Repository navigation
Certify pm-linear on PM CLI 2026.10.4 and consolidate pending dependency updates - #132
Conversation
…endency updates Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and pm-changelog 2026.9.25, take the @types/node lockfile bump (26.6.4) and the codeql-action pinned SHA group 2892aa5 from Dependabot, and recopy the canonical pm-ops merge-driver launcher byte-for-byte. Supersedes #125 #128 #129 #130 #131.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThe changes update development dependency pins and CodeQL action commits, refine ChangesPM CLI certification
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable issue remains from these comments; the change is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The installer now rejects broken or inconclusive package installations instead of silently skipping them. Current CI job permissions remain explicitly limited. An existing workflow-default permission issue remains, and recovery from interrupted driver registration was not verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR upgrades pm-linear’s PM tooling to the certified 2026.10.4 release, consolidates and locks the pending dependency and CodeQL updates, and synchronizes the merge-driver launcher with the new pm-ops template. Review should focus on lockfile consistency, the fail-closed package-presence logic in the installer launcher, and that the reported release, health, offline dogfood, and read-only pm-github checks cover the upgraded tooling without introducing tracked runtime state. Flow diagram for fail-closed pm-ops installer detectionflowchart TD
A["Resolve pm-ops installer entry"] --> B{"Resolution succeeds?"}
B -->|Yes| C["spawnSync installer"]
B -->|No| D["resolver.resolve pm-ops/package.json"]
D -->|Package resolves| E["Rethrow original resolution error"]
D -->|MODULE_NOT_FOUND| F["resolver.resolve.paths pm-ops/package.json"]
F --> G["lstatSync candidate pm-ops paths"]
G --> H{"Any package directory exists or lookup is inconclusive?"}
H -->|Yes| E
H -->|No| I["Skip with notice"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
Response to #132 (comment) Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence. |
|
Response to #132 (comment) Useful review guide. The latest candidate 1c0efe2 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item. |
|
Response to #132 (comment) The merge-driver regression request is addressed in 1c0efe2 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item. |
|
Response to #132 (review) The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Response to the completed CodeRabbit review and its command receipt: both CodeRabbit and Greptile cover 1c0efe2 and report no new actionable findings. The earlier broken-install regressions are fixed in that commit; the full release gate passes 222/222 with zero skips and both npm audits are clean. The optional architecture hardening proposals do not establish a regression in this candidate. The only CodeQL job already has explicit security-events:write, actions:read and contents:read permissions on main and this branch; this PR does not add a job or expand those grants. The launcher must remain byte-identical to the pm-ops 2026.10.4 template, so upstream installer lifecycle changes do not belong in this package certification. Tests demonstrate the requested lookup/failure behavior; concurrent registration, interruption recovery and dependency execution sandboxing remain outside the measured assurance scope. No lifecycle defect was demonstrated. Sourcery quota, neutral cubic and silent Gemini/Copilot remain missing review evidence, so the PR stays open for the orchestrator. |
What changed
Certifies pm-linear on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:
@unbrained/pm-cli2026.9.23 → 2026.10.4 (build(deps-dev): bump @unbrained/pm-cli from 2026.9.23 to 2026.9.30 #129 proposed 2026.9.30 — newer here),pm-ops→ 2026.10.4 (build(deps-dev): bump pm-ops from 2026.9.23 to 2026.9.29 #128 proposed 2026.9.29 — newer here),pm-changelog→ 2026.10.4 (build(deps-dev): bump pm-changelog from 2026.9.23 to 2026.9.25 #131).2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2(v4) forinitandanalyze.scripts/prepare-merge-driver.tsrecopied byte-for-byte from the installed pm-ops 2026.10.4 template.npm auditandnpm audit --omit=devboth 0 vulnerabilities.Gate commands + results
npm run release:check— PASS: typecheck, build, docstring gate, coverage at the configured 99/96/100 thresholds (unchanged),npm audit --omit=dev0 vulnerabilities,npm pack --dry-run, changelog check, changelog-date and publish-attestation gates.npx pm health(repo-pinned 2026.10.4 binary) — exit 0, two advisory categories (one stale item and inherited historical provenance audit receipts); no gate-failing findings.Dogfood evidence (real tracker, packed tarball, strictly offline)
Packed
pm-linear-2026.10.3.tgz, installed into a scratch copy of this repo's own real.agents/pm, registered viapm package install. Linear is a hosted service, so the dogfood exercises only the offline/dry-run surface — zero Linear network calls, zero hosted mutation:npx -y @unbrained/pm-cli@2026.10.4):linear validate(offline) → correct config report (readyForWrites: false,networkChecked: false);linear sync --team ENG --dry-run→ offline GraphQL plan, explicitly "no Linear network call is made";linear import --team ENG --dry-run→ same offline plan;linear export→ real create payloads rendered from the actual tracker items.bunx @unbrained/pm-cli@2026.10.4):linear validate,linear sync --dry-run,linear export,linear import --dry-runall identical, exit 0.pm-github preview (read-only)
pm github validate --repo unbraind/pm-linear→ ok (HTTP 200);pm github export --dry-run→ plan only, writes nothing;pm github sync --dry-run→ planned 0, no mutation. No issues created/modified, no scheduled sync enabled.Superseded Dependabot PRs
#125, #128, #129, #130, #131 — every update (same or newer version) is carried here.
pm item
https://github.com/unbraind/pm-linear/blob/main/.agents/pm/chores/pm-linear-2cy6.toon
Added unconditional regression fixtures for incomplete/dangling pm-ops installations and lookup errors, using junctions for Windows and isolating inherited NODE_PATH. The canonical launcher is unchanged; the hostile-environment launcher suite passes 9/9 with no new skips. Clean npm ci and the full gate repeat the offline packed real-tracker npm/bun validation.
Fresh full gate: 222/222 tests, zero skips, both audit scopes clean. Offline packed npx/bunx checks repeat the real-tracker validation without Linear API calls or writes. Historical provenance follow-up: https://github.com/unbraind/pm-linear/blob/main/.agents/pm/issues/pm-linear-jloc.toon.
Summary by Sourcery
Certify pm-linear on PM CLI/SDK 2026.10.4 while consolidating dependency, security, and installation-resilience updates.
New Features:
Bug Fixes:
Enhancements:
CI:
Tests:
Chores: