Repository navigation
Fix SDK graph census and Bun receipts; ship tested runtime bundles - #1421
Conversation
…dles Include bodies in strict and ordinary SDK assurance workspace contexts and recognize complete multi-hyphen identifiers without phantom prefix matches. Restore 346 evidence-backed historical graph edges through native PM history while preserving lifecycle metadata and verified historical release buckets. Recognize actual Bun filtered execution summaries and retain positive receipt codes with their output stream. Explicit empty output, failed assertions and nonzero process results remain failures. Separate receipt parsing from process orchestration within the existing source-size limits. Project the tested pnpm production closure into a shipped deterministic ledger, stage its physical packages without development dependencies or source maps, and publish that staged tarball through CI and the daily release workflow. Verify installed package identity and all 40 runtime versions, preserve the application artifact limits, and bound the optional Node declaration peer. Replace vulnerable MCP client/core development peers with aligned 2.2.0 overrides and frozen-lock evidence for GHSA-6qxp-vccf-f47h. Preserve metadata type compatibility and the SDK's independent issuer and scope controls. Deliver linked tests, SDK documentation, generated contracts, immutable PM closure evidence and the package-generated changelog together for pm-jprn58, pm-axotea, pm-gh1418, pm-gh1417 and pm-mcpoauth. Today's immutable version is not republished; the next eligible daily release carries this source.
|
Important Review skippedToo many files! This PR contains 166 files, which is 66 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configuration
⛔ Files ignored due to path filters (3)
📒 Files selected for processing (166)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR fixes SDK assurance and linked-test evidence handling, removes the vulnerable MCP development dependency path, and replaces ordinary packaging with a deterministic, tested production-runtime tarball used consistently by CI, smoke tests, and release publication; it also backfills evidence-backed historical PM graph relationships and release attribution. Sequence diagram for reproducible runtime packaging and publicationsequenceDiagram
participant CI
participant Lock as runtime-lock.mjs
participant Pack as package-distribution.mjs
participant NPM as npm
participant Verify as verify-runtime-installation.mjs
participant Registry as npm registry
CI->>Lock: check
Lock-->>CI: Tested ledger matches pnpm lock
CI->>Pack: package-distribution.mjs
Pack->>NPM: pack --dry-run
Pack->>Pack: stageRuntime
Pack->>NPM: pack staged tree
NPM-->>Pack: publication tarball
Pack-->>CI: tarball path
CI->>Verify: verifyRuntimeInstallation
Verify-->>CI: Runtime versions match ledger
CI->>Registry: publish tarball with provenance
Sequence diagram for SDK assurance and linked-test evidencesequenceDiagram
participant Consumer as SDK consumer
participant Runtime as Assurance runtime
participant Store as Item store
participant Tests as Linked test runner
participant Receipt as Receipt parser
Consumer->>Runtime: createAssuranceWorkspaceContext
Runtime->>Store: listAllItemMetadataWithBody
Store-->>Runtime: Items with metadata and bodies
Runtime->>Runtime: evaluateMeasurement
Runtime->>Runtime: evaluateAssuranceGate
Consumer->>Tests: Run filtered linked tests
Tests-->>Receipt: TestRunResult.execution_receipt
Receipt-->>Runtime: Recognized Bun summary and stdout or stderr
Runtime-->>Consumer: Assurance result
File-Level Changes
Assessment against linked issues
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Record the concrete PR and implementation source through native PM comments and immutable history. Keep hosted checks and reviewer completion explicitly pending until their exact-head receipts are available.
|
@greptileai Please review the current head, including the SDK assurance and Bun receipt changes, staged runtime closure, release decision boundary, dependency remediation and PM evidence. The final push adds PR linkage only; implementation and local verification are recorded in the PR description. |
|
|
Sourcery budget notice reviewed: #1421 (comment). The provider cannot perform a code review until its stated reset. The available guide is assessed separately, and this quota result is recorded as unavailable review evidence. The full PR scope and mandatory checks remain intact. |
|
CodeRabbit review-limit report reviewed: #1421 (comment). The complete 158-file scope exceeds the current 100-file allowance. This delivery includes source changes plus append-only historical PM graph evidence in one PR, as required. No files will be hidden or review thresholds reduced to turn this skipped result into an approval. A new full-review request will accompany the combined CI correction push; provider availability will remain explicit. |
|
Sourcery guide reviewed: #1421 (comment). The packaging and SDK scope descriptions are useful. The literal |
|
CodSpeed performance receipt reviewed: #1421 (comment). The exact comparison is 3a37856 against 686e764 and reports 11 untouched benchmarks. This is accepted for that measured benchmark scope; the separate million-item graph benchmark and installed-consumer receipts cover different behavior. Native Windows, static and coverage failures from this head are being corrected before renewed verification. |
|
CodeRabbit full-review command response reviewed: #1421 (comment). The requested review was skipped for the same documented 158/100 file limit. This response contains no implementation findings or approval. It is acknowledged separately from the primary limit report so every provider artifact is accounted for without repeating a review request on this head. |
Fail closed when bundled runtime byte or file ceilings are absent, non-integral, negative, or unsafe. Retain legacy unbundled acceptance and prove malformed profiles fail with real artifact validation controls. Restore executable package metadata removed during pnpm lock repair, without changing the repaired dependency versions or integrity values. Verify a fresh frozen offline install against the unchanged CodSpeed program and executable hash policy; synchronize runtime ledger metadata. Resolve the actual Windows npm installation in packer acceptance and bound each real lifecycle baseline and unsafe mutant independently. Group release environment exports for strict actionlint and ShellCheck. Keep all existing source, coverage, artifact and performance thresholds. Record focused acceptance, installed Node/Bun/npx/bunx consumers, actual artifact budgets, graph/history admission and mutation evidence in pm-gh1417. Preserve failed local timing receipts and require hosted full static, canonical coverage and native Windows checks before merge.
|
@greptileai Please review commit 81206c5 and the complete PR scope. This correction rejects malformed runtime ceilings, restores executable lock metadata verified through a fresh frozen install, fixes real Windows npm fixture resolution, independently bounds existing lifecycle baseline/mutant cases, and groups release environment writes for strict ShellCheck. All source, coverage, performance and artifact thresholds remain unchanged. Failed local timing receipts remain visible; the complete hosted gates must pass before merge. Previous provider capacity refusals remain recorded without narrowing or splitting this PR. |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Updated CodeRabbit capacity report reviewed: #1421 (comment). The correction head now has 159 selected files and still exceeds the 100-file allowance. This remains an unavailable review; the complete source and append-only PM evidence scope is preserved, with no paid capacity, reduced filters or alternate base. |
|
Updated CodSpeed receipt reviewed: #1421 (comment). The comparison now uses 81206c5 against main 686e764 and still reports 11 untouched benchmarks. This is accepted for that benchmark scope; mandatory hosted static and native Windows checks passed on this head, while exact branch coverage remains a separate unresolved gate being corrected. |
|
CodeRabbit renewed full-review response reviewed: #1421 (comment). The explicit request was skipped at 159/100 files. The response contains no findings or approval; it is recorded separately from the edited capacity report. Direct Greptile also returned free_reviews_limit_reached, so provider availability remains a limitation. |
|
Codecov coverage finding accepted: #1421 (comment). The downloaded canonical summary confirms 51,341/51,342 branches, with package-distribution.mjs line 22 missing the npm 12 keyed-receipt branch on the npm 11 hosted runner. All tests passed and other dimensions are exact 100%, but this is correctly blocked. pm-gh1417 is reopened to add an actual npm packing receipt compatibility regression, keeping the global and patch thresholds unchanged. |
Exercise the keyed npm 12 packing receipt on npm 11 CI runners while retaining both real npm child executions, complete actual packlists and the written tarball. Assert the staged runtime conflict locations and published package identity instead of synthesizing a successful artifact. The preceding canonical suite correctly rejected one uncovered branch at 51341/51342. Focused packer admission now covers 92/92 lines, 96/96 statements, 8/8 functions and 67/67 branches; linked distribution and correction suites pass 165 and 115 cases. Keep all exact global and patch coverage thresholds unchanged and require renewed hosted admission. Record reviewer dispositions, free-provider capacity limits, unchanged full hosted static and Windows admission, fresh operational observations and the corrected executable-metadata security evidence through native PM history. Preserve earlier failures and release the completed owner.
|
@greptileai Please review the complete PR at b4e61d4. The new compatibility regression retains real npm executions, actual source/final packlists and the written tarball while routing receipts through npm 12's keyed format on npm 11 runners. This closes the exact missing branch identified by Codecov; focused packer coverage is 92/92 lines, 96/96 statements, 8/8 functions and 67/67 branches, and distribution/correction suites pass 165/115 cases. No source implementation or mandatory threshold changed in this correction. Native PM history includes the preceding hosted failures, successful full static/Windows checks, provider limits and operational observations. Full hosted canonical coverage and every required check must renew for this head. |
|
|
Read the updated automatic-review notice at #1421 (comment). The fewer-than-ten-stars automatic-review policy is separate from the explicit full-review request, which returned the 159/100-file limit. Both are provider limitations, not code approval. The requested integrated PM/source delivery remains intact; all required checks pass at b4e61d4. |
|
Read the renewed b4e61d4 versus 686e764 report at #1421 (comment). Its eleven untouched benchmarks provide that measured scope. The independent mandatory static and transport budgets also pass on this exact hosted head; local timing failures remain preserved in PM receipts rather than erased or waived. |
|
Verified the renewed report at #1421 (comment) against workflow 37534129028 artifacts. All 768 measured source files have exact 100/100/100/100 coverage: 63919/63919 lines, 67071/67071 statements, 13834/13834 functions, 51342/51342 branches. JUnit records 9881 passed, two existing Windows-only skips, zero failures/errors; the separate native Windows job passes. The prior npm keyed-receipt branch gap is closed by a real-packing compatibility test without narrowing coverage. |
|
Read the explicit renewed-review refusal at #1421 (comment): 159 changed files exceed the 100-file allowance. This is not review approval and introduces no actionable code finding. The single integrated PR retains its native historical PM evidence and strict passing hosted gates; no scope exclusions or paid capacity purchase are used. |
Verify the exact GH1420 producer-limit50/output-limit30 report in a fresh 70-item temporary tracker. Current source resumes at position30 from the delivered index29; the immutable published version predates the existing PR1416 fix. Record the duplicate under pm-gh1413 without reopening completed work or creating a second owner. Retain the complete GH1419 entry-preserving linked-test editing proposal as a concrete fixture in the existing pm-gh1381 metadata identity and edit-semantics feature. Link its whole-collection replacement predecessor and the independently observed receipt boundary while leaving the future implementation open and unclaimed. Both GitHub reports now have canonical PM links. Regeneration with pm-changelog 2026.10.5 preserves all 2,582 completed-item entries and release buckets. Production source, tests and mandatory thresholds remain identical to the fully passing implementation head.
|
@greptileai Please renew review for af0d096. The supplemental push routes two newly arrived reports to existing canonical PM owners: the exact 70-row GH1420 reproduction confirms the already merged pagination fix, and GH1419 is retained as a future metadata editing fixture. No duplicate PM item or source/test change was introduced. Required checks must cover this final head; provider limitations remain explicit. |
|
|
Read the 94412bd revision at #1421 (comment): full review could not start at 161/100 selected files and unavailable capacity. This remains an explicit provider limitation; the integrated PM evidence and unchanged strict code gates are retained. |
|
Read the 94412bd comparison at #1421 (comment): eleven untouched benchmarks remain the measured scope. The subsequent af0d096 push changes only canonical PM report intake, with source and tests byte-identical to the passing b4e61d4 implementation. |
|
Read the renewed 161/100-file full-review refusal at #1421 (comment). No code review or approval was produced; scope remains one integrated PR, and the new metadata-only head has its own renewed request and mandatory checks. |
|
Read the af0d096 automatic-review notice at #1421 (comment). Its star-policy skip remains distinct from the explicit 165/100-file refusal. Both are unavailable review, not approval; the full integrated source and PM scope remains present. |
|
Read the af0d096 versus 686e764 receipt at #1421 (comment): eleven untouched benchmarks are unchanged. Exact-head canonical coverage and every native workflow job pass; missing Codecov notification remains a separate investigated required context rather than a performance finding. |
|
Read the explicit af0d096 review refusal at #1421 (comment): 165 files exceed the 100-file allowance. No code finding or approval is supplied. New report intake stays in its canonical PM owners and this single PR; no test/history exclusions or paid capacity change are used. |
Both metadata-only heads retain exact canonical 100/100/100/100 coverage and all native jobs pass. Codecov merges the authentic exact-head report at 100 percent, yet its required patch context remains absent even after a genuine upload retry. Remove notification scheduling dependencies on optional skipped or quota-limited review services. Keep both Codecov targets at 100 percent, zero tolerance and the existing failed-CI error behavior. Explicitly fail when a head report is missing. Every native quality gate and strict branch protection remain required; no success status is manufactured and no coverage scope is changed. The official Codecov validator accepts the policy, and the three existing authenticated-upload/checksum negative controls pass in linked receipt test-local-mux8pncm-pvkbhe. A fresh build passes. Reuse pm-gh1417 for this active correction and regenerate its current-state changelog projection. Exact-head provider admission remains required before closure and merge.
|
@greptileai Please renew review for 23eb473. Genuine exact-head coverage uploads merged at100% but the required Codecov notification remained absent on two metadata-only heads. This correction reports coverage independently of optional notification waits, preserves both100% targets/zero tolerance/failed-CI errors, explicitly fails missing reports, and leaves all26 strict required contexts intact. Official schema validation and authenticated checksum/upload negative controls pass. Only pm-gh1417 is actively in progress while actual provider admission is verified. |
|
|
Read the edited exact-head 23eb473 full-review refusal: 166 files exceed the 100-file allowance. This is unavailable review capacity, not code approval; the integrated scope is preserved. All 26 required contexts now pass on this head, including the genuine Codecov patch check after the notification correction. |
|
Read the updated exact-head 23eb473 comparison against main 686e764: all 11 measured CodSpeed benchmarks are untouched. The report establishes this benchmark result; it does not override the independently recorded SDK and transport latency failures or the mandatory hosted static admission, which now passes. |
|
Read the explicit renewed full-review command refusal at #1421 (comment): 166 selected files exceed the 100-file limit. No code review or approval was produced. This head retains the complete reviewed delivery and all required checks are green; provider capacity remains explicitly documented. |
Close and release pm-gh1417 with immutable evidence from reviewed head 23eb473. All 26 required contexts pass, including genuine Codecov patch notification and exact-head DeepScan and CodeFactor admission under unchanged strict main protection. The current hosted artifacts independently verify all 768 measured files at 100% lines, statements, functions and branches, with 9881 passed cases, zero failures or errors and two existing Windows-only Linux skips. Preserve original failed controls and provider capacity limitations. Regenerate CHANGELOG.md through the latest pm-changelog package, restore the completed runtime item and preserve every historical release section. The strict complete 2901-item corpus has no in-progress items, and all five implementation owners are closed with ownership released. Published 2026.10.6 remains immutable; the next daily publication is separate proof.
|
@greptileai Please review the complete current head |
|
Include the framework-generated receipt from the final changelog check, linked to the existing pm-jprn58 extension metadata evidence. The latest pm-changelog package remains 2026.10.5; every installed contribution, capability, source identity and entry field is unchanged. Only the native registry refresh timestamp advances to the completed check. Preserve the authoritative native output instead of editing tracker metadata by hand. This administrative closeout does not change source, tests, runtime package versions, coverage scope or any quality threshold.
|
Read the edited exact-head 3c03533 full-review refusal: 166 selected files exceed the 100-file allowance. This remains unavailable code review, not approval. The complete closure/changelog head independently passes all 26 required contexts, including genuine Codecov notification. One native generated extension-receipt timestamp is being included in the same PR and will receive its own renewed full review request and admission. |
|
Read the 3c03533 versus main 686e764 benchmark update: all 11 measured benchmarks are untouched. Every required current-head context also passes. The remaining native package-receipt timestamp does not change production code or benchmark scope; the next committed head will receive fresh mandatory checks. |
|
Read the explicit renewed full-review command refusal at #1421 (comment): 166 files exceed the 100-file allowance. No code review or approval was produced. Current-head mandatory admission is green, and the generated receipt closeout retains the full integrated scope and will renew review/check requests. |
|
@greptileai Please review the complete current head |
|
|
Read the final edited full-review refusal for exact head 77977d9: 166 selected files exceed the 100-file allowance. This remains unavailable review capacity, not code approval. The integrated scope is preserved. All 26 required contexts pass on this clean final head; genuine coverage artifacts independently verify every one of 768 source files at 100/100/100/100 and 9881 passed cases. Exact-head DeepScan and CodeFactor admission also passes. |
|
Read the final 77977d9 versus main 686e764 comparison: all 11 measured CodSpeed benchmarks are untouched. The final native workflows and all 26 required contexts pass independently, including unchanged static performance budgets. Earlier local latency failures remain in PM history; this benchmark result is recorded at its actual scope. |
|
Read the final explicit full-review command refusal at #1421 (comment): 166 files exceed the 100-file allowance. No code review or approval was produced. The complete final head independently passes all required admission and genuine exact-count coverage; all review-provider quota/capacity limitations remain explicit before merge. |
Workspace assurance previously omitted body-only references in strict reads and split valid item IDs with multiple hyphens. Bun filtered linked tests could also be rejected despite executing successfully, while package installs could resolve a different runtime dependency tree from the one tested in CI. This change fixes those SDK primitives and publishes a staged tarball containing the tested production closure.
The same delivery replaces the vulnerable MCP development client identified by GHSA-6qxp-vccf-f47h and restores evidence-backed relationships across historical PM work.
Changes
verifies, 108discovered_from, and 15related. Preserve lifecycle evidence and append-only history. Pin eight already verified historical releases so graph enrichment cannot move shipped work into Unreleased.PM lineage
Validation
77977d9ed1e295237327422714e7eab4524cfd76: all 26 required contexts pass, including genuinecodecov/patch, static, coverage, typecheck, Windows regression, security and six packed first-run environments. Workflow 37542981912 artifacts verify every one of 768 measured source files at exact 100/100/100/100: 63,919/63,919 lines, 67,071/67,071 statements, 13,834/13,834 functions and 51,342/51,342 branches. JUnit records 9,881 passed, two existing Windows-only skips on Linux, and zero failures/errors; the separate native Windows job passes. Earlier metadata-only heads reproduced exact coverage but lacked the required provider notification even after a genuine upload retry. Independent notification scheduling restores the actual provider check while retaining both 100% targets, zero tolerance, explicit missing-report failure and every required native gate. The official YAML validator and existing checksum/upload negative controls pass. Both the closure/changelog head and the final native receipt head independently pass all 26 required contexts; the final coverage artifact digest issha256:8310e94038a9e7837a7fa30b78881bcb6e3626fde0d1c269d70763752e5850ee.f81d9a5618f9d8bb131ac3ae5216c225e447111bhas the identical reviewed tree. Its independent CI run 37544404242 reproduces all four exact 100% totals across every measured file and 9,881 passed cases. All six main workflows finish successfully: CI, Security and Script Quality, CodeQL, Docs, CodSpeed and OSSF Scorecard. The issue-close release hooks skip without another publication. Fresh final security inventories and the dependency audit contain zero findings, and no PRs remain open. All five PM links resolve to actual files on main.pm-changelog2026.10.5 projects 2,582 selected completed items. All previously generated historical release sections are byte-for-byte preserved. All five implementation owners are closed and unclaimed; the complete strict 2,901-item corpus has zero in-progress items. The notification owner's immutable close event includes its actual hosted admission, and the generated changelog is included in this PR.Regression development includes failing controls for omitted bodies, identifier splitting and real Bun filtering; distribution tests use actual filesystem closures, npm packing and installed consumers. The exactly-once release fixture covers already-published days and packing failures before publication. Fresh temporary consumers exercise Node, Bun, npx, bunx and public SDK composition.
Review evidence
Round one reported fresh-install CodSpeed, Windows fixture/timing and actionlint failures; the combined corrections retain all source, inventory, coverage and quality thresholds. Every bot artifact was read, reacted to and acknowledged by revision. CodeRabbit refused the full 158-file scope under its 100-file allowance, and Sourcery reported an exhausted rolling review budget. Their unavailable code reviews are recorded explicitly; the PR scope is preserved. The authenticated direct Greptile committed-head review returned
free_reviews_limit_reached. CodeRabbit also reports its separate fewer-than-ten-stars automatic-review policy. Cubic also reports its monthly 40,000-line allowance exhausted. All four provider limitations remain explicit; no unavailable review is treated as approval. Round-two Codecov feedback identified one missing npm 12 receipt branch, which is now covered by a compatibility test retaining real npm child execution and actual tarballs. Exact-commit hosted admission verifies strict main protection and zero DeepScan/CodeFactor PR findings on final head 77977d9; Chrome separately confirms two existing generated plugin-copy duplication reports on main, tracked by the canonical duplication/CodeFactor lineage.Sourcery correctly identified that issue #1417 originally proposed
_hasShrinkwrap=true. This PR publishes the physical tested runtime closure for both npm and Bun, contains no npm-shrinkwrap.json, and leaves that literal metadata criterion unmet. The issue retains the original report and now documents the verified alternative. Cross-day installation of the next published version remains a separate publication observation.Fresh reports arriving during final review are routed without new PM duplicates: #1420 matches completed pm-gh1413. A fresh 70-item source probe verifies the exact 50/30 producer boundary resumes at position 30; registry adoption remains pending. #1419 is retained as a future linked-test editing fixture under the existing pm-gh1381 metadata-reference feature, which remains open and unclaimed. This PR records its complete proposal; it does not implement that future editor.
Release and remaining scope
The immutable npm version 2026.10.6 was already published before this work. This PR is eligible for the next daily release and does not republish today's version. The fresh dependency census records 13 newer upstream candidates with no current/wanted gap; major migrations remain assigned to canonical owners because peer, runtime and Sentry contracts are still unmet. Existing historical hierarchy, structured-evidence and docstring-content debt remain tracked; the static report identifies 4,130 legacy filler entries across 204 files. Graph waivers and the original prose-gap ceiling are unchanged. The fresh required operational gate reports zero high/critical Sentry issues, a 3.25% telemetry finish-error rate against the unchanged 6% limit and zero missing error-code rows. The native flush drained one pending valid entry to zero without an error; the newest stored event was 1.95 seconds old when inspected. Empty fresh trace results leave trace completeness unverified. Hosted Windows jobs provide the platform-specific evidence skipped locally.
Closes #1417
Closes #1418