Certify pm-csv on PM CLI 2026.10.4 and consolidate pending dependency updates - #146
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 37 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (3)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughDevelopment dependencies and the CodeQL action pins were updated, and the README now documents pm CLI/SDK 2026.10.4. The merge-driver launcher now distinguishes a confirmed missing Changespm-csv certification
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable issue was established in the dependency pins, merge-driver handling, or regression tests. The change is mergeable after normal checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 4 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR certifies pm-csv against PM CLI/SDK 2026.10.4, consolidates the pending Dependabot updates into refreshed package and lockfile versions, synchronizes the merge-driver launcher with the newer pm-ops template, updates the pinned CodeQL actions and documentation, and adds read-only pm-github preview registration. Release gates, audits, packaging scenarios, tests, and npm/bun dogfood flows are reported passing. Sequence diagram for packed tarball dogfood certificationsequenceDiagram
participant Maintainer
participant Tarball as Packed pm-csv tarball
participant NpmCLI as PM CLI 2026.10.4 npm
participant BunCLI as PM CLI 2026.10.4 bun
participant Tracker as Real PM tracker
Maintainer->>Tarball: npm pack --dry-run
Maintainer->>NpmCLI: package install Tarball
NpmCLI->>Tracker: csv export
Tracker-->>NpmCLI: CSV rows
NpmCLI->>Tracker: csv validate
NpmCLI->>Tracker: csv import
Tracker-->>NpmCLI: imported or updated items
Maintainer->>BunCLI: package install Tarball
BunCLI->>Tracker: csv export
Tracker-->>BunCLI: CSV rows
BunCLI->>Tracker: csv validate
BunCLI->>Tracker: csv import
Tracker-->>BunCLI: updated item
Flow diagram for safe pm-ops merge-driver installationflowchart TD
Start[Install pm-csv] --> Resolve[Resolve pm-ops installer entry]
Resolve -->|Resolved| Spawn[spawnSync installer]
Spawn -->|Success| Ready[Merge driver ready]
Spawn -->|Failure| Fail[Fail installation]
Resolve -->|Not resolved| Probe[Probe pm-ops package paths]
Probe -->|No package presence| Skip[Skip with notice]
Probe -->|Present or uncertain| Fail
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
The pm-github managed extension referenced in the PR body has since been re-verified at its new latest npm version 2026.10.4 (published during this certification): |
…ency updates Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and pm-changelog 2026.9.25, take over the pending Dependabot dependency updates (eslint 10.12.0, jscpd 5.4.0, @types/node 26.6.4) and the codeql-action pinned SHA group, and recopy the canonical pm-ops merge-driver launcher byte-for-byte. README gate host pin follows the dev dependency. pm-github is registered as a managed extension for read-only preview only. Supersedes #137 #142 #143 #144 #145 #140.
pm-github 2026.10.4 was published during the certification window; re-ran the read-only previews against the repo with the upgraded extension and recorded the result on pm-csv-hzn7.
44871e3 to
22a1491
Compare
|
Response to #146 (comment) Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence. |
|
Response to #146 (comment) Useful review guide. The latest candidate d579ba4 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item. |
|
Response to #146 (comment) The merge-driver regression request is addressed in d579ba4 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item. |
|
Response to #146 (review) The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
@coderabbitai review |
|
|
Response to #146 (comment) The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator. |
What changed
Certifies pm-csv on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:
@unbrained/pm-cli2026.9.28 → 2026.10.4,pm-ops2026.9.23 → 2026.10.4 (newer than Dependabot's 2026.9.29 proposal),pm-changelog2026.9.23 → 2026.10.4. All devDependencies now exact; lockfile regenerated and verified by cleannpm ci..github/workflows/codeql.ymlcodeql-action pinned SHA group →1c5b675653bb5c22dbe9b12b556ec555138e09fd(v4) for bothinitandanalyzescripts/prepare-merge-driver.tsrecopied byte-for-byte from the installed pm-ops 2026.10.4 template (the template gained new handling);test/prepare-merge-driver.test.tsbyte-identity passes.Gate commands + results
npm run release:check— PASS: typecheck, release-workflow verify, build, lint (0 warnings), jscpd (0 clones), docstring gate (71 declarations), coverage 100/100/100 (lines/branches/functions) acrossindex.ts+scripts/docstring-gate.ts, 238/238 tests, 0 skipped,npm audit --omit=dev0 vulnerabilities,npm audit(all deps) 0 vulnerabilities,npm pack --dry-run+accept:packedgreen (npm-current / bun-current / npm-minimum scenarios against CLI 2026.10.4 and the 2026.8.20 peer floor), changelog check green, publish-attestation + changelog-date gates green.npx pm health(repo-pinned 2026.10.4 binary) — exit 0; one advisory (stale_in_progress_itemsfrom the prior cycle's still-open cert item).Dogfood evidence (real tracker, packed tarball)
Packed
pm-csv-2026.10.4.tgz, installed it into a scratch copy of this repo's own real.agents/pm(107 original items; 108 after the isolated import) and registered it withpm package install:npx -y @unbrained/pm-cli@2026.10.4):csv export→ 107 original items; 108 after the isolated import;csv export --status open→ 6;csv validate→ 107 rows clean;csv import→ imported 1;csv import --key title→ updated 1, idempotent (no duplicate).bunx @unbrained/pm-cli@2026.10.4):csv export→ 109 items;csv validate→ clean;csv import --key title --source bunx-cert→ updated 1.pm-github preview (read-only)
pm github validate --repo unbraind/pm-csv→ ok (token via gh CLI, repo HTTP 200);pm github export --repo unbraind/pm-csv --dry-run→ plan only, writes nothing;pm github sync --dry-run --repo unbraind/pm-csv→ wouldSync 1, no mutation.Superseded Dependabot PRs
#137, #140, #142, #143, #144, #145 — each update is carried here (same or newer version).
pm item
https://github.com/unbraind/pm-csv/blob/main/.agents/pm/chores/pm-csv-hzn7.toon
Resumption validation: rebased onto the release commit on main; added three child-process regression fixtures for incomplete/dangling pm-ops installations and lookup errors. Canonical launcher unchanged. Full gate and packed real-tracker npx/bunx checks re-run; export 107 → 108 items, one create then idempotent updates. All npm audits remain clean.
Summary by Sourcery
Certify pm-csv on PM CLI/SDK 2026.10.4 while consolidating dependency maintenance and hardening merge-driver installation failures.
Bug Fixes:
Enhancements:
Build:
CI:
Documentation:
Tests:
Chores: