fix(rules): anchor workflow_audit paths; accept 0-AI-MANIFEST.deed - #888
hyperpolymath wants to merge 4 commits into
Conversation
workflow_audit findings carried the bare basename (`ci.yml`) as their file, so the uploaded SARIF did not anchor to a real path and `.hypatia-ignore` entries written as `.github/workflows/x.yml` could never match. Qualify at the CLI normalisation boundary; WorkflowAudit keeps basenames internally for its missing-workflow name checks. root_hygiene and rsr_conformance 2.3.1 now accept 0-AI-MANIFEST.deed (the DEED-manifest spelling panoply ships) as the manifest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
|
| Layer / File(s) | Summary |
|---|---|
Qualify workflow finding paths lib/hypatia/cli.ex, test/workflow_audit_path_test.exs |
The workflow audit qualifies bare filenames under .github/workflows, preserves paths that already contain /, and handles list-valued inputs. Tests cover the pipeline and helper cases. |
Manifest recognition
| Layer / File(s) | Summary |
|---|---|
Accept the deed manifest lib/rules/root_hygiene.ex, lib/rules/rsr_conformance.ex, test/root_hygiene_test.exs |
The root hygiene and conformance checks accept 0-AI-MANIFEST.deed as an alternative. Tests cover a present deed manifest and the missing-manifest finding when neither spelling is supplied. |
Priority: ⬇️ Low
Estimated code review effort: 2 (Simple) | ~10 minutes
Change: Bug fix
Merge Risk: ⚪ Minimal · up to 2364b
Workflow filenames are qualified and both manifest checks accept the deed spelling. No actionable merge-blocking issue remains; the existing multi-file formatting limitation can be addressed separately.
Security Architecture Review
Security architecture risk: ⚪ Minimal · up to 2364b
The changes correct workflow finding locations and recognize an alternative manifest filename. The inspected changes do not add file-access authority, weaken suppression policy, or remove existing content validation.
Retained concerns
No architecture-level concerns identified.
Security review details
Security Blast Radius
- inferred — The introduced effects are bounded to finding identity, suppression matching, and manifest-presence verdicts for the repository being evaluated. The inspected changes introduce no additional credential, execution, persistence, or cross-service authority.
Trust Boundaries and Controls
- observed — Qualified paths now reach the unchanged suppression predicate, enabling repository-relative ignore entries to match. Existing default and repository-local exemption sources remain in place; the PR does not add a new suppression authority or alter banned-language special handling.
🚥 Pre-merge checks | ✅ 4 | ❌ 1
❌ Failed checks (1 warning)
| Check name | Status | Explanation | Resolution |
|---|---|---|---|
| Docstring Coverage | Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 5 files. | Write docstrings for the functions missing them to satisfy the coverage threshold. |
✅ Passed checks (4 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly summarises the two main changes: anchoring workflow_audit paths and accepting 0-AI-MANIFEST.deed. |
| Description check | ✅ Passed | The description directly explains the workflow path fix, manifest support, and validation results. It is relevant to the changeset. |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
- Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
- Commit to this branch
- Create a new PR
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
- Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
Autopilot is currently an internal CodeRabbit preview.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks each workflow trail,
And tucks bare names where paths belong.
A deed can stand beside the manifest,
Two checks now recognise it too.
The tests hop through each changed case,
Then rest beneath the moon.
Comment @coderabbitai help to get the list of available commands.
|
Autopilot could not be updated. Open Coding to check access and billing. |
|
🤖 Completed: Fix pre-merge checks in PR #888 — View commit |
Summary
workflow_auditfindings reported a bare workflow file name (ci.yml), so SARIF locations and.hypatia-ignoreentries such asworkflow_audit/unpinned_action:.github/workflows/release.ymlnever matched. Names are now qualified to.github/workflows/<name>in the CLI normaliser (qualify_workflow_file/1).0-AI-MANIFEST.deedas the manifest, alongside0-AI-MANIFEST.a2ml(owner ruling, 2026-09-30 sweep).Tests
test/workflow_audit_path_test.exs(pipeline plus helper cases); 2 new root-hygiene cases.mix testgives 1703 tests, 0 failures;mix format --check-formattedis clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65