Placeholder the Bare-Tag Pin Example and Gate the Hub on Version Literals - #1962
Conversation
…rals GOVERNANCE.md "Workflow YAML Conventions" named a three-part version as its bare-tag pin example, which "Documentation Style Conventions" forbids in the four instruction documents. The example now reads `# X.Y.Z`. The audit's version-literal scan caught it on the hub's own run, but nothing ran that scan at pull request time, so the literal merged and carried. The pattern and file set move to spec/validate.py, which spec/audit.py already imports, and validate.py now scans the hub's four instruction documents whole, verbatim sections included, so the next one fails the pull request instead. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: ptr727/ProjectTemplate/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe validator now scans four instruction documents for three-part versions and commit SHAs, then adds matches to validation errors. The audit module reuses the validator’s scan definitions. The governance example now uses a placeholder format for bare version tags. ChangesVersion Literal Validation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to The version-literal gate and governance placeholder are ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new check is designed to reject version and commit literals before hub changes merge. The reviewed paths show no new privilege or trust-boundary expansion, but repository-level merge enforcement could not be verified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## develop #1962 +/- ##
==========================================
Coverage ? 55.41%
==========================================
Files ? 16
Lines ? 7247
Branches ? 0
==========================================
Hits ? 4016
Misses ? 3231
Partials ? 0
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is narrow, well-covered by new tests, and introduces only a minor documentation clarity nit.
Review effort: Lite
Findings: 1
What changed in this PR
This pull request updates the hub’s workflow-pinning guidance to avoid hard-coded version literals, and adds a spec/validate.py gate that rejects three-part versions and commit SHAs in the hub’s core instruction documents so the issue is caught at PR time rather than only during audits.
Changes:
- Updates
GOVERNANCE.md“Workflow YAML Conventions” action-pinning example to use a placeholder bare tag format instead of a concrete version. - Moves version-literal scanning patterns into
spec/validate.pyand addsversion_literal_errors()to enforce the hub’s instruction-document constraint. - Adds tests covering rejection inside a verbatim section, acceptance of placeholders, and cleanliness of the hub’s own instruction docs.
| File | Description |
|---|---|
| tests/test_spec_validate.py | Adds targeted tests for the new version/SHA literal gate. |
| spec/validate.py | Defines the version/SHA literal regex and enforces it via a new validation error list. |
| spec/audit.py | Aliases the moved constants from spec/validate.py to avoid duplication/circular imports. |
| GOVERNANCE.md | Replaces the concrete bare-tag example with a placeholder pattern in the pinning rule text. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The documentation change removes the offending literal, the new validation is correctly integrated into the existing spec gate, and tests cover both the rule behavior and the hub’s own documents.
Review effort: Lite
Findings: None
Resolved since last review (1)
… and Setup Tooling (#2000) ## Summary Promotes develop to main, carrying the 16 pull requests merged to develop since #1943. - **Wait-loop guard (requirement 7):** [#1999](#1999) credits a comparison bound only inside a `[`, `[[`, or `test` invocation, and [#1996](#1996) reconciles the requirement's README count and diagram with its hook. - **Registry:** [#1994](#1994) and [#1976](#1976) record Vantage-Config's line endings and description. - **Scripts and tooling:** - [#1988](#1988) and [#1972](#1972) harden `ruleset_id()`. - [#1974](#1974) and [#1949](#1949) fix `pr_review.py` `reply --match` and `wait`. - [#1969](#1969), [#1964](#1964), [#1954](#1954) and [#1951](#1951) fix host-setup tool shadowing, shims, hook ownership and dpkg ownership checks. - **Gates and audit:** - [#1980](#1980) triages a path collision. - [#1967](#1967) and [#1962](#1962) tighten sha-pin and version-literal checks. - [#1956](#1956) keeps a folded `if:` visible to the interface audit. Closes #1636 Closes #1639 Closes #1948 Closes #1971 Closes #1718 Closes #1934 Closes #1877 Closes #1880 Closes #1865 Closes #1889 Closes #1966 Closes #1906 Closes #1935 Closes #1901 Closes #1905 Closes #1866 Closes #1897 🤖 Generated with [Claude Code](https://claude.com/claude-code)

Summary
GOVERNANCE.md"Workflow YAML Conventions", Action pinning bullet: the bare-tag example is now the placeholder# X.Y.Zinstead of a three-part version, per "Documentation Style Conventions".spec/audit.pyintospec/validate.py, sincespec/audit.pyalready importsvalidateand the reverse import would be circular.spec/audit.pynow aliases them.spec/validate.pygainsversion_literal_errors, which scans the hub'sAGENTS.md,GOVERNANCE.md,CODESTYLE.md, andWORKFLOW.mdwhole, verbatim sections included, so a literal fails the hub's pull request gate instead of merging and carrying. Before this change only the audit's hub run reported it, and that is not a pull request gate.spec/files.jsondeclares verbatim is rejected, a placeholder is accepted, and the hub's own four documents are clean. The hub-tree test failed on the old text.The
commentslabel is here because the moved comment lines count as added inspec/validate.py.Closes on promotion: #1935
🤖 Generated with Claude Code
Summary by CodeRabbit
vprefix.