Skip to content

Certify pm-csv on PM CLI 2026.10.4 and consolidate pending dependency updates - #146

Merged
unbraind merged 5 commits into
mainfrom
chore/pm-csv-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 5 commits into
mainfrom
chore/pm-csv-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What changed

Certifies pm-csv on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:

Gate commands + results

  • npm run release:check — PASS: typecheck, release-workflow verify, build, lint (0 warnings), jscpd (0 clones), docstring gate (71 declarations), coverage 100/100/100 (lines/branches/functions) across index.ts + scripts/docstring-gate.ts, 238/238 tests, 0 skipped, npm audit --omit=dev 0 vulnerabilities, npm audit (all deps) 0 vulnerabilities, npm pack --dry-run + accept:packed green (npm-current / bun-current / npm-minimum scenarios against CLI 2026.10.4 and the 2026.8.20 peer floor), changelog check green, publish-attestation + changelog-date gates green.
  • npx pm health (repo-pinned 2026.10.4 binary) — exit 0; one advisory (stale_in_progress_items from the prior cycle's still-open cert item).

Dogfood evidence (real tracker, packed tarball)

Packed pm-csv-2026.10.4.tgz, installed it into a scratch copy of this repo's own real .agents/pm (107 original items; 108 after the isolated import) and registered it with pm package install:

  • npm (npx -y @unbrained/pm-cli@2026.10.4): csv export → 107 original items; 108 after the isolated import; csv export --status open → 6; csv validate → 107 rows clean; csv import → imported 1; csv import --key title → updated 1, idempotent (no duplicate).
  • bun (bunx @unbrained/pm-cli@2026.10.4): csv export → 109 items; csv validate → clean; csv import --key title --source bunx-cert → updated 1.
  • All commands exit 0; scratch copy deleted afterwards.

pm-github preview (read-only)

pm github validate --repo unbraind/pm-csv → ok (token via gh CLI, repo HTTP 200); pm github export --repo unbraind/pm-csv --dry-run → plan only, writes nothing; pm github sync --dry-run --repo unbraind/pm-csv → wouldSync 1, no mutation.

Superseded Dependabot PRs

#137, #140, #142, #143, #144, #145 — each update is carried here (same or newer version).

pm item

https://github.com/unbraind/pm-csv/blob/main/.agents/pm/chores/pm-csv-hzn7.toon

Resumption validation: rebased onto the release commit on main; added three child-process regression fixtures for incomplete/dangling pm-ops installations and lookup errors. Canonical launcher unchanged. Full gate and packed real-tracker npx/bunx checks re-run; export 107 → 108 items, one create then idempotent updates. All npm audits remain clean.

Summary by Sourcery

Certify pm-csv on PM CLI/SDK 2026.10.4 while consolidating dependency maintenance and hardening merge-driver installation failures.

Bug Fixes:

  • Ensure incomplete, dangling, or otherwise unresolvable pm-ops installations fail clearly instead of being treated as absent development dependencies.

Enhancements:

  • Certify the project against PM CLI/SDK 2026.10.4 and consolidate dependency updates with exact development dependency pins.
  • Refresh the canonical merge-driver launcher and document the updated reproducible gate host version.

Build:

  • Regenerate the lockfile for the updated dependency set.

CI:

  • Update CodeQL action pins to the current v4 commit.

Documentation:

  • Update the README to reference PM CLI/SDK 2026.10.4.

Tests:

  • Add regression coverage for incomplete installations, dangling package links, and failing module lookup paths.

Chores:

  • Record the associated project-management item and history entries.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 65f51e60-ba1d-4589-840d-0fb406560ac5
📥 Commits

Reviewing files that changed from the base of the PR and between d579ba4 and 2a8496a.

📒 Files selected for processing (3)
  • .agents/pm/chores/pm-csv-hzn7.toon
  • .agents/pm/history/pm-csv-hzn7.jsonl
  • test/prepare-merge-driver.test.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 2934942f-bcdd-46b7-b549-7e87393227a4
📥 Commits

Reviewing files that changed from the base of the PR and between 7473779 and d579ba4.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (7)
  • .agents/pm/chores/pm-csv-hzn7.toon
  • .agents/pm/history/pm-csv-hzn7.jsonl
  • .github/workflows/codeql.yml
  • README.md
  • package.json
  • scripts/prepare-merge-driver.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Improved merge-driver setup checks so incomplete or broken installations are reported as errors rather than incorrectly treated as optional. Setup failures now retain their original error details.
  • Chores
    • Updated development and release tooling to the latest certified PM CLI/SDK version and pinned dependency versions.
    • Updated the CodeQL security scanning actions.
    • Recorded validation results for release checks and package-manager workflows.

Walkthrough

Development dependencies and the CodeQL action pins were updated, and the README now documents pm CLI/SDK 2026.10.4. The merge-driver launcher now distinguishes a confirmed missing pm-ops package from other resolution failures. New regression tests cover incomplete packages, dangling symlinks, and looping NODE_PATH lookups.

Changes

pm-csv certification

Layer / File(s) Summary
Toolchain pins and certification records
package.json, README.md, .github/workflows/codeql.yml, .agents/pm/chores/*, .agents/pm/history/*
Development dependencies now use exact versions, the README documents pm CLI/SDK 2026.10.4, and CodeQL v4 actions use a new commit pin. The PM records document certification checks, dogfooding, previews, test results, and chore status.
pm-ops resolution and regression tests
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts, .agents/pm/history/*
The launcher skips installation only when resolution checks confirm that pm-ops is absent. Tests cover incomplete package directories, dangling symlinks, and looping NODE_PATH lookups. The PM history records the test results.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to d579b

No actionable issue was established in the dependency pins, merge-driver handling, or regression tests. The change is mergeable after normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to d579b

The change affects 4 systems.

Changed systems: package.json, README.md, scripts, test

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — README.md (service) was modified; 1 changed file maps to changed impact.
  • observed — scripts (service) was modified; 1 changed file maps to changed impact.
  • observed — test (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in README.md: The documented development and release gate version changes from pm CLI/SDK 2026.9.28 to 2026.10.4; the minimum-version statement is unchanged.
  • observed — Modified behavior in package.json: The development dependency versions are now exact pins. @babel/eslint-parser, @types/node, @unbrained/pm-cli, eslint, jscpd, pm-changelog, and pm-ops were updated; @babel/plugin-syntax-typescript, jiti, and typescript retain their versions but no longer use ranges.
  • observed — Modified behavior in scripts/prepare-merge-driver.ts: The comment now distinguishes a missing pm-ops package from other resolution failures, which fail installation; the script also imports lstatSync for package-presence checks.
  • observed — Modified behavior in scripts/prepare-merge-driver.ts: When the package-manifest probe fails, packagePresent remains true unless the error is MODULE_NOT_FOUND and every resolution-path check finds no pm-ops entry. The check includes Node’s global paths; an existing filesystem entry or a check error counts as present, preserving the original installer-resolution failure instead of skipping.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the PM CLI certification and dependency updates.
Description check ✅ Passed The description explains the certification, dependency updates, launcher changes, tests, and validation results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 22 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR certifies pm-csv against PM CLI/SDK 2026.10.4, consolidates the pending Dependabot updates into refreshed package and lockfile versions, synchronizes the merge-driver launcher with the newer pm-ops template, updates the pinned CodeQL actions and documentation, and adds read-only pm-github preview registration. Release gates, audits, packaging scenarios, tests, and npm/bun dogfood flows are reported passing.

Sequence diagram for packed tarball dogfood certification

sequenceDiagram
    participant Maintainer
    participant Tarball as Packed pm-csv tarball
    participant NpmCLI as PM CLI 2026.10.4 npm
    participant BunCLI as PM CLI 2026.10.4 bun
    participant Tracker as Real PM tracker
    Maintainer->>Tarball: npm pack --dry-run
    Maintainer->>NpmCLI: package install Tarball
    NpmCLI->>Tracker: csv export
    Tracker-->>NpmCLI: CSV rows
    NpmCLI->>Tracker: csv validate
    NpmCLI->>Tracker: csv import
    Tracker-->>NpmCLI: imported or updated items
    Maintainer->>BunCLI: package install Tarball
    BunCLI->>Tracker: csv export
    Tracker-->>BunCLI: CSV rows
    BunCLI->>Tracker: csv validate
    BunCLI->>Tracker: csv import
    Tracker-->>BunCLI: updated item
Loading

