Repository navigation
Certify pm-web on PM CLI 2026.10.4 and consolidate pending dependency updates - #168
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (4)
📒 Files selected for processing (20)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change updates dependencies and release tooling for PM CLI/SDK 2026.10.4, changes project initialization and merge-driver checks, installs a pinned managed GitHub extension in CI, and adds certification records. Certification remains not ready pending audit and review evidence. ChangesDependency and release certification
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Other Sequence Diagram(s)sequenceDiagram
participant CI as CI workflow
participant Installer as install-pm-github.sh
participant npm
participant Git
CI->>Installer: Run extension installation
Installer->>npm: Install pm-github 2026.10.4
Installer->>Installer: Verify installed version
Installer->>Git: Check whether registry is tracked
Installer->>Installer: Restore tracked registry or remove untracked registry
Merge Risk: 🟡 Moderate · up to The updated dependency set is not yet ready for certification because the full development audit remains blocked. Resolve that dependency chain or explicitly accept the certification delay before merging. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change explicitly targets each project’s own tracker and preserves existing authentication and CI permission controls. No introduced security issue was established, but recovery after interrupted initialization and concurrent deletion remains unverified for the new CLI command. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR certifies pm-web against the exact PM CLI/SDK 2026.10.4 candidate, consolidates dependency and managed-extension updates, hardens merge-driver lookup handling, and fixes nested project initialization. It adds targeted regressions, refreshed generated artifacts and fleet metadata, plus detailed validation evidence; certification remains blocked by four high-severity development audit findings. Sequence diagram for nested project workspace initializationsequenceDiagram
participant Web as pm-web
participant Runner as pm-runner
participant CLI as PM CLI 2026_10_4
participant Workspace as ChildWorkspace
participant Tracker as AncestorTracker
Web->>Runner: initProject(userId, slug, prefix)
Runner->>Workspace: mkdirSync(projectDir)
Runner->>CLI: runProcess(workspace init --workspace projectDir --prefix prefix --defaults --agent-guidance skip)
CLI->>Workspace: Initialize explicit child tracker
CLI->>Tracker: Read ancestor settings
Tracker-->>CLI: Preserve settings byte-identically
CLI-->>Runner: Initialization result
Runner->>Runner: configureLocalOllamaSearch()
Runner->>Runner: ensureGraphExtension(userId, slug)
Sequence diagram for fail-closed merge-driver package lookupsequenceDiagram
participant Installer as MergeDriverInstaller
participant Resolver as NodeResolver
participant Paths as ResolutionPaths
participant Filesystem as Filesystem
Installer->>Resolver: resolve(pm_ops/package.json)
Resolver-->>Installer: MODULE_NOT_FOUND or package error
Installer->>Resolver: resolve.paths(pm_ops/package.json)
Resolver-->>Paths: Local and global paths
loop Each resolution path
Installer->>Filesystem: lstatSync(path/pm_ops)
alt Entry exists
Filesystem-->>Installer: Package presence
else Lookup error
Filesystem-->>Installer: Filesystem error
Installer-->>Installer: Fail closed and preserve installer error
end
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Automatic review was skipped because this repository has fewer than10stars. This is missing review evidence, not approval. Requesting the permitted manual review of6c7d3094e590c5789cd92ce8a6a7dd771e887eaa; full-development audit remains blocked by pm-web-xucb. |
|
Useful review map acknowledged for6c7d3094e590c5789cd92ce8a6a7dd771e887eaa. Fullgate411/411 and actualCLI ancestor-initialization regression1/1 pass; copied real-tracker npm/nativeBun board/export/graph read all132items with deep export parity and preserved tracker bytes. Full-development audit remains fourhigh; coverage scope is32applicationfiles, hosted/privacy/realtime gates remain independent. The walkthrough is not substantive review approval. |
|
The seven-day diff-character budget prevents substantive review. Recorded as unavailable evidence, not approval; no finding can be inferred from a quota response. Keep the candidate open with full-development audit blocker pm-web-xucb and required reviewer evidence outstanding. |
|
@coderabbitai review |
|
|
Manual review trigger acknowledged for6c7d3094e590c5789cd92ce8a6a7dd771e887eaa. The review is still processing; triggering it is not approval. Exact-head Node22/26 CI is green; full-development audit and missing reviewer evidence remain open. |
|
|
Acknowledged the substantive review of6c7d3094e590c5789cd92ce8a6a7dd771e887eaa with no actionable findings. Child initialization and generated output pass actualCLI regression, full411-test gate and complete132-item npm/nativeBun acceptance. Follow-up500bf67 only corrects audit wording: fast-glob is a declared optional peer needed by duplication, not undeclared. The vulnerable peer chain remains a certification blocker; no missing-declaration defect is claimed. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
The original review was cancelled because the metadata correction changed the head; it supplied no completed source review. Treat this as unavailable evidence. A single follow-up re-review was requested at500bf67 after correcting the optional-peer receipt; source/gate commands are unchanged and CI/Greptile cover that head. |
|
The edited body currently skips automatic review at500bf679cc2e9849897fda8c67989af1abd80bf9. The first manual attempt was cancelled by the head change, so no substantive CodeRabbit coverage is claimed. The follow-up request is pending; missing evidence does not clear the audit condition. |
|
Acknowledged the updated substantive review explicitly covering500bf679cc2e9849897fda8c67989af1abd80bf9. It confirms the optional-peer wording correction and reports no actionable findings. Independent paginated GraphQL retrieval verifies zero unresolved threads; the review service could not retrieve them itself. Full-development audit remains blocked by pm-web-xucb. |
|
The second manual review trigger is acknowledged for500bf679cc2e9849897fda8c67989af1abd80bf9. It remains processing, not approval. The previous attempt was cancelled by the head change; the vulnerable optional-peer chain still blocks certification regardless of reviewer outcome. |
|
Acknowledged the completed substantive review of 500bf67, with no actionable comments. The full development audit remains blocked by pm-web-xucb; production audit is clean. The nested-tracker fix and regression are in 6c7d309. The proposed lifecycle coordination/recovery hardening concerns pre-existing behavior, and the review establishes no introduced regression. This certification does not claim atomic create/delete, interruption recovery, hosted deployment, or production readiness; broad lifecycle changes are outside the dependency certification scope. |
|
Acknowledged successful completion. The substantive body explicitly covers 500bf67 and reports no actionable comments. CodeRabbit review is now available; audit and other missing reviewer evidence remain separate readiness conditions. |
Certifies the dependency candidate on PM CLI/SDK 2026.10.4 after the orchestrator merged rebased prerequisite #163. Consolidates Dependabot #162, #164, #165 and #166: pg 8.23.1, tsx 4.23.15, types/node 26.6.4 and exact CodeQL v4.38.2 SHA2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2. Pins pm-ops/pm-changelog and managed pm-github 2026.10.4; every development dependency is exact, including jscpd 5.4.0. Existing CLI floor10.4 is retained.
Uses the byte-identical published launcher with a failing-before/passing-after malformed lookup regression. Updates the exact reviewed action allowlist and regenerates the 20-extension fleet snapshot without dropping catalog entries. Packed real-tracker acceptance exposed ancestor discovery during project creation; a regression executes the actual pinned CLI and now proves explicit child-workspace initialization with byte-identical ancestor settings. Regenerated server artifacts preserve the package build contract.
Validation, all heavy operations serialized with the shared flock:
npm ci,bun install --no-save, and freshrm -rf dist/npm run build: pass. No pre-existing Bun lock in this repository.npm run release:checkviapm test pm-web-8pml --run --only-index 3 --progress --jsonwith childenv -u PM_PATHand explicit canonical PM_FLEET_ROOT: 411/411 tests, zero skips, duplication 0/40537 lines,142sources,zero clone pairs.npx pm health --strict-exit --require-merge-drivers: exit0; one advisory finding covers2stale items.npm packinstalled into a copied REAL repository tracker: npm/npx and native Bun (bunx --bun @unbrained/pm-cli@2026.10.4) passedweb doctor, start/detach, status and stop. Authenticated local registration/project creation, board/export/observational graph include all132 lifecycle items, compared with unboundedlist --all; export values deeply match and tracker documents/history/settings stay byte-identical. Own native PostgreSQL17.10 cluster and servers stopped, scratch removed. Each CLI launches the documented packaged Node server. No hosted/Docker/deployment/liveidentity/realtime-scale claim.pm github sync --repo unbraind/pm-web --dry-run: synced0/skipped0/planned0, no provenance-linked cases; no issue writes or scheduled sync.Durable commands and measured boundaries.
PM: certification pm-web-8pml, full-audit blocker pm-web-xucb, prerequisite pm-web-8jjr, whole-source owner pm-web-fy9a. Hosted privacy #96 remains independent.
Summary by Sourcery
Certify pm-web against PM CLI/SDK 2026.10.4 while consolidating exact dependency updates, hardening workspace and merge-driver behavior, and documenting the remaining audit blocker.
New Features:
Bug Fixes:
Enhancements:
CI:
Documentation:
Tests:
Chores:
Summary by cubic
Certifies the pm-web dependency set on
@unbrained/pm-cli2026.10.4 and consolidates the pending Dependabot updates (pg8.23.1,tsx4.23.15,@types/node26.6.4, CodeQL v4.38.2). Pinspm-ops,pm-changelogand the managedpm-githubextension to 2026.10.4, makes every development dependency exact, and regenerates the distribution artifacts and fleet extension snapshot. Fullnpm auditremains blocked by four high-severity development entries through unpatchedbraces/micromatch/fast-glob/pm-ops; thefast-globentry cannot be dropped becausepm-opsrequires it as an optional peer for the canonical duplication gate and no patchedbracesrelease exists. Production audit is clean and no audit or gate thresholds were weakened, so certification is not final until that blocker is resolved.Bug fixes
CI
pm-githubextension.Written for commit 500bf67. Summary will update on new commits.
Summary by CodeRabbit
Bug Fixes
Maintenance