fix(cli): JSON output reports warn as medium for pre-bd9313a6 callers (D260) - #895
Conversation
… (D260) Since a63c432 (#763) the ResearchExtensions rules emit severity "warn". Callers pinned to standards' hypatia-scan-reusable.yml before bd9313a6 (8f2ee508, 81dbf2dd, 571cc734, 84355587, 092deda) validate the JSON findings against critical/high/medium/low/info and reject the whole array on a single "warn", failing with "Hypatia did not produce one valid findings array" on ~350 repos. The reusable clones hypatia HEAD, so mapping warn -> medium in the JSON sink clears every such caller at once. warn already ranks with medium in @severity_order, so no information is lost. SARIF ("warning") and GitHub output are unchanged. Removal criterion (owner ruling D260, standards#787): drop the shim once an enumerated census of hypatia-scan callers shows none pinned to a rejecting copy of the reusable. Test: CLI JSON output on the RE tripwire repo contains "medium", never "warn", and only the five accepted severities. Mutant (shim passes warn through) turns it red: 11 tests, 1 failure. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJ6PbZUYBcjJv7FTRfyogo
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (34)
🔇 Additional comments (3)
📝 SummarySummary by CodeRabbit
WalkthroughThe JSON output handler converts findings with severity "warn" to "medium" before encoding. A CLI test checks the conversion and confirms that output uses only the allowed severity values. ChangesJSON severity compatibility
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to Warning findings now emit the medium value accepted by older validators, and the CLI test checks that output. No actionable merge-blocking risk remains. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change translates warning-tier findings to medium only when producing JSON. It preserves findings, other severity levels, scan thresholds, and exit behavior. No material security risk was identified in this narrowly scoped change. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the JSON stream, Comment |
The D260 shim helpers sat between the output/2 clauses, which Elixir
warns about ("clauses with the same name and arity should be grouped
together"). escript-soundness.yml compiles with --warnings-as-errors,
so the job went red. Move json_compat_severity/1 below the last
output/2 clause; behaviour is unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YJ6PbZUYBcjJv7FTRfyogo
Why
Since a63c432 (#763), the ResearchExtensions rules emit severity
"warn". Callers pinned to copies ofstandards'hypatia-scan-reusable.ymlolder thanbd9313a6validate the JSON findings againstcritical/high/medium/low/info/informational. A single"warn"makes them reject the whole array, and they fail with:The estate health census (2026-09-30) found
hypatia-scan.ymlfailing on 354 repos. In a 100-pin sample, about 65 were on rejecting copies:8f2ee508,81dbf2dd,571cc734,84355587and092deda.The reusable runs
git clone --depth 1of hypatia HEAD, so a fix in the JSON sink clears every such caller at once. This is the owner ruling D260 ("Both") on standards#787.What
lib/hypatia/cli.ex:output(findings, "json")mapsseverity: "warn"→"medium".warnalready ranks withmediumin@severity_order, so no information is lost.level_for("warn")→"warning") is unchanged.test/research_extensions_wiring_test.exs: a new test.CLI.main(["scan", …, "--format", "json"])on the RE tripwire repo."medium"is present, that"warn"is absent, and that every severity is in the accepted five.hypatia-cli-bash.sh) never emits"warn", so the escript is the only path that needed the fix.Evidence
mix test test/research_extensions_wiring_test.exs: 11 tests, 0 failures.cli_test.exstogether with the wiring test: 18 tests, 0 failures.warnthrough unchanged, the suite gives 11 tests and 1 failure (the new test). The test bites.mix format --check-formattedis clean on both files.Removal criterion
This shim is temporary. Callers get repinned to
standards≥bd9313a6in the actions.lock regen sweep (E1a). A follow-up PR removes the mapping once an enumerated census of hypatia-scan callers (per-repo workflow listing, notgh search) shows none pinned to a rejecting copy.Post-merge verification
hyperpolymath/laniakeais the known-answer repo: it is pinned to8f2ee508, and its hypatia-scan must turn green after this merges.🤖 Generated with Claude Code
https://claude.ai/code/session_01YJ6PbZUYBcjJv7FTRfyogo