Flow diagram for safe pm-ops merge-driver installation

flowchart TD
    Start[Install pm-csv] --> Resolve[Resolve pm-ops installer entry]
    Resolve -->|Resolved| Spawn[spawnSync installer]
    Spawn -->|Success| Ready[Merge driver ready]
    Spawn -->|Failure| Fail[Fail installation]
    Resolve -->|Not resolved| Probe[Probe pm-ops package paths]
    Probe -->|No package presence| Skip[Skip with notice]
    Probe -->|Present or uncertain| Fail
Loading

File-Level Changes

Change Details Files
Certify the extension against PM CLI/SDK 2026.10.4 and consolidate dependency upgrades.
  • Raise exact PM tooling pins and refresh the lockfile.
  • Upgrade ESLint, jscpd, Node types, and related transitive dependencies.
  • Update the README’s reproducible gate-host version.
package.json
package-lock.json
README.md
Harden and synchronize the merge-driver installer with the pm-ops 2026.10.4 canonical template.
  • Detect broken or partially installed pm-ops packages as present instead of silently skipping them.
  • Fail closed when package-presence probing is inconclusive while preserving installer diagnostics.
  • Maintain byte identity with the installed template through the existing test.
scripts/prepare-merge-driver.ts
test/prepare-merge-driver.test.ts
Refresh the pinned CodeQL workflow action.
  • Move both CodeQL init and analyze steps to the new v4 commit SHA.
.github/workflows/codeql.yml
Register pm-github metadata for read-only preview workflows and record the associated PM work item.
  • Add the chore item and history records.
  • Register pm-github as a managed extension without enabling scheduled synchronization or mutations.
.agents/pm/chores/pm-csv-hzn7.toon
.agents/pm/history/pm-csv-hzn7.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Bumps development dependencies and updates build tooling.

The PR appears safe to merge; no actionable issue remains from this review.

What we checked:

  • Fixture lookup stays independent: The fixture links pm-ops into its own node_modules. The lookup-error test supplies a separate NODE_PATH, so the helper does not erase that test's setup.

Summary

This PR pins the development tools, updates the CodeQL actions, and refreshes merge-driver setup for PM CLI/SDK 2026.10.4.

  • Since the last review, the link fixtures now use junctions and the shared test helper clears ambient NODE_PATH.
  • Both earlier, unnumbered findings are addressed: broken-install cases have regression tests, and the two new link fixtures no longer require Windows symbolic-link privileges.
  • No new actionable issues were found. This review did not run the tests.

Reviews (4) · Last reviewed commit: "test: make merge-driver fixtures portabl..."

Comment thread scripts/prepare-merge-driver.ts
@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

The pm-github managed extension referenced in the PR body has since been re-verified at its new latest npm version 2026.10.4 (published during this certification): pm github validate --repo unbraind/pm-csv ok (HTTP 200) and pm github sync --dry-run --repo unbraind/pm-csv returned wouldSync 1 — still read-only with no GitHub mutation. Evidence recorded on the pm item.

…ency updates

Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and
pm-changelog 2026.9.25, take over the pending Dependabot dependency
updates (eslint 10.12.0, jscpd 5.4.0, @types/node 26.6.4) and the
codeql-action pinned SHA group, and recopy the canonical pm-ops
merge-driver launcher byte-for-byte. README gate host pin follows the
dev dependency. pm-github is registered as a managed extension for
read-only preview only.

Supersedes #137 #142 #143 #144 #145 #140.
pm-github 2026.10.4 was published during the certification window;
re-ran the read-only previews against the repo with the upgraded
extension and recorded the result on pm-csv-hzn7.
@unbraind
unbraind force-pushed the chore/pm-csv-pm-cli-2026-10-4 branch from 44871e3 to 22a1491 Compare October 4, 2026 10:57
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #146 (comment)

Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #146 (comment)

Useful review guide. The latest candidate d579ba4 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #146 (comment)

The merge-driver regression request is addressed in d579ba4 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #146 (review)

The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Comment thread test/prepare-merge-driver.test.ts Outdated
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to the completed CodeRabbit review and its command receipt: the review covered d579ba4 and found no actionable issues. The later Windows-fixture finding from the other reviewer is corrected in 2a8496a, with the full gate re-run. The new candidate awaits the single follow-up review request.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #146 (comment)

The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator.

@unbraind
unbraind merged commit 3cd0b91 into main Oct 4, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant