Skip to content

Fail closed on incomplete merge-driver dependencies and update SDK pins - #114

Merged
unbraind merged 4 commits into
mainfrom
chore/pm-ts-starter-cli-sdk-2026-9-29
Oct 3, 2026
Merged

unbraind merged 4 commits into
mainfrom
chore/pm-ts-starter-cli-sdk-2026-9-29

Conversation

@unbraind

@unbraind unbraind commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

An incomplete pm-ops directory previously made npm prepare exit successfully without installing the merge drivers. This change adopts the released canonical launcher and adds a regression that fails against the previous implementation.

Pins CLI/SDK and pm-ops to 2026.9.29 and pm-changelog to 2026.9.25 with a reproducible lockfile. The runtime compatibility floor stays 2026.8.7. README and manifest describe the tested SDK; the coverage documentation no longer equates line and statement coverage.

Owner: pm-ts-starter-n4ee.

Validation:

  • Clean npm ci, direct and PM-linked release:check: 184 tests pass, no skips on Linux.
  • Typecheck, lint, duplication (0%), production audit (zero findings), changelog and release-attestation checks pass.
  • Strict PM health and validate pass. Documentation gate reports 9 files / 20 declarations under its existing policy.
  • Coverage reports 100% lines, branches, functions across four measured files. Statements are not independently measured and the denominator omits other authored scripts. This does not satisfy full-source four-metric coverage.
  • Nine-file packed allowlist inspected. Clean npm/Node and Bun consumers pass project initialization, extension installation, hello, native list and info. No standalone bin is declared.

Merge blockers: full-source coverage and full declaration documentation remain incomplete; published pm-ops still omits TSX, tracked by pm-ops #132. Exact-head CI and substantive configured reviews must complete. No merge, release or deployment is requested while these blockers remain.

Scope is development tooling and its regression. The CLI brings its own transitive development dependencies; no telemetry configuration or hosted user data changes. Rollback is reverting this commit. No production migration is needed.

Summary by Sourcery

Fail closed on incomplete pm-ops installations and align the project’s development tooling with the latest tested SDK pins.

Bug Fixes:

  • Make npm prepare fail when pm-ops is present but incomplete, preventing merge-driver installation from being silently skipped.
  • Add regression coverage for incomplete pm-ops installations.

Enhancements:

  • Clarify that statement coverage is not independently measured by the coverage reporter.

Build:

  • Update the reproducible dependency lockfile and pin the CLI/SDK and pm-ops to 2026.9.29, with pm-changelog at 2026.9.25.

Documentation:

  • Update the README and manifest to document the tested SDK version while retaining the 2026.8.7 runtime compatibility floor and noting the TSX documentation limitation.

Summary by cubic

Fixes npm prepare so an incomplete pm-ops directory now fails the build instead of silently skipping Git merge-driver installation, with a regression test that fails against the previous launcher. Pins CLI/SDK and pm-ops to 2026.9.29 and pm-changelog to 2026.9.25.

  • The launcher probes installed pm-ops locations so a broken install without a resolvable package.json also fails closed.
  • A follow-up tracks consuming pm-ops' canonical repair of the session-only ENOTDIR diagnostic; the diagnostic is historical evidence, not a durable test.
  • Corrects the coverage-gate comment: passing line, branch, and function thresholds does not establish independent statement coverage.
  • README and manifest state the checked SDK (2026.9.29) and keep the runtime compatibility floor at 2026.8.7.
  • The documentation analyzer still omits TSX; the canonical fix is tracked in pm-ops #132.

Written for commit a903ec8. Summary will update on new commits.

Review in cubic

Use the published pm-ops 2026.9.29 launcher so a damaged package directory fails prepare rather than silently skipping Git merge drivers. Add a regression that fails on the prior launcher. Pin CLI SDK 2026.9.29 and changelog 2026.9.25 with the lockfile; correct the statement-coverage claim.

pm-ts-starter-n4ee: clean install and direct/PM-linked release gates pass 184 tests; packed npm/Node and Bun extension smoke pass. Keep acceptance blocked on full authored-source four-metric coverage, documentation completeness, the canonical TSX analyzer release, and exact-head reviews. No publication or deployment.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @unbraind, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 hours and 31 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f35e8e31-e6c8-4905-b7df-906b0cd7a93e

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a0452501-b5f5-4df1-a1b7-7542058cc228
📥 Commits

Reviewing files that changed from the base of the PR and between 3b2ed68 and 68202a8.

📒 Files selected for processing (2)
  • .agents/pm/chores/pm-ts-starter-n4ee.toon
  • .agents/pm/history/pm-ts-starter-n4ee.jsonl

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Documentation
    • Updated the TypeScript reference extension’s documentation to reflect its current CLI compatibility, development requirements, and known TSX documentation-analysis limitation.
  • Bug Fixes
    • Installation now fails with an error when an existing but incomplete pm-ops installation is detected, rather than skipping setup.
  • Chores
    • Updated the extension’s stated SDK compatibility version and development tooling versions. Other listed capabilities and examples remain unchanged.
    • Clarified that passing line, branch, and function coverage thresholds does not establish statement coverage.

Walkthrough

The update aligns the TypeScript starter’s SDK references and development dependency pins with newer versions. It documents certification criteria and blockers, clarifies coverage reporting, and changes how the prepare script handles incomplete pm-ops installations.

Changes

Starter certification

Layer / File(s) Summary
SDK pins and certification record
.agents/pm/chores/*, .agents/pm/history/*, README.md, manifest.json, package.json, scripts/coverage-gate.ts
The README and manifest identify pm-cli 2026.9.29; the README retains the runtime compatibility floor of 2026.8.7. Development dependency pins are updated. The coverage comment distinguishes statement coverage from Node’s reported metrics. The chore and history record certification criteria, validation notes, and outstanding blockers.
Fail-closed pm-ops detection
scripts/prepare-merge-driver.ts, test/prepare-merge-driver.test.ts
When resolving pm-ops/package.json fails with MODULE_NOT_FOUND, the script checks package search paths for a pm-ops filesystem entry. A present entry is not treated as an absent package. A test checks that an incomplete installation fails without the skip notice.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix

Possibly related PRs

  • unbraind/pm-ts-starter#56: Introduced the prepare-merge-driver launcher and the initial pm CLI/SDK dependency update. This PR updates that launcher and the same dependency set.

Merge Risk: 🟡 Moderate · up to 68202

The updated pins and fail-closed behavior are consistent, but the recorded certification prerequisites remain open. Do not treat this change as a completed SDK certification until those prerequisites are satisfied or explicitly accepted.

Architecture Summary

Architecture risk: 🔵 Low · up to 68202

The change affects 5 systems.

Changed systems: scripts, manifest.json, package.json, README.md, test

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — scripts (service) was modified; 2 changed files map to changed impact.
  • observed — manifest.json (service) was modified; 1 changed file maps to changed impact.
  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — README.md (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in README.md: The README changes the SDK alignment date from 2026.8.7 to 2026.9.29 and adds the unchanged runtime compatibility floor of 2026.8.7.
  • observed — Modified behavior in README.md: The README adds development dependency versions, states that the prepare hook rejects incomplete pm-ops installations, and documents the analyzer’s TSX omission and the tracked repair.
  • observed — Modified behavior in manifest.json: The description changes the SDK version identified as the reference from pm-cli 2026.7.6 to 2026.9.29; the remaining description is unchanged.
  • observed — Modified behavior in package.json: Updated the pinned versions of @unbrained/pm-cli and pm-ops from 2026.9.23 to 2026.9.29, and pm-changelog from 2026.9.23 to 2026.9.25; the other dependencies in this range are unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the two main changes: failing closed on incomplete merge-driver dependencies and updating SDK pins.
Description check ✅ Passed The description directly explains the merge-driver fix, regression test, dependency updates, documentation changes, validation results, and remaining blockers.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 3…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR updates the project to the 2026.9.29 CLI/SDK and pm-ops toolchain, adopts fail-closed merge-driver preparation for incomplete installations with regression coverage, and clarifies coverage documentation and SDK compatibility metadata. Reviewers should also account for the stated unresolved full-source coverage/documentation blockers and the external pm-ops TSX limitation before approval.

Sequence diagram for fail-closed merge-driver preparation

sequenceDiagram
    participant Prepare as prepare-merge-driver.ts
    participant Resolver as Node module resolver
    participant Filesystem as node_modules filesystem
    participant Installer as pm-ops installer

    Prepare->>Resolver: resolve(pm-ops/package.json)
    alt pm-ops is absent
        Resolver-->>Prepare: MODULE_NOT_FOUND
        Prepare->>Resolver: resolve.paths(pm-ops/package.json)
        Prepare->>Filesystem: lstatSync(node_modules/pm-ops)
        alt no incomplete package entry
            Prepare-->>Prepare: skip with notice
        else incomplete directory or link exists
            Prepare->>Installer: spawnSync installer
            Installer-->>Prepare: success or failure
        end
    else pm-ops package is present
        Prepare->>Installer: spawnSync installer
        Installer-->>Prepare: success or failure
    end
Loading

File-Level Changes

Change Details Files
Adopt the canonical merge-driver preparation logic and fail closed when pm-ops is present but incomplete.
  • Detect a broken or package-metadata-free pm-ops directory as present rather than treating it as absent.
  • Preserve the optional skip only for a genuinely missing pm-ops package; propagate resolution and installer failures.
  • Add a regression test covering an incomplete pm-ops directory.
scripts/prepare-merge-driver.ts
test/prepare-merge-driver.test.ts
Update development tooling pins and lockfile reproducibility for the tested SDK release.
  • Pin pm-cli/SDK and pm-ops to 2026.9.29.
  • Pin pm-changelog to 2026.9.25 and refresh the lockfile.
  • Document the tested SDK, runtime compatibility floor, prepare-hook behavior, and known TSX documentation limitation.
package.json
package-lock.json
README.md
manifest.json
Clarify coverage reporting so line coverage is not presented as statement coverage.
  • State that the Node reporter measures lines, branches, and functions without independently measuring statements.
  • Retain the existing three-metric threshold policy while explicitly documenting its limitation.
scripts/coverage-gate.ts
Record the pull-request ownership and automation metadata.
  • Add the PM chore owner record and execution history.
.agents/pm/chores/pm-ts-starter-n4ee.toon
.agents/pm/history/pm-ts-starter-n4ee.jsonl

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@unbraind

Copy link
Copy Markdown
Owner Author

@greptileai review

@coderabbitai full review

@sourcery-ai review

Please review head 3b2ed68. This candidate remains blocked on the explicitly documented coverage and documentation gaps; passing status contexts are not a substitute for substantive review.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@unbraind

Copy link
Copy Markdown
Owner Author

Review reconciliation for 3b2ed68: Sourcery review 5355923264 explicitly reports its free review budget exhausted, so it remains unavailable and is not counted as approval. Its guide comment 5894963710 has an inaccurate diagram: an incomplete package causes the original resolution error to be thrown before spawnSync, rather than starting the installer. The new behavioral test verifies the nonzero failure and absence of the skip notice. Added a negative reaction to that misleading guide; no source change is needed for the diagram. Greptile and CodeRabbit reviews are still running.

@greptile-apps

greptile-apps Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates SDK and build-tool dependencies with new merge-driver validation.

No new blocking issue was established, and the previously reported machine-specific test link has been removed.

Summary

The PR updates development-tool pins and documentation and changes the prepare launcher to fail when a pm-ops installation is incomplete.

  • Adds a regression test for an incomplete pm-ops directory.
  • Removes a machine-specific diagnostic from the task’s current test and file links while retaining its history.

Reviews (4) · Last reviewed commit: "docs(ts-starter): keep disposable diagno..."

@unbraind

Copy link
Copy Markdown
Owner Author

Acknowledged Greptile summary #114 (comment) for head 3b2ed68: 9 files reviewed, no introduced blocking defect, and existing coverage/documentation/review prerequisites remain merge blockers. Helpful summary upvoted. Additional isolated acceptance: two branches updating one synthetic item retained both notes, priority and description; trusted receipt reconciliation applied once, strict health passed with zero warnings, and all three original history record hashes survived. This is one bounded branch-merge case, not capacity or comprehensive concurrency certification.

@unbraind

Copy link
Copy Markdown
Owner Author

Final review reconciliation for head 3b2ed68: CodeRabbit comment 5894962059 (updated 2026-09-29T17:14:45Z) reports no actionable comments for this exact head; acknowledged and upvoted. Its lockfile exclusion and skipped diff-only docstring check are explicitly not full lockfile or documentation approval. The lockfile diff was inspected locally and clean npm ci passed. Greptile completed the same head with no new defect. All inline-comment pages are empty. Sourcery remains unavailable under its free budget; cubic skipped. Node 22/26 and CodeQL passed. Coverage/documentation/TSX prerequisites remain unresolved, so this PR stays unmerged and unreleased.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 9 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread scripts/prepare-merge-driver.ts
Comment thread .agents/pm/chores/pm-ts-starter-n4ee.toon
@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Feedback dispositions at 68202a8:

The incomplete pm-ops fail-closed fix remains verified by the PM-linked launcher suite. Release:check passes 184/184, zero skips, configured four-source L/B/F 100/100/100, strict health and tracked output equality. Whole-source coverage and TSX documentation remain incomplete under the existing pm-ops#132 dependency; no merge or publication.

  • Comment 5894971019: Acknowledged the review completion receipt. Checked head 68202a8.

  • Comment 5962438285: Acknowledged the review completion receipt. Checked head 68202a8.

  • Review 5355923264: This is a quota or skipped-review notice, not a substantive review or approval. Checked head 68202a8.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Feedback dispositions at f976aef:

Manifest tracking omission is corrected. Canonical non-ENOENT diagnostic repair is deferred to pm-ops publication under pm-ts-starter-rku9; the observed launcher still fails closed. Coverage, TSX/doc scope and required review prerequisites remain open.

  • Review 5397459742: Review findings are accounted for by the existing inline replies and the current verification below. Checked head f976aef.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 4 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread .agents/pm/chores/pm-ts-starter-n4ee.toon Outdated
Comment thread .agents/pm/chores/pm-ts-starter-n4ee.toon Outdated
@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Feedback dispositions at f976aef:

Manifest link fixed; canonical ENOTDIR diagnostic follow-up pm-ts-starter-rku9 remains open. Full gate 184/184 passed; TSX, coverage/documentation and quota-limited reviews remain blockers.

  • Comment 5962722988: This is a quota or skipped-review notice, not a substantive review or approval. Checked head f976aef.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review
@greptileai
/gemini review

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@unbraind have exceeded the limit for the number of chat messages per hour. Please wait 25 minutes and 9 seconds before sending another message.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Feedback dispositions at a903ec8:

Current durable PM links now reference repository files/tests only. Historical diagnostic is preserved as prose with portable reproduction steps; no claim of canonical masking repair. Coverage, TSX/documentation and review prerequisites remain blocking.

  • Review 5397620766: Review findings are accounted for by the existing inline replies and the current verification below. Checked head a903ec8.

  • Review 5397622215: This review record contains no written finding; it does not by itself establish substantive review. Checked head a903ec8.

@unbraind

unbraind commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Feedback dispositions at a903ec8:

Third round complete: disposable probe removed from durable links; portable repository tests remain. Historical diagnostic and canonical follow-up pm-ts-starter-rku9 retained. Final Node 22/26, Greptile, Hound and Cubic checks passed; CodeRabbit chat/review quota and Sourcery skip remain missing substantive reviews. No further review request on this head.

  • Comment 5962774994: This is a quota or skipped-review notice, not a substantive review or approval. Checked head a903ec8.

@unbraind
unbraind merged commit d1c6371 into main Oct 3, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant