refactor(advisories): add structured registry foundation - #6945
Conversation
Signed-off-by: Ho Lim <subhoya@gmail.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughAdds shared advisory contracts, immutable registry validation, a runner supporting filtering, skipping, resume caching, suppression, and metadata checks, plus console/JSON presentation and blocking enforcement with Vitest coverage. ChangesAdvisory Pipeline
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant Caller
participant runAdvisories
participant AdvisoryCheck
participant CachedResults
Caller->>runAdvisories: provide checks, context, and options
runAdvisories->>AdvisoryCheck: filter by phase and skipIf
runAdvisories->>CachedResults: read resume-safe cached result
CachedResults-->>runAdvisories: return cached advisory or null
runAdvisories->>AdvisoryCheck: execute eligible check when cache is not reused
AdvisoryCheck-->>runAdvisories: return advisory or null
runAdvisories-->>Caller: return advisories, results, and execution IDs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/advisories/registry.ts`:
- Around line 18-19: Add a GitHub issue or pull-request reference alongside the
ADVISORY_CHECKS declaration in the registry, linking the unresolved advisory
registration migration work. Keep the existing registry initialization and
comment behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 1fd35b93-35e9-4f56-95a2-a82b4502b276
📒 Files selected for processing (7)
src/lib/advisories/presenter.test.tssrc/lib/advisories/presenter.tssrc/lib/advisories/registry.test.tssrc/lib/advisories/registry.tssrc/lib/advisories/runner.test.tssrc/lib/advisories/runner.tssrc/lib/advisories/types.ts
|
✨ Thanks for the refactor. Adding a structured advisory registry with typed contracts, immutable registry, and resume-aware runner improves maintainability while preserving existing CLI behavior. Ready for maintainer review. Related open issues: |
Signed-off-by: Ho Lim <subhoya@gmail.com>
apurvvkumaria
left a comment
There was a problem hiding this comment.
Approved at exact head 6874d33 after independent correctness/security review. Phase-one registry contracts, ordered duplicate-safe registration, cache/suppression validation, presenter behavior, and fatal/blocking gates are fail-closed; there is no current CLI wiring or behavior change. Both commits are Verified and DCO-compliant; CodeRabbit is resolved. Non-blocking follow-up: add a malformed resume-cache metadata regression for runner.ts:83-89. The prior red E2E gate is a trusted-validation timeout on a stale base, not a test assertion failure; fresh exact-head/current-base validation is still required.
Co-authored-by: Ho Lim <subhoya@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Summary
Introduce the phase-1 structured advisory foundation from #3213 without changing existing CLI behavior. The new module defines typed advisory/check contracts, an explicit immutable registry, a resume-aware runner, and console/JSON presentation with a shared blocking gate.
Related Issue
Part of #3213.
Changes
Verification
npx vitest run --project cli src/lib/advisories/presenter.test.ts src/lib/advisories/registry.test.ts src/lib/advisories/runner.test.tsnpm run build:clinpm run typechecknpm run docs:check-agent-variantsnpm run check:diffSigned-off-by: Ho Lim subhoya@gmail.com
Summary by CodeRabbit