Certify complete tracker reads for TODO import and export - #55
Conversation
Replace both deprecated list-all consumers with one canonical strict, full, doubly-unbounded pm list reader backed by the public SDK certifier and narrow fail-closed receipt checks. Add exact-reader integration acceptance plus fresh packed npm/Bun current and minimum-host scenarios, align Node and pm dependency floors, and make changelog reads explicitly unbounded through the pinned host. Reconcile shipped PM items while retaining honest all-source coverage and reachable-history privacy blockers; do not merge or publish until those independent gates are resolved.
|
Warning Review limit reached
Next review available in: 29 minutes Limit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?Wait for the limit to reset, then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (21)
Summary by CodeRabbit
WalkthroughThe extension now uses SDK-certified complete-list reads for upsert and export. The pull request adds canonical-reader and packed-artifact acceptance checks, raises compatibility floors, expands release gates, and records release, coverage, and privacy metadata. ChangesCanonical reader and validation
Packed compatibility and release gates
PM release and audit records
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: 🟡 Moderate · up to The change tightens tracker reads and raises runtime compatibility requirements, but the advertised 2026.8.20 host floor is not yet shown compatible with the certified reader, and the packed acceptance matrix does not test Bun at that minimum version. Merge should wait for the compatibility contract and acceptance coverage to be corrected or explicitly accepted. Sequence Diagram(s)sequenceDiagram
participant Extension
participant pm_cli
participant SDK
Extension->>pm_cli: Run canonical pm list --all --json argv
pm_cli-->>Extension: Return complete-list envelope and receipts
Extension->>SDK: Certify and inspect the envelope
SDK-->>Extension: Return validated items or refusal diagnostics
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@greptileai review exact head 7476c66 |
|
@coderabbitai full review exact head 7476c66 |
|
/gemini review exact head 7476c66 |
|
@sourcery-ai review exact head 7476c66 |
|
@cubic-dev review exact head 7476c66 |
@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
✅ Action performedFull review finished. |
Reviewer's GuideReplaces deprecated TODO tracker reads with a single canonical, SDK-certified Sequence diagram for canonical pm list --all reader in TODO import and exportsequenceDiagram
actor User
participant TodosExtension
participant pm_cli as pm
participant pm_sdk as pm_sdk
User->>TodosExtension: runTodoImport(opts)
alt opts.upsert
TodosExtension->>TodosExtension: readCompletePmItems(pmRoot, "the --upsert key index")
TodosExtension->>pm_cli: spawnSync(pm, ["--pm-path", pmRoot, ...COMPLETE_LIST_COMMAND_ARGUMENTS])
pm_cli-->>TodosExtension: stdout (list --all envelope)
TodosExtension->>pm_sdk: inspectCompleteListResult(parsed)
pm_sdk-->>TodosExtension: findings
TodosExtension->>pm_sdk: certifyCompleteListResult(record)
pm_sdk-->>TodosExtension: items
TodosExtension->>TodosExtension: buildExistingTodoIndex(items)
end
TodosExtension-->>User: TodoImportResult
User->>TodosExtension: todos export (opts)
TodosExtension->>TodosExtension: fetchPmItems(opts)
TodosExtension->>TodosExtension: readCompletePmItems(pmRoot, "the TODO export")
TodosExtension->>pm_cli: spawnSync(pm, ["--pm-path", pmRoot, ...COMPLETE_LIST_COMMAND_ARGUMENTS])
pm_cli-->>TodosExtension: stdout (list --all envelope)
TodosExtension->>pm_sdk: inspectCompleteListResult(parsed)
pm_sdk-->>TodosExtension: findings
TodosExtension->>pm_sdk: certifyCompleteListResult(record)
pm_sdk-->>TodosExtension: items
TodosExtension->>TodosExtension: applyExportOrder(items, sort, reverse)
TodosExtension-->>User: exported TODO file
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Sourcery exact-head response reviewed: the generated guide accurately describes the canonical reader and gate changes and contains no actionable finding. The separate weekly quota response means a full Sourcery review was unavailable; that limitation is recorded and is not approval. References: #55 (comment) and #55 (comment) |
|
Cubic exact-head review could not start because the free monthly allowance is exhausted until 1 September 2026. This is recorded as unavailable review evidence, not approval: #55 (comment) |
|
CodeRabbit exact-head full review acknowledgement and in-progress summary reviewed. I will wait for the completed review and address every actionable thread before disposition: #55 (comment) and #55 (comment) |
Greptile SummaryThis PR replaces the deprecated tracker readers with a shared, fail-closed complete-corpus reader and expands release acceptance around supported hosts.
Confidence Score: 5/5The reviewed changes appear safe to merge because no blocking failure eligible for this follow-up review remains. No blocking failure remains.
|
| Filename | Overview |
|---|---|
| index.ts | Centralizes strict complete-corpus reads, validates receipt and row shapes, and introduces shell-free host CLI execution. |
| scripts/accept-packed.ts | Adds packed npm/Bun acceptance across current and minimum supported pm hosts. |
| scripts/accept-canonical-reader.ts | Adds integration acceptance for the exact canonical reader command and refusal behavior. |
| .github/workflows/ci.yml | Replaces fragmented checks with the complete mandatory release gate on exact Node floor and development lanes. |
| .github/workflows/release.yml | Uses the exact Node floor and passes explicit unbounded read arguments to changelog generation. |
| package.json | Raises the pm compatibility floor, exact-pins host tooling, and adds canonical-reader and packed acceptance gates. |
Sequence Diagram
sequenceDiagram
participant User
participant Todos as pm-todos
participant Host as pm CLI
participant SDK as pm SDK
User->>Todos: Import --upsert or export
Todos->>Host: pm list --all (strict, unbounded, full)
Host-->>Todos: Rows and completeness receipts
Todos->>SDK: Inspect and certify result
SDK-->>Todos: Certified rows or findings
alt Complete and valid
Todos-->>User: Import/export result
else Incomplete or malformed
Todos-->>User: Fail closed with diagnostics
end
Reviews (5): Last reviewed commit: "fix(todos): trust isolated pack artifact..." | Re-trigger Greptile
|
Greptile exact-head review read and up-voted. It reports no actionable code-correctness findings and explicitly recognizes the separate coverage and privacy blockers. I am retaining those blockers: this PR remains open and must not merge or publish despite the 5/5 code-review confidence. Reference: #55 (comment) |
Snapshot the fake-host invocation log after export and after upsert import so the integration gate proves each operation contributes exactly one canonical complete-list read rather than only checking the aggregate count. Record the strengthened evidence in the implementation PM item.
|
@greptileai review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9 |
|
@coderabbitai full review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9 |
|
/gemini review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9 |
|
@sourcery-ai review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9 |
|
@cubic-dev review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9 |
@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
|
|
Correction: @greptileai review exact head 1e07ebf |
|
Correction: @coderabbitai full review exact head 1e07ebf |
|
Correction: /gemini review exact head 1e07ebf |
|
Correction: @sourcery-ai review exact head 1e07ebf |
|
@cubic-dev review exact head bc31223 after all review fixes |
|
|
@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
Set both npm ignore-scripts environment controls around the machine-readable pack command so Node 22 npm cannot run prepare and prefix the JSON receipt with lifecycle output. Record the expanded-CI failure and exact local four-scenario rerun in the implementation PM item.
|
@greptileai review exact head bd0aa0c after the expanded-CI npm JSON fix |
|
@coderabbitai full review exact head bd0aa0c after the expanded-CI npm JSON fix |
|
/gemini review exact head bd0aa0c after the expanded-CI npm JSON fix |
|
@sourcery-ai review exact head bd0aa0c after the expanded-CI npm JSON fix |
|
@cubic-dev review exact head bd0aa0c after the expanded-CI npm JSON fix |
@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
|
|
The bc31223 exact-head Sourcery, CodeRabbit, and Cubic limitation responses were read and down-voted. Sourcery and Cubic were quota-limited; CodeRabbit was rate-limited after its earlier six actionable threads had already been processed. These are limitations, not approval, and that head has since been superseded by the CI fix. References: #55 (comment) #55 (comment) #55 (comment) |
|
Final-head bd0aa0c Sourcery and Cubic responses were read and down-voted because weekly and monthly quotas prevented review. Neither is approval. References: #55 (comment) #55 (comment) |
Use the freshly created npm pack destination as the authoritative acceptance receipt instead of parsing stdout that npm 10 can contaminate with prepare output. Require exactly one tarball and preserve the four npm/Bun current/minimum installed-host scenarios. Record the exact Node 22 CI evidence in pm-todos-x5my.
|
@greptileai review |
|
/gemini review |
|
@coderabbitai full review |
|
@sourcery-ai review |
|
@cubic-dev review |
@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews. To help optimise your usage, you can tune cubic to get the most out of your usage limits:
|
|
|
Acknowledged Sourcery’s exact-head response. It is a weekly quota limitation, not review evidence or approval; the limitation is recorded and the head remains gated on available reviewers plus CI. |
|
Acknowledged Cubic’s exact-head response. Its monthly quota prevents review until September, so this is explicitly a reviewer-availability limitation rather than approval. |
|
Acknowledged CodeRabbit’s exact-head response. The fair-use rate limit prevented this requested rerun; the earlier six-thread review was fully addressed, but it does not substitute for exact-head review. |
|
Exact-head review window closed after 20 minutes for |
Summary
list-allconsumers with one canonical strict, full, doubly-unboundedpm list --allreaderEvidence at exact head
Exact head:
9f720b6d7e7b4422ab78a8173754f46cf7665cccnpm run release:check: green locallypack --jsondespite ignore-scripts controls; the acceptance gate now requires exactly one tarball in a fresh pack destination and the full local gate is greenPM context
Gate status
Do not merge or publish from this PR. Exact 100/100/100/100 all-source coverage and reachable-history privacy remain independent blockers. CI and bot review are necessary review evidence, not release approval.
Summary by Sourcery
Certify complete, fail-closed tracker reads across TODO import and export while aligning host compatibility, release validation, and cross-package acceptance checks.
New Features:
pm list --allcontract.Bug Fixes:
Enhancements:
Build:
CI:
Documentation:
Tests:
Chores: