Skip to content

Certify pm-context on PM CLI 2026.10.4 and consolidate pending dependency updates - #128

Merged
unbraind merged 2 commits into
mainfrom
chore/pm-context-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 2 commits into
mainfrom
chore/pm-context-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Certifies pm-context against PM CLI/SDK 2026.10.4 and consolidates Dependabot #121, #124, #125, #126 and #127. PM CLI, pm-ops and pm-changelog are exact 2026.10.4 pins; Node types are 26.6.4 and all other development dependencies are exact. Both CodeQL actions use the exact SHA and version comment from #121. Brace-expansion security alert #5 is patched to 5.0.12 in this branch.

The launcher is byte-identical to published pm-ops 2026.10.4. Three real behavior regressions cover a package directory without a manifest, a dangling link and an ENOTDIR lookup: each preserves the original installer error, forbids the omit-dev skip and registers no drivers. The nine-case launcher suite passes with zero skipped.

Validation:

  • flock /tmp/claude-1000/heavy-gate.lock npm run release:check: 286/286 tests, zero failures/skips, 100% V8 lines/branches/functions across five configured sources. Independent statement coverage is not reported by the configured gate; pm-context-3s5f remains open for complete coverage.
  • CI's additional npm run changelog:check: PASS after regeneration. npx pm health --strict-exit --require-merge-drivers: PASS. Full npm audit and npm audit --omit=dev: zero vulnerabilities.
  • PM-linked focused launcher suite: 9/9 pass. PM-linked full gate returns wrapper exit 5 / command exit 1 because throwaway tracker initialization receives the injected sandbox tracker and throws init_existing_settings_requires_force; direct execution passes. This matches the previously reproduced sandbox defect class in pm-cli#1391, rather than a reason to weaken a package gate.

Packed real-data acceptance: npm pack, install the tarball with @unbrained/pm-cli@2026.10.4 into a disposable copy of this repo's actual tracker, then npx -y @unbrained/pm-cli@2026.10.4 package install <tarball> --project (copy.complete=true). Through both npx -y @unbrained/pm-cli@2026.10.4 and bunx --bun -y @unbrained/pm-cli@2026.10.4, run context-pack --id pm-context-ht20 --neighborhood-depth 1 --format compact, context-pack --tag cert --format json, and context-pack --status open --limit 2 --output <runtime>-pack.md: selected item/structured JSON render and both output files contain two selected items. Scratch copy removed.

Managed pm-github 2026.10.4 read-only preview: pm github sync --repo unbraind/pm-context --dry-run reports planned=0, synced=0.

Tracking: pm-context-ht20. Item and PR remain open for orchestrator verification and final-head review.

Summary by Sourcery

Certify pm-context against PM 2026.10.4 while hardening merge-driver setup and consolidating dependency updates.

Bug Fixes:

  • Ensure merge-driver installation failures remain fatal for incomplete, dangling, or otherwise invalid pm-ops installations instead of being incorrectly skipped.

Enhancements:

  • Certify the project against the PM 2026.10.4 toolchain and consolidate development dependency versions to exact pins.

CI:

  • Pin both CodeQL workflow actions to the updated verified commit.

Tests:

  • Add regression coverage for missing manifests, dangling package links, and ENOTDIR lookups, verifying installer errors are preserved and no drivers are registered.

Chores:

  • Record the associated PM tracking item and history.

Summary by cubic

Certifies pm-context against the PM CLI/SDK 2026.10.4 toolchain, hardens merge-driver setup for broken installs, and consolidates pending Dependabot updates.

Dependencies

  • Pins @unbrained/pm-cli, pm-ops, and pm-changelog to exact 2026.10.4 and makes all other development dependency versions exact.
  • Updates the CodeQL action SHAs and patches the brace-expansion security alert to 5.0.12.

Bug Fixes

  • The merge-driver launcher now preserves the original installer error for a pm-ops directory without a manifest, a dangling link, or an ENOTDIR lookup instead of skipping the install.
  • Adds three regression tests covering those cases, each also verifying no drivers are registered.

Written for commit 6184ea4. Summary will update on new commits.

Review in cubic

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 20 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 07046c92-4eef-44ca-9e8b-bfc0bd6b0bf2

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 588561a0-4336-4d52-9192-0227fe5528f3
📥 Commits

Reviewing files that changed from the base of the PR and between 63ef4a0 and 41a4305.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .agents/pm/chores/pm-context-ht20.toon
  • .agents/pm/history/pm-context-ht20.jsonl
  • .github/workflows/codeql.yml
  • package.json
  • scripts/prepare-merge-driver.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes

    • The merge-driver setup now reports installation errors when the package is missing its manifest, has a broken link, or cannot be reliably located, instead of incorrectly skipping setup.
  • Chores

    • Updated and pinned development tooling versions.
    • Recorded certification checks and regression-test results for the 2026.10.4 release.

Walkthrough

The pull request pins development dependencies, updates CodeQL action references, changes pm-ops package detection in the merge-driver launcher, adds regression tests, and records certification results.

Changes

PM tool certification

Layer / File(s) Summary
Toolchain version updates
.github/workflows/codeql.yml, package.json
Six development dependencies now use exact versions. Both CodeQL v4 action steps reference a different commit.
Merge-driver package detection
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts
The launcher checks package paths when resolving pm-ops/package.json fails. Regression tests cover a missing manifest, a dangling link, and an inconclusive lookup.
Certification records
.agents/pm/chores/*, .agents/pm/history/*
The chore record and history document tracked files, validation commands, reported checks, and pending final-head CI and reviews.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 41a43

This change pins development tools, updates CodeQL action references, and makes merge-driver setup fail loudly when a pm-ops install is broken instead of silently skipping. No merge-blocking risk was found.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 41a43

The launcher now rejects broken or uncertain installations instead of silently skipping setup. No expanded execution authority or introduced security defect was established. Risk remains low because cleanup and repeat-execution guarantees inside the updated installer could not be verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The intended mutable state is the consumer checkout's local Git configuration. The installer is nevertheless an ordinary child process, not a sandbox: its effective authority includes the launching account's inherited environment and permissions. This execution boundary already existed; the changed probe does not add authority.

Trust Boundaries and Controls

  • observed — Package selection remains based on Node resolution from the checkout. The newly inspected filesystem entries affect only whether failure may be classified as absence; they are not executed by the probe. Unreadable or malformed lookup paths now prevent a successful skip rather than weakening the setup gate.

Resilience and Maintainability Implications

  • observed — The launcher contains no rollback mechanism after invoking the installer. Existing failure and signal tests check status only, while repeated or concurrent preparation of one checkout is not exercised by this suite. Installer-owned cleanup and recovery therefore remain unverified, not established defects introduced by this PR.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the PM CLI 2026.10.4 certification and dependency updates, which are the main objectives of the pull request.
Description check ✅ Passed The description covers the certification, dependency updates, launcher changes, regression tests, and validation reported in the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (4 skipped: 4 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR certifies pm-context against PM CLI/SDK 2026.10.4, consolidates and pins dependency updates, hardens the merge-driver launcher against incomplete or malformed pm-ops installations, and adds regression coverage plus tracking metadata. Validation reports 286/286 release-gate tests, complete configured V8 coverage, passing changelog/health/audit checks, and 9/9 focused launcher tests; the documented PM-linked full-gate sandbox failure remains an external defect.

Sequence diagram for hardened pm-ops launcher resolution

sequenceDiagram
    participant Launcher as prepare-merge-driver
    participant Resolver as Node module resolver
    participant FS as Filesystem
    participant Installer as pm-ops installer

    Launcher->>Resolver: resolver.resolve(pm-ops entry)
    alt entry resolves
        Launcher->>Installer: spawnSync(installer)
        Installer-->>Launcher: installer result
    else lookup fails
        Launcher->>Resolver: resolver.resolve(pm-ops/package.json)
        alt package is absent everywhere
            Launcher-->>Launcher: omit-dev skip
        else package directory, dangling link, or malformed path exists
            Launcher->>Resolver: resolver.resolve.paths(pm-ops/package.json)
            Launcher->>FS: lstatSync(pm-ops)
            Launcher-->>Launcher: rethrow original installer error
        end
    end
Loading

File-Level Changes

Change Details Files
Certify the project against the 2026.10.4 PM toolchain and consolidate dependency updates with reproducible version pins.
  • Pin PM CLI, pm-ops, pm-changelog, Node types, and development dependencies to the requested exact versions.
  • Refresh the lockfile to match the consolidated dependency set and patch brace-expansion to 5.0.12.
  • Pin both CodeQL actions to the exact SHA while retaining the v4 version comments.
package.json
package-lock.json
.github/workflows/codeql.yml
Harden merge-driver installation so only a definitively absent pm-ops package is skipped.
  • Probe all Node resolution paths and treat directories without manifests, dangling links, and inconclusive lookup errors as present or uncertain.
  • Preserve the original installer resolution error, prevent omit-dev skip behavior, and avoid registering drivers for broken installations.
  • Keep the launcher byte-identical to the published pm-ops 2026.10.4 implementation.
scripts/prepare-merge-driver.ts
Expand regression coverage for broken pm-ops installations and record PM tracking metadata.
  • Add fixtures and assertions for a manifest-less package directory, dangling symlink, and ENOTDIR lookup.
  • Verify each case fails with the installer error, emits no skip notice, and registers no drivers.
  • Add the chore definition and execution history for orchestrator tracking.
test/prepare-merge-driver.test.ts
.agents/pm/chores/pm-context-ht20.toon
.agents/pm/history/pm-context-ht20.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 6184ea456d8e; merging remains with the orchestrator.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required.

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates build dependencies and merge-driver installer logic.

The PR appears safe to merge; no blocking code issues were found.

Summary

Certifies the development toolchain against PM CLI, pm-ops, and pm-changelog 2026.10.4.

  • Pins development dependencies, updates both CodeQL actions, and locks brace-expansion at 5.0.12.
  • Strengthens the merge-driver launcher and adds three broken-install regression tests.
  • Since the previous review, only tracker handoff notes and claim fields changed. No new actionable issues or repository-rule violations were found.
  • Tests were not rerun during this review.

Reviews (2) · Last reviewed commit: "Record review handoff and release certif..."

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 6184ea456d8e; merging remains with the orchestrator.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 6184ea456d8e; merging remains with the orchestrator.

@unbraind
unbraind merged commit 3da9317 into main Oct 4, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant