Skip to content

Restore Jira Cloud imports with validated search cursors - #120

Open
unbraind wants to merge 5 commits into
fix/pm-jira-cli-2026-09-27-github-pinfrom
fix/pm-jira-cloud-search-cursors
Open

unbraind wants to merge 5 commits into
fix/pm-jira-cli-2026-09-27-github-pinfrom
fix/pm-jira-cloud-search-cursors

Conversation

@unbraind

@unbraind unbraind commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Jira Cloud imports used the removed offset-search endpoint. All shared import paths now use /rest/api/3/search/jql and opaque cursors, validate malformed/repeated/cycling pages before tracker writes, permit empty advancing pages, and bound traversal. Empty imports avoid zero-mutation transactions, HTTPS preserves an explicit port, and dry runs expose the new request. Declared selfsigned 5.5.0 replaces external OpenSSL while retaining real TLS validation. Stacked on #119.

Owner pm-jira-h5bm at this head records the decisions and append-only verification history.

Validation at 65594da52cc20a8ebbd3dfaa85180a670d5e5765: npm run release:check passes (193 tests, 193 pass, 0 skips); strict local PM health with required merge drivers, fresh committed-dist comparison, the PM-linked focused test and bun install --no-save pass. Thresholds and gates are unchanged.

Coverage measures 100% lines/branches/functions over two runtime files. Statements and whole-source certification remain separate (pm-jira-gpjr). The issue-sync content privacy gate remains open; sync stays disabled. For #120, authenticated Jira Cloud acceptance and native Bun core issue #1349 remain separate.

Fresh exact-head CI and substantive reviewer results remain required. This PR remains open for the orchestrator to assess; nothing is merged, published or deployed.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 23 hours and 28 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8775c947-8ce3-4ae1-a439-67a4691bc2d6

📥 Commits

Reviewing files that changed from the base of the PR and between 3940905 and 0610d9e.

⛔ Files ignored due to path filters (5)
  • dist/index.d.ts is excluded by !**/dist/**
  • dist/index.d.ts.map is excluded by !**/dist/**, !**/*.map
  • dist/index.js is excluded by !**/dist/**
  • dist/index.js.map is excluded by !**/dist/**, !**/*.map
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (10)
  • .agents/pm/history/pm-jira-gpjr.jsonl
  • .agents/pm/history/pm-jira-h5bm.jsonl
  • .agents/pm/issues/pm-jira-gpjr.toon
  • .agents/pm/issues/pm-jira-h5bm.toon
  • README.md
  • index.ts
  • package.json
  • test/cloud-search.test.ts
  • test/coverage-runtime.test.ts
  • test/smoke.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • New Features
    • Jira Cloud imports now use cursor-based pagination and report fetched counts alongside the configured limit, rather than displaying an unavailable total.
    • Dry-run previews show the cursor-based search request without making a network call.
  • Bug Fixes
    • Imports now stop before writing issues when pages are malformed, oversized, duplicated, or have invalid continuation tokens. Empty results complete without opening an atomic transaction.
  • Documentation
    • Added guidance on pagination behavior, validation limits, and Jira Data Center support.

Walkthrough

Jira Cloud imports now use cursor-based enhanced search. The importer validates page responses and continuation tokens, reports progress without an exact total, and avoids opening an atomic transaction when no issues remain. The pull request also adds a coverage-tracking issue record.

Changes

Jira Cloud cursor pagination

Layer / File(s) Summary
Search contract and request construction
index.ts, README.md, test/smoke.test.ts, .agents/pm/issues/pm-jira-h5bm.toon
Search requests use /rest/api/3/search/jql and an optional nextPageToken. The response contract uses isLast and an optional continuation token. The README and smoke test reflect the updated request shape.
Cursor traversal and import validation
index.ts, test/cloud-search.test.ts, test/coverage-runtime.test.ts, .agents/pm/history/pm-jira-h5bm.jsonl, .agents/pm/issues/pm-jira-h5bm.toon, package.json
The importer validates pages and continuation tokens, stops at isLast or the requested limit, and reports progress without an exact Jira total. Empty results do not open an atomic transaction. HTTPS tests cover cursor traversal, invalid pages, limits, and empty results. The development dependency version is updated. The Jira issue records implementation notes and acceptance status.

Coverage tracking issue

Layer / File(s) Summary
Coverage issue record
.agents/pm/issues/pm-jira-gpjr.toon, .agents/pm/history/pm-jira-gpjr.jsonl
A new issue record lists coverage and runtime documentation acceptance criteria, along with issue metadata and history.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant Importer as Atomic importer
  participant Fetch as fetchAllJiraIssues
  participant Search as Jira Cloud search
  participant Tracker as Tracker
  Importer->>Fetch: Fetch issues
  Fetch->>Search: Send cursor-based search request
  Search-->>Fetch: Return issues and page cursor
  Fetch->>Fetch: Validate page and continuation token
  Fetch-->>Importer: Return validated issues
  Importer->>Tracker: Write issues when results remain
Loading

Merge Risk: ⚪ Minimal · up to 0610d

The change restores Jira Cloud cursor-based imports with page validation and empty-result handling. No actionable merge-blocking issue is established; normal checks and authenticated Jira acceptance remain appropriate.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0610d

The cursor migration strengthens validation before tracker writes, and no new remotely exploitable attack path was established. Explicit ports broaden configured destinations. Interrupted and concurrent imports still rely on recovery guarantees that were not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Relevant assets are the configured Jira credentials, retrieved issue data, and the caller-selected PM store. Destination manipulation requires influence over host options or environment configuration; remote attacker influence was not established. Honoring explicit ports expands reachable TLS endpoints, but does not grant a different Jira identity or additional tracker authority.

Trust Boundaries and Controls

  • observed — Continuation tokens from Jira remain URL-encoded query values on the configured destination. They cannot replace the hostname through request construction. The transport does not follow redirects, so it does not automatically forward Authorization to a redirect target.

Resilience and Maintainability Implications

  • observed — Atomic mutation IDs normalize issue keys, whereas the new reader detects duplicates using raw strings. Case variants can therefore map to the same mutation ID. That normalization existed in the available parent, whose reader did not reject duplicate keys, so this is not evidence of a PR-introduced regression. External duplicate-ID handling remains unverified. Sequential imports retain their existing non-atomic partial-failure behavior.

Hardening Proposals

  • proposed — If deployment permits less-trusted parties to influence destination configuration while credentials come from a more-trusted source, enforce an approved HTTPS host-and-port policy before attaching Authorization. This is conditional hardening, not a verified new vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 4 files. (6 skipped: 6… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the primary change: restoring Jira Cloud imports with validated cursor-based search.
Description check ✅ Passed The description directly explains the cursor-based Jira search changes, validation behavior, testing, and remaining acceptance work.
Full details: Docstring Coverage

Explanation

Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 4 files. (6 skipped: 6 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Reviewer's Guide

Restores Jira Cloud imports by replacing removed offset pagination with /rest/api/3/search/jql opaque cursors, validating the complete page chain before writes, preserving TLS ports, and covering the new behavior with local HTTPS/PM-store regressions and regenerated distribution artifacts.

Sequence diagram for validated Jira Cloud cursor import

sequenceDiagram
    participant Importer
    participant JiraCloud
    participant Tracker

    Importer->>JiraCloud: GET /rest/api/3/search/jql
    JiraCloud-->>Importer: issues, isLast, nextPageToken
    loop Until isLast or max-results reached
        Importer->>Importer: Validate page and issue keys
        Importer->>JiraCloud: GET /rest/api/3/search/jql with nextPageToken
        JiraCloud-->>Importer: issues, isLast, nextPageToken
    end
    Importer->>Importer: Validate complete page chain
    alt Valid results
        Importer->>Tracker: Write imported items
    else Invalid page, token, key, or page limit
        Importer-->>Tracker: No writes
    end
Loading

Sequence diagram for dry-run Jira request preview

sequenceDiagram
    participant User
    participant Importer

    User->>Importer: runImport with dry-run
    Importer->>Importer: buildSearchRequest with undefined cursor
    Importer-->>User: Display GET /rest/api/3/search/jql request
    Importer-->>User: Report no network call
Loading

Flow diagram for Jira Cloud cursor pagination safeguards

flowchart TD
    A[Build search request with cursor] --> B[Fetch Jira Cloud page]
    B --> C{Page shape and size valid?}
    C -- No --> X[Fail before tracker writes]
    C -- Yes --> D{Issue keys unique and valid?}
    D -- No --> X
    D -- Yes --> E{isLast?}
    E -- Yes --> F[Commit non-empty import]
    E -- No --> G{Continuation token valid and unseen?}
    G -- No --> X
    G -- Yes --> H{Under 1,000 pages?}
    H -- No --> X
    H -- Yes --> I[Fetch next cursor page]
    I --> C
Loading

File-Level Changes

Change Details Files
Migrate Jira Cloud imports from offset-based search to validated opaque-cursor pagination.
  • Switch requests to /rest/api/3/search/jql and encode nextPageToken cursors.
  • Validate page shape, page size, issue keys, continuation tokens, empty advancing pages, and the 1,000-page traversal limit before tracker writes.
  • Update progress output and dry-run previews to omit nonexistent Jira totals.
  • Skip atomic transaction creation when filtering produces no mutations.
index.ts
dist/index.js
dist/index.d.ts
README.md
Strengthen HTTPS request handling and SDK compatibility for the restored import flow.
  • Preserve explicitly configured URL ports in TLS requests.
  • Type exported helpers for cursor strings or undefined and update SDK module typing.
  • Upgrade the exact pm-cli dependency and lockfile to 2026.9.29.
index.ts
dist/index.js
dist/index.d.ts
package.json
package-lock.json
Add regression coverage for cursor contracts, validation failures, TLS behavior, and empty imports.
  • Exercise dry-run URL generation without offsets.
  • Run cursor traversal against a local HTTPS server, including encoded cursors and empty intermediate pages.
  • Verify malformed, repeated, oversized, incomplete, and overlong page chains fail without tracker mutations.
  • Update existing mocked pagination tests to the enhanced-search response shape.
test/cloud-search.test.ts
test/coverage-runtime.test.ts
test/smoke.test.ts
Document the new Jira Cloud search contract and track related project work.
  • Document cursor pagination, validation guarantees, progress semantics, page limits, and Cloud-only scope.
  • Add issue and history records for search repair and source-coverage/documentation work.
README.md
.agents/pm/issues/pm-jira-h5bm.toon
.agents/pm/issues/pm-jira-gpjr.toon
.agents/pm/history/pm-jira-h5bm.jsonl
.agents/pm/history/pm-jira-gpjr.jsonl
Regenerate and publish the distributable declaration and runtime artifacts.
  • Include compiled runtime and declaration changes corresponding to the TypeScript implementation.
  • Update source maps with the generated build output.
dist/index.js
dist/index.js.map
dist/index.d.ts
dist/index.d.ts.map

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@unbraind

Copy link
Copy Markdown
Owner Author

Please review current head 0610d9e, especially enhanced Jira Cloud cursor handling, refusal before tracker writes, empty atomic imports and the real TLS tests. This is stacked on #119; review this PR's diff.

@greptileai
/gemini review
@coderabbitai full review
@sourcery-ai review

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@unbraind

unbraind commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner Author

Feedback on Sourcery's guide: useful summary, upvoted. The no-write guarantee applies to invalid pagination chains within the requested result limit; it is not a Jira snapshot-consistency guarantee. The package validates the page envelope, cursor and issue keys, then maps the collected results before import.

Sourcery review 5358868471 reports exhausted included review capacity. Acknowledged as missing substantive review, not approval; no paid upgrade is enabled. Update: the top-level review has now also been upvoted through GitHub GraphQL addReaction after verifying that PullRequestReview implements Reactable. The earlier claim that review objects cannot receive reactions was incorrect; the disposition above is unchanged.

@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Migrates Jira Cloud search to new pagination API with validation.

The reviewed changes appear safe to merge from a code-review standpoint; the documented external checks remain separate.

Summary

This PR moves Jira Cloud imports to validated, bounded cursor pagination before tracker writes.

  • Updates dry-run requests and progress reporting, preserves explicit HTTPS ports, and avoids empty atomic transactions.
  • Adds real-TLS cursor tests and records the remaining external acceptance and review work.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Import request] --> B[Fetch Cloud search pages]
  B --> C[Validate pages and cursors]
  C --> D[Map selected issues]
  D --> E{Any items?}
  E -- Yes --> F[Import into tracker]
  E -- No --> G[Return empty result]
Loading

Reviews (6) · Last reviewed commit: "docs(jira): track external Hound review ..."

Comment thread test/cloud-search.test.ts Outdated
@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review

@unbraind

Copy link
Copy Markdown
Owner Author

Round-one artifact dispositions for 0610d9e:

  • CodeRabbit report 5899547012: upvoted and read with its file exclusions. It reports no actionable findings for this head; regenerated dist and lockfile were excluded by its configuration and remain independently checked. This receipt will not be treated as approval of the forthcoming test-dependency change.
  • CodeRabbit completion 5899567690: upvoted; completion acknowledged for the same head.
  • Greptile summary 5899662924 and review 5358944678: upvoted summary; the sole OpenSSL portability finding was separately upvoted and answered inline. Its fix uses a declared certificate-generation test dependency while preserving actual TLS verification; validation is running. No merge is authorized from a 4/5 summary alone.
  • Cubic's neutral check reports exhausted monthly included capacity, so substantive review is missing. Sourcery's exhausted quota remains separately acknowledged. No paid capacity or test-exclusion workaround was enabled.

Gemini has not responded to the original request; a standalone command has also been sent to eliminate ambiguity in command parsing.

@unbraind

Copy link
Copy Markdown
Owner Author

Additional feedback on CodeRabbit report 5899547012: its embedded pre-merge docstring warning is actionable even though no inline finding was emitted. Added a module contract and the missing runImport JSDoc describing offline dry-run, pagination refusal before writes, empty atomic results and sequential partial-success behavior. The repository-wide documentation gap remains tracked in pm-jira-gpjr; the selected 51-declaration local gate is not presented as complete documentation coverage.

@unbraind

Copy link
Copy Markdown
Owner Author

The first round received a full CodeRabbit review and Greptile's portability finding; Sourcery and cubic reported quota limits, and Gemini did not respond during the completed 20-minute window.

Please review new head 98beb93. Greptile 4138693215 is fixed with declared selfsigned 5.5.0 and real TLS tests that also pass with an empty PATH. Module/import JSDoc addresses CodeRabbit's embedded documentation warning. Exact-head release:check passes 193 tests, zero skips; full audit is clean. Native Bun strict health remains blocked by independently reproduced existing core #1349, as documented in the PR.

@greptileai
@coderabbitai full review
@sourcery-ai review

@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 39 minutes.

@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai please review current head 98beb93. The latest neutral check says "Review was cancelled", not completed. The prior inline OpenSSL dependency finding is fixed and answered in its thread; please verify that fix and the current diff.

@unbraind

Copy link
Copy Markdown
Owner Author

Round-two artifact feedback for 98beb93:

  • Read the edited Greptile summary 5899662924: it now identifies this exact head, confirms the OpenSSL fix and reports no new actionable findings (5/5). Its existing upvote remains appropriate; thank you for verifying the fix. The earlier cancelled check alone was not completion evidence.
  • Read the edited CodeRabbit report 5899547012 and new command receipt 5899942125; both are upvoted. The current-head review is explicitly rate limited, while the retained substantive review covers 0610d9e only. This is missing current-head review, not approval. No paid review capacity has been enabled.
  • Both Node 22 and Node 26 CI jobs passed at this head. Cubic remains quota-blocked. Sourcery emitted a successful no-blocking-security check, but its full review artifact remains the earlier exhausted-budget response; that narrower check is not represented as a comprehensive review.

Gemini remains pending within the second review window. The independently documented all-source coverage, native Bun #1349, live Jira acceptance and parent-PR gates still apply.

@unbraind

Copy link
Copy Markdown
Owner Author

Final review-window receipt for 98beb93, after the full 20-minute second-round window:

  • Exact-head release:check passes 193 tests with zero skips. Node 22/26 CI, DeepScan, Hound and Greptile pass; npm packed acceptance passes. Measured coverage remains three dimensions over two runtime files, not all-source 100/100/100/100.
  • Greptile's edited summary 5899662924 (22:11:46 UTC) covers this exact head, confirms finding 4138693215 fixed, and reports 5/5 with no new actionable finding. The finding is resolved, upvoted and answered inline. The top-level Greptile review is also upvoted through GraphQL.
  • Re-read CodeRabbit's edited report 5899547012 (22:22:59 UTC), including its embedded checks. The edit refreshed description checks and removed the quota banner, but its substantive review still explicitly ends at 0610d9e. Command receipt 5899942125 still records the rate limit. The prior docstring warning was addressed in source; it has not been remeasured by a current-head CodeRabbit review.
  • Sourcery's guide and budget-exhaustion review are read, upvoted and acknowledged. Its current no-blocking-security check is narrower than the missing comprehensive review. Cubic's neutral check reports exhausted included capacity; its PR-description summary is not a substantive review. Gemini did not respond to either round, including standalone commands.
  • Every returned bot comment/review has a vote and explicit disposition; review-object votes were verified using GraphQL Reactable. Paginated issue comments, inline comments and reviews were re-read after the window. No new unhandled finding remains in the returned artifacts, but missing reviews remain missing.

PR stays open: parent #119, authenticated live Jira acceptance, all-source documentation/coverage, native Bun strict health (existing upstream #1349), and complete current-head reviews are unresolved. No publication, deployment or telemetry change was performed. A rate limit or absent response is not treated as approval, and no paid capacity was enabled.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

unbraind added a commit that referenced this pull request Oct 2, 2026
@unbraind
unbraind force-pushed the fix/pm-jira-cloud-search-cursors branch from 98beb93 to dc64fdb Compare October 2, 2026 23:21
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@unbraind have exceeded the limit for the number of chat messages per hour. Please wait 0 minutes and 37 seconds before sending another message.

Comment thread .agents/pm/issues/pm-jira-h5bm.toon Outdated
Replace the removed offset search API across shared sync/import paths. Validate continuation tokens and issue identities before writes, bound stalled queries, retain configured HTTPS ports, and treat empty atomic imports as no-op success.

Add real TLS and PM transaction regressions, upgrade CLI SDK to 2026.9.29, regenerate dist, and track remaining all-source coverage scope separately. Direct release gate: 193 passing tests; isolated packed npm/npx and Bun/bunx acceptance and strict health pass.
Address Greptile review 4138693215 with pinned selfsigned 5.5.0 and native EC certificate generation. Preserve verified TLS, real PM-store assertions and a zero-skip regression that also passes with an empty PATH.

Document the import/module contracts called out by CodeRabbit. Full release gate remains 193 passing tests; all dependencies audit clean. Keep unavailable reviews and all-source quality gaps explicit.
@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@unbraind
unbraind force-pushed the fix/pm-jira-cloud-search-cursors branch from dc64fdb to 713d3c4 Compare October 2, 2026 23:48
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

On review 5397812588: Fixed in 713d3c4. Removed only the newly added publication-workflow test/file link; retained the original Cloud search/TLS command and used it as the focused issue evidence. Its PM-linked run and the full 193/193 release gate pass on the final parent 78caa84. Historical verification notes and every append-only history line remain intact.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

On issue 5963015617: This is an operational/quota notice, not a substantive review. The current head remains subject to the outstanding review gate; no code finding is reported here.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

On issue 5963266920: This is an operational/quota notice, not a substantive review. The current head remains subject to the outstanding review gate; no code finding is reported here.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

On issue 5963623538: This is a quota/skip notice, not a substantive review. No finding is reported. The current head still needs the missing review evidence before readiness can be claimed.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 17 files

You’re at about 94% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="README.md">

<violation number="1" location="README.md:8">
P3: The added paragraph documents the new progress format, but the "Progress + transparency notes (STDERR)" section below still says the importer prints `Fetched N/total...`. No live path produces that anymore: `fetchAllJiraIssues` always reports `jiraTotal === undefined` (index.ts:1265), so both call sites (index.ts:1881, :2516) print `Fetched N (limit M)...`. Update the stale section to match the new format or remove the old example.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread .agents/pm/issues/pm-jira-gpjr.toon
Comment thread test/cloud-search.test.ts
Comment thread test/cloud-search.test.ts
Comment thread README.md
Cloud imports use the [enhanced JQL search API](https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-search/#api-rest-api-3-search-jql-get)
at `/rest/api/3/search/jql`. All import entrypoints follow opaque
`nextPageToken` cursors until `isLast` or the requested `--max-results` limit.
Progress reports fetched counts and the configured limit because this API has

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: The added paragraph documents the new progress format, but the "Progress + transparency notes (STDERR)" section below still says the importer prints Fetched N/total.... No live path produces that anymore: fetchAllJiraIssues always reports jiraTotal === undefined (index.ts:1265), so both call sites (index.ts:1881, :2516) print Fetched N (limit M).... Update the stale section to match the new format or remove the old example.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At README.md, line 8:

<comment>The added paragraph documents the new progress format, but the "Progress + transparency notes (STDERR)" section below still says the importer prints `Fetched N/total...`. No live path produces that anymore: `fetchAllJiraIssues` always reports `jiraTotal === undefined` (index.ts:1265), so both call sites (index.ts:1881, :2516) print `Fetched N (limit M)...`. Update the stale section to match the new format or remove the old example.</comment>

<file context>
@@ -2,6 +2,22 @@
+Cloud imports use the [enhanced JQL search API](https://developer.atlassian.com/cloud/jira/platform/rest/v3/api-group-issue-search/#api-rest-api-3-search-jql-get)
+at `/rest/api/3/search/jql`. All import entrypoints follow opaque
+`nextPageToken` cursors until `isLast` or the requested `--max-results` limit.
+Progress reports fetched counts and the configured limit because this API has
+no exact total. Dry runs show the same initial request without making a network
+call. The exported `buildSearchRequest` helper now takes a cursor string or
</file context>

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Valid: the older progress section still says Fetched N/total, while the cursor importer reports a fetched count and configured limit. This arrived after the third permitted push/re-review round. It is left open for the orchestrator rather than starting an unauthorized fourth round; the README progress example needs correction before readiness. No runtime regression is asserted.

@unbraind

unbraind commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

On review 5398136363: Read all four late findings. Three are technically refused in their individual threads using the current scope, official Node agent defaults and registered cleanup/process isolation. The stale README progress example is valid and remains open because this review arrived after the third permitted push/re-review round. The orchestrator has the remaining disposition; no fourth request or gate weakening was introduced.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant