Skip to content

Certify pm-beads on PM CLI 2026.10.4 and consolidate pending dependency updates - #131

Merged
unbraind merged 3 commits into
mainfrom
chore/pm-beads-pm-cli-2026-10-4
Oct 4, 2026
Merged

unbraind merged 3 commits into
mainfrom
chore/pm-beads-pm-cli-2026-10-4

Conversation

@unbraind

@unbraind unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Certifies pm-beads against PM CLI/SDK 2026.10.4 and consolidates Dependabot #125, #126, #127 and #129. PM CLI, pm-ops and pm-changelog are exact 2026.10.4 pins; Node types are 26.6.4 and all other development dependencies are exact. Both CodeQL action SHAs and version comments come from #125. The launcher is copied byte-for-byte from published pm-ops 2026.10.4, with a real ENOTDIR fail-closed regression added to its existing broken-install suite.

Validation:

  • flock /tmp/claude-1000/heavy-gate.lock npm run release:check: 352/352 tests, zero failures/skips, 100% V8 lines/branches/functions. Statement coverage is not separately measured by this repository's configured gate.
  • npx pm health --strict-exit --require-merge-drivers: PASS. Full npm audit and npm audit --omit=dev: zero vulnerabilities. Regenerated changelog check passes.
  • pm test pm-beads-8h18 --match 'node --test test/prepare-merge-driver.test.ts' --run --progress: linked launcher suite passes.

Packed real-data acceptance: npm pack, install the tarball with @unbrained/pm-cli@2026.10.4 into a disposable copy of this repo's tracker, then npx -y @unbrained/pm-cli@2026.10.4 package install <tarball> --project (copy.complete=true). Through both npx -y @unbrained/pm-cli@2026.10.4 and bunx --bun -y @unbrained/pm-cli@2026.10.4, run beads export -o <file>, beads diff <file> --against-workspace --strict, beads validate <file> and beads import <file> --validate-only: all 89 actual tracker records export; 89/89 unchanged, drift=false; both validators pass. The earlier synthetic two-record import/upsert evidence is retained in the PM item. Scratch copy removed.

Managed pm-github 2026.10.4 read-only preview: pm github sync --repo unbraind/pm-beads --dry-run reports planned=0, synced=0. No open Dependabot security alerts were present.

Tracking: pm-beads-8h18. Item and PR remain open for orchestrator verification and final-head review.

Summary by Sourcery

Certify pm-beads against the 2026.10.4 PM toolchain while consolidating dependency updates and hardening merge-driver installation failures.

Bug Fixes:

  • Make merge-driver setup fail closed when pm-ops resolution encounters an inconclusive lookup path, including ENOTDIR conditions.

Enhancements:

  • Certify the project against PM CLI, pm-ops, and pm-changelog 2026.10.4 with exact development dependency pins.
  • Refresh the lockfile and pin CodeQL workflow actions to the updated v4 commit.

CI:

  • Update CodeQL initialization and analysis action references.

Tests:

  • Add regression coverage for unreadable pm-ops lookup paths during merge-driver installation.

…cy updates

Pin @unbrained/pm-cli to 2026.10.4 (supersedes Dependabot #129, which
proposed 2026.10.1) and pm-ops to 2026.10.4 (supersedes #127, which proposed
2026.9.29), bump the @types/node lockfile to 26.6.4 (newer than #126), and
pin the codeql-action SHAs to 2892aa5e (#125). pm-changelog stays 2026.9.25
(latest npm). Both npm audit and npm audit --omit=dev are clean; no open
Dependabot security alerts.

Re-copy scripts/prepare-merge-driver.ts byte-identical from the pm-ops
2026.10.4 template: its presence probe now fails closed when a lookup path
is unreadable (EACCES/EPERM/ENOTDIR/ELOOP) instead of treating an uncertain
probe as an omit-dev install (pm-ops #136). Add the matching fail-closed
regression so the launcher keeps full coverage.

Track the 2026.10.4 certification round in pm-beads-8h18 (pm-github managed
extension installed at 2026.10.4 with a clean read-only sync dry-run).

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 21 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 273e7538-f6a5-4514-aedf-f789e78a3b00

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 3e8d67a6-1406-452d-8b29-46fec00d52be
📥 Commits

Reviewing files that changed from the base of the PR and between 964adf1 and b76b13e.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .agents/pm/chores/pm-beads-8h18.toon
  • .agents/pm/history/pm-beads-8h18.jsonl
  • .github/workflows/codeql.yml
  • package.json
  • scripts/prepare-merge-driver.ts
  • test/prepare-merge-driver.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Bug Fixes
    • Merge-driver setup now distinguishes a genuinely missing package from an inaccessible or invalid dependency path. When Node cannot resolve the package because of a filesystem issue, setup preserves the original resolution error instead of incorrectly treating the package as absent; merge drivers are not registered after the failure.

Walkthrough

The update pins development dependencies and changes the CodeQL action commit. It also refines the launcher’s pm-ops presence check and adds a regression test. Certification records capture verification results and note that final-head CI and reviews were pending.

Changes

2026.10.4 certification update

Layer / File(s) Summary
Update dependency and CodeQL pins
package.json, .github/workflows/codeql.yml
The development dependency versions are updated, including exact pins for the listed packages. The CodeQL init and analyze steps use a different pinned commit.
Refine the pm-ops presence check
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts
The launcher inspects Node resolution paths with lstatSync. Existing entries and inspection errors count as package presence. The test checks that a file named node_modules in an ancestor leads to a MODULE_NOT_FOUND error and leaves merge drivers unregistered.
Record certification and verification results
.agents/pm/chores/pm-beads-8h18.toon, .agents/pm/history/pm-beads-8h18.jsonl
The records specify the 2026.10.4 certification criteria and report a 352/352 release gate, zero audit vulnerabilities, strict health checks, and packed npm and Bun checks across 89 real tracker records. They also record a read-only GitHub sync preview and note that final-head CI and reviews were pending.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to b76b1

This change pins development dependencies, updates the CodeQL action commit, and makes the pm-ops presence check more conservative. No actionable merge-blocking risk is evident beyond the normal final CI check.

Architecture Summary

Architecture risk: 🔵 Low · up to b76b1

The change affects 3 systems.

Changed systems: package.json, scripts, test

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — scripts (service) was modified; 1 changed file maps to changed impact.
  • observed — test (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: Updated the five development dependency versions: @types/node to 26.6.4, @unbrained/pm-cli and pm-changelog to 2026.10.4, pm-ops to 2026.10.4, and kept TypeScript at 7.0.2 while removing its ^ range.
  • observed — Modified behavior in scripts/prepare-merge-driver.ts: The presence check now inspects each resolution path with lstatSync and treats existing entries—including dangling links—or inspection errors as evidence that pm-ops is present. Only absent entries across all paths allow a MODULE_NOT_FOUND probe to establish package absence; other probe failures also count as present.
  • observed — Modified behavior in test/prepare-merge-driver.test.ts: Adds a test that creates a checkout beneath an ancestor where node_modules is a file, then runs the prepare launcher. It expects a nonzero exit, no omit-dev skip notice, a MODULE_NOT_FOUND error, and no registered merge drivers.
  • observed — Modified behavior in .agents/pm/chores/pm-beads-8h18.toon: The chore title now identifies the 2026.10.4 certification. Acceptance criteria now require exact development pins and clean full and production npm audits. The updated result records 2026.10.4 dependency pins, a 352/352 release gate, zero audit vulnerabilities, strict health and packed real-tracker npm/Bun checks across 89 records, and a read-only GitHub sync preview; final-head CI and required bot reviews are pending.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the PM CLI 2026.10.4 certification and dependency updates, which are the main changes.
Description check ✅ Passed The description covers the certification, dependency pins, launcher regression test, validation results, and pending review status.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR consolidates pending dependency updates around the 2026.10.4 PM CLI/pm-ops toolchain, refreshes the lockfile and pinned CodeQL actions, and hardens the merge-driver launcher to fail closed on inconclusive module-resolution probes. It adds regression coverage and records successful release, installation, dogfood, health, and integration checks for the certification.

Sequence diagram for fail-closed merge-driver package detection

sequenceDiagram
    participant Launcher as prepare-merge-driver
    participant Resolver as Node resolver
    participant FS as Filesystem
    participant Installer as Package installer

    Launcher->>Resolver: resolve(pm-ops/package.json)
    Resolver->>FS: lstatSync(package lookup path)
    alt package found
        FS-->>Resolver: package path
        Resolver-->>Launcher: packagePresent
        Launcher->>Installer: omit-dev installation
    else lookup path unreadable or malformed
        FS-->>Resolver: filesystem error
        Resolver-->>Launcher: packagePresent
        Launcher-->>Launcher: rethrow original installer error
    end
Loading

File-Level Changes

Change Details Files
Consolidate and pin the PM toolchain and dependency updates for the 2026.10.4 certification.
  • Pin the PM CLI and pm-ops development dependencies to 2026.10.4.
  • Refresh the lockfile, including @types/node to 26.6.4, while retaining pm-changelog at 2026.9.25.
  • Update CodeQL init and analyze actions to the specified v4 commit SHA.
  • Review the lockfile for transitive dependency changes and verify the reported audit and release checks.
package.json
package-lock.json
.github/workflows/codeql.yml
Make merge-driver installation fail closed when package presence cannot be determined.
  • Treat unreadable or malformed Node module lookup paths as an existing/uncertain pm-ops installation rather than silently omitting dev dependencies.
  • Preserve the original module-resolution error and avoid registering merge drivers when the probe is inconclusive.
  • Add a regression test covering an ancestor node_modules file that produces ENOTDIR.
scripts/prepare-merge-driver.ts
test/prepare-merge-driver.test.ts
Record certification and dependency-update tracking evidence.
  • Update the PM chore state and history with the 2026.10.4 certification results.
  • Capture release, health, linked-test, packaging, audit, and packed-artifact dogfood evidence.
  • Record the pm-github dry-run validation showing no linked issues or scheduled synchronization.
.agents/pm/chores/pm-beads-8h18.toon
.agents/pm/history/pm-beads-8h18.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@greptile-apps

greptile-apps Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates build tooling and dependency versions across the project.

The changes since the previous review appear safe to merge.

Summary

This PR pins the PM development tools to 2026.10.4, makes all development pins exact, updates CodeQL, and adds a broken-path test for the shared merge-driver launcher.

  • Since the previous review, only the certification item and its history changed.
  • The new history events match the recorded handoff and claim release.
  • No new actionable issues or applicable rule violations were found.

Reviews (4) · Last reviewed commit: "Record review handoff and release certif..."

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 5c208144f591; merging remains with the orchestrator.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 5c208144f591; merging remains with the orchestrator.

@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Review receipt: This is an unavailable-review receipt, not approval. The PR remains open; final-head review is still required.

@unbraind

unbraind commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner Author

Review receipt: Acknowledged the useful review summary. Validation and remaining limitations are recorded in the PR and its package PM item on 5c208144f591; merging remains with the orchestrator.

@unbraind
unbraind merged commit f768240 into main Oct 4, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant