Skip to content

Certify complete tracker reads for TODO import and export - #55

Merged
unbraind merged 5 commits into
mainfrom
fix/canonical-certified-list-reader-2026-8-21
Aug 21, 2026
Merged

unbraind merged 5 commits into
mainfrom
fix/canonical-certified-list-reader-2026-8-21

Conversation

@unbraind

@unbraind unbraind commented Aug 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • replace both deprecated list-all consumers with one canonical strict, full, doubly-unbounded pm list --all reader
  • delegate shared completeness policy to the public pm SDK and reject the remaining receipt gaps fail-closed with actual wrong-type diagnostics
  • securely resolve the host-declared pm executable on Windows without a shell
  • exact-pin the current host, preserve the proven 2026.8.20 behavior floor, and add mandatory exact-reader plus four-way packed npm/Bun acceptance
  • make CI execute the complete release gate and derive the exact tarball receipt from a fresh pack destination despite npm 10 lifecycle output
  • reconcile shipped PM work while retaining independent all-source coverage and reachable-history privacy blockers

Evidence at exact head

Exact head: 9f720b6d7e7b4422ab78a8173754f46cf7665ccc

  • npm run release:check: green locally
  • 157 unit tests plus exact-reader integration acceptance
  • configured index.ts-only coverage: 68.69% lines, 86.84% branches, 75.86% functions
  • packed matrix: npm and Bun on pm 2026.8.21 and pm 2026.8.20; exactly two real fixtures exported in every scenario
  • production audit: zero vulnerabilities
  • package: nine expected files, no PM data or test tooling
  • PM validate/merge dry-run/duplicate scan/strict health: clean apart from bounded legacy validation warnings and three pre-existing provenance advisories
  • CodeRabbit: six threads individually up-voted, replied to, and resolved; five fixes plus evidence-backed retention of the 2026.8.20 floor
  • exact-head Node 22 CI proved npm 10 still polluted pack --json despite ignore-scripts controls; the acceptance gate now requires exactly one tarball in a fresh pack destination and the full local gate is green

PM context

Gate status

Do not merge or publish from this PR. Exact 100/100/100/100 all-source coverage and reachable-history privacy remain independent blockers. CI and bot review are necessary review evidence, not release approval.

Summary by Sourcery

Certify complete, fail-closed tracker reads across TODO import and export while aligning host compatibility, release validation, and cross-package acceptance checks.

New Features:

  • Certify complete tracker reads for TODO upsert imports and exports through a canonical strict pm list --all contract.
  • Add packed acceptance coverage across npm and Bun using both current and minimum supported pm hosts.

Bug Fixes:

  • Prevent duplicate imports and partial exports by failing closed on incomplete, contradictory, or malformed tracker-read evidence.
  • Secure Windows pm executable resolution without invoking a shell.

Enhancements:

  • Centralize completeness validation through the public pm SDK with additional receipt checks and field validation.
  • Raise the supported pm compatibility floor to 2026.8.20 and pin development tooling to exact host versions.

Build:

  • Expand the mandatory release gate with canonical-reader and packed-extension acceptance checks, and isolate npm pack output from lifecycle scripts.

CI:

  • Run the complete release gate in CI on the exact Node 22.18.0 floor while retaining the Node 26 development lane.

Documentation:

  • Document the complete-corpus read guarantees, release acceptance matrix, and independent publication blockers.

Tests:

  • Replace legacy list-all completeness tests with canonical-reader, receipt-validation, compatibility-floor, and packed-host acceptance coverage.

Chores:

  • Update PM issue history and generated changelog entries for the shipped work.

Replace both deprecated list-all consumers with one canonical strict, full, doubly-unbounded pm list reader backed by the public SDK certifier and narrow fail-closed receipt checks.

Add exact-reader integration acceptance plus fresh packed npm/Bun current and minimum-host scenarios, align Node and pm dependency floors, and make changelog reads explicitly unbounded through the pinned host.

Reconcile shipped PM items while retaining honest all-source coverage and reachable-history privacy blockers; do not merge or publish until those independent gates are resolved.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@unbraind, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 29 minutes

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 321c688a-968c-433c-9337-de7a9c1cb062

📥 Commits

Reviewing files that changed from the base of the PR and between 79d5da7 and 9f720b6.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (21)
  • .agents/pm/history/pm-todos-irjt.jsonl
  • .agents/pm/history/pm-todos-ja6k.jsonl
  • .agents/pm/history/pm-todos-oz1n.jsonl
  • .agents/pm/history/pm-todos-qpst.jsonl
  • .agents/pm/history/pm-todos-x5my.jsonl
  • .agents/pm/issues/pm-todos-irjt.toon
  • .agents/pm/issues/pm-todos-ja6k.toon
  • .agents/pm/issues/pm-todos-oz1n.toon
  • .agents/pm/issues/pm-todos-qpst.toon
  • .agents/pm/issues/pm-todos-x5my.toon
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • CHANGELOG.md
  • README.md
  • index.ts
  • manifest.json
  • package.json
  • scripts/accept-canonical-reader.ts
  • scripts/accept-packed.ts
  • test/compatibility-floor.test.ts
  • test/list-all-completeness.test.ts

Summary by CodeRabbit

  • New Features

    • Upsert and export operations now use validated complete-list reads, preventing duplicate imports and partial exports.
    • Added packed-package acceptance checks across npm and Bun, including supported host versions.
    • Added compatibility checks for supported runtime and package-manager versions.
  • Bug Fixes

    • Improved diagnostics when workspace data is incomplete or malformed.
    • Fixed release ordering so packages publish only after protected-main updates.
  • Documentation

    • Documented canonical-reader requirements and expanded release-readiness checks.
    • Updated the 2026.8.10 changelog with these fixes.

Walkthrough

The extension now uses SDK-certified complete-list reads for upsert and export. The pull request adds canonical-reader and packed-artifact acceptance checks, raises compatibility floors, expands release gates, and records release, coverage, and privacy metadata.

Changes

Canonical reader and validation

Layer / File(s) Summary
Canonical reader runtime
index.ts, manifest.json, package.json, README.md
The extension validates complete pm list --all --json responses before upsert and export. The minimum host versions and SDK dependency versions increased.
Canonical reader validation
test/list-all-completeness.test.ts, scripts/accept-canonical-reader.ts
Tests cover canonical arguments, receipt requirements, malformed envelopes, item-field types, and one-read behavior for export and upsert.

Packed compatibility and release gates

Layer / File(s) Summary
Packed compatibility and release gates
scripts/accept-packed.ts, test/compatibility-floor.test.ts, package.json, .github/workflows/*, README.md, CHANGELOG.md
The release checks now pack and install the extension with npm and Bun, validate compatibility floors, pin Node.js 22.18.0, use unbounded changelog output, and document the expanded release gate.

PM release and audit records

Layer / File(s) Summary
PM release and audit records
.agents/pm/history/*, .agents/pm/issues/*
PM records document shipped fixes, canonical-reader evidence, coverage audits, and an unresolved privacy disclosure blocker.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: 🟡 Moderate · up to 7476c

The change tightens tracker reads and raises runtime compatibility requirements, but the advertised 2026.8.20 host floor is not yet shown compatible with the certified reader, and the packed acceptance matrix does not test Bun at that minimum version. Merge should wait for the compatibility contract and acceptance coverage to be corrected or explicitly accepted.

Sequence Diagram(s)

sequenceDiagram
  participant Extension
  participant pm_cli
  participant SDK
  Extension->>pm_cli: Run canonical pm list --all --json argv
  pm_cli-->>Extension: Return complete-list envelope and receipts
  Extension->>SDK: Certify and inspect the envelope
  SDK-->>Extension: Return validated items or refusal diagnostics
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 5 files. (16 skipped: 16 unsupported.)
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the main change: certifying complete tracker reads for TODO import and export.
Description check ✅ Passed The description directly explains the canonical reader, fail-closed validation, acceptance checks, compatibility updates, and known blockers.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/canonical-certified-list-reader-2026-8-21

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai review exact head 7476c66

@unbraind

Copy link
Copy Markdown
Owner Author

@coderabbitai full review exact head 7476c66

@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review exact head 7476c66

@unbraind

Copy link
Copy Markdown
Owner Author

@sourcery-ai review exact head 7476c66

@unbraind

Copy link
Copy Markdown
Owner Author

@cubic-dev review exact head 7476c66

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@cubic-dev-ai

cubic-dev-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

@cubic-dev review exact head 7476c66

@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews.

To help optimise your usage, you can tune cubic to get the most out of your usage limits:

Learn more →

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

@unbraind I will perform a full review of PR #55 at commit 7476c668513a550ee432e259e5e64b31ef03ff23.

✅ Action performed

Full review finished.

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Reviewer's Guide

Replaces deprecated TODO tracker reads with a single canonical, SDK-certified pm list --all reader; tightens completeness and receipt validation for imports/exports; raises the pm host floor and pins Node/pm-changelog behavior; and adds new acceptance tests plus compatibility guards around the new read path and release automation.

Sequence diagram for canonical pm list --all reader in TODO import and export

sequenceDiagram
  actor User
  participant TodosExtension
  participant pm_cli as pm
  participant pm_sdk as pm_sdk

  User->>TodosExtension: runTodoImport(opts)
  alt opts.upsert
    TodosExtension->>TodosExtension: readCompletePmItems(pmRoot, "the --upsert key index")
    TodosExtension->>pm_cli: spawnSync(pm, ["--pm-path", pmRoot, ...COMPLETE_LIST_COMMAND_ARGUMENTS])
    pm_cli-->>TodosExtension: stdout (list --all envelope)
    TodosExtension->>pm_sdk: inspectCompleteListResult(parsed)
    pm_sdk-->>TodosExtension: findings
    TodosExtension->>pm_sdk: certifyCompleteListResult(record)
    pm_sdk-->>TodosExtension: items
    TodosExtension->>TodosExtension: buildExistingTodoIndex(items)
  end
  TodosExtension-->>User: TodoImportResult

  User->>TodosExtension: todos export (opts)
  TodosExtension->>TodosExtension: fetchPmItems(opts)
  TodosExtension->>TodosExtension: readCompletePmItems(pmRoot, "the TODO export")
  TodosExtension->>pm_cli: spawnSync(pm, ["--pm-path", pmRoot, ...COMPLETE_LIST_COMMAND_ARGUMENTS])
  pm_cli-->>TodosExtension: stdout (list --all envelope)
  TodosExtension->>pm_sdk: inspectCompleteListResult(parsed)
  pm_sdk-->>TodosExtension: findings
  TodosExtension->>pm_sdk: certifyCompleteListResult(record)
  pm_sdk-->>TodosExtension: items
  TodosExtension->>TodosExtension: applyExportOrder(items, sort, reverse)
  TodosExtension-->>User: exported TODO file
Loading

File-Level Changes

Change Details Files
Unify TODO import/export on a canonical, SDK-certified complete pm list --all reader with stricter receipt validation.
  • Replace custom EXIT_CODE constant by importing EXIT_CODE and list-certification helpers from the public pm SDK.
  • Introduce COMPLETE_LIST_COMMAND_ARGUMENTS and a shared readCompletePmItems helper that invokes pm --pm-path ... list --all --json with strict, unbounded output settings.
  • Rewrite readItemsFromListAll and assertListAllComplete to use inspectCompleteListResult/certifyCompleteListResult plus additional checks on omission, read_output, budget, and field types, and wire both upsert indexing and export to this path.
index.ts
Add acceptance and regression tests to lock in canonical reader behavior, packed-host coverage, and compatibility contracts.
  • Add accept-canonical-reader.ts to prove upsert and export each issue exactly one complete corpus read with the expected argv.
  • Add accept-packed.ts to install the packed extension under multiple pm/manager combos, exercise real import/export flows, and assert deprecation-free stderr plus presence of real fixtures.
  • Introduce compatibility-floor.test.ts and expand list-all-completeness.test.ts to cover canonical argv, SDK finding coverage, supplemental gap checks, and item field validation.
  • Add new PM history/issue artifacts documenting coverage and privacy blockers and the implementation item.
scripts/accept-canonical-reader.ts
scripts/accept-packed.ts
test/compatibility-floor.test.ts
test/list-all-completeness.test.ts
.agents/pm/history/pm-todos-irjt.jsonl
.agents/pm/history/pm-todos-ja6k.jsonl
.agents/pm/history/pm-todos-oz1n.jsonl
.agents/pm/history/pm-todos-qpst.jsonl
.agents/pm/history/pm-todos-x5my.jsonl
.agents/pm/issues/pm-todos-irjt.toon
.agents/pm/issues/pm-todos-ja6k.toon
.agents/pm/issues/pm-todos-oz1n.toon
.agents/pm/issues/pm-todos-qpst.toon
.agents/pm/issues/pm-todos-x5my.toon
Tighten host/runtime floors and make changelog generation use the pinned pm host with unbounded output.
  • Raise pm_min_version and peer dependency floor to 2026.8.20 and pin dev pm-cli to 2026.8.21 plus updated pm-changelog/pm-ops versions.
  • Enforce exact Node 22.18.0 as the floor in CI and release workflows and test this contract in compatibility-floor.test.ts.
  • Update npm scripts and release workflow pm-changelog invocations to pass unbounded output-budget/output-limit and to use the local pm binary via --pm-bin, and wire these into the mandatory release:check gate.
manifest.json
package.json
.github/workflows/ci.yml
.github/workflows/release.yml
test/compatibility-floor.test.ts
Document the canonical tracker read policy and expanded release gate in user-facing docs.
  • Describe in README how upsert/export now use a complete, strict pm list --all --json reader with SDK-certified receipts and fail-closed behavior for unverifiable reads.
  • Update README release automation section to explain the new canonical-reader integration acceptance and packed matrix, and to clarify that independent coverage/privacy gates still block publication.
  • Record the new fixes in CHANGELOG under 2026.8.10, linking to the relevant PM issues.
README.md
CHANGELOG.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@unbraind

Copy link
Copy Markdown
Owner Author

Sourcery exact-head response reviewed: the generated guide accurately describes the canonical reader and gate changes and contains no actionable finding. The separate weekly quota response means a full Sourcery review was unavailable; that limitation is recorded and is not approval. References: #55 (comment) and #55 (comment)

@unbraind

Copy link
Copy Markdown
Owner Author

Cubic exact-head review could not start because the free monthly allowance is exhausted until 1 September 2026. This is recorded as unavailable review evidence, not approval: #55 (comment)

@unbraind

Copy link
Copy Markdown
Owner Author

CodeRabbit exact-head full review acknowledgement and in-progress summary reviewed. I will wait for the completed review and address every actionable thread before disposition: #55 (comment) and #55 (comment)

@greptile-apps

greptile-apps Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Greptile Summary

This PR replaces the deprecated tracker readers with a shared, fail-closed complete-corpus reader and expands release acceptance around supported hosts.

  • Validates SDK and supplemental completeness receipts before import or export consumes tracker rows.
  • Adds shell-free Windows resolution of the host-owned pm executable.
  • Exercises packed npm and Bun installations against current and minimum supported pm versions.
  • Runs the complete release gate in CI and tightens release packaging checks.

Confidence Score: 5/5

The reviewed changes appear safe to merge because no blocking failure eligible for this follow-up review remains.

No blocking failure remains.

Important Files Changed

Filename Overview
index.ts Centralizes strict complete-corpus reads, validates receipt and row shapes, and introduces shell-free host CLI execution.
scripts/accept-packed.ts Adds packed npm/Bun acceptance across current and minimum supported pm hosts.
scripts/accept-canonical-reader.ts Adds integration acceptance for the exact canonical reader command and refusal behavior.
.github/workflows/ci.yml Replaces fragmented checks with the complete mandatory release gate on exact Node floor and development lanes.
.github/workflows/release.yml Uses the exact Node floor and passes explicit unbounded read arguments to changelog generation.
package.json Raises the pm compatibility floor, exact-pins host tooling, and adds canonical-reader and packed acceptance gates.

Sequence Diagram

sequenceDiagram
    participant User
    participant Todos as pm-todos
    participant Host as pm CLI
    participant SDK as pm SDK
    User->>Todos: Import --upsert or export
    Todos->>Host: pm list --all (strict, unbounded, full)
    Host-->>Todos: Rows and completeness receipts
    Todos->>SDK: Inspect and certify result
    SDK-->>Todos: Certified rows or findings
    alt Complete and valid
        Todos-->>User: Import/export result
    else Incomplete or malformed
        Todos-->>User: Fail closed with diagnostics
    end
Loading

Reviews (5): Last reviewed commit: "fix(todos): trust isolated pack artifact..." | Re-trigger Greptile

@unbraind

Copy link
Copy Markdown
Owner Author

Greptile exact-head review read and up-voted. It reports no actionable code-correctness findings and explicitly recognizes the separate coverage and privacy blockers. I am retaining those blockers: this PR remains open and must not merge or publish despite the 5/5 code-review confidence. Reference: #55 (comment)

Snapshot the fake-host invocation log after export and after upsert import so the integration gate proves each operation contributes exactly one canonical complete-list read rather than only checking the aggregate count.

Record the strengthened evidence in the implementation PM item.
@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@unbraind

Copy link
Copy Markdown
Owner Author

@coderabbitai full review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@unbraind

Copy link
Copy Markdown
Owner Author

@sourcery-ai review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@unbraind

Copy link
Copy Markdown
Owner Author

@cubic-dev review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@cubic-dev-ai

cubic-dev-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

@cubic-dev review exact head 1e07ebf5c60cdcf50b66ec7a571203841f5509e9

@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews.

To help optimise your usage, you can tune cubic to get the most out of your usage limits:

Learn more →

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

@unbraind I will perform a full review of PR #55 at commit 1e07ebf5c60cdcf50b66ec7a571203841f5509e9.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 53 minutes.

@unbraind

Copy link
Copy Markdown
Owner Author

Correction: @greptileai review exact head 1e07ebf

@unbraind

Copy link
Copy Markdown
Owner Author

Correction: @coderabbitai full review exact head 1e07ebf

@unbraind

Copy link
Copy Markdown
Owner Author

Correction: /gemini review exact head 1e07ebf

@unbraind

Copy link
Copy Markdown
Owner Author

Correction: @sourcery-ai review exact head 1e07ebf

@unbraind

Copy link
Copy Markdown
Owner Author

@cubic-dev review exact head bc31223 after all review fixes

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

@unbraind I will perform a full review of PR #55 at commit bc312238dd1b051b9920dba7c7bf00d0db467abe.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 40 minutes.

@cubic-dev-ai

cubic-dev-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

@cubic-dev review exact head bc31223 after all review fixes

@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews.

To help optimise your usage, you can tune cubic to get the most out of your usage limits:

Learn more →

Set both npm ignore-scripts environment controls around the machine-readable pack command so Node 22 npm cannot run prepare and prefix the JSON receipt with lifecycle output.

Record the expanded-CI failure and exact local four-scenario rerun in the implementation PM item.
@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai review exact head bd0aa0c after the expanded-CI npm JSON fix

@unbraind

Copy link
Copy Markdown
Owner Author

@coderabbitai full review exact head bd0aa0c after the expanded-CI npm JSON fix

@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review exact head bd0aa0c after the expanded-CI npm JSON fix

@unbraind

Copy link
Copy Markdown
Owner Author

@sourcery-ai review exact head bd0aa0c after the expanded-CI npm JSON fix

@unbraind

Copy link
Copy Markdown
Owner Author

@cubic-dev review exact head bd0aa0c after the expanded-CI npm JSON fix

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@cubic-dev-ai

cubic-dev-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

@cubic-dev review exact head bd0aa0c after the expanded-CI npm JSON fix

@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews.

To help optimise your usage, you can tune cubic to get the most out of your usage limits:

Learn more →

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

@unbraind I will perform a full review of PR #55 at commit bd0aa0c154225eee049687c976ce63226e486e74.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 36 minutes.

@unbraind

Copy link
Copy Markdown
Owner Author

The bc31223 exact-head Sourcery, CodeRabbit, and Cubic limitation responses were read and down-voted. Sourcery and Cubic were quota-limited; CodeRabbit was rate-limited after its earlier six actionable threads had already been processed. These are limitations, not approval, and that head has since been superseded by the CI fix. References: #55 (comment) #55 (comment) #55 (comment)

@unbraind

Copy link
Copy Markdown
Owner Author

Final-head bd0aa0c Sourcery and Cubic responses were read and down-voted because weekly and monthly quotas prevented review. Neither is approval. References: #55 (comment) #55 (comment)

Use the freshly created npm pack destination as the authoritative acceptance receipt instead of parsing stdout that npm 10 can contaminate with prepare output. Require exactly one tarball and preserve the four npm/Bun current/minimum installed-host scenarios. Record the exact Node 22 CI evidence in pm-todos-x5my.
@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai review

@unbraind

Copy link
Copy Markdown
Owner Author

/gemini review

@unbraind

Copy link
Copy Markdown
Owner Author

@coderabbitai full review

@unbraind

Copy link
Copy Markdown
Owner Author

@sourcery-ai review

@unbraind

Copy link
Copy Markdown
Owner Author

@cubic-dev review

@sourcery-ai

sourcery-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

Sorry @unbraind, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@cubic-dev-ai

cubic-dev-ai Bot commented Aug 21, 2026

Copy link
Copy Markdown

@cubic-dev review

@unbraind I can't start this review because your workspace has reached its free monthly review limit. cubic has reviewed 61,966 of the 40,000 allowed lines of code this month. Reviews resume on 1 September 2026 (in 11 days). Paid plans include much higher monthly review limits. Upgrade now to resume reviews.

To help optimise your usage, you can tune cubic to get the most out of your usage limits:

Learn more →

@coderabbitai

coderabbitai Bot commented Aug 21, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 29 minutes.

@unbraind

Copy link
Copy Markdown
Owner Author

Acknowledged Sourcery’s exact-head response. It is a weekly quota limitation, not review evidence or approval; the limitation is recorded and the head remains gated on available reviewers plus CI.

@unbraind

Copy link
Copy Markdown
Owner Author

Acknowledged Cubic’s exact-head response. Its monthly quota prevents review until September, so this is explicitly a reviewer-availability limitation rather than approval.

@unbraind

Copy link
Copy Markdown
Owner Author

Acknowledged CodeRabbit’s exact-head response. The fair-use rate limit prevented this requested rerun; the earlier six-thread review was fully addressed, but it does not substitute for exact-head review.

@unbraind

Copy link
Copy Markdown
Owner Author

Exact-head review window closed after 20 minutes for 9f720b6d7e7b4422ab78a8173754f46cf7665ccc. Node 22.18.0 and Node 26 pass the complete release gate; Greptile and Hound pass; all review threads are resolved. CodeRabbit, Sourcery, and Cubic could not perform the requested exact-head review because of capacity limits, and each response was down-voted and acknowledged. Gemini did not respond. Silence, skipped checks, and quota limits are not approvals. PR #55 remains unmerged and unpublished behind pm-todos-qpst, pm-todos-oz1n, and issue #54.

@unbraind
unbraind merged commit 14cfe7b into main Aug 21, 2026
7 checks passed
@unbraind
unbraind deleted the fix/canonical-certified-list-reader-2026-8-21 branch August 21, 2026 23:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant