Certify pm-github on PM CLI 2026.10.4 and consolidate pending dependency updates - #106
Conversation
…endency updates Pin @unbrained/pm-cli and pm-ops to 2026.10.4 (pm-changelog already at 2026.9.25), take the @types/node lockfile bump (26.6.4) and the codeql-action pinned SHA group 2892aa5 from Dependabot, and recopy the canonical pm-ops merge-driver launcher byte-for-byte. Supersedes #101 #102 #103 #104.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 38 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThe PR pins development dependencies and the CodeQL action, adds certification progress and validation records, and updates merge-driver package detection with a regression test for a self-referential ChangesPM GitHub certification
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~15 minutes Change: Other Merge Risk: ⚪ Minimal · up to The dependency pins and merge-driver lookup changes have no established contract failure; the regression test covers the symlink lookup case. No concrete issue currently warrants holding the merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideUpdates pm-github to the PM CLI/SDK 2026.10.4 toolchain, consolidates pending Dependabot dependency and CodeQL pin updates, adopts the canonical hardened merge-driver launcher, and records successful release, security, and read-only GitHub dogfood validation. Sequence diagram for read-only GitHub dogfood validationsequenceDiagram
actor Maintainer
participant CLI as PM CLI 2026.10.4
participant GitHub as GitHub API
participant PM as Local PM data
Maintainer->>CLI: github validate
CLI->>GitHub: Repository API request
GitHub-->>CLI: HTTP 200
CLI-->>Maintainer: Validation ok
Maintainer->>CLI: github import unbraind/pm-cli
CLI->>GitHub: Fetch open issues
GitHub-->>CLI: Issue data
CLI->>PM: Write imported items with gh:owner/repo#N provenance
CLI-->>Maintainer: 26 new items
Maintainer->>CLI: github import unbraind/pm-cli
CLI->>GitHub: Fetch open issues
GitHub-->>CLI: Same issue data
CLI->>PM: Update existing items
CLI-->>Maintainer: 0 new, 26 updated
Maintainer->>CLI: github export --dry-run
CLI-->>Maintainer: Create/update plan only
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
Response to #106 (comment) Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence. |
|
Response to #106 (comment) Useful review guide. The latest candidate b927d55 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item. |
|
Response to #106 (comment) The merge-driver regression request is addressed in b927d55 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item. |
|
Response to #106 (review) The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Response to the completed CodeRabbit review and its command receipt: the review covers b927d55 and reports no actionable comments. Greptile confirms the lookup-error and inherited NODE_PATH regressions are addressed at the same head. The full gate passes 309/309 with zero skips, clean audits and packed read-only own-tracker npx/bunx checks. Sourcery quota and remaining silent reviewers remain missing evidence. |
|
@coderabbitai review |
|
|
Response to #106 (comment) The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator. |
What changed
Certifies pm-github on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:
@unbrained/pm-cli2026.9.26 → 2026.10.4 (chore(deps-dev): bump @unbrained/pm-cli from 2026.9.26 to 2026.10.1 #101 proposed 2026.10.1 — this carries a newer version),pm-ops2026.9.28 → 2026.10.4 (chore(deps-dev): bump pm-ops from 2026.9.28 to 2026.9.29 #103 proposed 2026.9.29 — newer here).pm-changelogstays at the latest 2026.10.4.2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2(v4) for bothinitandanalyze.scripts/prepare-merge-driver.tsrecopied byte-for-byte from the installed pm-ops 2026.10.4 template.npm auditandnpm audit --omit=devboth 0 vulnerabilities.Gate commands + results
npm run release:check— PASS: typecheck, build, docstring gate, privacy gate, coverage at the configured thresholds,npm audit --omit=dev0 vulnerabilities,npm pack --dry-run, changelog check, publish-attestation gate.npx pm health(repo-pinned 2026.10.4 binary) — exit 0; one pre-existing advisory (stale in-progress items).Dogfood evidence (real data, packed tarball, read-only on GitHub)
Packed
pm-github-2026.10.4.tgz, installed into a scratch copy of this repo's own real.agents/pm, registered viapm package install:npx -y @unbrained/pm-cli@2026.10.4):github validate --repo unbraind/pm-github→ ok (token via gh CLI, HTTP 200);github import unbraind/pm-github→ truthfully 0 (the repo has no open issues);github import unbraind/pm-cli→ Imported 26 new (real open issue data, read-only fetch); re-import → 0 new / 26 updated, provinggh:owner/repo#Nprovenance idempotency;github export --dry-run→ create/update plan only, writes nothing;github sync --dry-run --repo unbraind/pm-csv→ planned 0.bunx @unbrained/pm-cli@2026.10.4):github validateok;github import unbraind/pm-cli→ 0 new / 26 updated;export --dry-runandsync --dry-runidentical.pm-github preview (read-only)
pm github validate --repo unbraind/pm-github→ ok (HTTP 200);pm github export --repo unbraind/pm-github --dry-run→ plan only;pm github sync --dry-run --repo unbraind/pm-github→ planned 1 / skipped 1, no mutation. No issues created/modified, no scheduled sync enabled.Superseded Dependabot PRs
#101, #102, #103, #104 — every update (same or newer version) is carried here.
pm item
https://github.com/unbraind/pm-github/blob/main/.agents/pm/chores/pm-github-julo.toon
The canonical launcher is unchanged. Added the requested lookup-error regression, portable junction fixtures and isolation from inherited NODE_PATH; the hostile-environment launcher suite passes with no new skips. Clean npm ci verifies the pinned graph. Current certification repeats the packed npm/bun read-only own-repository validation, import preview, export preview and sync preview.
Fresh gate: 309/309 tests, zero skips, unchanged coverage thresholds, both audit scopes clean, privacy gate clean. Packed own-tracker export previews render 108 creates + 1 update on npm and bun; sync plans 1, wouldSync 0, skips 1. No GitHub writes.
Final full health receipt: exit 0 with stale_in_progress_items:2 advisory. This corrects the earlier zero-warning summary; package code and validated source are unchanged.
Summary by Sourcery
Certify pm-github on PM CLI 2026.10.4 while consolidating dependency, launcher reliability, and workflow security updates.
Bug Fixes:
Enhancements:
CI:
Tests:
Chores: