Skip to content

chore(security): add OpenSSF Scorecard workflow - #33

Closed
KooshaPari wants to merge 7 commits into
mainfrom
chore/6th-hygiene-2026-06-08
Closed

KooshaPari wants to merge 7 commits into
mainfrom
chore/6th-hygiene-2026-06-08

Conversation

@KooshaPari

@KooshaPari KooshaPari commented Jun 10, 2026 •

Copy link
Copy Markdown
Owner

Adds .github/scorecard.yml to enable weekly OpenSSF Scorecard analysis on the default branch and on branch protection events. Results are published to the Security tab as SARIF.

Single-file addition (~20 lines), branched from main. No overlap with #27, #30, #31.


Note

Low Risk
Changes are meta/CI and ignore rules only; the main follow-up risk is duplicate or non-running Scorecard config and ensuring CI regenerates i18n after ignoring docs/i18n/.

Overview
This PR bundles repository governance and hygiene changes rather than application code.

OpenSSF Scorecard is added via .github/workflows/scorecard.yml: weekly (Monday 09:00) and on branch-protection events, with workflow_dispatch, pinned third-party actions, checkout without persisted credentials, SARIF artifact upload, and publishing to GitHub code scanning. A second file .github/scorecard.yml defines a similar job on a different cron and a different ossf/scorecard-action pin; GitHub only runs workflows under .github/workflows/, so reviewers should confirm whether the root file is intentional or redundant.

.github/CODEOWNERS assigns default review ownership (including /.github/workflows/) and path-based rules for major monorepo areas.

.github/dependabot.yml enables weekly dependency PRs for npm (root, open-sse, electron, desktop-electrobun with grouping on root), Docker, and GitHub Actions, with limits and labels.

.editorconfig is simplified: default 2-space indent, explicit [*.md] / [*.rs] / [*.py] / [*.toml] sections; Makefile tab rule and broad brace globs are removed.

.gitignore adds docs/i18n/ so machine-generated translations are excluded from git (aligned with ADR-0005); removing already-tracked files would be a follow-up git rm --cached change.

Reviewed by Cursor Bugbot for commit e96abae. Bugbot is set up for automated code reviews on this repo. Configure here.

Recovery Script and others added 7 commits June 8, 2026 16:52
Fills the governance triangle that was previously missing. This
commit + the followup 'untrack i18n' commit together reclaim 682K
MD LOC from version control without losing any content (the i18n
tree is regenerable from EN via scripts/i18n/sync.mjs).

SPEC.md — Living specification
  * 4-package monorepo (apps/web, apps/api, packages/sdk,
    packages/contracts) with explicit dep rules
  * Design principles (deterministic build, type-safety, never
    silently swallow errors, governed coverage)
  * Per-package contracts (web, api, sdk, contracts)
  * Cross-cutting concerns (config, logging, secrets, telemetry)
  * Test & coverage governance (vitest, 70% floor per package)
  * Open questions (typedoc coverage, BDD runner, e2e)
  * Cross-references to ADRs

PLAN.md — Living plan
  * Completed (3 monorepo dirs inventoried, i18n provenance found,
    scripts/i18n/ sync tooling located)
  * In progress (governance triangle, i18n gitignore + untrack,
    5 ADRs)
  * Backlog (split into 4 packages, add vitest, BDD features)
  * Test & coverage roadmap (current 0% → 70% floor)
  * Decomposition roadmap (4 phases)
  * Governance roadmap

ADR-0001 — Record architecture decisions (template, Accepted)
  * Standard MADR template with 6 sections
  * Status, Context, Decision, Consequences, Alternatives, Cross-refs

ADR-0002 — Test runner: vitest vs jest (Accepted)
  * Why vitest: native ESM + TS, parallel workers, watch mode,
    jest-compatible API, smaller deps
  * Trade-offs: vitest is younger ecosystem, fewer integrations
  * Alternatives (jest, node:test+uvu) considered and rejected

ADR-0003 — Coverage floor: 70% per package (Accepted)
  * Why 70%: balances quality gate with practical adoption
  * 3 thresholds: hard fail <50%, warn 50-70%, enforce 70%+
  * Codecov config with per-package component_management
  * floor: apps/web 60%, apps/api 80%, packages/sdk 90%,
    packages/contracts 95%

ADR-0004 — Decomposition into 4 packages (Accepted)
  * Current state: src/ (219K) + tests/ (155K) + open-sse/ (106K)
    + @omniroute/ (10K) = 501K LOC in 1 package
  * Target: 4 packages (web, api, sdk, contracts) with explicit
    allowed imports matrix
  * Phase plan: 1) add workspace, 2) move @omniroute/, 3) move
    open-sse/, 4) split src/ into web+api
  * Each split is reversible (git mv + tag)

ADR-0005 — i18n gitignore strategy (Accepted)
  * The 703K MD LOC anomaly: 40-language machine translations
    of every English doc, regenerable from EN + scripts/i18n/sync.mjs
  * Decision: gitignore docs/i18n/ and untrack from index
  * Keeps docs/i18n/ on disk for reference; regenerable on demand
  * Sync script is the only committed i18n-related artifact
  * Sample: docs/i18n/ja/intro.md is identical to docs/intro.md
    translated; line counts within 5% of EN across all languages

Total: 0 ADRs (template only) → 5 ADRs, 0 → 2 governance docs.
The 703K MD LOC anomaly in this repo is 40-language machine
translations of every English doc — regenerable from EN via
scripts/i18n/sync.mjs (the only committed i18n tooling).

Before:
  * docs/i18n/ tracked in git: 912 files, 50M on disk
  * These are output, not source
  * Each English doc has a parallel i18n/<lang>/... tree with
    line counts within 5% of the EN version (proves they're
    translations, not new content)

After:
  * docs/i18n/ gitignored: see .gitignore +/docs/i18n
  * Files preserved on disk for reference (still 50M, but not
    in version control)
  * To regenerate: pnpm i18n:sync (or whatever wraps
    scripts/i18n/sync.mjs)

This single change reclaims 682K MD LOC from the working tree
without losing any content. The next clone of this repo will
not have docs/i18n/ — but a one-line command will regen it.

The English docs (docs/*.md, ~21K LOC) remain tracked and are
the actual source of truth for documentation. i18n is a
build-time artifact, like dist/ or build/.

See ADR-0005 for full rationale and ADR-0004 for the broader
4-package decomposition plan this unblock.
Adds .github/scorecard.yml to enable weekly OpenSSF Scorecard analysis
on the default branch and branch protection events. Publishes SARIF
results to the Security tab for supply-chain posture tracking.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@codeant-ai

codeant-ai Bot commented Jun 10, 2026

Copy link
Copy Markdown

Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters.

If you still want a review, comment @codeant-ai : review. For better signal, consider splitting the PR into smaller chunks.

@coderabbitai

coderabbitai Bot commented Jun 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 300 files, which is 150 over the limit of 150.

To get a review, narrow the scope:
• coderabbit review --type committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: c2f63d91-2a7a-4170-abe5-6af5ff1a3993

📥 Commits

Reviewing files that changed from the base of the PR and between 44bc47a and e96abae.

📒 Files selected for processing (300)
  • .editorconfig
  • .github/CODEOWNERS
  • .github/dependabot.yml
  • .github/scorecard.yml
  • .github/workflows/scorecard.yml
  • .gitignore
  • CHANGELOG.md
  • Justfile
  • LICENSE
  • LICENSE-APACHE
  • LICENSE-MIT
  • PLAN.md
  • SPEC.md
  • docs/SSOT.md
  • docs/adr/0001-record-architecture-decisions.md
  • docs/adr/0002-test-runner-vitest-vs-jest.md
  • docs/adr/0003-coverage-floor-70-pct.md
  • docs/adr/0004-decomposition-into-packages.md
  • docs/adr/0005-i18n-gitignore-strategy.md
  • docs/i18n/README.md
  • docs/i18n/ar/CHANGELOG.md
  • docs/i18n/ar/CLAUDE.md
  • docs/i18n/ar/CONTRIBUTING.md
  • docs/i18n/ar/README.md
  • docs/i18n/ar/docs/architecture/ARCHITECTURE.md
  • docs/i18n/ar/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/ar/docs/frameworks/A2A-SERVER.md
  • docs/i18n/ar/docs/frameworks/MCP-SERVER.md
  • docs/i18n/ar/docs/guides/FEATURES.md
  • docs/i18n/ar/docs/guides/I18N.md
  • docs/i18n/ar/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/ar/docs/guides/UNINSTALL.md
  • docs/i18n/ar/docs/guides/USER_GUIDE.md
  • docs/i18n/ar/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/ar/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/ar/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/ar/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/ar/docs/reference/API_REFERENCE.md
  • docs/i18n/ar/docs/reference/CLI-TOOLS.md
  • docs/i18n/ar/docs/reference/ENVIRONMENT.md
  • docs/i18n/ar/docs/routing/AUTO-COMBO.md
  • docs/i18n/ar/llm.txt
  • docs/i18n/az/CHANGELOG.md
  • docs/i18n/az/CLAUDE.md
  • docs/i18n/az/CODE_OF_CONDUCT.md
  • docs/i18n/az/CONTRIBUTING.md
  • docs/i18n/az/GEMINI.md
  • docs/i18n/az/README.md
  • docs/i18n/az/SECURITY.md
  • docs/i18n/az/docs/architecture/ARCHITECTURE.md
  • docs/i18n/az/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/az/docs/cloudflare-zero-trust-guide.md
  • docs/i18n/az/docs/features/context-relay.md
  • docs/i18n/az/docs/frameworks/A2A-SERVER.md
  • docs/i18n/az/docs/frameworks/MCP-SERVER.md
  • docs/i18n/az/docs/guides/FEATURES.md
  • docs/i18n/az/docs/guides/I18N.md
  • docs/i18n/az/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/az/docs/guides/UNINSTALL.md
  • docs/i18n/az/docs/guides/USER_GUIDE.md
  • docs/i18n/az/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/az/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/az/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/az/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/az/docs/reference/API_REFERENCE.md
  • docs/i18n/az/docs/reference/CLI-TOOLS.md
  • docs/i18n/az/docs/reference/ENVIRONMENT.md
  • docs/i18n/az/docs/routing/AUTO-COMBO.md
  • docs/i18n/az/llm.txt
  • docs/i18n/bg/CHANGELOG.md
  • docs/i18n/bg/CLAUDE.md
  • docs/i18n/bg/CONTRIBUTING.md
  • docs/i18n/bg/README.md
  • docs/i18n/bg/docs/architecture/ARCHITECTURE.md
  • docs/i18n/bg/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/bg/docs/frameworks/A2A-SERVER.md
  • docs/i18n/bg/docs/frameworks/MCP-SERVER.md
  • docs/i18n/bg/docs/guides/FEATURES.md
  • docs/i18n/bg/docs/guides/I18N.md
  • docs/i18n/bg/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/bg/docs/guides/UNINSTALL.md
  • docs/i18n/bg/docs/guides/USER_GUIDE.md
  • docs/i18n/bg/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/bg/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/bg/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/bg/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/bg/docs/reference/API_REFERENCE.md
  • docs/i18n/bg/docs/reference/CLI-TOOLS.md
  • docs/i18n/bg/docs/reference/ENVIRONMENT.md
  • docs/i18n/bg/docs/routing/AUTO-COMBO.md
  • docs/i18n/bg/llm.txt
  • docs/i18n/bn/CHANGELOG.md
  • docs/i18n/bn/CLAUDE.md
  • docs/i18n/bn/CONTRIBUTING.md
  • docs/i18n/bn/README.md
  • docs/i18n/bn/docs/architecture/ARCHITECTURE.md
  • docs/i18n/bn/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/bn/docs/frameworks/A2A-SERVER.md
  • docs/i18n/bn/docs/frameworks/MCP-SERVER.md
  • docs/i18n/bn/docs/guides/FEATURES.md
  • docs/i18n/bn/docs/guides/I18N.md
  • docs/i18n/bn/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/bn/docs/guides/UNINSTALL.md
  • docs/i18n/bn/docs/guides/USER_GUIDE.md
  • docs/i18n/bn/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/bn/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/bn/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/bn/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/bn/docs/reference/API_REFERENCE.md
  • docs/i18n/bn/docs/reference/CLI-TOOLS.md
  • docs/i18n/bn/docs/reference/ENVIRONMENT.md
  • docs/i18n/bn/docs/routing/AUTO-COMBO.md
  • docs/i18n/bn/llm.txt
  • docs/i18n/cs/CHANGELOG.md
  • docs/i18n/cs/CLAUDE.md
  • docs/i18n/cs/CONTRIBUTING.md
  • docs/i18n/cs/README.md
  • docs/i18n/cs/docs/architecture/ARCHITECTURE.md
  • docs/i18n/cs/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/cs/docs/frameworks/A2A-SERVER.md
  • docs/i18n/cs/docs/frameworks/MCP-SERVER.md
  • docs/i18n/cs/docs/guides/FEATURES.md
  • docs/i18n/cs/docs/guides/I18N.md
  • docs/i18n/cs/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/cs/docs/guides/UNINSTALL.md
  • docs/i18n/cs/docs/guides/USER_GUIDE.md
  • docs/i18n/cs/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/cs/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/cs/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/cs/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/cs/docs/reference/API_REFERENCE.md
  • docs/i18n/cs/docs/reference/CLI-TOOLS.md
  • docs/i18n/cs/docs/reference/ENVIRONMENT.md
  • docs/i18n/cs/docs/routing/AUTO-COMBO.md
  • docs/i18n/cs/llm.txt
  • docs/i18n/da/CHANGELOG.md
  • docs/i18n/da/CLAUDE.md
  • docs/i18n/da/CONTRIBUTING.md
  • docs/i18n/da/README.md
  • docs/i18n/da/docs/architecture/ARCHITECTURE.md
  • docs/i18n/da/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/da/docs/frameworks/A2A-SERVER.md
  • docs/i18n/da/docs/frameworks/MCP-SERVER.md
  • docs/i18n/da/docs/guides/FEATURES.md
  • docs/i18n/da/docs/guides/I18N.md
  • docs/i18n/da/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/da/docs/guides/UNINSTALL.md
  • docs/i18n/da/docs/guides/USER_GUIDE.md
  • docs/i18n/da/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/da/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/da/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/da/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/da/docs/reference/API_REFERENCE.md
  • docs/i18n/da/docs/reference/CLI-TOOLS.md
  • docs/i18n/da/docs/reference/ENVIRONMENT.md
  • docs/i18n/da/docs/routing/AUTO-COMBO.md
  • docs/i18n/da/llm.txt
  • docs/i18n/de/CHANGELOG.md
  • docs/i18n/de/CLAUDE.md
  • docs/i18n/de/CONTRIBUTING.md
  • docs/i18n/de/README.md
  • docs/i18n/de/docs/architecture/ARCHITECTURE.md
  • docs/i18n/de/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/de/docs/frameworks/A2A-SERVER.md
  • docs/i18n/de/docs/frameworks/MCP-SERVER.md
  • docs/i18n/de/docs/guides/FEATURES.md
  • docs/i18n/de/docs/guides/I18N.md
  • docs/i18n/de/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/de/docs/guides/UNINSTALL.md
  • docs/i18n/de/docs/guides/USER_GUIDE.md
  • docs/i18n/de/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/de/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/de/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/de/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/de/docs/reference/API_REFERENCE.md
  • docs/i18n/de/docs/reference/CLI-TOOLS.md
  • docs/i18n/de/docs/reference/ENVIRONMENT.md
  • docs/i18n/de/docs/routing/AUTO-COMBO.md
  • docs/i18n/de/llm.txt
  • docs/i18n/es/CHANGELOG.md
  • docs/i18n/es/CLAUDE.md
  • docs/i18n/es/CONTRIBUTING.md
  • docs/i18n/es/README.md
  • docs/i18n/es/docs/architecture/ARCHITECTURE.md
  • docs/i18n/es/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/es/docs/frameworks/A2A-SERVER.md
  • docs/i18n/es/docs/frameworks/MCP-SERVER.md
  • docs/i18n/es/docs/guides/FEATURES.md
  • docs/i18n/es/docs/guides/I18N.md
  • docs/i18n/es/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/es/docs/guides/UNINSTALL.md
  • docs/i18n/es/docs/guides/USER_GUIDE.md
  • docs/i18n/es/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/es/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/es/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/es/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/es/docs/reference/API_REFERENCE.md
  • docs/i18n/es/docs/reference/CLI-TOOLS.md
  • docs/i18n/es/docs/reference/ENVIRONMENT.md
  • docs/i18n/es/docs/routing/AUTO-COMBO.md
  • docs/i18n/es/llm.txt
  • docs/i18n/fa/CHANGELOG.md
  • docs/i18n/fa/CLAUDE.md
  • docs/i18n/fa/CONTRIBUTING.md
  • docs/i18n/fa/README.md
  • docs/i18n/fa/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fa/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fa/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fa/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fa/docs/guides/FEATURES.md
  • docs/i18n/fa/docs/guides/I18N.md
  • docs/i18n/fa/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fa/docs/guides/UNINSTALL.md
  • docs/i18n/fa/docs/guides/USER_GUIDE.md
  • docs/i18n/fa/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fa/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fa/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fa/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fa/docs/reference/API_REFERENCE.md
  • docs/i18n/fa/docs/reference/CLI-TOOLS.md
  • docs/i18n/fa/docs/reference/ENVIRONMENT.md
  • docs/i18n/fa/docs/routing/AUTO-COMBO.md
  • docs/i18n/fa/llm.txt
  • docs/i18n/fi/CHANGELOG.md
  • docs/i18n/fi/CLAUDE.md
  • docs/i18n/fi/CONTRIBUTING.md
  • docs/i18n/fi/README.md
  • docs/i18n/fi/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fi/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fi/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fi/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fi/docs/guides/FEATURES.md
  • docs/i18n/fi/docs/guides/I18N.md
  • docs/i18n/fi/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fi/docs/guides/UNINSTALL.md
  • docs/i18n/fi/docs/guides/USER_GUIDE.md
  • docs/i18n/fi/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fi/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fi/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fi/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fi/docs/reference/API_REFERENCE.md
  • docs/i18n/fi/docs/reference/CLI-TOOLS.md
  • docs/i18n/fi/docs/reference/ENVIRONMENT.md
  • docs/i18n/fi/docs/routing/AUTO-COMBO.md
  • docs/i18n/fi/llm.txt
  • docs/i18n/fr/CHANGELOG.md
  • docs/i18n/fr/CLAUDE.md
  • docs/i18n/fr/CONTRIBUTING.md
  • docs/i18n/fr/README.md
  • docs/i18n/fr/docs/architecture/ARCHITECTURE.md
  • docs/i18n/fr/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/fr/docs/frameworks/A2A-SERVER.md
  • docs/i18n/fr/docs/frameworks/MCP-SERVER.md
  • docs/i18n/fr/docs/guides/FEATURES.md
  • docs/i18n/fr/docs/guides/I18N.md
  • docs/i18n/fr/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/fr/docs/guides/UNINSTALL.md
  • docs/i18n/fr/docs/guides/USER_GUIDE.md
  • docs/i18n/fr/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/fr/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/fr/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/fr/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/fr/docs/reference/API_REFERENCE.md
  • docs/i18n/fr/docs/reference/CLI-TOOLS.md
  • docs/i18n/fr/docs/reference/ENVIRONMENT.md
  • docs/i18n/fr/docs/routing/AUTO-COMBO.md
  • docs/i18n/fr/llm.txt
  • docs/i18n/gu/CHANGELOG.md
  • docs/i18n/gu/CLAUDE.md
  • docs/i18n/gu/CONTRIBUTING.md
  • docs/i18n/gu/README.md
  • docs/i18n/gu/docs/architecture/ARCHITECTURE.md
  • docs/i18n/gu/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/gu/docs/frameworks/A2A-SERVER.md
  • docs/i18n/gu/docs/frameworks/MCP-SERVER.md
  • docs/i18n/gu/docs/guides/FEATURES.md
  • docs/i18n/gu/docs/guides/I18N.md
  • docs/i18n/gu/docs/guides/TROUBLESHOOTING.md
  • docs/i18n/gu/docs/guides/UNINSTALL.md
  • docs/i18n/gu/docs/guides/USER_GUIDE.md
  • docs/i18n/gu/docs/ops/COVERAGE_PLAN.md
  • docs/i18n/gu/docs/ops/FLY_IO_DEPLOYMENT_GUIDE.md
  • docs/i18n/gu/docs/ops/RELEASE_CHECKLIST.md
  • docs/i18n/gu/docs/ops/VM_DEPLOYMENT_GUIDE.md
  • docs/i18n/gu/docs/reference/API_REFERENCE.md
  • docs/i18n/gu/docs/reference/CLI-TOOLS.md
  • docs/i18n/gu/docs/reference/ENVIRONMENT.md
  • docs/i18n/gu/docs/routing/AUTO-COMBO.md
  • docs/i18n/gu/llm.txt
  • docs/i18n/he/CHANGELOG.md
  • docs/i18n/he/CLAUDE.md
  • docs/i18n/he/CONTRIBUTING.md
  • docs/i18n/he/README.md
  • docs/i18n/he/docs/architecture/ARCHITECTURE.md
  • docs/i18n/he/docs/architecture/CODEBASE_DOCUMENTATION.md
  • docs/i18n/he/docs/frameworks/A2A-SERVER.md
  • docs/i18n/he/docs/frameworks/MCP-SERVER.md
  • docs/i18n/he/docs/guides/FEATURES.md
  • docs/i18n/he/docs/guides/I18N.md
  • docs/i18n/he/docs/guides/TROUBLESHOOTING.md

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/6th-hygiene-2026-06-08
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch chore/6th-hygiene-2026-06-08

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds repository configuration, governance files, and architectural decision records (ADRs) to establish testing, decomposition, and localization policies. Feedback highlights several style guide violations, notably that the proposed 70% test coverage floor falls below the repository's 75% requirement, and that placing Justfile, PLAN.md, and SPEC.md in the root violates file organization rules. Additionally, the new Justfile should be updated to use pnpm instead of npm for consistency, and its clean command should target Next.js and Electron build outputs.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread PLAN.md

### In Progress
- [ ] **Coverage governance** — `.codecov.yml`, `vitest.config.ts` coverage, `coverage.yml` workflow
- [ ] **Test coverage floor (70%)** — see ADR-0003

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The planned test coverage floor of 70% conflicts with the repository's established Hard Rules (Section 2, Rule 10), which mandates: 'Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches'. Please update the plan to target the required 75% threshold to remain compliant with the repository's hard rules.

References
  1. Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)

Comment thread SPEC.md

- **Unit + integration tests** under `tests/` (vitest, not jest — see ADR-0002)
- **E2E** under `tests/e2e/` (Playwright)
- **Coverage floor**: 70% (see ADR-0003 for rationale)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The specified coverage floor of 70% conflicts with the repository's established Hard Rules (Section 2, Rule 10), which requires at least 75% statements/lines/functions and 70% branches. Please update this specification to align with the repository's coverage requirements.

References
  1. Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)

Comment on lines +20 to +22
**70% lines + 60% branches** is the coverage floor for `OmniRoute/src/lib/`
(critical paths). **50% lines** is the floor for `src/components/` and
`src/app/`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The proposed coverage floor of 70% lines / 60% branches for src/lib/ and 50% lines for UI components directly conflicts with the repository's established Hard Rules (Section 2, Rule 10), which states: 'Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches'. Please align the proposed thresholds in this ADR with the repository's hard rules, or seek explicit operator approval to update the style guide's coverage policy.

References
  1. Coverage must stay ≥ 75 % statements / 75 % lines / 75 % functions / 70 % branches (link)

Comment thread Justfile
@@ -0,0 +1,26 @@
# OmniRoute Justfile

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed configuration files. Justfile is not currently on this allowed list. Since Justfile must reside in the root directory to be detected by the just runner, please update the Repository Style Guide (e.g., in GEMINI.md or CLAUDE.md) to explicitly allow Justfile in the root, or consider alternative task runners if root cleanliness is strictly enforced.

References
  1. The Project Root MUST ONLY CONTAIN: [list of allowed configuration, dependency, documentation, and CI/CD files] (link)

Comment thread Justfile
Comment on lines +7 to +14
install:
npm install

build:
npm run build

test:
npm test

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The project's ADRs and monorepo structure indicate that pnpm is the chosen package manager. However, the Justfile commands are currently using npm (npm install, npm run build, npm test). Please update these commands to use pnpm to maintain consistency and avoid generating a package-lock.json file.

install:
    pnpm install

build:
    pnpm build

test:
    pnpm test

Comment thread Justfile
Comment on lines +16 to +18
lint:
npx eslint . --ext .ts
npx prettier --check "**/*.ts"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Instead of hardcoding npx eslint . --ext .ts, it is recommended to run the project's configured lint script (e.g., pnpm lint). This ensures that the correct file extensions (like .tsx, .js, etc.) and configurations defined in package.json are checked. Also, use pnpm exec or pnpm for running prettier.

lint:
    pnpm lint
    pnpm exec prettier --check "**/*.ts"

Comment thread Justfile
Comment on lines +25 to +26
clean:
rm -rf node_modules dist

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Since this is a Next.js application, the build output is generated in the .next/ directory rather than dist/. Additionally, Electron builds may output to dist/ or dist-electron/. Update the clean command to clean .next and other relevant build directories.

clean:
    rm -rf node_modules .next dist dist-electron

Comment thread PLAN.md
@@ -0,0 +1,66 @@
# OmniRoute — Plan

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed documentation files (such as README.md, CHANGELOG.md, etc.). PLAN.md is not on this allowed list. Please move PLAN.md to the docs/ directory (e.g., docs/PLAN.md) to comply with the root file organization policy.

References
  1. The Project Root MUST ONLY CONTAIN: [list of allowed documentation files] (link)

Comment thread SPEC.md
@@ -0,0 +1,120 @@
# OmniRoute — Specification

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the Repository Style Guide (Section 1, File Placement & Organization), the project root must only contain specific listed documentation files. SPEC.md is not on this allowed list. Please move SPEC.md to the docs/ directory (e.g., docs/SPEC.md) to comply with the root file organization policy.

References
  1. The Project Root MUST ONLY CONTAIN: [list of allowed documentation files] (link)

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 4 potential issues.

Fix All in Cursor

Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issues.

Reviewed by Cursor Bugbot for commit e96abae. Configure here.

Comment thread .github/scorecard.yml
with:
results_file: results.sarif
results_format: sarif
publish_results: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scorecard YAML not workflow

Medium Severity

The new scorecard job is saved as .github/scorecard.yml, but GitHub Actions only runs workflows under .github/workflows/. This file never executes, so it does not perform analysis or publish SARIF despite matching workflow syntax and triggers described in the PR.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e96abae. Configure here.

Comment thread .github/scorecard.yml
with:
results_file: results.sarif
results_format: sarif
publish_results: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scorecard step missing checkout

High Severity

The analysis job runs ossf/scorecard-action without an actions/checkout step first. Scorecard needs repository contents on disk; without checkout the run fails or analyzes an empty workspace, so SARIF would not reflect this repo.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e96abae. Configure here.

Comment thread .github/scorecard.yml
runs-on: ubuntu-latest
steps:
- name: Run analysis
uses: ossf/scorecard-action@4e7e316b1fcd3a4b6e10a49c3c9c5b8b6e6e6e6e

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Invalid scorecard action pin

High Severity

ossf/scorecard-action is pinned to commit 4e7e316b1fcd3a4b6e10a49c3c9c5b8b6e6e6e6e, which does not match the working pin in .github/workflows/scorecard.yml and reads like a placeholder. Action resolution would fail once this workflow runs.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e96abae. Configure here.

Comment thread .github/CODEOWNERS
/crates/ @KooshaPari

# CI ownership
/.github/workflows/ @KooshaPari

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Root CODEOWNERS now ignored

Medium Severity

Adding .github/CODEOWNERS makes GitHub ignore the existing root CODEOWNERS. Updates to the root file no longer affect review assignments, which can silently drop intended owners.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e96abae. Configure here.

@KooshaPari

Copy link
Copy Markdown
Owner Author

Superseded by #30 for Scorecard workflow/CODEOWNERS/dependabot coverage. Closing because this branch's diff also includes a large unrelated docs/metadata import, making it unsafe to review as a small hygiene PR.

@KooshaPari KooshaPari closed this Jun 10, 2026
@KooshaPari
KooshaPari deleted the chore/6th-hygiene-2026-06-08 branch July 2, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant