Skip to content

Fix SDK graph census and Bun receipts; ship tested runtime bundles - #1421

Merged
unbraind merged 9 commits into
mainfrom
fix/prose-census-bun-receipts-runtime-bundles
Oct 6, 2026
Merged

unbraind merged 9 commits into
mainfrom
fix/prose-census-bun-receipts-runtime-bundles

Conversation

@unbraind

@unbraind unbraind commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Workspace assurance previously omitted body-only references in strict reads and split valid item IDs with multiple hyphens. Bun filtered linked tests could also be rejected despite executing successfully, while package installs could resolve a different runtime dependency tree from the one tested in CI. This change fixes those SDK primitives and publishes a staged tarball containing the tested production closure.

The same delivery replaces the vulnerable MCP development client identified by GHSA-6qxp-vccf-f47h and restores evidence-backed relationships across historical PM work.

Changes

  • Read item bodies consistently through the SDK workspace assurance adapter; recognize complete numeric, case-insensitive and multi-hyphen identifiers without shorter-prefix phantom references.
  • Record positive linked-test execution evidence and its output stream. Real Bun summaries pass; explicit empty runs, failing assertions and nonzero exits continue to fail. Receipt parsing is a separate production module within the unchanged file-length limits.
  • Derive a deterministic 40-package production ledger from the tested pnpm lock. Stage physical runtime packages without the development store or source maps, reject manifest/version/closure drift, and use the same tarball path for CI, smoke acceptance and provenance publication.
  • Preserve the existing application artifact budget and impose separate runtime payload limits. Missing, non-integer or unsafe runtime ceilings fail closed. Version synchronization includes both ledger identities. TypeScript consumers declare the bounded optional Node types peer.
  • Report Codecov coverage independently of optional skipped or quota-limited reviews while retaining strict branch protection, both 100% targets and zero tolerance. Missing provider reports now explicitly fail.
  • Preserve executable metadata during lock repair so fresh frozen installations generate the complete CodSpeed launcher programs. Use the real Windows npm installation in packer fixtures, split lifecycle baseline/mutant cases into independent unchanged time bounds, and group release environment exports for strict ShellCheck admission.
  • Align MCP client/core development peers at 2.2.0. The repository consumes erased server metadata types and does not call the vulnerable upstream OAuth flow; existing issuer/scope controls remain verified.
  • Add 346 historical graph edges across 56 sources: 223 verifies, 108 discovered_from, and 15 related. Preserve lifecycle evidence and append-only history. Pin eight already verified historical releases so graph enrichment cannot move shipped work into Unreleased.

PM lineage

Validation

  • Complete final-head hosted admission at 77977d9ed1e295237327422714e7eab4524cfd76: all 26 required contexts pass, including genuine codecov/patch, static, coverage, typecheck, Windows regression, security and six packed first-run environments. Workflow 37542981912 artifacts verify every one of 768 measured source files at exact 100/100/100/100: 63,919/63,919 lines, 67,071/67,071 statements, 13,834/13,834 functions and 51,342/51,342 branches. JUnit records 9,881 passed, two existing Windows-only skips on Linux, and zero failures/errors; the separate native Windows job passes. Earlier metadata-only heads reproduced exact coverage but lacked the required provider notification even after a genuine upload retry. Independent notification scheduling restores the actual provider check while retaining both 100% targets, zero tolerance, explicit missing-report failure and every required native gate. The official YAML validator and existing checksum/upload negative controls pass. Both the closure/changelog head and the final native receipt head independently pass all 26 required contexts; the final coverage artifact digest is sha256:8310e94038a9e7837a7fa30b78881bcb6e3626fde0d1c269d70763752e5850ee.
  • Merged main f81d9a5618f9d8bb131ac3ae5216c225e447111b has the identical reviewed tree. Its independent CI run 37544404242 reproduces all four exact 100% totals across every measured file and 9,881 passed cases. All six main workflows finish successfully: CI, Security and Script Quality, CodeQL, Docs, CodSpeed and OSSF Scorecard. The issue-close release hooks skip without another publication. Fresh final security inventories and the dependency audit contain zero findings, and no PRs remain open. All five PM links resolve to actual files on main.
  • Four TypeScript projects, frozen installation and the full dependency audit pass. Initial hosted feedback found fresh-install launcher metadata, Windows fixture/timing and ShellCheck problems; the combined corrections pass without changing any thresholds. The subsequent 51,341/51,342 branch refusal led to one npm 12 keyed-receipt compatibility case that retains real npm execution and actual tarballs. Complete hosted coverage now passes. Native PM history preserves the original failures and successful fixes, including local SDK/transport latency failures followed by hosted success under unchanged budgets. A fresh offline frozen installation passes the unchanged CodSpeed program/hash policy, and checksummed actionlint 1.7.12 passes.
  • Temporary staged-tarball acceptance passes Node, Bun, npx, bunx, public SDK compilation/composition and 40-package installed-runtime verification. The corrected application artifact including the generated changelog measures 19,979,822 bytes / 1,757 files; runtime bundle: 23,334,884 bytes / 4,731 files; zero source maps. The restored ledger adds executable metadata without changing its 40 package versions; the actual correction artifact passes the unchanged budgets.
  • Latest pm-changelog 2026.10.5 projects 2,582 selected completed items. All previously generated historical release sections are byte-for-byte preserved. All five implementation owners are closed and unclaimed; the complete strict 2,901-item corpus has zero in-progress items. The notification owner's immutable close event includes its actual hosted admission, and the generated changelog is included in this PR.

Regression development includes failing controls for omitted bodies, identifier splitting and real Bun filtering; distribution tests use actual filesystem closures, npm packing and installed consumers. The exactly-once release fixture covers already-published days and packing failures before publication. Fresh temporary consumers exercise Node, Bun, npx, bunx and public SDK composition.

Review evidence

Round one reported fresh-install CodSpeed, Windows fixture/timing and actionlint failures; the combined corrections retain all source, inventory, coverage and quality thresholds. Every bot artifact was read, reacted to and acknowledged by revision. CodeRabbit refused the full 158-file scope under its 100-file allowance, and Sourcery reported an exhausted rolling review budget. Their unavailable code reviews are recorded explicitly; the PR scope is preserved. The authenticated direct Greptile committed-head review returned free_reviews_limit_reached. CodeRabbit also reports its separate fewer-than-ten-stars automatic-review policy. Cubic also reports its monthly 40,000-line allowance exhausted. All four provider limitations remain explicit; no unavailable review is treated as approval. Round-two Codecov feedback identified one missing npm 12 receipt branch, which is now covered by a compatibility test retaining real npm child execution and actual tarballs. Exact-commit hosted admission verifies strict main protection and zero DeepScan/CodeFactor PR findings on final head 77977d9; Chrome separately confirms two existing generated plugin-copy duplication reports on main, tracked by the canonical duplication/CodeFactor lineage.

Sourcery correctly identified that issue #1417 originally proposed _hasShrinkwrap=true. This PR publishes the physical tested runtime closure for both npm and Bun, contains no npm-shrinkwrap.json, and leaves that literal metadata criterion unmet. The issue retains the original report and now documents the verified alternative. Cross-day installation of the next published version remains a separate publication observation.

Fresh reports arriving during final review are routed without new PM duplicates: #1420 matches completed pm-gh1413. A fresh 70-item source probe verifies the exact 50/30 producer boundary resumes at position 30; registry adoption remains pending. #1419 is retained as a future linked-test editing fixture under the existing pm-gh1381 metadata-reference feature, which remains open and unclaimed. This PR records its complete proposal; it does not implement that future editor.

Release and remaining scope

The immutable npm version 2026.10.6 was already published before this work. This PR is eligible for the next daily release and does not republish today's version. The fresh dependency census records 13 newer upstream candidates with no current/wanted gap; major migrations remain assigned to canonical owners because peer, runtime and Sentry contracts are still unmet. Existing historical hierarchy, structured-evidence and docstring-content debt remain tracked; the static report identifies 4,130 legacy filler entries across 204 files. Graph waivers and the original prose-gap ceiling are unchanged. The fresh required operational gate reports zero high/critical Sentry issues, a 3.25% telemetry finish-error rate against the unchanged 6% limit and zero missing error-code rows. The native flush drained one pending valid entry to zero without an error; the newest stored event was 1.95 seconds old when inspected. Empty fresh trace results leave trace completeness unverified. Hosted Windows jobs provide the platform-specific evidence skipped locally.

Closes #1417
Closes #1418

…dles

Include bodies in strict and ordinary SDK assurance workspace contexts and
recognize complete multi-hyphen identifiers without phantom prefix matches.
Restore 346 evidence-backed historical graph edges through native PM history
while preserving lifecycle metadata and verified historical release buckets.

Recognize actual Bun filtered execution summaries and retain positive receipt
codes with their output stream. Explicit empty output, failed assertions and
nonzero process results remain failures. Separate receipt parsing from process
orchestration within the existing source-size limits.

Project the tested pnpm production closure into a shipped deterministic ledger,
stage its physical packages without development dependencies or source maps,
and publish that staged tarball through CI and the daily release workflow.
Verify installed package identity and all 40 runtime versions, preserve the
application artifact limits, and bound the optional Node declaration peer.

Replace vulnerable MCP client/core development peers with aligned 2.2.0
overrides and frozen-lock evidence for GHSA-6qxp-vccf-f47h. Preserve metadata
type compatibility and the SDK's independent issuer and scope controls.

Deliver linked tests, SDK documentation, generated contracts, immutable PM
closure evidence and the package-generated changelog together for pm-jprn58,
pm-axotea, pm-gh1418, pm-gh1417 and pm-mcpoauth. Today's immutable version is
not republished; the next eligible daily release carries this source.
@sourcery-ai

sourcery-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 23 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 166 files, which is 66 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Repository UI (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: c4b6e416-1024-494a-af75-e4486269d712
📥 Commits

Reviewing files that changed from the base of the PR and between 686e764 and 77977d9.

⛔ Files ignored due to path filters (3)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • src/sdk/generated/generated-error-code-catalog-part-1.ts is excluded by !**/generated/**
  • src/sdk/generated/generated-error-code-catalog-part-2.ts is excluded by !**/generated/**
📒 Files selected for processing (166)
  • .agents/pm/chores/pm-3rgp.toon
  • .agents/pm/chores/pm-o043.toon
  • .agents/pm/chores/pm-osea.toon
  • .agents/pm/chores/pm-othr.toon
  • .agents/pm/chores/pm-p37b.toon
  • .agents/pm/chores/pm-tq5t.toon
  • .agents/pm/chores/pm-wc0d.toon
  • .agents/pm/chores/pm-yj8n.toon
  • .agents/pm/chores/pm-zyse.toon
  • .agents/pm/epics/pm-33cw.toon
  • .agents/pm/epics/pm-qwoy.toon
  • .agents/pm/epics/pm-u9d0.toon
  • .agents/pm/extensions/.managed-extensions.json
  • .agents/pm/features/pm-d2wfig.toon
  • .agents/pm/features/pm-f3pa.toon
  • .agents/pm/features/pm-gh1381.toon
  • .agents/pm/features/pm-i1z6.toon
  • .agents/pm/features/pm-jyie.toon
  • .agents/pm/features/pm-mfl1.toon
  • .agents/pm/features/pm-o3nr.toon
  • .agents/pm/features/pm-pl53.toon
  • .agents/pm/features/pm-qo36.toon
  • .agents/pm/features/pm-rmjy.toon
  • .agents/pm/features/pm-rpag.toon
  • .agents/pm/features/pm-tb42.toon
  • .agents/pm/features/pm-tyj8.toon
  • .agents/pm/features/pm-u8n5.toon
  • .agents/pm/features/pm-v68d.toon
  • .agents/pm/features/pm-wt0g.toon
  • .agents/pm/features/pm-y1z0.toon
  • .agents/pm/features/pm-yj9w.toon
  • .agents/pm/features/pm-z9ho.toon
  • .agents/pm/history/pm-33cw.jsonl
  • .agents/pm/history/pm-34gb.jsonl
  • .agents/pm/history/pm-3rgp.jsonl
  • .agents/pm/history/pm-5dbn.jsonl
  • .agents/pm/history/pm-89qv6b.jsonl
  • .agents/pm/history/pm-axotea.jsonl
  • .agents/pm/history/pm-ayg31c.jsonl
  • .agents/pm/history/pm-b4cp.jsonl
  • .agents/pm/history/pm-d2wfig.jsonl
  • .agents/pm/history/pm-f3pa.jsonl
  • .agents/pm/history/pm-gh1381.jsonl
  • .agents/pm/history/pm-gh1413.jsonl
  • .agents/pm/history/pm-gh1417.jsonl
  • .agents/pm/history/pm-gh1418.jsonl
  • .agents/pm/history/pm-gnya.jsonl
  • .agents/pm/history/pm-hu11.jsonl
  • .agents/pm/history/pm-i1z6.jsonl
  • .agents/pm/history/pm-ixm6.jsonl
  • .agents/pm/history/pm-jprn58.jsonl
  • .agents/pm/history/pm-jyie.jsonl
  • .agents/pm/history/pm-ltbr.jsonl
  • .agents/pm/history/pm-m2kl.jsonl
  • .agents/pm/history/pm-mcpoauth.jsonl
  • .agents/pm/history/pm-mcxr.jsonl
  • .agents/pm/history/pm-mfl1.jsonl
  • .agents/pm/history/pm-miju.jsonl
  • .agents/pm/history/pm-nh73.jsonl
  • .agents/pm/history/pm-nnro.jsonl
  • .agents/pm/history/pm-o043.jsonl
  • .agents/pm/history/pm-o3nr.jsonl
  • .agents/pm/history/pm-osea.jsonl
  • .agents/pm/history/pm-othr.jsonl
  • .agents/pm/history/pm-p37b.jsonl
  • .agents/pm/history/pm-pl53.jsonl
  • .agents/pm/history/pm-qo36.jsonl
  • .agents/pm/history/pm-qwoy.jsonl
  • .agents/pm/history/pm-r0z2.jsonl
  • .agents/pm/history/pm-rmjy.jsonl
  • .agents/pm/history/pm-rpag.jsonl
  • .agents/pm/history/pm-tb42.jsonl
  • .agents/pm/history/pm-tk1z.jsonl
  • .agents/pm/history/pm-tq5t.jsonl
  • .agents/pm/history/pm-tra4.jsonl
  • .agents/pm/history/pm-tyj8.jsonl
  • .agents/pm/history/pm-u42x.jsonl
  • .agents/pm/history/pm-u8n5.jsonl
  • .agents/pm/history/pm-u9d0.jsonl
  • .agents/pm/history/pm-v3f1n4.jsonl
  • .agents/pm/history/pm-v4iypw.jsonl
  • .agents/pm/history/pm-v68d.jsonl
  • .agents/pm/history/pm-vk7zek.jsonl
  • .agents/pm/history/pm-wc0d.jsonl
  • .agents/pm/history/pm-wenq.jsonl
  • .agents/pm/history/pm-wo7x.jsonl
  • .agents/pm/history/pm-wt0g.jsonl
  • .agents/pm/history/pm-xugp.jsonl
  • .agents/pm/history/pm-xvt7ps.jsonl
  • .agents/pm/history/pm-xy9n.jsonl
  • .agents/pm/history/pm-y1z0.jsonl
  • .agents/pm/history/pm-yj8n.jsonl
  • .agents/pm/history/pm-yj9w.jsonl
  • .agents/pm/history/pm-yy8rmx.jsonl
  • .agents/pm/history/pm-z9ho.jsonl
  • .agents/pm/history/pm-zyse.jsonl
  • .agents/pm/issues/pm-axotea.toon
  • .agents/pm/issues/pm-ayg31c.toon
  • .agents/pm/issues/pm-gh1413.toon
  • .agents/pm/issues/pm-gh1417.toon
  • .agents/pm/issues/pm-gh1418.toon
  • .agents/pm/issues/pm-jprn58.toon
  • .agents/pm/issues/pm-ltbr.toon
  • .agents/pm/issues/pm-mcpoauth.toon
  • .agents/pm/issues/pm-mcxr.toon
  • .agents/pm/issues/pm-u42x.toon
  • .agents/pm/issues/pm-v3f1n4.toon
  • .agents/pm/issues/pm-vk7zek.toon
  • .agents/pm/issues/pm-xvt7ps.toon
  • .agents/pm/issues/pm-xy9n.toon
  • .agents/pm/stories/pm-34gb.toon
  • .agents/pm/stories/pm-5dbn.toon
  • .agents/pm/stories/pm-b4cp.toon
  • .agents/pm/stories/pm-gnya.toon
  • .agents/pm/stories/pm-hu11.toon
  • .agents/pm/stories/pm-ixm6.toon
  • .agents/pm/stories/pm-m2kl.toon
  • .agents/pm/stories/pm-miju.toon
  • .agents/pm/stories/pm-nh73.toon
  • .agents/pm/stories/pm-nnro.toon
  • .agents/pm/stories/pm-r0z2.toon
  • .agents/pm/stories/pm-tra4.toon
  • .agents/pm/stories/pm-wo7x.toon
  • .agents/pm/stories/pm-xugp.toon
  • .agents/pm/tasks/pm-89qv6b.toon
  • .agents/pm/tasks/pm-tk1z.toon
  • .agents/pm/tasks/pm-v4iypw.toon
  • .agents/pm/tasks/pm-wenq.toon
  • .agents/pm/tasks/pm-yy8rmx.toon
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • CHANGELOG.md
  • codecov.yml
  • docs/RELEASING.md
  • docs/SDK.md
  • package.json
  • pnpm-workspace.yaml
  • runtime-dependencies.json
  • scripts/release/hosted-analysis-gate.mjs
  • scripts/release/package-artifact-budget.json
  • scripts/release/package-artifact-gate.mjs
  • scripts/release/package-distribution.mjs
  • scripts/release/runtime-lock.mjs
  • scripts/release/verify-runtime-installation.mjs
  • scripts/release/version-manifests.mjs
  • scripts/smoke-npx-from-pack.mjs
  • scripts/sync-versions.mjs
  • sdk/public-surface.json
  • src/sdk/governance/assurance-runtime.ts
  • src/sdk/governance/assurance.ts
  • src/sdk/test/execution-receipts.ts
  • src/sdk/test/execution.ts
  • tests/fixtures/contracts/full.json
  • tests/helpers/releaseContracts.ts
  • tests/integration/assurance-runtime.integration.spec.ts
  • tests/integration/ci-workflow-contract.spec.ts
  • tests/integration/release-automation-contract.spec.ts
  • tests/integration/test-execution/linked-test-bun-receipts.integration.spec.ts
  • tests/unit/scripts/lifecycle-evidence-control.spec.ts
  • tests/unit/scripts/package-distribution.spec.ts
  • tests/unit/scripts/release/package-artifact-gate.spec.ts
  • tests/unit/scripts/runtime-lock.spec.ts
  • tests/unit/scripts/smoke-npx-from-pack.spec.ts
  • tests/unit/scripts/sync-versions.spec.ts
  • tests/unit/sdk/governance/assurance-relationship-sources.spec.ts
  • tests/unit/sdk/test/execution-receipts.spec.ts

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR fixes SDK assurance and linked-test evidence handling, removes the vulnerable MCP development dependency path, and replaces ordinary packaging with a deterministic, tested production-runtime tarball used consistently by CI, smoke tests, and release publication; it also backfills evidence-backed historical PM graph relationships and release attribution.

Sequence diagram for reproducible runtime packaging and publication

sequenceDiagram
    participant CI
    participant Lock as runtime-lock.mjs
    participant Pack as package-distribution.mjs
    participant NPM as npm
    participant Verify as verify-runtime-installation.mjs
    participant Registry as npm registry

    CI->>Lock: check
    Lock-->>CI: Tested ledger matches pnpm lock
    CI->>Pack: package-distribution.mjs
    Pack->>NPM: pack --dry-run
    Pack->>Pack: stageRuntime
    Pack->>NPM: pack staged tree
    NPM-->>Pack: publication tarball
    Pack-->>CI: tarball path
    CI->>Verify: verifyRuntimeInstallation
    Verify-->>CI: Runtime versions match ledger
    CI->>Registry: publish tarball with provenance
Loading

Sequence diagram for SDK assurance and linked-test evidence

sequenceDiagram
    participant Consumer as SDK consumer
    participant Runtime as Assurance runtime
    participant Store as Item store
    participant Tests as Linked test runner
    participant Receipt as Receipt parser

    Consumer->>Runtime: createAssuranceWorkspaceContext
    Runtime->>Store: listAllItemMetadataWithBody
    Store-->>Runtime: Items with metadata and bodies
    Runtime->>Runtime: evaluateMeasurement
    Runtime->>Runtime: evaluateAssuranceGate
    Consumer->>Tests: Run filtered linked tests
    Tests-->>Receipt: TestRunResult.execution_receipt
    Receipt-->>Runtime: Recognized Bun summary and stdout or stderr
    Runtime-->>Consumer: Assurance result
Loading

File-Level Changes

Change Details Files
Make SDK assurance workspace projections and prose graph census complete and identifier-safe.
  • Include item bodies in both strict and ordinary assurance reads.
  • Match complete case-insensitive numeric and multi-hyphen IDs while preventing prefix or embedded-token false matches.
  • Add integration and regression coverage for body-only references and identifier edge cases.
src/sdk/governance/assurance-runtime.ts
src/sdk/governance/assurance.ts
tests/integration/assurance-runtime.integration.spec.ts
tests/unit/sdk/governance/assurance-relationship-sources.spec.ts
docs/SDK.md
Record reliable execution receipts for linked tests, including Bun filtered runs.
  • Extract positive runner summaries with their originating output stream.
  • Recognize Bun pass and executed-test summaries without weakening empty-run, exit-code, or assertion-failure handling.
  • Move receipt parsing into a dedicated production module and test SDK/CLI/test-all behavior.
src/sdk/test/execution-receipts.ts
src/sdk/test/execution.ts
tests/unit/sdk/test/execution-receipts.spec.ts
tests/integration/test-execution/linked-test-bun-receipts.integration.spec.ts
docs/SDK.md
Publish the exact production runtime closure tested in CI through a staged tarball.
  • Project the pnpm lock's integrity-checked production graph into a deterministic runtime ledger preserving conflicts, optional edges, peer contexts, and cycles.
  • Stage physical runtime packages without development dependencies or source maps, validate manifest/ledger/installed-version consistency, and reject unsafe or drifted closures.
  • Use the staging path for CI, smoke tests, release publication, provenance, and separate runtime/application artifact budgets.
  • Synchronize ledger identities during version updates and declare bounded optional Node types as a peer for TypeScript consumers.
runtime-dependencies.json
scripts/release/runtime-lock.mjs
scripts/release/package-distribution.mjs
scripts/release/verify-runtime-installation.mjs
scripts/release/package-artifact-gate.mjs
scripts/release/package-artifact-budget.json
scripts/release/version-manifests.mjs
scripts/sync-versions.mjs
package.json
pnpm-lock.yaml
docs/RELEASING.md
docs/SDK.md
.github/workflows/ci.yml
.github/workflows/release.yml
scripts/smoke-npx-from-pack.mjs
tests/unit/scripts/runtime-lock.spec.ts
tests/unit/scripts/package-distribution.spec.ts
tests/unit/scripts/release/package-artifact-gate.spec.ts
tests/unit/scripts/smoke-npx-from-pack.spec.ts
tests/unit/scripts/sync-versions.spec.ts
Remove the vulnerable MCP development client dependency path while retaining compatible MCP development peers and existing security controls.
  • Pin MCP client and core development peers to 2.2.0.
  • Update lockfile, changelog, and assurance metadata documenting the non-use of the vulnerable OAuth flow.
pnpm-workspace.yaml
pnpm-lock.yaml
CHANGELOG.md
.agents/pm/issues/pm-mcpoauth.toon
.agents/pm/history/pm-mcpoauth.jsonl
Restore historical PM graph lineage and release attribution evidence.
  • Add 346 evidence-backed typed relationships across 56 historical sources while preserving append-only history and lifecycle evidence.
  • Pin already verified historical releases so enrichment does not move shipped work to Unreleased.
  • Update changelog ordering and historical PM records.
.agents/pm/chores/pm-3rgp.toon
.agents/pm/chores/pm-o043.toon
.agents/pm/chores/pm-osea.toon
.agents/pm/chores/pm-othr.toon
.agents/pm/chores/pm-p37b.toon
.agents/pm/chores/pm-tq5t.toon
.agents/pm/chores/pm-wc0d.toon
.agents/pm/chores/pm-yj8n.toon
.agents/pm/chores/pm-zyse.toon
.agents/pm/epics/pm-33cw.toon
.agents/pm/epics/pm-qwoy.toon
.agents/pm/features/pm-d2wfig.toon
.agents/pm/features/pm-f3pa.toon
.agents/pm/features/pm-i1z6.toon
.agents/pm/features/pm-jyie.toon
.agents/pm/features/pm-mfl1.toon
.agents/pm/features/pm-o3nr.toon
.agents/pm/features/pm-pl53.toon
.agents/pm/features/pm-qo36.toon
.agents/pm/features/pm-rmjy.toon
.agents/pm/features/pm-rpag.toon
.agents/pm/features/pm-tb42.toon
.agents/pm/features/pm-tyj8.toon
.agents/pm/features/pm-u8n5.toon
.agents/pm/features/pm-v68d.toon
.agents/pm/features/pm-wt0g.toon
.agents/pm/features/pm-y1z0.toon
.agents/pm/features/pm-yj9w.toon
.agents/pm/features/pm-z9ho.toon
.agents/pm/issues/pm-axotea.toon
.agents/pm/issues/pm-ayg31c.toon
.agents/pm/issues/pm-gh1417.toon
.agents/pm/issues/pm-gh1418.toon
.agents/pm/issues/pm-jprn58.toon
.agents/pm/issues/pm-ltbr.toon
.agents/pm/issues/pm-mcpoauth.toon
.agents/pm/issues/pm-mcxr.toon
.agents/pm/issues/pm-u42x.toon
.agents/pm/issues/pm-v3f1n4.toon
.agents/pm/issues/pm-vk7zek.toon
.agents/pm/issues/pm-xvt7ps.toon
.agents/pm/issues/pm-xy9n.toon
.agents/pm/history/pm-33cw.jsonl
.agents/pm/history/pm-34gb.jsonl
.agents/pm/history/pm-3rgp.jsonl
.agents/pm/history/pm-5dbn.jsonl
.agents/pm/history/pm-89qv6b.jsonl
.agents/pm/history/pm-axotea.jsonl
.agents/pm/history/pm-ayg31c.jsonl
.agents/pm/history/pm-d2wfig.jsonl
.agents/pm/history/pm-f3pa.jsonl
.agents/pm/history/pm-gh1417.jsonl
.agents/pm/history/pm-gh1418.jsonl
.agents/pm/history/pm-gnya.jsonl
.agents/pm/history/pm-hu11.jsonl
.agents/pm/history/pm-i1z6.jsonl
.agents/pm/history/pm-ixm6.jsonl
.agents/pm/history/pm-jprn58.jsonl
.agents/pm/history/pm-jyie.jsonl
.agents/pm/history/pm-ltbr.jsonl
.agents/pm/history/pm-m2kl.jsonl
.agents/pm/history/pm-mcpoauth.jsonl
.agents/pm/history/pm-mcxr.jsonl
.agents/pm/history/pm-mfl1.jsonl
.agents/pm/history/pm-miju.jsonl
.agents/pm/history/pm-nh73.jsonl
.agents/pm/history/pm-nnro.jsonl
.agents/pm/history/pm-o043.jsonl
.agents/pm/history/pm-o3nr.jsonl
.agents/pm/history/pm-osea.jsonl
.agents/pm/history/pm-othr.jsonl
.agents/pm/history/pm-p37b.jsonl
.agents/pm/history/pm-pl53.jsonl
.agents/pm/history/pm-qo36.jsonl
.agents/pm/history/pm-qwoy.jsonl
.agents/pm/history/pm-r0z2.jsonl
.agents/pm/history/pm-rmjy.jsonl
.agents/pm/history/pm-rpag.jsonl
.agents/pm/history/pm-tb42.jsonl
.agents/pm/history/pm-tk1z.jsonl
.agents/pm/history/pm-tq5t.jsonl
.agents/pm/history/pm-tra4.jsonl
.agents/pm/history/pm-tyj8.jsonl
.agents/pm/history/pm-u42x.jsonl
.agents/pm/history/pm-u8n5.jsonl
.agents/pm/history/pm-v3f1n4.jsonl
.agents/pm/history/pm-v4iypw.jsonl
.agents/pm/history/pm-v68d.jsonl
.agents/pm/history/pm-vk7zek.jsonl
.agents/pm/history/pm-wc0d.jsonl
.agents/pm/history/pm-wenq.jsonl
.agents/pm/history/pm-wo7x.jsonl
.agents/pm/history/pm-wt0g.jsonl
.agents/pm/history/pm-xugp.jsonl
.agents/pm/history/pm-xvt7ps.jsonl
.agents/pm/history/pm-xy9n.jsonl
.agents/pm/history/pm-y1z0.jsonl
.agents/pm/history/pm-yj8n.jsonl
.agents/pm/history/pm-yj9w.jsonl
.agents/pm/history/pm-yy8rmx.jsonl
.agents/pm/history/pm-z9ho.jsonl
.agents/pm/history/pm-zyse.jsonl
.agents/pm/issues/pm-jprn58.toon
.agents/pm/stories/pm-34gb.toon
.agents/pm/stories/pm-5dbn.toon
.agents/pm/stories/pm-b4cp.toon
.agents/pm/stories/pm-gnya.toon
.agents/pm/stories/pm-hu11.toon
.agents/pm/stories/pm-ixm6.toon
.agents/pm/stories/pm-m2kl.toon
.agents/pm/stories/pm-miju.toon
.agents/pm/stories/pm-nh73.toon
.agents/pm/stories/pm-nnro.toon
.agents/pm/stories/pm-r0z2.toon
.agents/pm/stories/pm-tra4.toon
.agents/pm/stories/pm-wo7x.toon
.agents/pm/stories/pm-xugp.toon
.agents/pm/tasks/pm-89qv6b.toon
.agents/pm/tasks/pm-tk1z.toon
.agents/pm/tasks/pm-v4iypw.toon
.agents/pm/tasks/pm-wenq.toon
.agents/pm/tasks/pm-yy8rmx.toon
.agents/pm/extensions/.managed-extensions.json
CHANGELOG.md

