Repository navigation
Certify pm-graph on PM CLI 2026.10.4 and consolidate pending dependency updates - #124
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 25 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (20)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThis change updates PM Graph’s development dependencies and release checks for PM CLI/SDK 2026.10.4. It adjusts test setup and merge-driver package detection, records npm and Bun acceptance results, and documents an unresolved development-audit blocker. ChangesPM Graph 2026.10.4 certification
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Other Possibly related PRs
Merge Risk: ⚪ Minimal · up to No PR-introduced merge blocker is established. The development audit remains an open, pre-existing certification constraint. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR consolidates and pins the dependency/toolchain updates for PM CLI/SDK 2026.10.4, hardens merge-driver and entrypoint behavior, removes newly detected test duplication through shared helpers, and makes contract tests exercise the packed distribution across Node and Bun. Review the certification receipts and specifically the still-open high-severity development dependency audit blocker before considering the release certified. Sequence diagram for packed distribution contract validationsequenceDiagram
participant Test as Contract tests
participant Pack as npm pack
participant Install as Package installation
participant CLI as PM CLI 2026.10.4
participant Graph as pm-graph
Test->>Pack: npm pack
Pack-->>Install: packed archive
Install->>CLI: install archive and CLI 2026.10.4
Test->>CLI: run graph commands
CLI->>Graph: ping, export, analyze
CLI->>Graph: cycles, cypher, critical-path
CLI->>Graph: impact, path
Graph-->>Test: matching results and ordering
Test-->>Test: validate 185 nodes and 330 edges
Sequence diagram for fail-closed merge-driver package detectionsequenceDiagram
participant Launcher as Merge-driver launcher
participant Resolver as Node package resolver
participant FS as Filesystem
Launcher->>Resolver: resolve pm-ops/package.json
alt package found
Resolver-->>Launcher: package path
Launcher-->>Launcher: retain installer diagnostic
else module not found
Resolver->>Resolver: resolve.paths pm-ops/package.json
Resolver->>FS: lstatSync package directories
alt lookup is inconclusive
FS-->>Resolver: filesystem error
Resolver-->>Launcher: package presence uncertain
Launcher-->>Launcher: fail closed
else package absent
FS-->>Resolver: no package directory
Resolver-->>Launcher: package absent
Launcher-->>Launcher: omit-dev installation allowed
end
end
Flow diagram for certification gates and audit blockerflowchart TD
A[Pin CLI SDK and PM dependencies to 2026.10.4] --> B[Run release and contract validation]
B --> C{All tests and quality gates pass?}
C -->|Yes| D[Validate packed Node and Bun acceptance]
C -->|No| E[Certification fails]
D --> F{npm audit including dev dependencies clean?}
F -->|Yes| G[Release can be certified]
F -->|No| H[Certification blocked by four high development vulnerabilities]
H --> I[pm-graph-g8uc owns remediation]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
Re this comment: This is an automatic-review eligibility skip for a repository below the star threshold, not a code review. A manual review request is being posted. No repository policy or gate was weakened to suppress it. |
|
Re this comment: Useful summary acknowledged. The full development audit remains blocked under pm-graph-g8uc, and the configured coverage owner remains open. Exact-head CI also exposed a Node22/npm10 fixture parsing failure, reproduced locally; the strict actual-tarball repair is being validated before push. |
|
Re this comment: Useful summary acknowledged. The full development audit remains blocked under pm-graph-g8uc, and the configured coverage owner remains open. Exact-head CI also exposed a Node22/npm10 fixture parsing failure, reproduced locally; the strict actual-tarball repair is being validated before push. |
|
Re this comment: This review body reports an exhausted review quota and supplies no source findings. It remains unavailable evidence, rather than approval; the reported tests and remaining blockers are independent. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
The completed manual review covers 82b249f and reports no actionable findings. Reproduced npm10 contract failure was fixed test-first in82b249f; Node22/26CI green. Full development audit remains blocked by pm-graph-g8uc; no quota/neutral/missing review is treated as approval. |
|
Acknowledged the updated substantive review explicitly covering 82b249f, with no new actionable findings. Known certification blockers remain documented; zero unresolved threads and green configured checks do not replace missing reviewer evidence. |
|
Manual command completed; the substantive summary covers 82b249f with no actionable findings. The audit condition remains open. |
|
@coderabbitai review |
|
|
The re-review command is rate limited until the included review allowance resets. This is missing exact-head review evidence, not approval. Prior substantive CodeRabbit coverage is82b249f; b5cb065 only corrects the optional-peer audit receipt. The full development audit remains blocked by pm-graph-g8uc. |
|
The edited body now declines review of b5cb065 because the included OSS review allowance is exhausted. Its retained no-actionable assessment covers82b249f. Record the final metadata head as not reviewed by this bot; no skipped/rate-limited status clears the vulnerable optional-peer audit condition. |
|
Acknowledged the substantive review explicitly coveringb5cb065b343a48445955e8e9b4e109c3e0128b43. The installed manifest confirms fast-glob is a declared optional peer required by duplication consumers. No new actionable finding; actual development audit4high remains the certification blocker. Current Node22/26 CI is green; quota/absent reviewers remain missing evidence. |
Pins CLI/SDK, pm-ops, pm-changelog and managed pm-github to 2026.10.4, makes every devDependency exact, and consolidates Dependabot #118, #119, #120 and #121, including their exact CodeQL SHA bump. Uses the byte-identical published merge-driver launcher; retains the SDK floor.
jscpd 5.4.0 exposed duplicated guard/test fixtures, which now share implementations without exclusions or threshold changes. Contract tests install a packed distribution because CLI 2026.10.4 correctly refuses incomplete source snapshots. Added a real malformed-lookup launcher regression. Repaired an inherited hash-only history mismatch with canonical audited history-repair: zero discarded/repaired patches and byte-identical owner item.
Validation (heavy commands serialized with the shared flock):
npm run release:checkthroughpm test pm-graph-lcmc --run --only-index 1 --progress --jsonusingenv -u PM_PATHfor the CI child: 301/301 pass, zero skips on both local Node 24 and Node 22.23.1/npm 10.9.8.npx pm health --strict-exit --require-merge-drivers: exit 0; one advisory finding covers two stale items.npm audit --omit=dev: clean. Full npm audit remains blocked: four high development entries from unpatched braces 3.0.3 through fast-glob/pm-ops; no compatible patched release is published. Do not merge as certified until this is resolved.npm packinto a copied real tracker; npm/npx and native Bun (bunx --bun @unbrained/pm-cli@2026.10.4) passed ping, export, analyze, cycles, cypher, critical-path, impact and path. Graph values/order matched 185 nodes / 330 edges after independent timestamp validation; scratch removed.dryRun=true,wouldSync=0,skipped=1,planned=1. No issue writes or scheduling changes.Durable commands and results.
PM: certification pm-graph-lcmc, audit blocker pm-graph-g8uc, coverage owner pm-graph-6zil, repaired history owner pm-graph-3a1p.
Summary by Sourcery
Certify pm-graph against the 2026.10.4 PM toolchain while consolidating dependency updates and strengthening package, launcher, and release validation.
New Features:
Bug Fixes:
Enhancements:
CI:
Documentation:
Tests:
Chores: