Certify pm-context on PM CLI 2026.10.4 and consolidate pending dependency updates - #128
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThe pull request pins development dependencies, updates CodeQL action references, changes ChangesPM tool certification
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Other Merge Risk: ⚪ Minimal · up to This change pins development tools, updates CodeQL action references, and makes merge-driver setup fail loudly when a pm-ops install is broken instead of silently skipping. No merge-blocking risk was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The launcher now rejects broken or uncertain installations instead of silently skipping setup. No expanded execution authority or introduced security defect was established. Risk remains low because cleanup and repeat-execution guarantees inside the updated installer could not be verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR certifies pm-context against PM CLI/SDK 2026.10.4, consolidates and pins dependency updates, hardens the merge-driver launcher against incomplete or malformed pm-ops installations, and adds regression coverage plus tracking metadata. Validation reports 286/286 release-gate tests, complete configured V8 coverage, passing changelog/health/audit checks, and 9/9 focused launcher tests; the documented PM-linked full-gate sandbox failure remains an external defect. Sequence diagram for hardened pm-ops launcher resolutionsequenceDiagram
participant Launcher as prepare-merge-driver
participant Resolver as Node module resolver
participant FS as Filesystem
participant Installer as pm-ops installer
Launcher->>Resolver: resolver.resolve(pm-ops entry)
alt entry resolves
Launcher->>Installer: spawnSync(installer)
Installer-->>Launcher: installer result
else lookup fails
Launcher->>Resolver: resolver.resolve(pm-ops/package.json)
alt package is absent everywhere
Launcher-->>Launcher: omit-dev skip
else package directory, dangling link, or malformed path exists
Launcher->>Resolver: resolver.resolve.paths(pm-ops/package.json)
Launcher->>FS: lstatSync(pm-ops)
Launcher-->>Launcher: rethrow original installer error
end
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required. |
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
|
Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required. |
|
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
Certifies pm-context against PM CLI/SDK 2026.10.4 and consolidates Dependabot #121, #124, #125, #126 and #127. PM CLI, pm-ops and pm-changelog are exact 2026.10.4 pins; Node types are 26.6.4 and all other development dependencies are exact. Both CodeQL actions use the exact SHA and version comment from #121. Brace-expansion security alert #5 is patched to 5.0.12 in this branch.
The launcher is byte-identical to published pm-ops 2026.10.4. Three real behavior regressions cover a package directory without a manifest, a dangling link and an ENOTDIR lookup: each preserves the original installer error, forbids the omit-dev skip and registers no drivers. The nine-case launcher suite passes with zero skipped.
Validation:
flock /tmp/claude-1000/heavy-gate.lock npm run release:check: 286/286 tests, zero failures/skips, 100% V8 lines/branches/functions across five configured sources. Independent statement coverage is not reported by the configured gate; pm-context-3s5f remains open for complete coverage.npm run changelog:check: PASS after regeneration.npx pm health --strict-exit --require-merge-drivers: PASS. Fullnpm auditandnpm audit --omit=dev: zero vulnerabilities.init_existing_settings_requires_force; direct execution passes. This matches the previously reproduced sandbox defect class in pm-cli#1391, rather than a reason to weaken a package gate.Packed real-data acceptance:
npm pack, install the tarball with@unbrained/pm-cli@2026.10.4into a disposable copy of this repo's actual tracker, thennpx -y @unbrained/pm-cli@2026.10.4 package install <tarball> --project(copy.complete=true). Through bothnpx -y @unbrained/pm-cli@2026.10.4andbunx --bun -y @unbrained/pm-cli@2026.10.4, runcontext-pack --id pm-context-ht20 --neighborhood-depth 1 --format compact,context-pack --tag cert --format json, andcontext-pack --status open --limit 2 --output <runtime>-pack.md: selected item/structured JSON render and both output files contain two selected items. Scratch copy removed.Managed pm-github 2026.10.4 read-only preview:
pm github sync --repo unbraind/pm-context --dry-runreports planned=0, synced=0.Tracking: pm-context-ht20. Item and PR remain open for orchestrator verification and final-head review.
Summary by Sourcery
Certify pm-context against PM 2026.10.4 while hardening merge-driver setup and consolidating dependency updates.
Bug Fixes:
Enhancements:
CI:
Tests:
Chores:
Summary by cubic
Certifies
pm-contextagainst the PM CLI/SDK 2026.10.4 toolchain, hardens merge-driver setup for broken installs, and consolidates pending Dependabot updates.Dependencies
@unbrained/pm-cli,pm-ops, andpm-changelogto exact 2026.10.4 and makes all other development dependency versions exact.brace-expansionsecurity alert to 5.0.12.Bug Fixes
pm-opsdirectory without a manifest, a dangling link, or an ENOTDIR lookup instead of skipping the install.Written for commit 6184ea4. Summary will update on new commits.