Assessment against linked issues

Issue Objective Addressed Explanation
#1417 Publish a tested, exact production dependency tree with the CLI so pinned npm installs are reproducible and cannot re-resolve floating transitive dependencies. ❌ The PR implements an alternative mechanism: it generates a runtime dependency ledger and publishes the tested runtime closure as bundled physical dependencies, with CI and installation verification. This likely makes npm and Bun installs reproducible, but it explicitly does not ship npm-shrinkwrap.json, so the stated acceptance criterion that npm view ... _hasShrinkwrap is true is not met.
#1417 Remove @types/node from runtime dependencies and replace the unbounded range with a bounded, optional consumer-facing type dependency. ✅
#1417 Ensure the release artifact and publication process use the exact runtime tree tested by CI, with validation against dependency and package drift. ✅
#1418 Recognize successful, name-filtered Bun test executions as having positive execution receipts when Bun reports a nonzero pass count or a nonzero executed-test summary on either stdout or stderr. ✅
#1418 Classify filtered runs as empty only when output explicitly indicates that zero tests matched or ran, while continuing to fail runs with nonzero exit codes or failed assertions. ✅
#1418 Preserve explainable execution evidence in the run result and avoid rewriting a zero exit code to 1 unless a specific matched empty-run or assertion reason justifies it. ✅

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Record the concrete PR and implementation source through native PM comments and immutable history. Keep hosted checks and reviewer completion explicitly pending until their exact-head receipts are available.
@codspeed

codspeed Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 11 untouched benchmarks


Comparing fix/prose-census-bun-receipts-runtime-bundles (77977d9) with main (686e764)

Open in CodSpeed

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review

Please review the current head, including the SDK assurance and Bun receipt changes, staged runtime closure, release decision boundary, dependency remediation and PM evidence. The final push adds PR linkage only; implementation and local verification are recorded in the PR description.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 158 files exceed the limit of 100.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Sourcery budget notice reviewed: #1421 (comment). The provider cannot perform a code review until its stated reset. The available guide is assessed separately, and this quota result is recorded as unavailable review evidence. The full PR scope and mandatory checks remain intact.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

CodeRabbit review-limit report reviewed: #1421 (comment). The complete 158-file scope exceeds the current 100-file allowance. This delivery includes source changes plus append-only historical PM graph evidence in one PR, as required. No files will be hidden or review thresholds reduced to turn this skipped result into an approval. A new full-review request will accompany the combined CI correction push; provider availability will remain explicit.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Sourcery guide reviewed: #1421 (comment). The packaging and SDK scope descriptions are useful. The literal _hasShrinkwrap=true acceptance mismatch is accurate and is now documented on issue #1417: #1417 (comment). The verified mechanism bundles all 40 tested runtime packages for npm and Bun; no shrinkwrap metadata assertion or cross-day published result is claimed. The possible #1413 link reflects historical tracker references; this PR adds no amount-only pagination implementation.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

CodSpeed performance receipt reviewed: #1421 (comment). The exact comparison is 3a37856 against 686e764 and reports 11 untouched benchmarks. This is accepted for that measured benchmark scope; the separate million-item graph benchmark and installed-consumer receipts cover different behavior. Native Windows, static and coverage failures from this head are being corrected before renewed verification.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

CodeRabbit full-review command response reviewed: #1421 (comment). The requested review was skipped for the same documented 158/100 file limit. This response contains no implementation findings or approval. It is acknowledged separately from the primary limit report so every provider artifact is accounted for without repeating a review request on this head.

Fail closed when bundled runtime byte or file ceilings are absent,
non-integral, negative, or unsafe. Retain legacy unbundled acceptance and
prove malformed profiles fail with real artifact validation controls.

Restore executable package metadata removed during pnpm lock repair,
without changing the repaired dependency versions or integrity values.
Verify a fresh frozen offline install against the unchanged CodSpeed
program and executable hash policy; synchronize runtime ledger metadata.

Resolve the actual Windows npm installation in packer acceptance and
bound each real lifecycle baseline and unsafe mutant independently.
Group release environment exports for strict actionlint and ShellCheck.
Keep all existing source, coverage, artifact and performance thresholds.

Record focused acceptance, installed Node/Bun/npx/bunx consumers, actual
artifact budgets, graph/history admission and mutation evidence in
pm-gh1417. Preserve failed local timing receipts and require hosted full
static, canonical coverage and native Windows checks before merge.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please review commit 81206c5 and the complete PR scope. This correction rejects malformed runtime ceilings, restores executable lock metadata verified through a fresh frozen install, fixes real Windows npm fixture resolution, independently bounds existing lifecycle baseline/mutant cases, and groups release environment writes for strict ShellCheck. All source, coverage, performance and artifact thresholds remain unchanged. Failed local timing receipts remain visible; the complete hosted gates must pass before merge. Previous provider capacity refusals remain recorded without narrowing or splitting this PR.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 159 files exceed the limit of 100.

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Updated CodeRabbit capacity report reviewed: #1421 (comment). The correction head now has 159 selected files and still exceeds the 100-file allowance. This remains an unavailable review; the complete source and append-only PM evidence scope is preserved, with no paid capacity, reduced filters or alternate base.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Updated CodSpeed receipt reviewed: #1421 (comment). The comparison now uses 81206c5 against main 686e764 and still reports 11 untouched benchmarks. This is accepted for that benchmark scope; mandatory hosted static and native Windows checks passed on this head, while exact branch coverage remains a separate unresolved gate being corrected.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

CodeRabbit renewed full-review response reviewed: #1421 (comment). The explicit request was skipped at 159/100 files. The response contains no findings or approval; it is recorded separately from the edited capacity report. Direct Greptile also returned free_reviews_limit_reached, so provider availability remains a limitation.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Codecov coverage finding accepted: #1421 (comment). The downloaded canonical summary confirms 51,341/51,342 branches, with package-distribution.mjs line 22 missing the npm 12 keyed-receipt branch on the npm 11 hosted runner. All tests passed and other dimensions are exact 100%, but this is correctly blocked. pm-gh1417 is reopened to add an actual npm packing receipt compatibility regression, keeping the global and patch thresholds unchanged.

Exercise the keyed npm 12 packing receipt on npm 11 CI runners while
retaining both real npm child executions, complete actual packlists and
the written tarball. Assert the staged runtime conflict locations and
published package identity instead of synthesizing a successful artifact.

The preceding canonical suite correctly rejected one uncovered branch
at 51341/51342. Focused packer admission now covers 92/92 lines, 96/96
statements, 8/8 functions and 67/67 branches; linked distribution and
correction suites pass 165 and 115 cases. Keep all exact global and patch
coverage thresholds unchanged and require renewed hosted admission.

Record reviewer dispositions, free-provider capacity limits, unchanged
full hosted static and Windows admission, fresh operational observations
and the corrected executable-metadata security evidence through native
PM history. Preserve earlier failures and release the completed owner.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please review the complete PR at b4e61d4. The new compatibility regression retains real npm executions, actual source/final packlists and the written tarball while routing receipts through npm 12's keyed format on npm 11 runners. This closes the exact missing branch identified by Codecov; focused packer coverage is 92/92 lines, 96/96 statements, 8/8 functions and 67/67 branches, and distribution/correction suites pass 165/115 cases. No source implementation or mandatory threshold changed in this correction. Native PM history includes the preceding hosted failures, successful full static/Windows checks, provider limits and operational observations. Full hosted canonical coverage and every required check must renew for this head.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 159 files exceed the limit of 100.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the updated automatic-review notice at #1421 (comment). The fewer-than-ten-stars automatic-review policy is separate from the explicit full-review request, which returned the 159/100-file limit. Both are provider limitations, not code approval. The requested integrated PM/source delivery remains intact; all required checks pass at b4e61d4.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the renewed b4e61d4 versus 686e764 report at #1421 (comment). Its eleven untouched benchmarks provide that measured scope. The independent mandatory static and transport budgets also pass on this exact hosted head; local timing failures remain preserved in PM receipts rather than erased or waived.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Verified the renewed report at #1421 (comment) against workflow 37534129028 artifacts. All 768 measured source files have exact 100/100/100/100 coverage: 63919/63919 lines, 67071/67071 statements, 13834/13834 functions, 51342/51342 branches. JUnit records 9881 passed, two existing Windows-only skips, zero failures/errors; the separate native Windows job passes. The prior npm keyed-receipt branch gap is closed by a real-packing compatibility test without narrowing coverage.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the explicit renewed-review refusal at #1421 (comment): 159 changed files exceed the 100-file allowance. This is not review approval and introduces no actionable code finding. The single integrated PR retains its native historical PM evidence and strict passing hosted gates; no scope exclusions or paid capacity purchase are used.

Verify the exact GH1420 producer-limit50/output-limit30 report in a
fresh 70-item temporary tracker. Current source resumes at position30
from the delivered index29; the immutable published version predates
the existing PR1416 fix. Record the duplicate under pm-gh1413 without
reopening completed work or creating a second owner.

Retain the complete GH1419 entry-preserving linked-test editing proposal
as a concrete fixture in the existing pm-gh1381 metadata identity and
edit-semantics feature. Link its whole-collection replacement predecessor
and the independently observed receipt boundary while leaving the
future implementation open and unclaimed.

Both GitHub reports now have canonical PM links. Regeneration with
pm-changelog 2026.10.5 preserves all 2,582 completed-item entries and
release buckets. Production source, tests and mandatory thresholds
remain identical to the fully passing implementation head.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please renew review for af0d096. The supplemental push routes two newly arrived reports to existing canonical PM owners: the exact 70-row GH1420 reproduction confirms the already merged pagination fix, and GH1419 is retained as a future metadata editing fixture. No duplicate PM item or source/test change was introduced. Required checks must cover this final head; provider limitations remain explicit.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 165 files exceed the limit of 100.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the 94412bd revision at #1421 (comment): full review could not start at 161/100 selected files and unavailable capacity. This remains an explicit provider limitation; the integrated PM evidence and unchanged strict code gates are retained.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the 94412bd comparison at #1421 (comment): eleven untouched benchmarks remain the measured scope. The subsequent af0d096 push changes only canonical PM report intake, with source and tests byte-identical to the passing b4e61d4 implementation.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the renewed 161/100-file full-review refusal at #1421 (comment). No code review or approval was produced; scope remains one integrated PR, and the new metadata-only head has its own renewed request and mandatory checks.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the af0d096 automatic-review notice at #1421 (comment). Its star-policy skip remains distinct from the explicit 165/100-file refusal. Both are unavailable review, not approval; the full integrated source and PM scope remains present.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the af0d096 versus 686e764 receipt at #1421 (comment): eleven untouched benchmarks are unchanged. Exact-head canonical coverage and every native workflow job pass; missing Codecov notification remains a separate investigated required context rather than a performance finding.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the explicit af0d096 review refusal at #1421 (comment): 165 files exceed the 100-file allowance. No code finding or approval is supplied. New report intake stays in its canonical PM owners and this single PR; no test/history exclusions or paid capacity change are used.

Both metadata-only heads retain exact canonical 100/100/100/100 coverage
and all native jobs pass. Codecov merges the authentic exact-head report
at 100 percent, yet its required patch context remains absent even after
a genuine upload retry. Remove notification scheduling dependencies on
optional skipped or quota-limited review services.

Keep both Codecov targets at 100 percent, zero tolerance and the existing
failed-CI error behavior. Explicitly fail when a head report is missing.
Every native quality gate and strict branch protection remain required;
no success status is manufactured and no coverage scope is changed.

The official Codecov validator accepts the policy, and the three existing
authenticated-upload/checksum negative controls pass in linked receipt
test-local-mux8pncm-pvkbhe. A fresh build passes. Reuse pm-gh1417 for this
active correction and regenerate its current-state changelog projection.
Exact-head provider admission remains required before closure and merge.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please renew review for 23eb473. Genuine exact-head coverage uploads merged at100% but the required Codecov notification remained absent on two metadata-only heads. This correction reports coverage independently of optional notification waits, preserves both100% targets/zero tolerance/failed-CI errors, explicitly fails missing reports, and leaves all26 strict required contexts intact. Official schema validation and authenticated checksum/upload negative controls pass. Only pm-gh1417 is actively in progress while actual provider admission is verified.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 166 files exceed the limit of 100.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the edited exact-head 23eb473 full-review refusal: 166 files exceed the 100-file allowance. This is unavailable review capacity, not code approval; the integrated scope is preserved. All 26 required contexts now pass on this head, including the genuine Codecov patch check after the notification correction.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the updated exact-head 23eb473 comparison against main 686e764: all 11 measured CodSpeed benchmarks are untouched. The report establishes this benchmark result; it does not override the independently recorded SDK and transport latency failures or the mandatory hosted static admission, which now passes.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the explicit renewed full-review command refusal at #1421 (comment): 166 selected files exceed the 100-file limit. No code review or approval was produced. This head retains the complete reviewed delivery and all required checks are green; provider capacity remains explicitly documented.

Close and release pm-gh1417 with immutable evidence from reviewed head
23eb473. All 26 required contexts pass,
including genuine Codecov patch notification and exact-head DeepScan and
CodeFactor admission under unchanged strict main protection.

The current hosted artifacts independently verify all 768 measured files
at 100% lines, statements, functions and branches, with 9881 passed cases,
zero failures or errors and two existing Windows-only Linux skips.
Preserve original failed controls and provider capacity limitations.

Regenerate CHANGELOG.md through the latest pm-changelog package, restore
the completed runtime item and preserve every historical release section.
The strict complete 2901-item corpus has no in-progress items, and all
five implementation owners are closed with ownership released. Published
2026.10.6 remains immutable; the next daily publication is separate proof.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please review the complete current head 3c03533137ec358d20b6650bd875092cfff6a4bd. This final commit records the actual strict notification admission from 23eb473, closes and releases the runtime owner, and regenerates the changelog through the latest package while preserving all historical release sections. Production code, dependency identities, measured coverage scope and every strict quality threshold are unchanged. The genuine Codecov patch notification now passes alongside all 26 required contexts; this final metadata head must independently pass the same checks before merge. Provider quota/capacity limitations remain explicit and are not treated as approval.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 166 files exceed the limit of 100.

Include the framework-generated receipt from the final changelog check,
linked to the existing pm-jprn58 extension metadata evidence. The latest
pm-changelog package remains 2026.10.5; every installed contribution,
capability, source identity and entry field is unchanged. Only the native
registry refresh timestamp advances to the completed check.

Preserve the authoritative native output instead of editing tracker
metadata by hand. This administrative closeout does not change source,
tests, runtime package versions, coverage scope or any quality threshold.
@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the edited exact-head 3c03533 full-review refusal: 166 selected files exceed the 100-file allowance. This remains unavailable code review, not approval. The complete closure/changelog head independently passes all 26 required contexts, including genuine Codecov notification. One native generated extension-receipt timestamp is being included in the same PR and will receive its own renewed full review request and admission.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the 3c03533 versus main 686e764 benchmark update: all 11 measured benchmarks are untouched. Every required current-head context also passes. The remaining native package-receipt timestamp does not change production code or benchmark scope; the next committed head will receive fresh mandatory checks.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the explicit renewed full-review command refusal at #1421 (comment): 166 files exceed the 100-file allowance. No code review or approval was produced. Current-head mandatory admission is green, and the generated receipt closeout retains the full integrated scope and will renew review/check requests.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

@greptileai
@coderabbitai full review
@sourcery-ai review

Please review the complete current head 77977d9ed1e295237327422714e7eab4524cfd76. The only new change includes the native pm-changelog activation receipt timestamp from the completed final check; all registry entries, contribution identities, source, tests, runtime versions and quality thresholds are unchanged. The preceding closure/changelog head 3c03533 independently passes all 26 required contexts, including genuine Codecov patch notification. This clean final receipt head is receiving the same complete mandatory admission. The current-head direct Greptile request again returned free_reviews_limit_reached; all provider limitations remain explicitly recorded as unavailable reviews.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped: 166 files exceed the limit of 100.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the final edited full-review refusal for exact head 77977d9: 166 selected files exceed the 100-file allowance. This remains unavailable review capacity, not code approval. The integrated scope is preserved. All 26 required contexts pass on this clean final head; genuine coverage artifacts independently verify every one of 768 source files at 100/100/100/100 and 9881 passed cases. Exact-head DeepScan and CodeFactor admission also passes.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the final 77977d9 versus main 686e764 comparison: all 11 measured CodSpeed benchmarks are untouched. The final native workflows and all 26 required contexts pass independently, including unchanged static performance budgets. Earlier local latency failures remain in PM history; this benchmark result is recorded at its actual scope.

@unbraind

unbraind commented Oct 6, 2026

Copy link
Copy Markdown
Owner Author

Read the final explicit full-review command refusal at #1421 (comment): 166 files exceed the 100-file allowance. No code review or approval was produced. The complete final head independently passes all required admission and genuine exact-count coverage; all review-provider quota/capacity limitations remain explicit before merge.

@unbraind
unbraind merged commit f81d9a5 into main Oct 6, 2026
40 checks passed
@unbraind
unbraind deleted the fix/prose-census-bun-receipts-runtime-bundles branch October 6, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant