
Most public demo apps are too simple to test meaningfully. I built TestFlow to change that — a realistic web application with authentication, multi-role workflows, and API layers that mirror what you'd find in production. Six automation suites run against it: Cypress, Playwright, PyTest, Appium, k6 and Selenium. The app ships as a Docker image so anyone can spin it up in seconds.
Who it's for: QA engineers learning Cypress, Playwright, PyTest, Appium, k6 or Selenium, interview prep, workshops, and anyone who wants a production-like sandbox without building the app from scratch.
Web sandbox built for QA automation practice — the target app for testflow-cypress, testflow-playwright, testflow-pytest, testflow-appium, testflow-k6 and testflow-selenium.
docker pull qaschool/testflow:latest
docker run -p 5050:5050 qaschool/testflow:latest
Cypress 15 E2E + component suite: smoke, auth, dashboard, team, wizard, API, a11y, visual regression via Percy. Parallel CI on GitHub Actions — results recorded to Cypress Cloud with Test Replay.
↗ runs against testflow @ :5050 ↗ View commit historyPlaywright TypeScript suite — mirror of the Cypress coverage with POM, axe-core a11y, visual regression and cross-browser projects (Chromium / Firefox / WebKit). 17 parallel CI matrix jobs across smoke, auth, API, wizard, a11y and visual.
↗ runs against testflow @ :5050 ↗ View commit historyPyTest + Playwright for Python suite for TestFlow — mirror of the Cypress and Playwright coverage with Page Object Model, fixtures, factories and data-testid selectors. 12 suites: smoke, auth, dashboard, team, settings, components, wizard, activity, advanced, states, API and visual regression. axe-playwright a11y, pytest markers (@smoke, @critical, @a11y) and traceable [TC-xxxx] ids. GitHub Actions parallel matrix against qaschool/testflow @ :5050.
Appium 2 + WebdriverIO 9 mobile web suite for TestFlow — mirror of the Cypress, Playwright and PyTest coverage through Chrome on Android and Safari on iOS, plus REST API checks without a device. 17 specs including gestures, device orientation, WEBVIEW contexts and locator strategies. POM with data-testid, Allure reports and traceable [TC-xxxx] ids. CI: API smoke + Android emulator on GitHub Actions; Allure published to GitHub Pages.
k6 performance suite for TestFlow — smoke CI gate, load (auth/users/mixed), stress, spike and soak scenarios, multi-step journeys and k6 browser login. SLO thresholds for P95 latency and error rate; GitHub Actions smoke on push/PR plus manual load profiles. Mirrors functional API coverage on /health, /api/auth/login and /api/users @ :5050.
Production-quality Rest Assured suite for Spring Petclinic REST — reusable API clients, dynamic test data, JSON schema validation, WireMock stubs, parameterized negatives and multi-step E2E flows. Java 17 · JUnit 5 · Maven · Allure · Docker Compose for local and CI.
↗ runs against spring-petclinic-rest @ :9966 ↗ View commit history
Selenium WebDriver 4 E2E suite for TestFlow — pure Selenium mirror of testflow-cypress (no WebDriverIO/Nightwatch) with Page Object Model, data-testid selectors, Mocha + Chai, mochawesome reports and Ajv JSON Schema API checks. 11 suites (@smoke · @regression · @api) with traceable [TC-xxxx] ids. GitHub Actions against qaschool/testflow @ :5050.
QAs spent 1–3 hours per sprint manually copying Jira, SonarCloud and Test Pyramid data into spreadsheets and Slides — and retrospectives stalled when a QA was absent. Open-source Docker stack: Newman collects APIs → InfluxDB → 3 Grafana dashboards; any team member can run it with docker-compose up.
git clone https://github.com/lflucasferreira/qametrics.git
docker-compose up
Newman writes Jira bug metrics into InfluxDB as a time series. Fields such as pingPongIndex feed the Grafana Jira dashboard and the PPI formula in Metrics.
pingPongIndexPPI sourceseverityBug impactsprintCadence slicerootCauseRework taxonomyenvironmentSIT / UAT / PRODteamNameSquad filtertimeSpentEffortbugTypeBug classBesides Jira bugs, Newman also writes SonarCloud metrics into the same InfluxDB. Measurements tree + metric tags power the Grafana Sonar dashboard (project keys omitted).
| metric tag | means | feeds |
|---|---|---|
coverage |
Test coverage | Sonar dashboard |
ncloc |
Lines of code | Sonar dashboard |
security_hotspots |
Security review | Sonar dashboard |
vulnerabilities |
Security | Sonar dashboard |
code_smells |
Maintainability | Sonar dashboard |
critical_violations |
Severity | Sonar dashboard |
sonarqube,metric=coverage,type=PERCENT value=72.4
sonarqube,metric=security_hotspots,type=INT value=12
Semi-manual step outside docker-compose up: the open-source Python tool test-reader scans service repos using YAML RegEx rules (@Test, file paths, descriptions), classifies automated tests by pyramid layer (Unit · Integration · Component · E2E) and exports counts to a Google Sheets metrics tab. Newman then reads that sheet via Google Sheets API into InfluxDB — powering the Pyramid Grafana dashboard alongside Jira and SonarCloud.
Configured per repo in YAML (TCC §3.2.8). Not wired into the Docker pipeline — run once per sprint before refreshing metrics.