Skip to content

feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml - #1456

Merged
don-petry merged 2 commits into
mainfrom
dev-lead/issue-1455-20260803-1023
Aug 3, 2026
Merged

don-petry merged 2 commits into
mainfrom
dev-lead/issue-1455-20260803-1023

Conversation

@don-petry

@don-petry don-petry commented Aug 3, 2026 •

Copy link
Copy Markdown
Collaborator

User description

Closes #1455

Implemented by dev-lead agent. Please review.


CodeAnt-AI Description

Prevent vendored dependency files from breaking Markdown lint checks

What Changed

  • Markdown linting now skips Markdown files under node_modules, while continuing to report violations in project documentation
  • Removed the accidentally committed Bats dependency and its package metadata from the repository
  • Added regression tests covering the lint configuration, dependency tracking, and scoped ignore behavior
  • The new regression test runs as part of the CI lint test suite

Impact

✅ Fewer CI lint failures from third-party Markdown
✅ No committed vendored dependency files
✅ Project documentation violations remain visible

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Bug Fixes

    • Markdown linting now correctly ignores vendored npm dependency files while continuing to report issues in project documentation.
  • Tests

    • Added regression coverage for Markdown lint configuration, Git tracking rules, configuration validity, and linting behavior.
  • Chores

    • Removed the unused npm package manifest and added ignore rules for npm dependency artifacts.

@don-petry
don-petry requested a review from a team as a code owner August 3, 2026 10:33
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@codeant-ai

codeant-ai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR c988fd6 Aug 03, 2026 · 10:33 10:35

@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 44 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b7d6699c-83b8-4047-97e1-c5dbe36dead5

📥 Commits

Reviewing files that changed from the base of the PR and between c988fd6 and d466659.

📒 Files selected for processing (2)
  • .github/workflows/lint.yml
  • tests/test_markdownlint_config.bats
📝 Walkthrough

Walkthrough

The repository now excludes node_modules/ from Git and Markdownlint processing. A Bats regression suite validates the configuration and linter behavior. The lint workflow runs the new test, and package.json is removed.

Changes

Markdownlint vendored dependency exclusion

Layer / File(s) Summary
Configure npm dependency exclusion
.gitignore, .markdownlint-cli2.jsonc, package.json
Git ignores node_modules/. Markdownlint ignores node_modules/**. The package.json dependency declaration is removed.
Validate exclusion behavior
tests/test_markdownlint_config.bats, .github/workflows/lint.yml
Bats tests parse the configuration, check Git tracking, and verify that vendored Markdown is ignored while documentation violations remain reported. The lint workflow runs the test.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: size:S

🚥 Pre-merge checks | ✅ 1 | ❌ 4

❌ Failed checks (4 warnings)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title names a CI workflow change, but the pull request changes Markdown linting, dependency files, and tests instead. Use a title that describes the Markdown lint configuration and vendored dependency cleanup.
Description check ⚠️ Warning The description summarizes the code changes but omits the required Summary, Interaction contract, and Checklist sections. Complete the repository template, mark the interaction contract as N/A if applicable, and complete the checklist.
Linked Issues check ⚠️ Warning The issue concerns degraded .github/workflows/ci.yml, but the pull request provides no evidence that this workflow or its reported metrics were addressed. Update .github/workflows/ci.yml or provide evidence that the changes directly resolve the issue's degraded workflow status.
Out of Scope Changes check ⚠️ Warning The Markdown lint configuration, npm metadata removal, and regression tests are not tied to the linked issue about degraded .github/workflows/ci.yml. Limit the pull request to changes that address .github/workflows/ci.yml, or link an issue that covers the Markdown lint and dependency changes.
✅ Passed checks (1 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-1455-20260803-1023

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Aug 3, 2026
@don-petry

don-petry commented Aug 3, 2026 •

Copy link
Copy Markdown
Collaborator Author

Dependency Advisory

Package Change Ecosystem Risk Notes
bats 1.13.0 → removed npm LOW Removal of a dev-only test runner; no runtime impact

Risk Legend

  • LOW — Patch/minor bump, lockfile regeneration, well-maintained package
  • MEDIUM — Minor bump with new APIs, new direct dependency, deprecation notice
  • HIGH — Major version bump, package with recent CVE, unusual transitive deps
  • CRITICAL — Active CVE, known supply-chain risk, abandoned package

Details

All dependency changes appear low-risk. No action required.

bats (Bash Automated Testing System) is a well-maintained MIT-licensed shell testing framework with no production runtime use. Its removal eliminates the node_modules/ directory and package.json entirely, which is consistent with migrating to a system-installed or GitHub Actions-provided bats binary rather than managing it via npm. No transitive dependencies were present. Verify that any CI steps invoking bats still have access to the binary via another mechanism (e.g., actions/setup-bats, a pre-installed runner tool, or direct install in the workflow).

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request removes the accidentally committed vendored bats dependency and updates both .gitignore and .markdownlint-cli2.jsonc to exclude node_modules/. It also introduces a new test suite, tests/test_markdownlint_config.bats, to ensure that node_modules/ is not tracked by git and is correctly ignored by the markdown linter. The feedback suggests refactoring the newly added behavioral test to leverage the built-in $BATS_TEST_TMPDIR variable for automatic cleanup and to enforce a strict exit status check of 1 for negative grep assertions to prevent false positives.

Comment thread tests/test_markdownlint_config.bats Outdated
Comment thread tests/test_markdownlint_config.bats
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Fix markdownlint CI regression: ignore node_modules and add guard tests

🐞 Bug fix 🧪 Tests ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Stop markdownlint scanning vendored dependency docs by ignoring node_modules.
• Prevent re-vendoring npm artifacts by gitignoring node_modules and removing npm files.
• Add a Bats regression test to validate markdownlint config and CI behavior.
Diagram

graph TD
  A["CI: lint.yml"] --> B["Bats test suite"] --> C["test_markdownlint_config.bats"] --> D[".markdownlint-cli2.jsonc"] --> E["Ignore: node_modules/**"]
  C --> F["Git index check"] --> G[".gitignore"]
  C --> H["markdownlint-cli2 bin"]

  subgraph Legend
    direction LR
    _wf["Workflow"] ~~~ _t["Test"] ~~~ _cfg["Config"]
  end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Exclude node_modules in the CI invocation
  • ➕ Keeps repo-wide markdownlint config unchanged
  • ➕ Makes the CI intent explicit in the workflow step
  • ➖ Local runs would still fail without the ignore
  • ➖ Other workflows/scripts could reintroduce the bad glob
2. Narrow markdownlint target globs (avoid **/*.md)
  • ➕ Reduces scanning scope and runtime
  • ➕ Less reliance on ignore rules
  • ➖ Easy to miss new markdown locations unless maintained
  • ➖ Doesn’t codify the policy that vendored content shouldn’t be linted
3. Add a CI guard to block committing vendor trees
  • ➕ Prevents recurrence at the source (before CI fails)
  • ➕ Can enforce multiple vendor directories consistently
  • ➖ More tooling/process overhead
  • ➖ Still advisable to keep markdownlint ignores for defense-in-depth

Recommendation: The current approach (markdownlint ignore + gitignore + regression/behavioral test + removing vendored artifacts) is the best defense-in-depth: it fixes CI immediately, applies to local runs, and adds an automated guard to prevent the regression from returning.

Files changed (4) +86 / -1

Bug fix (1) +3 / -1
.markdownlint-cli2.jsoncExclude node_modules from markdownlint scanning +3/-1

Exclude node_modules from markdownlint scanning

• Extends the markdownlint-cli2 ignores list to include node_modules/**. Avoids lint failures caused by third-party markdown under vendored dependencies.

.markdownlint-cli2.jsonc

Tests (1) +79 / -0
test_markdownlint_config.batsAdd Bats regression + behavioral tests for markdownlint/node_modules +79/-0

Add Bats regression + behavioral tests for markdownlint/node_modules

• Adds tests that validate the JSONC config parses, assert node_modules is ignored by markdownlint, assert node_modules is not tracked by git, and (when markdownlint-cli2 is present) prove node_modules markdown is ignored while real docs still fail.

tests/test_markdownlint_config.bats

Other (2) +4 / -0
lint.ymlRun markdownlint regression guard in lint workflow +1/-0

Run markdownlint regression guard in lint workflow

• Adds the new markdownlint configuration regression test to the Bats test list executed by the lint workflow. Ensures CI fails if markdownlint starts scanning vendored content again.

.github/workflows/lint.yml

.gitignoreIgnore node_modules to prevent vendoring npm artifacts +3/-0

Ignore node_modules to prevent vendoring npm artifacts

• Adds node_modules/ to .gitignore with context that Bats is installed via apt in CI. Prevents accidental commits of npm dependencies.

.gitignore

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #1456
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-08-03T11:07:23Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-08-03T11:07:23Z

@don-petry
don-petry enabled auto-merge (squash) August 3, 2026 10:37
coderabbitai[bot]
coderabbitai Bot previously requested changes Aug 3, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test_markdownlint_config.bats`:
- Around line 41-44: Update the test ".markdownlint-cli2.jsonc ignores
node_modules" to assert that the ignores collection contains the exact pattern
"node_modules/**", rather than accepting any entry merely containing
"node_modules".
- Around line 47-55: Extend the “node_modules/ is not tracked by git” test to
directly validate the ignore rule by running git check-ignore with --no-index
against a representative path such as node_modules/example/package.json, and
assert the command succeeds. Keep the existing git ls-files assertions to
preserve the tracked-file regression check.
- Around line 62-70: Update the CI workflow that runs
tests/test_markdownlint_config.bats to install a pinned markdownlint-cli2 before
executing the test, or explicitly fail when the CLI is unavailable, so the
behavioral ignore-rule check cannot silently skip. Use the existing lint
workflow’s test step and dependency-install mechanism.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 8c1a1d59-1066-4de3-93dc-db62a12135d6

📥 Commits

Reviewing files that changed from the base of the PR and between e2a42cf and c988fd6.

⛔ Files ignored due to path filters (33)
  • node_modules/.bin/bats is excluded by !**/node_modules/**
  • node_modules/.package-lock.json is excluded by !**/node_modules/**
  • node_modules/bats/LICENSE.md is excluded by !**/node_modules/**
  • node_modules/bats/README.md is excluded by !**/node_modules/**
  • node_modules/bats/bin/bats is excluded by !**/node_modules/**
  • node_modules/bats/install.sh is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/common.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/formatter.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/preprocessing.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/semaphore.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/test_functions.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/tracing.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/validator.bash is excluded by !**/node_modules/**
  • node_modules/bats/lib/bats-core/warnings.bash is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-exec-file is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-exec-suite is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-exec-test is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-format-cat is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-format-junit is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-format-pretty is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-format-tap is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-format-tap13 is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-gather-tests is excluded by !**/node_modules/**
  • node_modules/bats/libexec/bats-core/bats-preprocess is excluded by !**/node_modules/**
  • node_modules/bats/man/Makefile is excluded by !**/node_modules/**
  • node_modules/bats/man/README.md is excluded by !**/node_modules/**
  • node_modules/bats/man/bats.1 is excluded by !**/node_modules/**
  • node_modules/bats/man/bats.1.ronn is excluded by !**/node_modules/**
  • node_modules/bats/man/bats.7 is excluded by !**/node_modules/**
  • node_modules/bats/man/bats.7.ronn is excluded by !**/node_modules/**
  • node_modules/bats/package.json is excluded by !**/node_modules/**
  • node_modules/bats/uninstall.sh is excluded by !**/node_modules/**
📒 Files selected for processing (5)
  • .github/workflows/lint.yml
  • .gitignore
  • .markdownlint-cli2.jsonc
  • package.json
  • tests/test_markdownlint_config.bats
💤 Files with no reviewable changes (1)
  • package.json

Comment thread tests/test_markdownlint_config.bats
Comment thread tests/test_markdownlint_config.bats
Comment thread tests/test_markdownlint_config.bats Outdated
@qodo-code-review

qodo-code-review Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 51 rules

Grey Divider


Remediation recommended

1. Markdownlint guard can skip ✓ Resolved 🐞 Bug ☼ Reliability
Description
tests/test_markdownlint_config.bats adds a behavioral regression test that skips unless
markdownlint-cli2 is installed, but the lint workflow’s bats job does not install
markdownlint-cli2. This can leave the new regression guard non-enforcing in CI, reducing
confidence that the ignore behavior is actually validated.
Code

tests/test_markdownlint_config.bats[R62-63]

+@test "markdownlint ignores node_modules markdown but still flags non-ignored files" {
+  command -v markdownlint-cli2 >/dev/null 2>&1 || skip "markdownlint-cli2 not installed"
Relevance

●●● Strong

Similar issue accepted: CI installed missing test dependency (PyYAML) in PR #483; team enforces
non-skipped CI tests.

PR-#483
PR-#276

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The behavioral test is explicitly skipped when markdownlint-cli2 is missing, and the workflow
running bats does not install it, so the test may not execute in CI.

tests/test_markdownlint_config.bats[57-70]
.github/workflows/lint.yml[33-44]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`tests/test_markdownlint_config.bats` contains a behavioral test that is skipped when `markdownlint-cli2` is not present on PATH. The `lint.yml` bats job currently installs `bats` and Python deps only, so this behavioral check may not run in CI.

### Issue Context
The intent of the new test is to prove that `node_modules/**` is ignored *and* that non-ignored Markdown still fails linting. If the binary is absent, the “behavioral guard” portion silently skips.

### Fix Focus Areas
- .github/workflows/lint.yml[33-44]
- tests/test_markdownlint_config.bats[62-70]

### Suggested fix
Option A (recommended): In `.github/workflows/lint.yml` `bats` job, add a pinned Node setup + install step for `markdownlint-cli2` (so the behavioral test always runs), e.g.:
- `actions/setup-node` with a fixed node-version
- `npm install -g markdownlint-cli2@<pinned>`

Option B: If you don’t want to install it in this workflow, remove the behavioral test (or move it to a workflow/job where `markdownlint-cli2` is guaranteed to be available), keeping only the config-structure assertions.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

To customize comments, go to the Qodo configuration screen, or learn more in the docs.

Qodo Logo

Comment thread tests/test_markdownlint_config.bats
@don-petry
don-petry disabled auto-merge August 3, 2026 10:39
@donpetry-bot

donpetry-bot commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor
Superseded by automated re-review at d4666595a48a9b1eb29071d1fe1349cdb9a1eebf — click to expand prior review.

Review — fix requested (cycle 1/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: LOW
Reviewed commit: c988fd637b4ce99c7efa60ea2810b44079fe8b1f
Cascade: triage → deep (triage: haiku 4.5 → deep: opus 4.8 + duck: o4-mini → audit: fable 5)

Summary

LOW-risk hygiene PR: removes the accidentally vendored node_modules/bats tree + package.json (#1435 regression), adds node_modules/ to .gitignore and .markdownlint-cli2.jsonc ignores, and adds tests/test_markdownlint_config.bats wired into lint.yml. No security, secrets, auth, migration, or standards signals; CI is green (Lint, shellcheck, bats, unit-tests, CodeQL, gitleaks, SonarCloud all SUCCESS; CANCELLED entries are superseded reruns). Downstream impact: (none). Not a security concern, so no Tier-3 audit needed, but valid advisory findings on the new test file remain unaddressed and reviewDecision is CHANGES_REQUESTED, so it should not auto-approve yet.

Findings

  • major: Behavioral test 'markdownlint ignores node_modules markdown but still flags non-ignored files' skips when markdownlint-cli2 is absent, and the bats CI job installs only bats + Python (not markdownlint-cli2), so this test is a no-op in CI and never verifies the scoped-ignore behavior. The three config/git-tracking tests still run and guard the core regression, but the behavioral guard provides no CI coverage. Install markdownlint-cli2 in the bats job or fail when the binary is missing. (codeant-ai)
  • minor: The ignores assertion uses a loose substring check (any('node_modules' in p ...)) which would also accept unrelated patterns like 'vendor/node_modules/'. Assert the exact pattern 'node_modules/'. (coderabbitai)
  • minor: Negative grep assertion uses '! grep -q ...' which passes on any non-zero exit (grep returns 2 on error), risking a false pass. Use 'run grep -q ...' and assert status -eq 1. Also prefer $BATS_TEST_TMPDIR over mktemp -d + rm -rf for automatic per-test isolation/cleanup. (gemini-code-assist)

Reviewed by the PR-review cascade (triage: haiku 4.5 → deep: opus 4.8 + duck: o4-mini → audit: fable 5). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 3, 2026 10:49
@donpetry-bot
donpetry-bot dismissed coderabbitai[bot]’s stale review August 3, 2026 10:49

Auto-dismissed (#617): coderabbitai[bot] CHANGES_REQUESTED on a superseded commit. The bot re-reviews the new head automatically — a valid concern will return as a fresh review.

@sonarqubecloud

sonarqubecloud Bot commented Aug 3, 2026

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge August 3, 2026 10:49
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) August 3, 2026 10:50

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: d4666595a48a9b1eb29071d1fe1349cdb9a1eebf
Review mode: triage-approved (single reviewer)

Summary

LOW-risk hygiene PR confirming the triage assessment: removes the accidentally vendored node_modules/bats tree and package.json (pure deletions, 0 added lines under node_modules/), adds node_modules/ to .gitignore and .markdownlint-cli2.jsonc ignores, and adds regression tests wired into lint.yml. All three findings from the prior review cycle (at c988fd6) are resolved by the fix commit: markdownlint-cli2@0.23.2 is now installed in the bats CI job so the behavioral test is no longer a silent skip, the ignores assertion checks the exact pattern 'node_modules/**', and the negative grep assertion uses run + status -eq 1 with $BATS_TEST_TMPDIR. All review threads resolved, CI fully green.

Linked issue analysis

Closes #1455 (Fleet Monitor: ci.yml DEGRADED, 27.5% failure rate). Root cause was commit e2a42cf (#1435) accidentally committing node_modules/bats/, whose README.md failed markdownlint on every main push. This PR substantively addresses it: deletes the vendored tree, scopes the markdownlint ignore to node_modules/, gitignores node_modules/, and adds tests/test_markdownlint_config.bats (config validity, exact ignore pattern, git-tracking guard, and a behavioral fixture test proving the ignore is scoped and does not blanket-suppress real findings).

Findings

No new issues. Prior cycle-1 findings all resolved:

  • (major, resolved) markdownlint-cli2 absent in CI made the behavioral test a no-op → lint.yml now installs markdownlint-cli2@0.23.2 (exact version) and runs tests/test_markdownlint_config.bats.
  • (minor, resolved) loose substring ignores check → now asserts exact pattern 'node_modules/**'.
  • (minor, resolved) '! grep -q' false-pass risk → now 'run grep -q' with [ "$status" -eq 1 ]; mktemp replaced with $BATS_TEST_TMPDIR.
    Secret scan: gitleaks CI check SUCCESS; run_secret_scanning MCP tool unavailable in this run (noted, not blocking). No secrets, auth, migration, or workflow-security smells in the added content; modified lint.yml is not a frozen caller stub.

CI status

All required checks green: Lint, shellcheck, actionlint, bats, unit-tests, CodeQL (actions + python), gitleaks, SonarCloud quality gate passed, agent-shield, caller-stub-freeze, template-drift, all validators SUCCESS. Skipped entries are conditional jobs (pnpm/pip/cargo/govulncheck audits, dependabot-automerge, Graphite).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry merged commit d008124 into main Aug 3, 2026
44 checks passed
@don-petry
don-petry deleted the dev-lead/issue-1455-20260803-1023 branch August 3, 2026 10:53
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-08-03T11:54:07Z.

don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 18, 2026
…private — .github/workflows/ci.yml (#1456)

* feat: implement issue #1455 — [Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

* fix(reviews): address review comments [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Fleet Monitor] petry-projects/.github-private — .github/workflows/ci.yml

2 participants