Repository navigation
Upgrade jscpd 5.3.2 and repair pm-web duplication, catalog, and dependency audit - #163
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@greptileai Please review exact head 42d86eb, especially the two PM list routes, real-Postgres test refactors, packed acceptance isolation, and package catalog privacy boundaries. |
|
/gemini review |
|
@coderabbitai full review |
|
@sourcery-ai review |
|
Acknowledged Sourcery review-budget response for exact head 42d86eb with a positive reaction. Its green status is not substantive review; Greptile, Gemini, CodeRabbit and the remaining Node check are still being reconciled. The separate all-source coverage and hosted publication gates remain open. |
|
|
Acknowledged Greptile’s exact-head 42d86eb review with a positive reaction. It found no actionable regression in the changed code. The PM-linked release gate and exact-head Node/CodeQL checks also pass. I am keeping the PR open because the package still lacks all-source 100/100/100/100 coverage (pm-web-fy9a), its CLI pin is 2026.9.23, and historical privacy/live hosted acceptance remain separate from this diff review. |
|
@coderabbitai review |
|
Acknowledged the positively reacted CodeRabbit summary: it skipped the Dependabot-authored PR at exact head 42d86eb, so its green status is not a substantive review. I also invoked the single-review command the bot requested; I will read any response before considering this review gate resolved. |
|
Historical privacy boundary for this candidate: pm-web-priv and GitHub issue #96 record the August maintainer decision to retain legacy PM-prose host paths and author identities while gating new changes. The forward identity audit passes 4/4. A fresh bounded scan of 5,979 reachable Git objects (3,042 blobs) still found nine blobs with host-home-path matches; six token-prefix-like matches are known test fixtures. The scan found no hosted tenant mount, private-key header, or personal mailbox in blob content, but it is not a complete secret certification. The current user criterion asks for zero private or personal data anywhere in public history. The earlier decision does not itself settle that stricter criterion. Keep this PR unmerged and unpublished while classification and any coordinated remediation are decided. Do not rewrite reachable history without an approved recovery and downstream migration plan. Exact-head CI and Greptile review are green, while all-source coverage, the older CLI pin, and missing CodeRabbit/Sourcery/Gemini substantive reviews remain separate gaps. |
|
Exact-head 42d86eb review window reached 20 minutes. Node 22/26, CodeQL, Hound, Greptile and the PM-linked release gate pass; Greptile reviewed this head and found no actionable regression. There are no inline review comments. CodeRabbit still skipped this Dependabot-authored PR despite the single-review request, Sourcery reported budget exhaustion (positively reacted to and acknowledged), and Gemini supplied no substantive response. Their silence or green status is not approval. The historical privacy criterion, all-source coverage gap, older CLI pin and untested hosted collaboration/scale keep the PR open and unmerged. |
|
@coderabbitai review |
|
|
On issue 5963631193: This author-exclusion notice provides no substantive review of the new head. The earlier Greptile summary applies to 42d86eb only; it is not approval of f1d5a7a. The exact-head reviewer gap remains recorded. |
|
On issue 5963634984: This is a quota/skip notice, not a substantive review. No finding is reported. The current head still needs the missing review evidence before readiness can be claimed. |
|
@coderabbitai review |
f1d5a7a to
192cf80
Compare
|
|
On issue 5963744707: This is a skipped-review notice, not a substantive review. The repaired exact head has passing Node 22/26 CI and a clean Greptile review, but the missing CodeRabbit review remains a separate readiness gap. |
|
A newer version of jscpd exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Bumps [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) from 4.3.0 to 5.3.2. - [Release notes](https://github.com/kucherenko/jscpd/releases) - [Commits](https://github.com/kucherenko/jscpd/commits/v5.3.2/rust/jscpd) --- updated-dependencies: - dependency-name: jscpd dependency-version: 5.3.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Share graph, route, and real-Postgres test setup so jscpd 5.3.2 reports zero clone pairs at the unchanged threshold. Align the pm-ado catalog description and fleet snapshot with its current manifest. Resolve the production ip-address advisories in the lockfile. Isolate packed acceptance fixtures from PM-linked tracker context and use the canonical package install command. Record the work and remaining coverage gap in pm-web-8jjr, pm-web-k77v, pm-web-bw5d, and pm-web-fy9a.
192cf80 to
e07ad10
Compare
|
@coderabbitai review |
Rate Limit Exceeded
|
|
Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval. |
|
Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval. |
|
Re this comment: Useful summary acknowledged. The same human repairs and audited redaction are preserved in rebased head e07ad10. Local release:check passes 409/409, and fresh exact-head review/CI was requested. The known whole-source, development-audit and hosted boundaries remain separate. |
|
Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval. |
|
Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval. |
|
Re this comment: The prerequisite rebase deliberately preserves the human jscpd 5.3.2 update and its repairs. After the orchestrator merges this PR, the separate consolidated certification branch will use the latest available dependency versions. This worker does not merge or close dependency PRs. |
|
Re this comment: This is a skipped, quota-limited or excluded-author response and supplies no substantive source review. The rebased candidate is e07ad10, with the 409-test local gate passing. A fresh review request is posted; this notice is retained as unavailable evidence, not approval. |
|
Re this comment: The accompanying inline host-path finding was valid and its audited redaction is preserved in the rebase, verified at e07ad10. This empty review body adds no separate finding; fresh exact-head review was requested. |
|
The updated review explicitly covers e07ad10. The new owner-link finding is declined because the task requires persistent blob/main PM links, which become available after the orchestrator merges. Source changes and durable receipts remain verified by green Node 22/26 CI. |
|
Acknowledged the accompanying review of e07ad10. Its owner-link finding is declined under the explicit blob/main PM-link requirement; no source defect was identified. |
Upgrade jscpd to 5.3.2 and share graph filtering, PM list registration, entry guards and repeated test setup so the unchanged zero-duplication gate passes. Preserve the catalog/snapshot corrections and packed-context isolation, while rebasing the human commits onto current main after #161. The rebased lockfile keeps main's CLI 2026.10.4 and newer ip-address 10.7.3.
At
e07ad101dec125497b322eea5524d59898dea385, the serialized fullnpm run release:checkpasses 409/409 tests, zero skips, using disposable native PostgreSQL 17.10 and explicit canonicalPM_FLEET_ROOT. Duplication is zero. Coverage remains 84.41% lines / 80.54% branches / 77.82% functions across 32 configured files with unchanged thresholds; statements are unmeasured. Fresh committed-dist comparison,npm ci,bun install --no-save, strict PM health with required drivers, catalog 12/12, and built-in packed npm/Bun acceptance on host 2026.10.4 pass. The PostgreSQL fixture is stopped and removed.The cumulative tracker merge preserves both sides' collections. Canonical original-Git-state restoration audited the first unpushed attempt as abandoned; four final scalar receipts are reviewed and reconciled, and all six privacy-bounded durable receipt files are committed with their history. No receipt deletion, ownership override, provenance normalization or gate weakening.
Owner pm-web-8jjr remains open. Rebase receipts and commands document the scope.
This is the prerequisite repair. The separate consolidated PM CLI/SDK 2026.10.4 certification branch starts only after the orchestrator merges #163. Production audit is clean; the full development audit's fast-glob/micromatch/braces chain remains a certification blocker. Whole-source quality stays open in pm-web-fy9a. Historical privacy issue #96, real-tracker dogfood for the later certification, and hosted tenant/realtime/scale/deployment acceptance remain separate.
Fresh exact-head CI and substantive reviewer evidence remain required. CodeRabbit bot-seat skips and quota/neutral responses are unavailable review evidence. Nothing is merged, published or deployed by this worker.