Skip to content

Clarify pin-integrity and automerge contracts and scanner comments - #878

Merged
hyperpolymath merged 15 commits into
mainfrom
coderabbit/improve-changed-function-docstrings/ece16dd1
Oct 1, 2026
Merged

hyperpolymath merged 15 commits into
mainfrom
coderabbit/improve-changed-function-docstrings/ece16dd1

Conversation

@coderabbitai

@coderabbitai coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Across three commits, expand docstrings for pin version parsing, literal lockfile refs, comment relabeling, automerge version deltas, and decision manifests. Document the shell relabel helper’s behavior and replace credential-shaped examples in scanner suppression comments with prose.

All changes are documentation or comments; runtime behavior is unchanged.

Validation was not run.

View coding task

hyperpolymath and others added 6 commits September 30, 2026 10:37
…merge (#869)

- pin_integrity/pr_automerge: escape the in-class `/` in three ~r/…/ sigils
  (the sigil ended at the bare slash -> MismatchedDelimiterError, #869).
- claimed_version/1: Regex.run drops trailing unmatched groups, so the
  `v`-branch never matched; take the first non-empty capture.
- relabel/2 + relabel_line/2: one contract (a `#`-led comment in and out);
  relabel_line no longer double-prefixes `##`, and a bare claim from
  pin_sites/1 normalises to `# vX`.
- pr_automerge: pin deltas are wrapped per file (flat_map over a map yielded
  tuples); the verdict carries the scan facts it was decided on; a pin-only
  change onto the denylist is rejected (close_poison_only) instead of armed;
  manifest vetoes use string keys like the rest of the manifest.
- test: the permissions-block fixture now actually edits the block.

mix compile --warnings-as-errors: clean. mix test: 1673 tests, 0 failures
(242 :verisim_data excluded as before).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
…n shell twin

Promoting the lead to " " before slicing ate the claim's first character, so
relabel("4.38.1", …) silently returned its input. Slice first, then promote.
relabel_comment in estate-pin-integrity.sh gets the same bare-input
normalisation so the two readers stay behaviourally identical.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
#832 was closed on 2026-09-27 but mise.toml still provisioned python and
denojs, so Language Policy Blockers has been red on main since. Removes the
banned runtimes, the tools only they can run (pip, black, isort, ruff,
pytest), the orphaned PYTHON* env, and the alias fallbacks that called them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

Important

Review skipped

This PR was authored by the user configured for CodeRabbit reviews. CodeRabbit does not review PRs authored by this user. It's recommended to use a dedicated user account to post CodeRabbit review feedback.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Essentials

Run ID: e6b2140a-6f0a-4a55-8e77-b43f0a9902cb

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@gitguardian

gitguardian Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37657201 Triggered Generic High Entropy Secret c6b94a3 test/scanner_suppression_test.exs View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

hyperpolymath and others added 5 commits September 30, 2026 11:02
…t, proof suites (#879)

Stacked on #875 (base `fix/issue-sweep`; GitHub retargets to `main` when
#875 merges). Merge #875 first.

## What
- **WH006** skips reusable-workflow caller jobs (job-level `uses:`),
where GitHub rejects `timeout-minutes:`. Refs standards#943.
- **`extract_job_blocks`**: the **last job of every workflow was never
checked** (in-flight job not flushed), and later jobs reported the first
job's line number. Both fixed. Expect WH006 to find a few more *true*
positives estate-wide.
- **WH013/WH002**: `git push <named non-origin remote>`
(gitlab/codeberg/backup mirrors) authenticates with its own key/token,
so it doesn't need `contents: write`. Bare, `origin` and `"$VAR"` pushes
still count. Refs standards#943.
- **ScannerSuppression**: `harvested-registry/` is exempt for
`secret_detected` only. Closes #865.
- **npx_in_workflow** message now recommends `bunx`/`bun run` (Deno
banned 2026-09-22). Refs standards#938.
- **honest_completion `no_tests`**: a proof suite whose checker runs in
CI counts as tests. Refs echo-types#271.

## Verification (local)
- `mix test`: 1682 tests, 0 failures (242 excluded)
- `mix compile --warnings-as-errors --force`: clean
- Every change has fires / does-not-fire tests.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65

---------

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Base automatically changed from fix/issue-sweep to main September 30, 2026 10:21
…gs/ece16dd1

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 1, 2026 15:03
@hyperpolymath
hyperpolymath merged commit 9d2a924 into main Oct 1, 2026
37 of 42 checks passed
@hyperpolymath
hyperpolymath deleted the coderabbit/improve-changed-function-docstrings/ece16dd1 branch October 1, 2026 15:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant