Certify pm-beads on PM CLI 2026.10.4 and consolidate pending dependency updates - #131
Conversation
…cy updates Pin @unbrained/pm-cli to 2026.10.4 (supersedes Dependabot #129, which proposed 2026.10.1) and pm-ops to 2026.10.4 (supersedes #127, which proposed 2026.9.29), bump the @types/node lockfile to 26.6.4 (newer than #126), and pin the codeql-action SHAs to 2892aa5e (#125). pm-changelog stays 2026.9.25 (latest npm). Both npm audit and npm audit --omit=dev are clean; no open Dependabot security alerts. Re-copy scripts/prepare-merge-driver.ts byte-identical from the pm-ops 2026.10.4 template: its presence probe now fails closed when a lookup path is unreadable (EACCES/EPERM/ENOTDIR/ELOOP) instead of treating an uncertain probe as an omit-dev install (pm-ops #136). Add the matching fail-closed regression so the launcher keeps full coverage. Track the 2026.10.4 certification round in pm-beads-8h18 (pm-github managed extension installed at 2026.10.4 with a clean read-only sync dry-run).
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThe update pins development dependencies and changes the CodeQL action commit. It also refines the launcher’s Changes2026.10.4 certification update
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to This change pins development dependencies, updates the CodeQL action commit, and makes the pm-ops presence check more conservative. No actionable merge-blocking risk is evident beyond the normal final CI check. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 3 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR consolidates pending dependency updates around the 2026.10.4 PM CLI/pm-ops toolchain, refreshes the lockfile and pinned CodeQL actions, and hardens the merge-driver launcher to fail closed on inconclusive module-resolution probes. It adds regression coverage and records successful release, installation, dogfood, health, and integration checks for the certification. Sequence diagram for fail-closed merge-driver package detectionsequenceDiagram
participant Launcher as prepare-merge-driver
participant Resolver as Node resolver
participant FS as Filesystem
participant Installer as Package installer
Launcher->>Resolver: resolve(pm-ops/package.json)
Resolver->>FS: lstatSync(package lookup path)
alt package found
FS-->>Resolver: package path
Resolver-->>Launcher: packagePresent
Launcher->>Installer: omit-dev installation
else lookup path unreadable or malformed
FS-->>Resolver: filesystem error
Resolver-->>Launcher: packagePresent
Launcher-->>Launcher: rethrow original installer error
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required. |
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
|
Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required. |
|
Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on |
Certifies pm-beads against PM CLI/SDK 2026.10.4 and consolidates Dependabot #125, #126, #127 and #129. PM CLI, pm-ops and pm-changelog are exact 2026.10.4 pins; Node types are 26.6.4 and all other development dependencies are exact. Both CodeQL action SHAs and version comments come from #125. The launcher is copied byte-for-byte from published pm-ops 2026.10.4, with a real ENOTDIR fail-closed regression added to its existing broken-install suite.
Validation:
flock /tmp/claude-1000/heavy-gate.lock npm run release:check: 352/352 tests, zero failures/skips, 100% V8 lines/branches/functions. Statement coverage is not separately measured by this repository's configured gate.npx pm health --strict-exit --require-merge-drivers: PASS. Fullnpm auditandnpm audit --omit=dev: zero vulnerabilities. Regenerated changelog check passes.pm test pm-beads-8h18 --match 'node --test test/prepare-merge-driver.test.ts' --run --progress: linked launcher suite passes.Packed real-data acceptance:
npm pack, install the tarball with@unbrained/pm-cli@2026.10.4into a disposable copy of this repo's tracker, thennpx -y @unbrained/pm-cli@2026.10.4 package install <tarball> --project(copy.complete=true). Through bothnpx -y @unbrained/pm-cli@2026.10.4andbunx --bun -y @unbrained/pm-cli@2026.10.4, runbeads export -o <file>,beads diff <file> --against-workspace --strict,beads validate <file>andbeads import <file> --validate-only: all 89 actual tracker records export; 89/89 unchanged, drift=false; both validators pass. The earlier synthetic two-record import/upsert evidence is retained in the PM item. Scratch copy removed.Managed pm-github 2026.10.4 read-only preview:
pm github sync --repo unbraind/pm-beads --dry-runreports planned=0, synced=0. No open Dependabot security alerts were present.Tracking: pm-beads-8h18. Item and PR remain open for orchestrator verification and final-head review.
Summary by Sourcery
Certify pm-beads against the 2026.10.4 PM toolchain while consolidating dependency updates and hardening merge-driver installation failures.
Bug Fixes:
Enhancements:
CI:
Tests: