Skip to content

Certify pm-linear on PM CLI 2026.10.4 and consolidate pending dependency updates - #132

Merged
unbraind merged 2 commits into
mainfrom
chore/pm-linear-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 2 commits into
mainfrom
chore/pm-linear-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What changed

Certifies pm-linear on PM CLI/SDK 2026.10.4 and consolidates every pending Dependabot update into one PR:

Gate commands + results

  • npm run release:check — PASS: typecheck, build, docstring gate, coverage at the configured 99/96/100 thresholds (unchanged), npm audit --omit=dev 0 vulnerabilities, npm pack --dry-run, changelog check, changelog-date and publish-attestation gates.
  • npx pm health (repo-pinned 2026.10.4 binary) — exit 0, two advisory categories (one stale item and inherited historical provenance audit receipts); no gate-failing findings.

Dogfood evidence (real tracker, packed tarball, strictly offline)

Packed pm-linear-2026.10.3.tgz, installed into a scratch copy of this repo's own real .agents/pm, registered via pm package install. Linear is a hosted service, so the dogfood exercises only the offline/dry-run surface — zero Linear network calls, zero hosted mutation:

  • npm (npx -y @unbrained/pm-cli@2026.10.4): linear validate (offline) → correct config report (readyForWrites: false, networkChecked: false); linear sync --team ENG --dry-run → offline GraphQL plan, explicitly "no Linear network call is made"; linear import --team ENG --dry-run → same offline plan; linear export → real create payloads rendered from the actual tracker items.
  • bun (bunx @unbrained/pm-cli@2026.10.4): linear validate, linear sync --dry-run, linear export, linear import --dry-run all identical, exit 0.
  • Scratch copy deleted afterwards.

pm-github preview (read-only)

pm github validate --repo unbraind/pm-linear → ok (HTTP 200); pm github export --dry-run → plan only, writes nothing; pm github sync --dry-run → planned 0, no mutation. No issues created/modified, no scheduled sync enabled.

Superseded Dependabot PRs

#125, #128, #129, #130, #131 — every update (same or newer version) is carried here.

pm item

https://github.com/unbraind/pm-linear/blob/main/.agents/pm/chores/pm-linear-2cy6.toon

Added unconditional regression fixtures for incomplete/dangling pm-ops installations and lookup errors, using junctions for Windows and isolating inherited NODE_PATH. The canonical launcher is unchanged; the hostile-environment launcher suite passes 9/9 with no new skips. Clean npm ci and the full gate repeat the offline packed real-tracker npm/bun validation.

Fresh full gate: 222/222 tests, zero skips, both audit scopes clean. Offline packed npx/bunx checks repeat the real-tracker validation without Linear API calls or writes. Historical provenance follow-up: https://github.com/unbraind/pm-linear/blob/main/.agents/pm/issues/pm-linear-jloc.toon.

Summary by Sourcery

Certify pm-linear on PM CLI/SDK 2026.10.4 while consolidating dependency, security, and installation-resilience updates.

New Features:

  • Certify pm-linear against PM CLI/SDK 2026.10.4, including npm and Bun offline tracker workflows and read-only pm-github previews.

Bug Fixes:

  • Ensure incomplete, dangling, or otherwise unresolved pm-ops installations fail safely instead of being treated as optional development dependencies.

Enhancements:

  • Consolidate development tooling and type dependency updates at current exact versions.
  • Add regression coverage for hostile pm-ops installation and module lookup environments.

CI:

  • Update CodeQL actions to the current pinned v4 revision.

Tests:

  • Verify the updated package through full release gates, clean audits, and 222 passing tests with no skips.

Chores:

  • Register pm-github as an unmanaged per-clone preview extension and record the associated project history and follow-up items.

…endency updates

Pin @unbrained/pm-cli to 2026.10.4 with pm-ops 2026.10.4 and
pm-changelog 2026.9.25, take the @types/node lockfile bump (26.6.4) and
the codeql-action pinned SHA group 2892aa5 from Dependabot, and recopy
the canonical pm-ops merge-driver launcher byte-for-byte.

Supersedes #125 #128 #129 #130 #131.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 21 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 160f7c17-0de2-4034-9fc1-133dbeacd090
📥 Commits

Reviewing files that changed from the base of the PR and between cb914b2 and 1c0efe2.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (8)
  • .agents/pm/chores/pm-linear-2cy6.toon
  • .agents/pm/history/pm-linear-2cy6.jsonl
  • .agents/pm/history/pm-linear-jloc.jsonl
  • .agents/pm/issues/pm-linear-jloc.toon
  • .github/workflows/codeql.yml
  • package.json
  • scripts/prepare-merge-driver.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Improved setup handling when the optional operations package cannot be resolved. Incomplete or unreadable installations now surface the original error instead of being incorrectly treated as an installation where the package is absent.
  • Maintenance
    • Updated internal tooling and security-analysis components. No end-user features or workflows changed.

Walkthrough

The changes update development dependency pins and CodeQL action commits, refine pm-ops detection in the merge-driver installer, add launcher tests, and record PM CLI certification results and a provenance-warning investigation.

Changes

PM CLI certification

Layer / File(s) Summary
Release pins and certification records
package.json, .github/workflows/codeql.yml, .agents/pm/chores/*, .agents/pm/history/pm-linear-2cy6.jsonl
The manifest pins development dependencies and updates PM package versions. The CodeQL action steps use a different v4 commit. PM records document certification checks, offline previews, and results.
Merge-driver package detection
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts
The installer checks Node resolution paths and filesystem entries before treating pm-ops as absent. Tests cover incomplete directories, dangling links, and a looping NODE_PATH.
Historical provenance warning
.agents/pm/issues/pm-linear-jloc.toon, .agents/pm/history/pm-linear-jloc.jsonl
New PM records track investigation of the historical provenance warning, including synthetic reproduction criteria and instructions to preserve audit records.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 1c0ef

No actionable issue remains from these comments; the change is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1c0ef

The installer now rejects broken or inconclusive package installations instead of silently skipping them. Current CI job permissions remain explicitly limited. An existing workflow-default permission issue remains, and recovery from interrupted driver registration was not verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The launcher's intended persistent outcome is merge-driver registration in the checkout's local Git configuration. Dependency code executes with the invoking process's authority, however, so the configuration scope is not an execution sandbox or a bound on compromised dependency behavior.

Security Findings and Attack Paths

  • observed — The retained low-severity finding concerns the missing workflow-level permission default. Source-backed base/head comparisons show that this condition predates the PR and that the sole current job already has explicit grants. Protection for future jobs is relevant hardening, but no newly unscoped job or broader token grant is demonstrated by this change.

Trust Boundaries and Controls

  • observed — The production launcher resolves dependency code from the working directory using Node resolution, including global lookup paths. The new presence check fails closed on ambiguous installation state; it does not authenticate dependency provenance. Clearing NODE_PATH in the test helper does not impose that restriction on production execution.

Resilience and Maintainability Implications

  • observed — Failure and signal-interruption tests check process status but not resulting Git configuration. Persistent mutation is delegated to the unavailable pm-ops installer implementation. Atomic registration, idempotency, concurrent execution, cleanup, and recovery therefore remain unverified, rather than established defects introduced by this PR.

Hardening Proposals

  • proposed — A workflow-level empty permissions default could protect future jobs that omit explicit grants while preserving the CodeQL job's existing permissions. This would harden a preexisting condition, not address a demonstrated increase in current-job authority.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: certifying pm-linear on PM CLI 2026.10.4 and consolidating dependency updates.
Description check ✅ Passed The description directly covers the certification, dependency and CodeQL updates, launcher changes, test results, and offline validation reported in the changeset.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (6 skipped: 6 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR upgrades pm-linear’s PM tooling to the certified 2026.10.4 release, consolidates and locks the pending dependency and CodeQL updates, and synchronizes the merge-driver launcher with the new pm-ops template. Review should focus on lockfile consistency, the fail-closed package-presence logic in the installer launcher, and that the reported release, health, offline dogfood, and read-only pm-github checks cover the upgraded tooling without introducing tracked runtime state.

Flow diagram for fail-closed pm-ops installer detection

flowchart TD
    A["Resolve pm-ops installer entry"] --> B{"Resolution succeeds?"}
    B -->|Yes| C["spawnSync installer"]
    B -->|No| D["resolver.resolve pm-ops/package.json"]
    D -->|Package resolves| E["Rethrow original resolution error"]
    D -->|MODULE_NOT_FOUND| F["resolver.resolve.paths pm-ops/package.json"]
    F --> G["lstatSync candidate pm-ops paths"]
    G --> H{"Any package directory exists or lookup is inconclusive?"}
    H -->|Yes| E
    H -->|No| I["Skip with notice"]
Loading

File-Level Changes

Change Details Files
Certify the project against PM CLI/SDK 2026.10.4 while consolidating dependency updates.
  • Raise exact development-tool pins for pm-cli and pm-ops to 2026.10.4 and pm-changelog to 2026.9.25.
  • Refresh the lockfile, including the newer Node type definitions and related resolved dependencies.
  • Verify the resulting dependency tree through release checks, health checks, and vulnerability scans.
package.json
package-lock.json
Refresh the pinned CodeQL workflow action revision.
  • Update both CodeQL initialization and analysis steps to the v4 commit SHA 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2.
.github/workflows/codeql.yml
Synchronize the merge-driver launcher with the pm-ops 2026.10.4 canonical template and harden missing-package detection.
  • Add filesystem probing for broken or dangling pm-ops installations.
  • Fail closed when package presence cannot be determined instead of incorrectly treating the package as absent.
  • Preserve the existing behavior of skipping only a genuinely absent pm-ops package and surfacing other resolution or installer failures.
scripts/prepare-merge-driver.ts
Record the consolidated dependency-update work in the project-management history.
  • Add the chore item and its history record for the consolidated Dependabot updates.
.agents/pm/chores/pm-linear-2cy6.toon
.agents/pm/history/pm-linear-2cy6.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates development dependencies and build tooling.

The PR appears safe to merge; no blocking issue was found.

What we checked:

  • Changelog still supports Node 22: Both declare Node >=22.18.0, so the dependency does not raise the supported runtime floor.

Summary

Updates the development dependencies and CodeQL pins, keeps the canonical merge-driver launcher, and adds tests for broken package installs.

  • The previous missing-test concern is addressed.
  • No new actionable issues or repository-rule violations were found.
  • The tracker records release checks and offline npm/Bun checks. Those checks were not rerun during this review.

Reviews (2) · Last reviewed commit: "test: cover broken installs and finish e..."

Comment thread scripts/prepare-merge-driver.ts
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #132 (comment)

Automatic review was skipped because of repository eligibility. A manual review request is included in the single follow-up request. This skip is missing review evidence.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #132 (comment)

Useful review guide. The latest candidate 1c0efe2 has exact development pins, pm-changelog 2026.10.4, unchanged coverage thresholds and the canonical merge-driver launcher. Validation and remaining review/security boundaries are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #132 (comment)

The merge-driver regression request is addressed in 1c0efe2 with focused child-process fixtures while preserving the launcher byte for byte. Full gate and real-tracker npm/bun evidence are recorded in the certification item.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to #132 (review)

The provider review budget is exhausted. No code finding was supplied; this is missing review evidence and the PR remains open for the orchestrator.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Response to the completed CodeRabbit review and its command receipt: both CodeRabbit and Greptile cover 1c0efe2 and report no new actionable findings. The earlier broken-install regressions are fixed in that commit; the full release gate passes 222/222 with zero skips and both npm audits are clean.

The optional architecture hardening proposals do not establish a regression in this candidate. The only CodeQL job already has explicit security-events:write, actions:read and contents:read permissions on main and this branch; this PR does not add a job or expand those grants. The launcher must remain byte-identical to the pm-ops 2026.10.4 template, so upstream installer lifecycle changes do not belong in this package certification. Tests demonstrate the requested lookup/failure behavior; concurrent registration, interruption recovery and dependency execution sandboxing remain outside the measured assurance scope. No lifecycle defect was demonstrated. Sourcery quota, neutral cubic and silent Gemini/Copilot remain missing review evidence, so the PR stays open for the orchestrator.

@unbraind
unbraind merged commit 9bf2dfb into main Oct 4, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant