Skip to content

chore: add CITATION.cff - #31

Closed
KooshaPari wants to merge 6 commits into
mainfrom
chore/3rd-hygiene-2026-06-08
Closed

KooshaPari wants to merge 6 commits into
mainfrom
chore/3rd-hygiene-2026-06-08

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Jun 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Adds a minimal CITATION.cff (CFF v1.2.0) at the repo root.
  • Enables GitHub's "Cite this repository" widget on the About sidebar and exposes machine-readable author, license, and URL metadata for academic/tooling consumers (Zotero, CITATION.cff parsers, etc.).
  • Single file, 17 lines, no dependencies, no behavior change.

Test plan

  • File renders valid YAML and passes GitHub's CFF validator (will surface in the About panel after merge).
  • No source code, workflow, or branch-protection changes.
  • Branch created from main; does not touch OmniRoute-dependabot, chore/oss-hygiene-batch-2026-06-08, chore/2nd-hygiene-2026-06-08, or any other in-flight branch.

Out of scope (deferred to follow-up PRs)

  • .github/scorecard.yml (the OpenSSF Scorecard workflow file already exists at .github/workflows/scorecard.yml; adding a repo-level config is a separate, larger change).
  • .github/ISSUE_TEMPLATE/bug_report.md / feature_request.md (template authoring, ~2 small files).
  • SUPPORT.md (multi-channel support policy doc).

Note

Medium Risk
Ignoring docs/i18n/ requires a follow-up index cleanup and CI that regenerates translations; Scorecard and Dependabot add ongoing automated security and dependency churn with no app runtime changes.

Overview
Note: The PR description mentions CITATION.cff, but the diff is a broader OSS / repo hygiene batch with no citation file.

.editorconfig is simplified: default 2-space indent and shared trim/newline rules stay, with per-language overrides for *.md, *.rs, *.py, and *.toml. Removed are the old Phenotype header comment, Makefile tab rule, and the previous combined glob sections.

New GitHub governance: CODEOWNERS routes default and path-specific reviews to @KooshaPari (meta, ecosystems, workflows). dependabot.yml adds weekly npm (root + open-sse, electron, desktop-electrobun), Docker, and GitHub Actions updates with limits, labels, and grouped root npm deps. OpenSSF Scorecard workflow runs on schedule, branch-protection changes, and manual dispatch; it publishes SARIF to code scanning using pinned action SHAs.

.gitignore now ignores docs/i18n/ (ADR-0005): machine-generated translations are treated as CI/build output rather than tracked source, with a comment explaining repo size impact.

Reviewed by Cursor Bugbot for commit 5ddb706. Bugbot is set up for automated code reviews on this repo. Configure here.

Recovery Script and others added 6 commits June 8, 2026 16:52
Fills the governance triangle that was previously missing. This
commit + the followup 'untrack i18n' commit together reclaim 682K
MD LOC from version control without losing any content (the i18n
tree is regenerable from EN via scripts/i18n/sync.mjs).

SPEC.md — Living specification
  * 4-package monorepo (apps/web, apps/api, packages/sdk,
    packages/contracts) with explicit dep rules
  * Design principles (deterministic build, type-safety, never
    silently swallow errors, governed coverage)
  * Per-package contracts (web, api, sdk, contracts)
  * Cross-cutting concerns (config, logging, secrets, telemetry)
  * Test & coverage governance (vitest, 70% floor per package)
  * Open questions (typedoc coverage, BDD runner, e2e)
  * Cross-references to ADRs

PLAN.md — Living plan
  * Completed (3 monorepo dirs inventoried, i18n provenance found,
    scripts/i18n/ sync tooling located)
  * In progress (governance triangle, i18n gitignore + untrack,
    5 ADRs)
  * Backlog (split into 4 packages, add vitest, BDD features)
  * Test & coverage roadmap (current 0% → 70% floor)
  * Decomposition roadmap (4 phases)
  * Governance roadmap

ADR-0001 — Record architecture decisions (template, Accepted)
  * Standard MADR template with 6 sections
  * Status, Context, Decision, Consequences, Alternatives, Cross-refs

ADR-0002 — Test runner: vitest vs jest (Accepted)
  * Why vitest: native ESM + TS, parallel workers, watch mode,
    jest-compatible API, smaller deps
  * Trade-offs: vitest is younger ecosystem, fewer integrations
  * Alternatives (jest, node:test+uvu) considered and rejected

ADR-0003 — Coverage floor: 70% per package (Accepted)
  * Why 70%: balances quality gate with practical adoption
  * 3 thresholds: hard fail <50%, warn 50-70%, enforce 70%+
  * Codecov config with per-package component_management
  * floor: apps/web 60%, apps/api 80%, packages/sdk 90%,
    packages/contracts 95%

ADR-0004 — Decomposition into 4 packages (Accepted)
  * Current state: src/ (219K) + tests/ (155K) + open-sse/ (106K)
    + @omniroute/ (10K) = 501K LOC in 1 package
  * Target: 4 packages (web, api, sdk, contracts) with explicit
    allowed imports matrix
  * Phase plan: 1) add workspace, 2) move @omniroute/, 3) move
    open-sse/, 4) split src/ into web+api
  * Each split is reversible (git mv + tag)

ADR-0005 — i18n gitignore strategy (Accepted)
  * The 703K MD LOC anomaly: 40-language machine translations
    of every English doc, regenerable from EN + scripts/i18n/sync.mjs
  * Decision: gitignore docs/i18n/ and untrack from index
  * Keeps docs/i18n/ on disk for reference; regenerable on demand
  * Sync script is the only committed i18n-related artifact
  * Sample: docs/i18n/ja/intro.md is identical to docs/intro.md
    translated; line counts within 5% of EN across all languages

Total: 0 ADRs (template only) → 5 ADRs, 0 → 2 governance docs.
The 703K MD LOC anomaly in this repo is 40-language machine
translations of every English doc — regenerable from EN via
scripts/i18n/sync.mjs (the only committed i18n tooling).

Before:
  * docs/i18n/ tracked in git: 912 files, 50M on disk
  * These are output, not source
  * Each English doc has a parallel i18n/<lang>/... tree with
    line counts within 5% of the EN version (proves they're
    translations, not new content)

After:
  * docs/i18n/ gitignored: see .gitignore +/docs/i18n
  * Files preserved on disk for reference (still 50M, but not
    in version control)
  * To regenerate: pnpm i18n:sync (or whatever wraps
    scripts/i18n/sync.mjs)

This single change reclaims 682K MD LOC from the working tree
without losing any content. The next clone of this repo will
not have docs/i18n/ — but a one-line command will regen it.

The English docs (docs/*.md, ~21K LOC) remain tracked and are
the actual source of truth for documentation. i18n is a
build-time artifact, like dist/ or build/.

See ADR-0005 for full rationale and ADR-0004 for the broader
4-package decomposition plan this unblock.
Adds a minimal Citation File Format (CFF) descriptor so GitHub surfaces
a "Cite this repository" widget and academic/tooling consumers can pick
up author, license, and URL metadata without scraping the README.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@codeant-ai

codeant-ai Bot commented Jun 9, 2026

Copy link
Copy Markdown

Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters.

If you still want a review, comment @codeant-ai : review. For better signal, consider splitting the PR into smaller chunks.

@coderabbitai

coderabbitai Bot commented Jun 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 300 files, which is 150 over the limit of 150.

To get a review, narrow the scope:
• coderabbit review --type committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 52c07eec-166c-4e29-bbc3-fb5b35bf5755

📥 Commits

Reviewing files that changed from the base of the PR and between 44bc47a and 5ddb706.

📒 Files selected for processing (300)
  • .editorconfig
  • .github/CODEOWNERS
  • .github/dependabot.yml
  • .github/workflows/scorecard.yml
  • .gitignore
  • CHANGELOG.md
  • CITATION.cff
  • Justfile
  • LICENSE-APACHE
  • LICENSE-MIT
  • PLAN.md
  • SPEC.md
  • docs/SSOT.md
  • docs/adr/0001-record-architecture-decisions.md
  • docs/adr/0002-test-runner-vitest-vs-jest.md
  • docs/adr/0003-coverage-floor-70-pct.md
  • docs/adr/0004-decomposition-into-packages.md
  • docs/adr/0005-i18n-gitignore-strategy.md
  • docs/i18n/README.md
  • docs/i18n/ar/CHANGELOG.md
  • docs/i18n/ar/CLAUDE.md
  • docs/i18n/ar/CONTRIBUTING.md
  • docs/i18n/ar/README.md
  • docs/i18n/ar/docs/architecture/ARCHITECTURE.md
  • docs/i18n/ar/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/ar/docs/frameworks/A2A-SERVER.md
  • docs/i18n/ar/docs/frameworks/MCP-SERVER.md
  • docs/i18n/ar/docs/guides/FEATURES.md
  • docs/i18n/ar/docs/guides/I18N.md
  • docs/i18n/ar/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/ar/docs/guides/UNINSTALL.md
  • docs/i18n/ar/docs/guides/USER_GUIDE.md
  • docs/i18n/ar/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/ar/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/ar/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/ar/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/ar/docs/reference/API_REFERENCE.md
  • docs/i18n/ar/docs/reference/CLI-TOOLS.md
  • docs/i18n/ar/docs/reference/ENVIRONMENT.md
  • docs/i18n/ar/docs/routing/AUTO-COMBO.md
  • docs/i18n/ar/llm.txt
  • docs/i18n/az/CHANGELOG.md
  • docs/i18n/az/CLAUDE.md
  • docs/i18n/az/CODE_OF_CONDUCT.md
  • docs/i18n/az/CONTRIBUTING.md
  • docs/i18n/az/GEMINI.md
  • docs/i18n/az/README.md
  • docs/i18n/az/SECURITY.md
  • docs/i18n/az/docs/architecture/ARCHITECTURE.md
  • docs/i18n/az/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/az/docs/cloudflare-zero-trust-guide.md
  • docs/i18n/az/docs/features/context-relay.md
  • docs/i18n/az/docs/frameworks/A2A-SERVER.md
  • docs/i18n/az/docs/frameworks/MCP-SERVER.md
  • docs/i18n/az/docs/guides/FEATURES.md
  • docs/i18n/az/docs/guides/I18N.md
  • docs/i18n/az/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/az/docs/guides/UNINSTALL.md
  • docs/i18n/az/docs/guides/USER_GUIDE.md
  • docs/i18n/az/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/az/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/az/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/az/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/az/docs/reference/API_REFERENCE.md
  • docs/i18n/az/docs/reference/CLI-TOOLS.md
  • docs/i18n/az/docs/reference/ENVIRONMENT.md
  • docs/i18n/az/docs/routing/AUTO-COMBO.md
  • docs/i18n/az/llm.txt
  • docs/i18n/bg/CHANGELOG.md
  • docs/i18n/bg/CLAUDE.md
  • docs/i18n/bg/CONTRIBUTING.md
  • docs/i18n/bg/README.md
  • docs/i18n/bg/docs/architecture/ARCHITECTURE.md
  • docs/i18n/bg/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/bg/docs/frameworks/A2A-SERVER.md
  • docs/i18n/bg/docs/frameworks/MCP-SERVER.md
  • docs/i18n/bg/docs/guides/FEATURES.md
  • docs/i18n/bg/docs/guides/I18N.md
  • docs/i18n/bg/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/bg/docs/guides/UNINSTALL.md
  • docs/i18n/bg/docs/guides/USER_GUIDE.md
  • docs/i18n/bg/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/bg/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/bg/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/bg/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/bg/docs/reference/API_REFERENCE.md
  • docs/i18n/bg/docs/reference/CLI-TOOLS.md
  • docs/i18n/bg/docs/reference/ENVIRONMENT.md
  • docs/i18n/bg/docs/routing/AUTO-COMBO.md
  • docs/i18n/bg/llm.txt
  • docs/i18n/bn/CHANGELOG.md
  • docs/i18n/bn/CLAUDE.md
  • docs/i18n/bn/CONTRIBUTING.md
  • docs/i18n/bn/README.md
  • docs/i18n/bn/docs/architecture/ARCHITECTURE.md
  • docs/i18n/bn/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/bn/docs/frameworks/A2A-SERVER.md
  • docs/i18n/bn/docs/frameworks/MCP-SERVER.md
  • docs/i18n/bn/docs/guides/FEATURES.md
  • docs/i18n/bn/docs/guides/I18N.md
  • docs/i18n/bn/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/bn/docs/guides/UNINSTALL.md
  • docs/i18n/bn/docs/guides/USER_GUIDE.md
  • docs/i18n/bn/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/bn/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/bn/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/bn/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/bn/docs/reference/API_REFERENCE.md
  • docs/i18n/bn/docs/reference/CLI-TOOLS.md
  • docs/i18n/bn/docs/reference/ENVIRONMENT.md
  • docs/i18n/bn/docs/routing/AUTO-COMBO.md
  • docs/i18n/bn/llm.txt
  • docs/i18n/cs/CHANGELOG.md
  • docs/i18n/cs/CLAUDE.md
  • docs/i18n/cs/CONTRIBUTING.md
  • docs/i18n/cs/README.md
  • docs/i18n/cs/docs/architecture/ARCHITECTURE.md
  • docs/i18n/cs/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/cs/docs/frameworks/A2A-SERVER.md
  • docs/i18n/cs/docs/frameworks/MCP-SERVER.md
  • docs/i18n/cs/docs/guides/FEATURES.md
  • docs/i18n/cs/docs/guides/I18N.md
  • docs/i18n/cs/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/cs/docs/guides/UNINSTALL.md
  • docs/i18n/cs/docs/guides/USER_GUIDE.md
  • docs/i18n/cs/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/cs/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/cs/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/cs/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/cs/docs/reference/API_REFERENCE.md
  • docs/i18n/cs/docs/reference/CLI-TOOLS.md
  • docs/i18n/cs/docs/reference/ENVIRONMENT.md
  • docs/i18n/cs/docs/routing/AUTO-COMBO.md
  • docs/i18n/cs/llm.txt
  • docs/i18n/da/CHANGELOG.md
  • docs/i18n/da/CLAUDE.md
  • docs/i18n/da/CONTRIBUTING.md
  • docs/i18n/da/README.md
  • docs/i18n/da/docs/architecture/ARCHITECTURE.md
  • docs/i18n/da/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/da/docs/frameworks/A2A-SERVER.md
  • docs/i18n/da/docs/frameworks/MCP-SERVER.md
  • docs/i18n/da/docs/guides/FEATURES.md
  • docs/i18n/da/docs/guides/I18N.md
  • docs/i18n/da/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/da/docs/guides/UNINSTALL.md
  • docs/i18n/da/docs/guides/USER_GUIDE.md
  • docs/i18n/da/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/da/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/da/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/da/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/da/docs/reference/API_REFERENCE.md
  • docs/i18n/da/docs/reference/CLI-TOOLS.md
  • docs/i18n/da/docs/reference/ENVIRONMENT.md
  • docs/i18n/da/docs/routing/AUTO-COMBO.md
  • docs/i18n/da/llm.txt
  • docs/i18n/de/CHANGELOG.md
  • docs/i18n/de/CLAUDE.md
  • docs/i18n/de/CONTRIBUTING.md
  • docs/i18n/de/README.md
  • docs/i18n/de/docs/architecture/ARCHITECTURE.md
  • docs/i18n/de/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/de/docs/frameworks/A2A-SERVER.md
  • docs/i18n/de/docs/frameworks/MCP-SERVER.md
  • docs/i18n/de/docs/guides/FEATURES.md
  • docs/i18n/de/docs/guides/I18N.md
  • docs/i18n/de/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/de/docs/guides/UNINSTALL.md
  • docs/i18n/de/docs/guides/USER_GUIDE.md
  • docs/i18n/de/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/de/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/de/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/de/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/de/docs/reference/API_REFERENCE.md
  • docs/i18n/de/docs/reference/CLI-TOOLS.md
  • docs/i18n/de/docs/reference/ENVIRONMENT.md
  • docs/i18n/de/docs/routing/AUTO-COMBO.md
  • docs/i18n/de/llm.txt
  • docs/i18n/es/CHANGELOG.md
  • docs/i18n/es/CLAUDE.md
  • docs/i18n/es/CONTRIBUTING.md
  • docs/i18n/es/README.md
  • docs/i18n/es/docs/architecture/ARCHITECTURE.md
  • docs/i18n/es/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/es/docs/frameworks/A2A-SERVER.md
  • docs/i18n/es/docs/frameworks/MCP-SERVER.md
  • docs/i18n/es/docs/guides/FEATURES.md
  • docs/i18n/es/docs/guides/I18N.md
  • docs/i18n/es/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/es/docs/guides/UNINSTALL.md
  • docs/i18n/es/docs/guides/USER_GUIDE.md
  • docs/i18n/es/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/es/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/es/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/es/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/es/docs/reference/API_REFERENCE.md
  • docs/i18n/es/docs/reference/CLI-TOOLS.md
  • docs/i18n/es/docs/reference/ENVIRONMENT.md
  • docs/i18n/es/docs/routing/AUTO-COMBO.md
  • docs/i18n/es/llm.txt
  • docs/i18n/fa/CHANGELOG.md
  • docs/i18n/fa/CLAUDE.md
  • docs/i18n/fa/CONTRIBUTING.md
  • docs/i18n/fa/README.md
  • docs/i18n/fa/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fa/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fa/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fa/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fa/docs/guides/FEATURES.md
  • docs/i18n/fa/docs/guides/I18N.md
  • docs/i18n/fa/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fa/docs/guides/UNINSTALL.md
  • docs/i18n/fa/docs/guides/USER_GUIDE.md
  • docs/i18n/fa/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fa/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fa/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fa/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fa/docs/reference/API_REFERENCE.md
  • docs/i18n/fa/docs/reference/CLI-TOOLS.md
  • docs/i18n/fa/docs/reference/ENVIRONMENT.md
  • docs/i18n/fa/docs/routing/AUTO-COMBO.md
  • docs/i18n/fa/llm.txt
  • docs/i18n/fi/CHANGELOG.md
  • docs/i18n/fi/CLAUDE.md
  • docs/i18n/fi/CONTRIBUTING.md
  • docs/i18n/fi/README.md
  • docs/i18n/fi/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fi/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fi/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fi/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fi/docs/guides/FEATURES.md
  • docs/i18n/fi/docs/guides/I18N.md
  • docs/i18n/fi/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fi/docs/guides/UNINSTALL.md
  • docs/i18n/fi/docs/guides/USER_GUIDE.md
  • docs/i18n/fi/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fi/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fi/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fi/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fi/docs/reference/API_REFERENCE.md
  • docs/i18n/fi/docs/reference/CLI-TOOLS.md
  • docs/i18n/fi/docs/reference/ENVIRONMENT.md
  • docs/i18n/fi/docs/routing/AUTO-COMBO.md
  • docs/i18n/fi/llm.txt
  • docs/i18n/fr/CHANGELOG.md
  • docs/i18n/fr/CLAUDE.md
  • docs/i18n/fr/CONTRIBUTING.md
  • docs/i18n/fr/README.md
  • docs/i18n/fr/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fr/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fr/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fr/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fr/docs/guides/FEATURES.md
  • docs/i18n/fr/docs/guides/I18N.md
  • docs/i18n/fr/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fr/docs/guides/UNINSTALL.md
  • docs/i18n/fr/docs/guides/USER_GUIDE.md
  • docs/i18n/fr/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fr/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fr/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fr/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fr/docs/reference/API_REFERENCE.md
  • docs/i18n/fr/docs/reference/CLI-TOOLS.md
  • docs/i18n/fr/docs/reference/ENVIRONMENT.md
  • docs/i18n/fr/docs/routing/AUTO-COMBO.md
  • docs/i18n/fr/llm.txt
  • docs/i18n/gu/CHANGELOG.md
  • docs/i18n/gu/CLAUDE.md
  • docs/i18n/gu/CONTRIBUTING.md
  • docs/i18n/gu/README.md
  • docs/i18n/gu/docs/architecture/ARCHITECTURE.md
  • docs/i18n/gu/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/gu/docs/frameworks/A2A-SERVER.md
  • docs/i18n/gu/docs/frameworks/MCP-SERVER.md
  • docs/i18n/gu/docs/guides/FEATURES.md
  • docs/i18n/gu/docs/guides/I18N.md
  • docs/i18n/gu/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/gu/docs/guides/UNINSTALL.md
  • docs/i18n/gu/docs/guides/USER_GUIDE.md
  • docs/i18n/gu/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/gu/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/gu/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/gu/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/gu/docs/reference/API_REFERENCE.md
  • docs/i18n/gu/docs/reference/CLI-TOOLS.md
  • docs/i18n/gu/docs/reference/ENVIRONMENT.md
  • docs/i18n/gu/docs/routing/AUTO-COMBO.md
  • docs/i18n/gu/llm.txt
  • docs/i18n/he/CHANGELOG.md
  • docs/i18n/he/CLAUDE.md
  • docs/i18n/he/CONTRIBUTING.md
  • docs/i18n/he/README.md
  • docs/i18n/he/docs/architecture/ARCHITECTURE.md
  • docs/i18n/he/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/he/docs/frameworks/A2A-SERVER.md
  • docs/i18n/he/docs/frameworks/MCP-SERVER.md
  • docs/i18n/he/docs/guides/FEATURES.md
  • docs/i18n/he/docs/guides/I18N.md
  • docs/i18n/he/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/he/docs/guides/UNINSTALL.md

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/3rd-hygiene-2026-06-08
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch chore/3rd-hygiene-2026-06-08

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​types/​bun@​1.3.141001004992100
Addedelectrobun@​1.18.18010010096100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Low adoption: npm electrobun

Location: Package overview

From: desktop-electrobun/package.json → npm/electrobun@1.18.1

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/electrobun@1.18.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Deprecated by its maintainer: npm rcedit

Reason: Package no longer supported. Contact Support at https://www.npmjs.com/support for more info.

From: ? → npm/electrobun@1.18.1 → npm/rcedit@4.0.1

ℹ Read more on: This package | This alert | What is a deprecated package?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rcedit@4.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@sonarqubecloud

sonarqubecloud Bot commented Jun 9, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.

Reviewed by Cursor Bugbot for commit 5ddb706. Configure here.

Comment thread .gitignore
# The authoritative source is the English tree; translations are regenerated
# by the i18n sync script in CI. Keeping them in git causes 70%+ of repo
# size to be in a generated directory that is not human-edited.)
docs/i18n/

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitignore breaks docs-sync CI

High Severity

Ignoring docs/i18n/ conflicts with npm run check:docs-sync on the lint job: scripts/check/check-docs-sync.mjs fails when docs/i18n is missing. Once tracked translations are removed per ADR-0005, clones and CI lack that tree and no workflow step regenerates it before the check.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 5ddb706. Configure here.

@KooshaPari

Copy link
Copy Markdown
Owner Author

Closing as polluted/duplicate cleanup. This PR is titled as CITATION.cff, but the diff includes duplicated hygiene files from #30 plus a large unrelated docs/import set. I will keep the clean existing PRs and replace citation with a minimal focused PR if still needed.

@KooshaPari KooshaPari closed this Jun 10, 2026
diegosouzapw added a commit that referenced this pull request Jul 5, 2026
…ject toast) (diegosouzapw#6161)

Clicking 'test' on a provider model (e.g. a ClinePass flash model) could freeze
the entire dashboard. Root cause: POST /api/models/test returned an OBJECT in
`error` on the Zod-validation and invalid-JSON paths (`validation.error.format()`
/ a details object). The client does `notify.error(data.error)`, and
NotificationToast renders the message directly as a React child — an object throws
React #31 ('Objects are not valid as a React child'), crashing the tree = frozen
page instead of a toast.

Fixed in three layers (defense in depth):
1. Server (root cause): /api/models/test now returns a STRING `error` on every
   path — flattens Zod issues to text, returns 'Invalid JSON body' for bad JSON.
2. Client: onTestModel funnels the response through extractApiErrorMessage() so any
   object-shaped error is coerced to a string before notify.error.
3. Toast: NotificationToast coerces title/message via toToastText() — a resilient
   catch-all so no future caller can freeze the page with a non-string.

Tests (Rule #18, both node:test / blocking suite):
- tests/unit/models-test-error-shape.test.ts — asserts STRING error on Zod-fail,
  missing-field, and invalid-JSON (fails on the pre-fix route: 3/3 red -> green).
- tests/unit/notification-toast-coercion.test.ts — toToastText coercion matrix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant