Skip to content

test(ui): add AGPL-3.0 badge to footer to validate visual-capture pipeline - #4180

Closed
JSONbored wants to merge 2 commits into
mainfrom
visual-capture-test-gittensory
Closed

test(ui): add AGPL-3.0 badge to footer to validate visual-capture pipeline#4180
JSONbored wants to merge 2 commits into
mainfrom
visual-capture-test-gittensory

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Summary

  • This is a deliberate test PR, not a feature. It adds a small, real, visible "AGPL-3.0" badge to the site footer (reusing the existing Badge UI component, variant="outline") purely to validate the newly-activated before/after visual-capture pipeline end-to-end on a real gittensory-ui PR.
  • Verified locally in a dev server first (preview_eval/DOM inspection confirmed the badge renders with the correct classes and a real, visible bounding box).
  • Expecting: the bot's review comment to show a before/after table (production vs. this PR's preview deploy) with the badge visible in the "after" shot at both desktop and mobile viewports.

Scope

  • The PR title follows type(scope): short summary Conventional Commit format.
  • This PR is focused (one file, one small visible change) and does not mix unrelated backend/UI/MCP/docs/dependency/deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves -- N/A, deliberate test PR, no feature being solved.

Validation

  • git diff --check
  • npm --workspace @jsonbored/gittensory-ui run typecheck
  • npm --workspace @jsonbored/gittensory-ui run lint (0 errors; pre-existing warnings elsewhere untouched)
  • npm --workspace @jsonbored/gittensory-ui run format (no changes needed)
  • npm run ui:build
  • Manually verified in a local dev server via DOM inspection (real bounding box, correct Badge classes)
  • npm run test:coverage -- N/A, apps/** is not measured by Codecov and no src/** logic changed.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, PATs, private keys, trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized and low-noise.
  • Auth/cookie/CORS/GitHub App/Cloudflare/session changes include negative-path tests. -- N/A, no such changes.
  • API/OpenAPI/MCP behavior is updated and tested where needed. -- N/A, no such surface touched.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs. -- N/A.

UI Evidence

Intentionally left blank -- this PR's entire purpose is to let the bot's own visual-capture pipeline produce that evidence automatically. See the gittensory-orb review comment for the actual before/after table once it renders.

Notes

  • This PR is expected to be held for manual review regardless of CI outcome (apps/gittensory-ui/src/components/** is in this repo's hardGuardrailGlobs) -- that's expected and fine, this isn't meant to auto-merge.

…eline

Deliberate small, real, visible test change -- not a feature PR. Used to
confirm the newly-activated before/after screenshot capture pipeline
renders correctly end-to-end on a real gittensory-ui PR (production
before-shot vs. this PR's preview-deploy after-shot).
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 8, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
gittensory-ui 59275be Commit Preview URL

Branch Preview URL
Jul 08 2026, 07:09 PM

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 8, 2026
@loopover-orb

loopover-orb Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Warning

🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨

⏸️ Gittensory review result - manual review recommended

Review updated: 2026-07-08 20:32:30 UTC

1 file · 2 blockers · readiness 93/100 · CI green · clean

⏸️ Suggested Action - Manual Review

  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
  • Maintainer requires a linked issue — Link the relevant issue (for example Closes #123) before opening the PR.
Nits — 1 non-blocking
  • Code changes lack test evidence — Add focused regression tests or explain why existing coverage is sufficient.

Concerns raised — review before merging

  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
  • Maintainer requires a linked issue — Link the relevant issue (for example Closes #123) before opening the PR.
Signal Result Evidence
Code review ❌ 2 blockers No AI review summary
Linked issue ⚠️ Missing No linked issue or no-issue rationale found.
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (no linked issue context).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 52 registered-repo PR(s), 43 merged, 497 issue(s).
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 52 PR(s), 497 issue(s).
Gate result ❌ Blocking Repo-configured hard blocker found.
Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: Python, TypeScript, JavaScript, Ruby, Go, Kotlin, MDX, Shell
  • Official Gittensor activity: 52 PR(s), 497 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Treat this as maintainer-lane context rather than normal contributor-lane activity.
  • Explain no-issue PR.
  • Link the issue being solved, or explicitly explain why this is a no-issue PR.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
Visual preview
Route Viewport Before (production) After (this PR's preview) Diff
/ desktop after /
/ mobile after / (mobile)

Click any thumbnail to open the full-size screenshot. Before = production · After = this PR's preview deploy.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

  • Re-run Gittensory review

…cket

Empty commit to force a fresh gittensory-orb capture cycle after wiring
edge-us-01 to REVIEW_AUDIT_S3_PUBLIC_URL, to confirm screenshot URLs now
point at the public bucket instead of the Tailscale-only origin.
@JSONbored JSONbored closed this Jul 8, 2026
JSONbored added a commit that referenced this pull request Jul 16, 2026
…ntry can see them

Advances #6325 -- covers the alerting half only; the issue stays open
until the live PUBLIC_API_ORIGIN misconfiguration itself is corrected.

sqliteBackupAdvisory and publicOriginReachabilityAdvisory both log via
console.warn with the explicit intent to "warn LOUDLY" -- but
installStructuredLogForwarding (wired inside initSentry) only intercepts
console.log (forwarded only with an explicit level:error/fatal) and
console.error (always forwarded); console.warn is never wrapped at all.
Both advisories were therefore silently unreachable by Sentry regardless
of whether Sentry was configured or the advisory condition was true.

Confirmed live: the self-hosted instance reviewing JSONbored's own repos
has PUBLIC_API_ORIGIN set to a bare Tailscale hostname
(edge-nl-01.raccoon-bushi.ts.net) with no Funnel serve/funnel config
enabled on that node (verified via `tailscale funnel status` / `tailscale
serve status`, both "No serve config") -- genuinely, provably unreachable
from GitHub's public image-fetching servers, not a false-positive Funnel
case. publicOriginReachabilityAdvisory exists specifically to catch this
(#4180), and PUBLIC_ORIGIN_ACKNOWLEDGED is unset on that
box, so the advisory has been firing at every boot the whole time --
just never reaching anyone, because of this bug.

Switches both advisories from console.warn to console.error. `level:
"warn"` stays in the JSON payload, so this only changes which console
method reaches the Sentry forwarder, not the reported severity
(forwardStructuredLogToSentry still maps it to Sentry's "warning" level,
not "error").

emptyConfigDirAdvisory has the identical bug but fires BEFORE initSentry
in the boot sequence, so the same one-line fix doesn't help it -- that
needs the Sentry-init call moved earlier, a distinct and slightly riskier
change, tracked separately rather than scope-creeping into this PR.

The live PUBLIC_API_ORIGIN value itself is unchanged by this PR -- fixing
the actual misconfiguration (pointing it at a genuinely public origin, or
enabling Funnel) is an infra decision for the operator, not a code change.
@JSONbored
JSONbored deleted the visual-capture-test-gittensory branch July 19, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. manual-review Gittensor contributor context

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant