Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion plugins/source-control/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
"name": "source-control",
"version": "0.53.5",
"version": "0.53.6",
"description": "Git and GitHub delivery workflow: /commit (Conventional Commits + Co-Authored-By trailer via safe heredoc mechanics), /pull-request (prep, create, CI monitoring, review-comment triage, merge, CI-log fetch), /babysit-prs (self-pacing fleet loop \u2014 safe by default; opt-in worker/autopilot tiers add gate-checked merge and thread resolution behind a deterministic Python engine), /babysit-loop (the loop-lane merge lane: a standing or drain loop that invokes babysit-prs per cycle, configured through repo-scoped babysit_loop_* keys on the layered source-control.md seam, with merge authority human-only until the target repo's tracked config adopts the lane, a gate-proven C2-mechanical baseline once adopted, and standing merge-rung raises binding from the team-tracked layer only \u2014 with one named exception, where an invocation line explicitly typing both the autopilot tier keyword and the dedicated raise argument --merge c3-this-run widens that single invocation's merge authority up to C3 behind a fresh independent frontier-tier resolver, while C4-structural and C5-untrusted-provenance stay unconditionally human-merge), /worktree (create, status, cleanup, audit for parallel-session isolation), /setup (check the effective commit-subject / PR-title convention merged across its config layers and the babysit-prs config, or apply \u2014 interview the repo and write the convention config to a chosen layer), and /resolve-conflicts (intent-first merge/rebase conflict resolution with a semantic-conflict sweep \u2014 never --abort). The commit-subject / PR-title convention is configurable via a source-control.md config written by a re-runnable setup skill, layered across a ~/.claude user-global file, the tracked team file, and a gitignored .claude/source-control.local.md personal overlay merged per key; Conventional Commits is the default when no convention is declared.",
"author": {
"name": "Melodic Software",
Expand Down
8 changes: 8 additions & 0 deletions plugins/source-control/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,14 @@
All notable changes to the `source-control` plugin are documented here. Format follows
[Keep a Changelog](https://keepachangelog.com/en/1.1.0/); this plugin uses semantic versioning.

## [0.53.6]

### Fixed

- **`fetch_pull_request_commits` fails closed when GitHub's 250-commit API cap truncates the walk
(#2387).** Compares the walked count to the PR's `commits` field and raises when the endpoint
cannot return the full list, preserving the over-report-only invariant for signature enforcement.

## [0.53.5]

### Fixed
Expand Down
15 changes: 15 additions & 0 deletions plugins/source-control/skills/babysit-prs/scripts/babysit_gh.py
Original file line number Diff line number Diff line change
Expand Up @@ -481,11 +481,26 @@ def fetch_pull_request_commits(repo: str, number: int) -> list[dict[str, Any]]:
whose verification block is missing is reported unverified with reason
`unreadable` rather than skipped: the caller enforcing a signature rule may
only ever over-report.

GitHub's `GET /repos/{owner}/{repo}/pulls/{n}/commits` endpoint returns at
most **250** commits regardless of pagination; when the PR carries more, this
raises `RuntimeError` so callers fail closed rather than under-report.
"""
rows = fetch_paginated_api(
f"repos/{repo}/pulls/{number}/commits?per_page=100",
f"{repo}#{number} commits",
)
reported_total = gh_json(
["api", f"repos/{repo}/pulls/{number}", "--jq", ".commits"]
)
total = int(reported_total) if isinstance(reported_total, int) else 0
Comment thread
kyle-sexton marked this conversation as resolved.
# GitHub documents a 250-commit ceiling on this endpoint; pagination does not
# lift it, so a short walk against a larger PR is under-reporting.
if total > len(rows) and len(rows) >= 250:
raise RuntimeError(
f"commit list exceeded the API's 250-commit cap "
f"(walked {len(rows)} of {total})"
)
out: list[dict[str, Any]] = []
for row in rows:
commit = row.get("commit")
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -288,7 +288,7 @@ def test_verification_is_projected_per_commit(self) -> None:
"commit": {"verification": {"verified": False, "reason": "no_user"}},
},
]
with mock.patch.object(gh, "gh_json", return_value=rows) as gh_json:
with mock.patch.object(gh, "gh_json", side_effect=[rows, len(rows)]) as gh_json:
out = gh.fetch_pull_request_commits("owner/repo", 5)
self.assertEqual(
out,
Expand All @@ -297,11 +297,26 @@ def test_verification_is_projected_per_commit(self) -> None:
{"sha": "b" * 40, "verified": False, "reason": "no_user"},
],
)
[call] = gh_json.call_args_list
endpoint = call.args[0][1]
commits_call = gh_json.call_args_list[0]
endpoint = commits_call.args[0][1]
self.assertIn("repos/owner/repo/pulls/5/commits", endpoint)
self.assertIn("per_page=100", endpoint)
self.assertIn("--paginate", call.args[0])
self.assertIn("--paginate", commits_call.args[0])

def test_pull_commits_cap_raises_when_walk_is_short(self) -> None:
rows = [
{
"sha": f"{i:040x}",
"commit": {"verification": {"verified": True, "reason": "valid"}},
}
for i in range(250)
]
with mock.patch.object(gh, "gh_json") as gh_json_mock:
gh_json_mock.side_effect = [rows, 300]
with self.assertRaises(RuntimeError) as ctx:
gh.fetch_pull_request_commits("owner/repo", 5)
self.assertIn("250-commit cap", str(ctx.exception))
self.assertIn("walked 250 of 300", str(ctx.exception))

def test_missing_verification_reads_unverified_unreadable(self) -> None:
rows = [
Expand Down
Loading