Skip to content

Certify pm-graph on PM CLI 2026.10.4 and consolidate pending dependency updates - #124

Merged
unbraind merged 5 commits into
mainfrom
chore/pm-graph-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 5 commits into
mainfrom
chore/pm-graph-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Pins CLI/SDK, pm-ops, pm-changelog and managed pm-github to 2026.10.4, makes every devDependency exact, and consolidates Dependabot #118, #119, #120 and #121, including their exact CodeQL SHA bump. Uses the byte-identical published merge-driver launcher; retains the SDK floor.

jscpd 5.4.0 exposed duplicated guard/test fixtures, which now share implementations without exclusions or threshold changes. Contract tests install a packed distribution because CLI 2026.10.4 correctly refuses incomplete source snapshots. Added a real malformed-lookup launcher regression. Repaired an inherited hash-only history mismatch with canonical audited history-repair: zero discarded/repaired patches and byte-identical owner item.

Validation (heavy commands serialized with the shared flock):

  • npm run release:check through pm test pm-graph-lcmc --run --only-index 1 --progress --json using env -u PM_PATH for the CI child: 301/301 pass, zero skips on both local Node 24 and Node 22.23.1/npm 10.9.8.
  • Fixed the reproduced Node 22/npm 10 pack-output parser failure by validating the actual archive in the fresh pack directory; the custom-tracker contract fails before the fix and passes afterwards.
  • Duplication: zero; measured coverage 99.66% lines / 94.07% branches / 100% functions, four configured files; Node 22 measures 99.63/93.98/100. Statements unmeasured; coverage owner remains open.
  • Scoped launcher 8/8, analytics/docstring 61/61, integration 12/12 and packed contracts 19/19 pass.
  • npx pm health --strict-exit --require-merge-drivers: exit 0; one advisory finding covers two stale items.
  • npm audit --omit=dev: clean. Full npm audit remains blocked: four high development entries from unpatched braces 3.0.3 through fast-glob/pm-ops; no compatible patched release is published. Do not merge as certified until this is resolved.
  • npm pack into a copied real tracker; npm/npx and native Bun (bunx --bun @unbrained/pm-cli@2026.10.4) passed ping, export, analyze, cycles, cypher, critical-path, impact and path. Graph values/order matched 185 nodes / 330 edges after independent timestamp validation; scratch removed.
  • Managed pm-github dry-run: dryRun=true, wouldSync=0, skipped=1, planned=1. No issue writes or scheduling changes.
  • Regenerated changelog after PM mutations; check passes.

Durable commands and results.

PM: certification pm-graph-lcmc, audit blocker pm-graph-g8uc, coverage owner pm-graph-6zil, repaired history owner pm-graph-3a1p.

Summary by Sourcery

Certify pm-graph against the 2026.10.4 PM toolchain while consolidating dependency updates and strengthening package, launcher, and release validation.

New Features:

  • Certify pm-graph against PM CLI/SDK and related managed tooling version 2026.10.4 across packed npm and native Bun usage.
  • Add durable certification records covering validation gates, real-tracker acceptance, managed GitHub preview, audit status, and repaired PM history.

Bug Fixes:

  • Make packed contract testing reliable across npm lifecycle output and prevent incomplete source snapshots from being treated as package acceptance.
  • Harden merge-driver installation against malformed or inconclusive module lookups so failures remain explicit.
  • Correct impact command filtering coverage and consolidate duplicated analytics and fixture implementations.

Enhancements:

  • Pin all development dependencies exactly and refresh the dependency lockfile.
  • Extract shared invocation and test helpers while preserving existing coverage thresholds and adding the launcher regression coverage.

CI:

  • Update CodeQL workflow actions to the audited v4 commit.

Documentation:

  • Document the 2026.10.4 certification results, acceptance checks, audit blocker, and managed GitHub dry-run.

Tests:

  • Expand validation across launcher, analytics, integration, packed contract, Node 22, npm, and native Bun acceptance paths.

Chores:

  • Update managed pm-github and PM metadata to 2026.10.4 and repair inherited PM history-chain metadata.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 20 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 25 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: fff853f1-5487-4ada-b713-c571e00fc7a4
📥 Commits

Reviewing files that changed from the base of the PR and between 82b249f and b5cb065.

📒 Files selected for processing (2)
  • .agents/pm/history/pm-graph-g8uc.jsonl
  • .agents/pm/issues/pm-graph-g8uc.toon

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: cee39281-cdd0-4cb5-b219-75f9372634b1
📥 Commits

Reviewing files that changed from the base of the PR and between 1d47a84 and 82b249f.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (20)
  • .agents/pm/chores/pm-graph-lcmc.toon
  • .agents/pm/extensions/.managed-extensions.json
  • .agents/pm/history/pm-graph-3a1p.jsonl
  • .agents/pm/history/pm-graph-g8uc.jsonl
  • .agents/pm/history/pm-graph-lcmc.jsonl
  • .agents/pm/issues/pm-graph-g8uc.toon
  • .github/workflows/codeql.yml
  • docs/certification-2026.10.4.md
  • package.json
  • scripts/docstring-gate.ts
  • scripts/install-pm-github.sh
  • scripts/prepare-merge-driver.ts
  • test/analytics.test.ts
  • test/export-and-contract.test.ts
  • test/fixtures/neo4j-retry-default-loader.ts
  • test/fixtures/neo4j-retry-loader.ts
  • test/fixtures/neo4j-retry-named-loader.ts
  • test/helpers.ts
  • test/impact-command.test.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Compatibility

    • Certified the release on Node.js 22 and 24, with successful npm and Bun package-install checks.
    • Updated the managed GitHub integration to version 2026.10.4.
  • Bug Fixes

    • Improved merge-driver setup so inconclusive dependency checks fail explicitly instead of silently skipping installation.
  • Maintenance

    • Updated and pinned development tools. A development dependency audit issue remains unresolved; production audit checks passed.

Walkthrough

This change updates PM Graph’s development dependencies and release checks for PM CLI/SDK 2026.10.4. It adjusts test setup and merge-driver package detection, records npm and Bun acceptance results, and documents an unresolved development-audit blocker.

Changes

PM Graph 2026.10.4 certification

Layer / File(s) Summary
Dependency pins and audit blocker
package.json, .agents/pm/extensions/.managed-extensions.json, scripts/install-pm-github.sh, .github/workflows/codeql.yml, .agents/pm/issues/pm-graph-g8uc.toon, .agents/pm/history/pm-graph-g8uc.jsonl
Updates development dependency pins and the managed pm-github version, changes the CodeQL action commit, and records the unresolved braces audit issue.
Release-check implementation and tests
scripts/docstring-gate.ts, scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts, test/fixtures/neo4j-retry-*.ts, test/export-and-contract.test.ts, test/helpers.ts, test/impact-command.test.ts, test/analytics.test.ts
Moves isMainInvocation to an imported module and centralizes the Neo4j retry resolver. Merge-driver detection now preserves the installer error when filesystem checks are inconclusive. Tests use packed npm archives and shared fixture and graph helpers.
Certification evidence and status
docs/certification-2026.10.4.md, .agents/pm/chores/pm-graph-lcmc.toon, .agents/pm/history/pm-graph-lcmc.jsonl, .agents/pm/history/pm-graph-3a1p.jsonl
Records passing release checks, packed npm/Bun parity, history verification, and the remaining development-audit blocker. The certification chore remains in progress.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Possibly related PRs

  • unbraind/pm-graph#57: Both PRs update PM CLI/SDK and pm-changelog versions and change the TypeScript merge-driver prepare lifecycle.

Merge Risk: ⚪ Minimal · up to 82b24

No PR-introduced merge blocker is established. The development audit remains an open, pre-existing certification constraint.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: certifying pm-graph on PM CLI 2026.10.4 and consolidating dependency updates.
Description check ✅ Passed The description directly relates to the changeset and explains the dependency updates, test changes, validation results, and outstanding audit blocker.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 11 files. (9 skipped: 9…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR consolidates and pins the dependency/toolchain updates for PM CLI/SDK 2026.10.4, hardens merge-driver and entrypoint behavior, removes newly detected test duplication through shared helpers, and makes contract tests exercise the packed distribution across Node and Bun. Review the certification receipts and specifically the still-open high-severity development dependency audit blocker before considering the release certified.

Sequence diagram for packed distribution contract validation

sequenceDiagram
    participant Test as Contract tests
    participant Pack as npm pack
    participant Install as Package installation
    participant CLI as PM CLI 2026.10.4
    participant Graph as pm-graph
    Test->>Pack: npm pack
    Pack-->>Install: packed archive
    Install->>CLI: install archive and CLI 2026.10.4
    Test->>CLI: run graph commands
    CLI->>Graph: ping, export, analyze
    CLI->>Graph: cycles, cypher, critical-path
    CLI->>Graph: impact, path
    Graph-->>Test: matching results and ordering
    Test-->>Test: validate 185 nodes and 330 edges
Loading

Sequence diagram for fail-closed merge-driver package detection

sequenceDiagram
    participant Launcher as Merge-driver launcher
    participant Resolver as Node package resolver
    participant FS as Filesystem
    Launcher->>Resolver: resolve pm-ops/package.json
    alt package found
        Resolver-->>Launcher: package path
        Launcher-->>Launcher: retain installer diagnostic
    else module not found
        Resolver->>Resolver: resolve.paths pm-ops/package.json
        Resolver->>FS: lstatSync package directories
        alt lookup is inconclusive
            FS-->>Resolver: filesystem error
            Resolver-->>Launcher: package presence uncertain
            Launcher-->>Launcher: fail closed
        else package absent
            FS-->>Resolver: no package directory
            Resolver-->>Launcher: package absent
            Launcher-->>Launcher: omit-dev installation allowed
        end
    end
Loading

Flow diagram for certification gates and audit blocker

flowchart TD
    A[Pin CLI SDK and PM dependencies to 2026.10.4] --> B[Run release and contract validation]
    B --> C{All tests and quality gates pass?}
    C -->|Yes| D[Validate packed Node and Bun acceptance]
    C -->|No| E[Certification fails]
    D --> F{npm audit including dev dependencies clean?}
    F -->|Yes| G[Release can be certified]
    F -->|No| H[Certification blocked by four high development vulnerabilities]
    H --> I[pm-graph-g8uc owns remediation]
Loading

File-Level Changes

Change Details Files
Certified the project against the 2026.10.4 PM toolchain and consolidated dependency updates.
  • Pinned CLI/SDK, pm-ops, pm-changelog, and managed pm-github to 2026.10.4.
  • Made development dependency versions exact and refreshed the lockfile.
  • Bumped CodeQL actions to the audited commit SHA.
  • Added durable certification receipts, PM records, and history repairs; note the unresolved full development-audit blocker before treating the certification as complete.
package.json
package-lock.json
scripts/install-pm-github.sh
.github/workflows/codeql.yml
docs/certification-2026.10.4.md
.agents/pm/chores/pm-graph-lcmc.toon
.agents/pm/issues/pm-graph-g8uc.toon
.agents/pm/history/pm-graph-lcmc.jsonl
.agents/pm/history/pm-graph-g8uc.jsonl
.agents/pm/history/pm-graph-3a1p.jsonl
.agents/pm/extensions/.managed-extensions.json
Hardened merge-driver installation and centralized main-entry detection.
  • Preserved global/module resolution paths and fail-closed behavior for malformed or unreadable lookups.
  • Moved canonical main-invocation detection into a shared module.
  • Added regression coverage for a non-directory lookup path and verified byte-identical launcher behavior.
scripts/prepare-merge-driver.ts
scripts/docstring-gate.ts
scripts/main-invocation.ts
test/prepare-merge-driver.test.ts
Refactored tests and fixtures to remove duplication while preserving existing gates.
  • Shared graph-node and downstream-impact fixtures and generalized item creation by type.
  • Shared Neo4j retry-loader behavior across default and named-export fixtures.
  • Added the shared invocation guard to measured coverage without changing thresholds or exclusions.
test/analytics.test.ts
test/helpers.ts
test/fixtures/neo4j-retry-loader.ts
test/fixtures/neo4j-retry-default-loader.ts
test/fixtures/neo4j-retry-named-loader.ts
package.json
Changed contract tests to validate the packed npm distribution and expanded runtime acceptance coverage.
  • Packed the declared distribution once and installed the archive into isolated contract workspaces, including custom tracker paths.
  • Added direct handler invocation helpers for impact command filtering tests.
  • Documented Node/npx and native Bun acceptance against a copied real tracker, including graph equivalence checks.
test/export-and-contract.test.ts
test/impact-command.test.ts
docs/certification-2026.10.4.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates build tools and dependency versions with exact pins.

The changes since the previous review appear safe; they correct tracking records without changing executable code or dependencies.

What we checked:

  • The dependency correction matches: The locked pm-ops manifest lists fast-glob under peerDependencies and marks it optional.

Summary

This PR pins the PM toolchain to 2026.10.4, makes development dependencies exact, updates CodeQL, and strengthens packed-package and launcher tests.

  • Since the previous review, only the audit issue and its history changed. They correct fast-glob from an allegedly undeclared dependency to a declared optional peer.
  • No new actionable issues were found in those changes.
  • unbraind explicitly identifies the development audit problem as known and says certification must wait for a compatible fix. This review does not treat that acknowledgment as completed certification.

Reviews (5) · Last reviewed commit: "Clarify vulnerable fast-glob optional pe..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Re this comment: This is an automatic-review eligibility skip for a repository below the star threshold, not a code review. A manual review request is being posted. No repository policy or gate was weakened to suppress it.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Re this comment: Useful summary acknowledged. The full development audit remains blocked under pm-graph-g8uc, and the configured coverage owner remains open. Exact-head CI also exposed a Node22/npm10 fixture parsing failure, reproduced locally; the strict actual-tarball repair is being validated before push.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Re this comment: Useful summary acknowledged. The full development audit remains blocked under pm-graph-g8uc, and the configured coverage owner remains open. Exact-head CI also exposed a Node22/npm10 fixture parsing failure, reproduced locally; the strict actual-tarball repair is being validated before push.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Re this comment: This review body reports an exhausted review quota and supplies no source findings. It remains unavailable evidence, rather than approval; the reported tests and remaining blockers are independent.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

The completed manual review covers 82b249f and reports no actionable findings. Reproduced npm10 contract failure was fixed test-first in82b249f; Node22/26CI green. Full development audit remains blocked by pm-graph-g8uc; no quota/neutral/missing review is treated as approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Acknowledged the updated substantive review explicitly covering 82b249f, with no new actionable findings. Known certification blockers remain documented; zero unresolved threads and green configured checks do not replace missing reviewer evidence.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Manual command completed; the substantive summary covers 82b249f with no actionable findings. The audit condition remains open.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

The re-review command is rate limited until the included review allowance resets. This is missing exact-head review evidence, not approval. Prior substantive CodeRabbit coverage is82b249f; b5cb065 only corrects the optional-peer audit receipt. The full development audit remains blocked by pm-graph-g8uc.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

The edited body now declines review of b5cb065 because the included OSS review allowance is exhausted. Its retained no-actionable assessment covers82b249f. Record the final metadata head as not reviewed by this bot; no skipped/rate-limited status clears the vulnerable optional-peer audit condition.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Acknowledged the substantive review explicitly coveringb5cb065b343a48445955e8e9b4e109c3e0128b43. The installed manifest confirms fast-glob is a declared optional peer required by duplication consumers. No new actionable finding; actual development audit4high remains the certification blocker. Current Node22/26 CI is green; quota/absent reviewers remain missing evidence.

@unbraind
unbraind merged commit 0e905e0 into main Oct 4, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant