fix(tooling)!: adopt shared approvals and generated command help - #266
Conversation
- Replace owner-issued CodeRabbit requests with the pinned MCMC Dependabot approval workflow and document the repository settings. - Fail workflow security checks on findings before exporting SARIF. - Generate sorted Just help and keep usage, contributor guidance, and active documentation navigation with their respective owners. - Replace duplicate process and zizmor implementations with the published research-repo-tools APIs. BREAKING CHANGE: contributor recipes use audit, shell-fix, toml-fix, and test-unit. Redundant aliases and help-workflows are removed; use bare just to discover the canonical commands. Closes #260 Refs #258
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: acgetchell/la-stack/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour. 📝 WalkthroughWalkthroughThe pull request updates repository automation, review settings, and security workflows. It migrates process utilities to a shared package while retaining benchmark adapters. It also reorganizes Just recipes, updates command-discovery and contributor guidance, and revises repository navigation links. ChangesRepository automation and security workflows
Shared process tooling migration
Command discovery and repository guidance
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The selected test changes show no substantiated issue that should block merging. 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Full details: Out of Scope Changes checkExplanation The PR contains changes unrelated to the coding scope of
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #266 +/- ##
=======================================
Coverage 98.02% 98.02%
=======================================
Files 13 13
Lines 6726 6726
=======================================
Hits 6593 6593
Misses 133 133
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
- Remove in-source-suppressed results before GitHub code scanning ingests the report so reviewed inline exceptions stay effective. - Preserve unsuppressed findings, their metadata, and the scanner's original exit status for the blocking security gate. Refs #258
- Declare LF and CRLF benchmark snapshot inputs explicitly instead of inheriting the host's text-write behavior. - Check exact worktree bytes and staged contents against the selected line ending while preserving tracked-file and index guarantees.
Dependabot PRs can have a successful CodeRabbit status while remaining blocked without an approving review. This adopts markov-chain-monte-carlo's pinned research-repo-tools approval workflow, which verifies signed bot commits, complete ecosystem/file allowlists, and the current head before approving and enabling native squash auto-merge. The trusted caller never checks out or executes PR code.
The patch also replaces hand-maintained help with a complete generated Just list, sorts and documents recipes, moves contributor validation out of README usage, and preserves active navigation on
main. Historical measurements and citation provenance remain pinned. Duplicate subprocess and zizmor implementations and their unit tests are removed in favor of research-repo-tools; la-stack retains its benchmark schemas, scientific policy, and thin benchmark phase adapters. Zizmor findings now block CI before a separate SARIF export. Semgrep uploads honor reviewed inline suppressions, and benchmark snapshot fixtures verify exact LF and CRLF preservation across platforms.Contributor command compatibility changes: use
audit,shell-fix,toml-fix, andtest-unitinstead ofsecurity-osv,shell-fmt,toml-fmt, andtest-lib. Redundant aliases andhelp-workflowsare removed; barejustlists canonical commands. The Rust library API is unchanged.Validation
just cipassed onf748db0: 528 Python tests, 893 Rust tests, default and exact doctests, examples, benchmark compilation, and the tooling/security checks composed by the recipe.just markdown-fix markdown-ci doc-check.Deployment and remaining verification
The repository settings are already applied and verified: read-only default Actions permissions with PR approvals enabled, the two shared approval dependencies added to the existing selected-action allowlist, and stale-review dismissal enabled. The six required checks, one required approval, strict checks, resolved-thread requirement, and existing bypass policy are preserved. Enabling Actions approvals intentionally replaces #258's earlier CodeRabbit-only approach, as requested.
After merge, trigger a fresh eligible Dependabot event and record the current-head approval, workflow run, squash merge, and resulting default-branch checks. Old workflow reruns retain their original definition. Keep the old review token until the caller on
mainhas been replaced and no remaining consumer needs it. The procedure is documented in Managing Changes. CodeRabbit's underlying provider failure remains unconfirmed, so #258 stays open for rollout verification.Closes #260
Refs #258
Summary by CodeRabbit
Documentation
Chores