Skip to content

Certify pm-github on PM CLI 2026.10.4 and consolidate pending dependency updates - #106

Merged
unbraind merged 3 commits into
mainfrom
chore/pm-github-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
chore/pm-github-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What changed

Certifies pm-github on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:

Gate commands + results

  • npm run release:check — PASS: typecheck, build, docstring gate, privacy gate, coverage at the configured thresholds, npm audit --omit=dev 0 vulnerabilities, npm pack --dry-run, changelog check, publish-attestation gate.
  • npx pm health (repo-pinned 2026.10.4 binary) — exit 0; one pre-existing advisory (stale in-progress items).

Dogfood evidence (real data, packed tarball, read-only on GitHub)

Packed pm-github-2026.10.4.tgz, installed into a scratch copy of this repo's own real .agents/pm, registered via pm package install:

  • npm (npx -y @unbrained/pm-cli@2026.10.4): github validate --repo unbraind/pm-github → ok (token via gh CLI, HTTP 200); github import unbraind/pm-github → truthfully 0 (the repo has no open issues); github import unbraind/pm-cli → Imported 26 new (real open issue data, read-only fetch); re-import → 0 new / 26 updated, proving gh:owner/repo#N provenance idempotency; github export --dry-run → create/update plan only, writes nothing; github sync --dry-run --repo unbraind/pm-csv → planned 0.
  • bun (bunx @unbrained/pm-cli@2026.10.4): github validate ok; github import unbraind/pm-cli → 0 new / 26 updated; export --dry-run and sync --dry-run identical.
  • Zero GitHub mutation (reads + local scratch writes only); scratch copy deleted afterwards.

pm-github preview (read-only)

pm github validate --repo unbraind/pm-github → ok (HTTP 200); pm github export --repo unbraind/pm-github --dry-run → plan only; pm github sync --dry-run --repo unbraind/pm-github → planned 1 / skipped 1, no mutation. No issues created/modified, no scheduled sync enabled.

Superseded Dependabot PRs

#101, #102, #103, #104 — every update (same or newer version) is carried here.

pm item

https://github.com/unbraind/pm-github/blob/main/.agents/pm/chores/pm-github-julo.toon

The canonical launcher is unchanged. Added the requested lookup-error regression, portable junction fixtures and isolation from inherited NODE_PATH; the hostile-environment launcher suite passes with no new skips. Clean npm ci verifies the pinned graph. Current certification repeats the packed npm/bun read-only own-repository validation, import preview, export preview and sync preview.

Fresh gate: 309/309 tests, zero skips, unchanged coverage thresholds, both audit scopes clean, privacy gate clean. Packed own-tracker export previews render 108 creates + 1 update on npm and bun; sync plans 1, wouldSync 0, skips 1. No GitHub writes.

Final full health receipt: exit 0 with stale_in_progress_items:2 advisory. This corrects the earlier zero-warning summary; package code and validated source are unchanged.

Summary by Sourcery

Certify pm-github on PM CLI 2026.10.4 while consolidating dependency, launcher reliability, and workflow security updates.

Bug Fixes:

  • Preserve the merge-driver install error when module lookup paths are unreadable or malformed instead of incorrectly skipping installation.
  • Add regression coverage for looping module lookup paths and isolate launcher tests from inherited NODE_PATH.

Enhancements:

  • Certify pm-github against PM CLI, SDK, and tooling releases 2026.10.4 with consolidated exact dependency updates.
  • Refresh the canonical merge-driver launcher and lockfile for the updated dependency graph.
  • Add project tracking metadata for the pm-github maintenance item and history.

CI:

  • Update CodeQL workflow actions to the pinned v4 commit.

Tests:

  • Maintain and validate the full test suite with portable junction fixtures and hostile-environment launcher coverage.

Chores:

  • Consolidate the pending Dependabot updates into the certified dependency refresh.

…endency updates

Pin @unbrained/pm-cli and pm-ops to 2026.10.4 (pm-changelog already
at 2026.9.25), take the @types/node lockfile bump (26.6.4) and the
codeql-action pinned SHA group 2892aa5 from Dependabot, and recopy the
canonical pm-ops merge-driver launcher byte-for-byte.

Supersedes #101 #102 #103 #104.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 21 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 38 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 70ae68c3-737a-4a72-98a3-f84ac6b91d06
📥 Commits

Reviewing files that changed from the base of the PR and between b927d55 and 45b74a5.

📒 Files selected for processing (2)
  • .agents/pm/chores/pm-github-julo.toon
  • .agents/pm/history/pm-github-julo.jsonl

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0d433ee9-9f70-4606-bae0-d29818eb524d
📥 Commits

Reviewing files that changed from the base of the PR and between 2daff95 and b927d55.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .agents/pm/chores/pm-github-julo.toon
  • .agents/pm/history/pm-github-julo.jsonl
  • .github/workflows/codeql.yml
  • package.json
  • scripts/prepare-merge-driver.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Improved merge-driver setup when package paths include dangling or self-referential links. Setup now preserves the original installation error instead of incorrectly skipping installation or reporting a link-resolution error.
  • Chores
    • Updated pinned versions for development tools and the CodeQL analysis action. Configuration for CodeQL languages and build mode remains unchanged.

Walkthrough

The PR pins development dependencies and the CodeQL action, adds certification progress and validation records, and updates merge-driver package detection with a regression test for a self-referential NODE_PATH symlink.

Changes

PM GitHub certification

Layer / File(s) Summary
Pinned tools and certification records
.github/workflows/codeql.yml, package.json, .agents/pm/chores/*, .agents/pm/history/*
The CodeQL action steps use a different pinned commit. Five development dependencies now use exact versions. The chore and history records document certification progress, affected files, and reported validation results.
Merge-driver package lookup
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts
The launcher checks package entries across resolution paths and treats inconclusive lookup errors as package presence. The test helper clears NODE_PATH. A regression test checks that a self-referential NODE_PATH symlink preserves the original installer-resolution error and does not register drivers.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to b927d

The dependency pins and merge-driver lookup changes have no established contract failure; the regression test covers the symlink lookup case. No concrete issue currently warrants holding the merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (4 skipped: 4 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the PM CLI 2026.10.4 certification and dependency update consolidation, which are the main changes.
Description check ✅ Passed The description explains the toolchain certification, dependency updates, launcher changes, regression tests, and reported validation results.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

Updates pm-github to the PM CLI/SDK 2026.10.4 toolchain, consolidates pending Dependabot dependency and CodeQL pin updates, adopts the canonical hardened merge-driver launcher, and records successful release, security, and read-only GitHub dogfood validation.

Sequence diagram for read-only GitHub dogfood validation

sequenceDiagram
    actor Maintainer
    participant CLI as PM CLI 2026.10.4
    participant GitHub as GitHub API
    participant PM as Local PM data

    Maintainer->>CLI: github validate
    CLI->>GitHub: Repository API request
    GitHub-->>CLI: HTTP 200
    CLI-->>Maintainer: Validation ok
    Maintainer->>CLI: github import unbraind/pm-cli
    CLI->>GitHub: Fetch open issues
    GitHub-->>CLI: Issue data
    CLI->>PM: Write imported items with gh:owner/repo#N provenance
    CLI-->>Maintainer: 26 new items
    Maintainer->>CLI: github import unbraind/pm-cli
    CLI->>GitHub: Fetch open issues
    GitHub-->>CLI: Same issue data
    CLI->>PM: Update existing items
    CLI-->>Maintainer: 0 new, 26 updated
    Maintainer->>CLI: github export --dry-run
    CLI-->>Maintainer: Create/update plan only
Loading

File-Level Changes

Change Details Files
Certify the project against PM CLI/SDK 2026.10.4 while consolidating dependency updates and refreshing the lockfile.
  • Raise the exact pm-cli and pm-ops pins to 2026.10.4 while retaining pm-changelog 2026.9.25.
  • Update the resolved @types/node dependency and related lockfile entries.
  • Verify release, audit, packaging, and PM health gates against the new toolchain.
package.json
package-lock.json
Harden the merge-driver preparation logic and synchronize it with the pm-ops 2026.10.4 canonical template.
  • Improve package-presence probing across global and local Node resolution paths.
  • Fail closed when filesystem probing is inconclusive instead of masking installer diagnostics.
  • Use the installed pm-ops template as the launcher implementation.
scripts/prepare-merge-driver.ts
Refresh the pinned CodeQL action revision for both analysis phases.
  • Update the init and analyze action references to the v4 commit SHA 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2.
.github/workflows/codeql.yml
Record the PM work item and history generated for this dependency and certification update.
  • Add the chore item and corresponding history record.
.agents/pm/chores/pm-github-julo.toon
.agents/pm/history/pm-github-julo.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates development dependencies and build tooling.

The PR appears safe to merge; no blocking issue remains.

Summary

Updates the development tools to PM 2026.10.4, pins dependencies exactly, updates CodeQL, and preserves the original merge-driver error when a lookup fails.

  • Since the previous review, only the tracker and its history changed. They correct the health result to disclose two stale-item warnings.
  • The earlier lookup-test request is addressed: the test checks the original installer error, rejects a skip notice, and confirms no driver was registered.
  • No new actionable issues or repository-rule violations were found.

Reviews (4) · Last reviewed commit: "docs(pm): correct the health advisory re..."

Comment thread scripts/prepare-merge-driver.ts
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #106 (comment)

Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #106 (comment)

Useful review guide. The latest candidate b927d55 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #106 (comment)

The merge-driver regression request is addressed in b927d55 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #106 (review)

The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to the completed CodeRabbit review and its command receipt: the review covers b927d55 and reports no actionable comments. Greptile confirms the lookup-error and inherited NODE_PATH regressions are addressed at the same head. The full gate passes 309/309 with zero skips, clean audits and packed read-only own-tracker npx/bunx checks. Sourcery quota and remaining silent reviewers remain missing evidence.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #106 (comment)

The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator.

@unbraind
unbraind merged commit 888b29f into main Oct 4, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant