Fail closed on incomplete merge-driver dependencies and update SDK pins - #114
Conversation
Use the published pm-ops 2026.9.29 launcher so a damaged package directory fails prepare rather than silently skipping Git merge drivers. Add a regression that fails on the prior launcher. Pin CLI SDK 2026.9.29 and changelog 2026.9.25 with the lockfile; correct the statement-coverage claim. pm-ts-starter-n4ee: clean install and direct/PM-linked release gates pass 184 tests; packed npm/Node and Bun extension smoke pass. Keep acceptance blocked on full authored-source four-metric coverage, documentation completeness, the canonical TSX analyzer release, and exact-head reviews. No publication or deployment.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Summary by CodeRabbit
WalkthroughThe update aligns the TypeScript starter’s SDK references and development dependency pins with newer versions. It documents certification criteria and blockers, clarifies coverage reporting, and changes how the prepare script handles incomplete ChangesStarter certification
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix Possibly related PRs
Merge Risk: 🟡 Moderate · up to The updated pins and fail-closed behavior are consistent, but the recorded certification prerequisites remain open. Do not treat this change as a completed SDK certification until those prerequisites are satisfied or explicitly accepted. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 5 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewer's GuideThis PR updates the project to the 2026.9.29 CLI/SDK and pm-ops toolchain, adopts fail-closed merge-driver preparation for incomplete installations with regression coverage, and clarifies coverage documentation and SDK compatibility metadata. Reviewers should also account for the stated unresolved full-source coverage/documentation blockers and the external pm-ops TSX limitation before approval. Sequence diagram for fail-closed merge-driver preparationsequenceDiagram
participant Prepare as prepare-merge-driver.ts
participant Resolver as Node module resolver
participant Filesystem as node_modules filesystem
participant Installer as pm-ops installer
Prepare->>Resolver: resolve(pm-ops/package.json)
alt pm-ops is absent
Resolver-->>Prepare: MODULE_NOT_FOUND
Prepare->>Resolver: resolve.paths(pm-ops/package.json)
Prepare->>Filesystem: lstatSync(node_modules/pm-ops)
alt no incomplete package entry
Prepare-->>Prepare: skip with notice
else incomplete directory or link exists
Prepare->>Installer: spawnSync installer
Installer-->>Prepare: success or failure
end
else pm-ops package is present
Prepare->>Installer: spawnSync installer
Installer-->>Prepare: success or failure
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@greptileai review @coderabbitai full review @sourcery-ai review Please review head 3b2ed68. This candidate remains blocked on the explicitly documented coverage and documentation gaps; passing status contexts are not a substitute for substantive review. |
✅ Action performedFull review finished. |
|
Review reconciliation for 3b2ed68: Sourcery review 5355923264 explicitly reports its free review budget exhausted, so it remains unavailable and is not counted as approval. Its guide comment 5894963710 has an inaccurate diagram: an incomplete package causes the original resolution error to be thrown before spawnSync, rather than starting the installer. The new behavioral test verifies the nonzero failure and absence of the skip notice. Added a negative reaction to that misleading guide; no source change is needed for the diagram. Greptile and CodeRabbit reviews are still running. |
|
|
Acknowledged Greptile summary #114 (comment) for head 3b2ed68: 9 files reviewed, no introduced blocking defect, and existing coverage/documentation/review prerequisites remain merge blockers. Helpful summary upvoted. Additional isolated acceptance: two branches updating one synthetic item retained both notes, priority and description; trusted receipt reconciliation applied once, strict health passed with zero warnings, and all three original history record hashes survived. This is one bounded branch-merge case, not capacity or comprehensive concurrency certification. |
|
Final review reconciliation for head 3b2ed68: CodeRabbit comment 5894962059 (updated 2026-09-29T17:14:45Z) reports no actionable comments for this exact head; acknowledged and upvoted. Its lockfile exclusion and skipped diff-only docstring check are explicitly not full lockfile or documentation approval. The lockfile diff was inspected locally and clean npm ci passed. Greptile completed the same head with no new defect. All inline-comment pages are empty. Sourcery remains unavailable under its free budget; cubic skipped. Node 22/26 and CodeQL passed. Coverage/documentation/TSX prerequisites remain unresolved, so this PR stays unmerged and unreleased. |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
All reported issues were addressed across 9 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
|
Feedback dispositions at The incomplete pm-ops fail-closed fix remains verified by the PM-linked launcher suite. Release:check passes 184/184, zero skips, configured four-source L/B/F 100/100/100, strict health and tracked output equality. Whole-source coverage and TSX documentation remain incomplete under the existing pm-ops#132 dependency; no merge or publication. |
|
@coderabbitai review |
|
|
Feedback dispositions at Manifest tracking omission is corrected. Canonical non-ENOENT diagnostic repair is deferred to pm-ops publication under pm-ts-starter-rku9; the observed launcher still fails closed. Coverage, TSX/doc scope and required review prerequisites remain open.
|
There was a problem hiding this comment.
All reported issues were addressed across 4 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
|
Feedback dispositions at Manifest link fixed; canonical ENOTDIR diagnostic follow-up pm-ts-starter-rku9 remains open. Full gate 184/184 passed; TSX, coverage/documentation and quota-limited reviews remain blockers.
|
|
@coderabbitai review |
Rate Limit Exceeded
|
|
Feedback dispositions at Current durable PM links now reference repository files/tests only. Historical diagnostic is preserved as prose with portable reproduction steps; no claim of canonical masking repair. Coverage, TSX/documentation and review prerequisites remain blocking. |
|
Feedback dispositions at Third round complete: disposable probe removed from durable links; portable repository tests remain. Historical diagnostic and canonical follow-up pm-ts-starter-rku9 retained. Final Node 22/26, Greptile, Hound and Cubic checks passed; CodeRabbit chat/review quota and Sourcery skip remain missing substantive reviews. No further review request on this head.
|
An incomplete pm-ops directory previously made npm prepare exit successfully without installing the merge drivers. This change adopts the released canonical launcher and adds a regression that fails against the previous implementation.
Pins CLI/SDK and pm-ops to 2026.9.29 and pm-changelog to 2026.9.25 with a reproducible lockfile. The runtime compatibility floor stays 2026.8.7. README and manifest describe the tested SDK; the coverage documentation no longer equates line and statement coverage.
Owner: pm-ts-starter-n4ee.
Validation:
Merge blockers: full-source coverage and full declaration documentation remain incomplete; published pm-ops still omits TSX, tracked by pm-ops #132. Exact-head CI and substantive configured reviews must complete. No merge, release or deployment is requested while these blockers remain.
Scope is development tooling and its regression. The CLI brings its own transitive development dependencies; no telemetry configuration or hosted user data changes. Rollback is reverting this commit. No production migration is needed.
Summary by Sourcery
Fail closed on incomplete pm-ops installations and align the project’s development tooling with the latest tested SDK pins.
Bug Fixes:
Enhancements:
Build:
Documentation:
Summary by cubic
Fixes
npm prepareso an incompletepm-opsdirectory now fails the build instead of silently skipping Git merge-driver installation, with a regression test that fails against the previous launcher. Pins CLI/SDK andpm-opsto 2026.9.29 andpm-changelogto 2026.9.25.pm-opslocations so a broken install without a resolvablepackage.jsonalso fails closed.Written for commit a903ec8. Summary will update on new commits.