Skip to content

Upgrade jscpd 5.3.2 and repair pm-web duplication, catalog, and dependency audit - #163

Merged
unbraind merged 6 commits into
mainfrom
dependabot/npm_and_yarn/jscpd-5.3.2
Oct 4, 2026
Merged

unbraind merged 6 commits into
mainfrom
dependabot/npm_and_yarn/jscpd-5.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Upgrade jscpd to 5.3.2 and share graph filtering, PM list registration, entry guards and repeated test setup so the unchanged zero-duplication gate passes. Preserve the catalog/snapshot corrections and packed-context isolation, while rebasing the human commits onto current main after #161. The rebased lockfile keeps main's CLI 2026.10.4 and newer ip-address 10.7.3.

At e07ad101dec125497b322eea5524d59898dea385, the serialized full npm run release:check passes 409/409 tests, zero skips, using disposable native PostgreSQL 17.10 and explicit canonical PM_FLEET_ROOT. Duplication is zero. Coverage remains 84.41% lines / 80.54% branches / 77.82% functions across 32 configured files with unchanged thresholds; statements are unmeasured. Fresh committed-dist comparison, npm ci, bun install --no-save, strict PM health with required drivers, catalog 12/12, and built-in packed npm/Bun acceptance on host 2026.10.4 pass. The PostgreSQL fixture is stopped and removed.

The cumulative tracker merge preserves both sides' collections. Canonical original-Git-state restoration audited the first unpushed attempt as abandoned; four final scalar receipts are reviewed and reconciled, and all six privacy-bounded durable receipt files are committed with their history. No receipt deletion, ownership override, provenance normalization or gate weakening.

Owner pm-web-8jjr remains open. Rebase receipts and commands document the scope.

This is the prerequisite repair. The separate consolidated PM CLI/SDK 2026.10.4 certification branch starts only after the orchestrator merges #163. Production audit is clean; the full development audit's fast-glob/micromatch/braces chain remains a certification blocker. Whole-source quality stays open in pm-web-fy9a. Historical privacy issue #96, real-tracker dogfood for the later certification, and hosted tenant/realtime/scale/deployment acceptance remain separate.

Fresh exact-head CI and substantive reviewer evidence remain required. CodeRabbit bot-seat skips and quota/neutral responses are unavailable review evidence. Nothing is merged, published or deployed by this worker.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: unbraind/pm-web/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8cf2833a-bf82-4f0d-9670-f48092bf321e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@unbraind unbraind changed the title chore(deps-dev): bump jscpd from 4.3.0 to 5.3.2 Upgrade jscpd 5.3.2 and repair pm-web duplication, catalog, and dependency audit Sep 29, 2026
@unbraind

Copy link
Copy Markdown
Owner

@greptileai Please review exact head 42d86eb, especially the two PM list routes, real-Postgres test refactors, packed acceptance isolation, and package catalog privacy boundaries.

@unbraind

Copy link
Copy Markdown
Owner

/gemini review

@unbraind

Copy link
Copy Markdown
Owner

@coderabbitai full review

@unbraind

Copy link
Copy Markdown
Owner

@sourcery-ai review

@sourcery-ai

sourcery-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 6 hours and 52 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@unbraind

Copy link
Copy Markdown
Owner

Acknowledged Sourcery review-budget response for exact head 42d86eb with a positive reaction. Its green status is not substantive review; Greptile, Gemini, CodeRabbit and the remaining Node check are still being reconciled. The separate all-source coverage and hosted publication gates remain open.

@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Dependency upgrade and build artifact changes with test modifications.

The PR appears safe to merge; the broken pre-merge documentation link is non-blocking.

Findings

  1. P2 Owner link misses new file ▶
Fix with agent prompt
### Issue 1
docs/rebase-163-2026.10.4.md:3
The owner link points to `main`, but this PR introduces the linked file, so reviewers cannot open it there before the PR merges. Link to the file in this PR so the verification record is accessible during review.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR upgrades jscpd and refactors duplicated graph, route, script, and test code while refreshing dependency and PM records. The rebased changes also incorporate observational graph reads and an updated PM CLI dependency. One pre-merge documentation link needs correction.

Reviews (4) · Last reviewed commit: "Verify rebased pm-web dependency candida..."

@unbraind

Copy link
Copy Markdown
Owner

Acknowledged Greptile’s exact-head 42d86eb review with a positive reaction. It found no actionable regression in the changed code. The PM-linked release gate and exact-head Node/CodeQL checks also pass. I am keeping the PR open because the package still lacks all-source 100/100/100/100 coverage (pm-web-fy9a), its CLI pin is 2026.9.23, and historical privacy/live hosted acceptance remain separate from this diff review.

@unbraind

Copy link
Copy Markdown
Owner

@coderabbitai review

@unbraind

Copy link
Copy Markdown
Owner

Acknowledged the positively reacted CodeRabbit summary: it skipped the Dependabot-authored PR at exact head 42d86eb, so its green status is not a substantive review. I also invoked the single-review command the bot requested; I will read any response before considering this review gate resolved.

@unbraind

Copy link
Copy Markdown
Owner

Historical privacy boundary for this candidate: pm-web-priv and GitHub issue #96 record the August maintainer decision to retain legacy PM-prose host paths and author identities while gating new changes. The forward identity audit passes 4/4. A fresh bounded scan of 5,979 reachable Git objects (3,042 blobs) still found nine blobs with host-home-path matches; six token-prefix-like matches are known test fixtures. The scan found no hosted tenant mount, private-key header, or personal mailbox in blob content, but it is not a complete secret certification.

The current user criterion asks for zero private or personal data anywhere in public history. The earlier decision does not itself settle that stricter criterion. Keep this PR unmerged and unpublished while classification and any coordinated remediation are decided. Do not rewrite reachable history without an approved recovery and downstream migration plan. Exact-head CI and Greptile review are green, while all-source coverage, the older CLI pin, and missing CodeRabbit/Sourcery/Gemini substantive reviews remain separate gaps.

@unbraind

Copy link
Copy Markdown
Owner

Exact-head 42d86eb review window reached 20 minutes. Node 22/26, CodeQL, Hound, Greptile and the PM-linked release gate pass; Greptile reviewed this head and found no actionable regression. There are no inline review comments. CodeRabbit still skipped this Dependabot-authored PR despite the single-review request, Sourcery reported budget exhaustion (positively reacted to and acknowledged), and Gemini supplied no substantive response. Their silence or green status is not approval. The historical privacy criterion, all-source coverage gap, older CLI pin and untested hosted collaboration/scale keep the PR open and unmerged.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner

On issue 5963631193: This author-exclusion notice provides no substantive review of the new head. The earlier Greptile summary applies to 42d86eb only; it is not approval of f1d5a7a. The exact-head reviewer gap remains recorded.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner

On issue 5963634984: This is a quota/skip notice, not a substantive review. No finding is reported. The current head still needs the missing review evidence before readiness can be claimed.

Comment thread .agents/pm/history/pm-web-bw5d.jsonl Outdated
@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner

@coderabbitai review
@greptileai
/gemini review

@unbraind
unbraind force-pushed the dependabot/npm_and_yarn/jscpd-5.3.2 branch from f1d5a7a to 192cf80 Compare October 3, 2026 00:42
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner

On issue 5963744707: This is a skipped-review notice, not a substantive review. The repaired exact head has passing Node 22/26 CI and a clean Greptile review, but the missing CodeRabbit review remains a separate readiness gap.

@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of jscpd exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

dependabot Bot and others added 2 commits October 4, 2026 14:55
Bumps [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) from 4.3.0 to 5.3.2.
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.3.2/rust/jscpd)

---
updated-dependencies:
- dependency-name: jscpd
  dependency-version: 5.3.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Share graph, route, and real-Postgres test setup so jscpd 5.3.2 reports zero clone pairs at the unchanged threshold. Align the pm-ado catalog description and fleet snapshot with its current manifest. Resolve the production ip-address advisories in the lockfile. Isolate packed acceptance fixtures from PM-linked tracker context and use the canonical package install command. Record the work and remaining coverage gap in pm-web-8jjr, pm-web-k77v, pm-web-bw5d, and pm-web-fy9a.
@unbraind
unbraind force-pushed the dependabot/npm_and_yarn/jscpd-5.3.2 branch from 192cf80 to e07ad10 Compare October 4, 2026 13:13
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@unbraind have exceeded the limit for the number of chat messages per hour. Please wait 0 minutes and 52 seconds before sending another message.

Comment thread docs/rebase-163-2026.10.4.md
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: Useful summary acknowledged. The same human repairs and audited redaction are preserved in rebased head e07ad10. Local release:check passes 409/409, and fresh exact-head review/CI was requested. The known whole-source, development-audit and hosted boundaries remain separate.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: The prerequisite rebase deliberately preserves the human jscpd 5.3.2 update and its repairs. After the orchestrator merges this PR, the separate consolidated certification branch will use the latest available dependency versions. This worker does not merge or close dependency PRs.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Re this comment: The accompanying inline host-path finding was valid and its audited redaction is preserved in the rebase, verified at e07ad10. This empty review body adds no separate finding; fresh exact-head review was requested.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

The updated review explicitly covers e07ad10. The new owner-link finding is declined because the task requires persistent blob/main PM links, which become available after the orchestrator merges. Source changes and durable receipts remain verified by green Node 22/26 CI.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Acknowledged the accompanying review of e07ad10. Its owner-link finding is declined under the explicit blob/main PM-link requirement; no source defect was identified.

@unbraind
unbraind merged commit 86c31b1 into main Oct 4, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/jscpd-5.3.2 branch October 4, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant