Repository navigation
Clarify pin-integrity and automerge contracts and scanner comments - #878
hyperpolymath merged 15 commits into
Conversation
…merge (#869) - pin_integrity/pr_automerge: escape the in-class `/` in three ~r/…/ sigils (the sigil ended at the bare slash -> MismatchedDelimiterError, #869). - claimed_version/1: Regex.run drops trailing unmatched groups, so the `v`-branch never matched; take the first non-empty capture. - relabel/2 + relabel_line/2: one contract (a `#`-led comment in and out); relabel_line no longer double-prefixes `##`, and a bare claim from pin_sites/1 normalises to `# vX`. - pr_automerge: pin deltas are wrapped per file (flat_map over a map yielded tuples); the verdict carries the scan facts it was decided on; a pin-only change onto the denylist is rejected (close_poison_only) instead of armed; manifest vetoes use string keys like the rest of the manifest. - test: the permissions-block fixture now actually edits the block. mix compile --warnings-as-errors: clean. mix test: 1673 tests, 0 failures (242 :verisim_data excluded as before). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
…n shell twin
Promoting the lead to " " before slicing ate the claim's first character, so
relabel("4.38.1", …) silently returned its input. Slice first, then promote.
relabel_comment in estate-pin-integrity.sh gets the same bare-input
normalisation so the two readers stay behaviourally identical.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
#832 was closed on 2026-09-27 but mise.toml still provisioned python and denojs, so Language Policy Blockers has been red on main since. Removes the banned runtimes, the tools only they can run (pip, black, isort, ruff, pytest), the orphaned PYTHON* env, and the alias fallbacks that called them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
|
Important Review skippedThis PR was authored by the user configured for CodeRabbit reviews. CodeRabbit does not review PRs authored by this user. It's recommended to use a dedicated user account to post CodeRabbit review feedback. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Essentials Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
…on-docstrings/ece16dd1
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37657201 | Triggered | Generic High Entropy Secret | c6b94a3 | test/scanner_suppression_test.exs | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
…on-docstrings/ece16dd1
…t, proof suites (#879) Stacked on #875 (base `fix/issue-sweep`; GitHub retargets to `main` when #875 merges). Merge #875 first. ## What - **WH006** skips reusable-workflow caller jobs (job-level `uses:`), where GitHub rejects `timeout-minutes:`. Refs standards#943. - **`extract_job_blocks`**: the **last job of every workflow was never checked** (in-flight job not flushed), and later jobs reported the first job's line number. Both fixed. Expect WH006 to find a few more *true* positives estate-wide. - **WH013/WH002**: `git push <named non-origin remote>` (gitlab/codeberg/backup mirrors) authenticates with its own key/token, so it doesn't need `contents: write`. Bare, `origin` and `"$VAR"` pushes still count. Refs standards#943. - **ScannerSuppression**: `harvested-registry/` is exempt for `secret_detected` only. Closes #865. - **npx_in_workflow** message now recommends `bunx`/`bun run` (Deno banned 2026-09-22). Refs standards#938. - **honest_completion `no_tests`**: a proof suite whose checker runs in CI counts as tests. Refs echo-types#271. ## Verification (local) - `mix test`: 1682 tests, 0 failures (242 excluded) - `mix compile --warnings-as-errors --force`: clean - Every change has fires / does-not-fire tests. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65 --------- Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…on-docstrings/ece16dd1
…on-docstrings/ece16dd1
…gs/ece16dd1 Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Across three commits, expand docstrings for pin version parsing, literal lockfile refs, comment relabeling, automerge version deltas, and decision manifests. Document the shell relabel helper’s behavior and replace credential-shaped examples in scanner suppression comments with prose.
All changes are documentation or comments; runtime behavior is unchanged.
Validation was not run.
View coding task