🧑💻 Intermediate Issue — a complex task spanning multiple modules, with real design decisions to own.
Time: ~25 hours · Prerequisites: comfortable navigating this repo (a completed beginner issue is the usual route; demonstrated CI/CD proficiency substitutes for workflow-focused issues).
We expect more than "it works": maintainable code that fits the existing architecture.
The task
Blocked by #359 — the ci_health engine and findings contract must exist first.
Problem:
The audit checklist requires dependabot to cover all relevant ecosystems, but a presence check on .github/dependabot.yml can't see the real failure: a repo declaring pip while also shipping package.json, Dockerfiles, and GitHub Actions workflows. The gap between declared and needed ecosystems is the finding.
What done looks like:
A dependabot_ecosystems check in the ci_health engine: parse the repo's dependabot.yml (missing file = its own finding), detect present ecosystems from the same .github/tree fetch the engine already makes (no extra quota) — npm, pip/uv, docker, github-actions, gomod at minimum — and emit one findings row per uncovered ecosystem with the manifest path as evidence. Repos with no manifests for an ecosystem are na, not pass. Tests cover declared-but-unneeded, needed-but-undeclared, and no-config cases.
Modules involved / constraints: the ci_health pipeline from #359 (copy its seed-check pattern); ecosystem→manifest mapping should be data, not if-chains, since the supported-ecosystems list grows.
How to work on this
- Claim it: comment
/assign and wait to be assigned — unassigned PRs are closed automatically.
- Get a plan: once assigned, comment
@coderabbitai plan for a draft plan, then do your own investigation — docs/architecture.md maps the layers and their rules.
- Propose your approach as a comment before coding. A paragraph is enough; early feedback here routinely saves days of rework.
🤖 AI: tools are welcome; verified work is required — you can explain every line and defend every design choice. See the AI policy. Fully automated bot PRs are closed.
Worth knowing about this repo before you design:
- The layer rules in docs/architecture.md are strict — review will hold your solution to them.
- Tests mirror src (
tests/<pkg>/test_<module>.py), and the output-contract test pins the pipeline output surface — if your change adds or renames outputs, update the contract deliberately.
Before opening your PR:
Stuck? Comment here with what you've tried — see getting help.
The task
Blocked by #359 — the ci_health engine and findings contract must exist first.
Problem:
The audit checklist requires dependabot to cover all relevant ecosystems, but a presence check on
.github/dependabot.ymlcan't see the real failure: a repo declaringpipwhile also shippingpackage.json, Dockerfiles, and GitHub Actions workflows. The gap between declared and needed ecosystems is the finding.What done looks like:
A
dependabot_ecosystemscheck in the ci_health engine: parse the repo'sdependabot.yml(missing file = its own finding), detect present ecosystems from the same.github/tree fetch the engine already makes (no extra quota) — npm, pip/uv, docker, github-actions, gomod at minimum — and emit one findings row per uncovered ecosystem with the manifest path as evidence. Repos with no manifests for an ecosystem arena, notpass. Tests cover declared-but-unneeded, needed-but-undeclared, and no-config cases.Modules involved / constraints: the ci_health pipeline from #359 (copy its seed-check pattern); ecosystem→manifest mapping should be data, not if-chains, since the supported-ecosystems list grows.
How to work on this
/assignand wait to be assigned — unassigned PRs are closed automatically.@coderabbitai planfor a draft plan, then do your own investigation — docs/architecture.md maps the layers and their rules.🤖 AI: tools are welcome; verified work is required — you can explain every line and defend every design choice. See the AI policy. Fully automated bot PRs are closed.
Worth knowing about this repo before you design:
tests/<pkg>/test_<module>.py), and the output-contract test pins the pipeline output surface — if your change adds or renames outputs, update the contract deliberately.Before opening your PR:
Stuck? Comment here with what you've tried — see getting help.