Repository navigation
fix(web): add v0.27.0 changelog entry and clarify release-data ownership - #2075
Conversation
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 9 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe change adds a reusable release-entry synchronizer, integrates it with Release Please automation, records version ChangesWeb release synchronization
Estimated code review effort: 3 (Moderate) | ~25 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 6 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (6 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@web/src/data/releases.ts`:
- Around line 20-31: Add a focused test for the release data exported by
web/src/data/releases.ts, verifying releases[0] has version 0.27.0, date
2026-07-30, and exactly the expected five highlights. Keep the test scoped to
the new release entry and use the existing test conventions.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 69f5d796-d4ab-422c-8da6-1bf96ed12f62
📒 Files selected for processing (1)
web/src/data/releases.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
TypeScript code in this repository must use strict mode and ESM imports.
**/*.{ts,tsx}: Add or update tests when a TypeScript or TSX change affects behavior.
Run the relevant TypeScript validation checks for changed code, includingbun run typecheckand, when applicable,bun run typecheck:type-tests.
Files:
web/src/data/releases.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*: Preserve existing repository patterns unless intentionally refactoring them.
Keep changes small, readable, and focused; avoid broad rewrites or unrelated cleanup.
Do not reformat unrelated files, and keep comments useful and concise.
Update documentation when setup, commands, or user-facing behavior changes.
Review AI-generated changes for correctness, style consistency, unnecessary noise, and adherence to project architecture before submitting them.
Provider changes must follow the documented integration patterns indocs/integrations/overview.mdand the focused guides underdocs/integrations/how-to/.
When changing provider behavior, avoid breaking third-party providers and test the exact provider/model path changed when possible.
Provider pull requests must explicitly identify affected providers, limitations, and follow-up work.
Run the narrowest meaningful validation command for the touched area, and ensure relevant CI checks pass before merging.
Usebun installto install dependencies and the repository's Bun scripts for building, testing, smoke testing, and development.
Dependency changes require a concrete project benefit such as a bug fix, security issue, or approved feature; preference alone is insufficient.
Do not change the project's language, core runtime, or dependency stack, or introduce a new runtime, without prior maintainer agreement.
Keep each pull request focused on one issue or clearly scoped improvement and avoid bundling unrelated fixes, features, or refactors.
Files:
web/src/data/releases.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
web/src/data/releases.ts
web/**/*.{ts,tsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing the web application, run
bun run web:typecheckandbun run web:build.
Files:
web/src/data/releases.ts
web/**
⚙️ CodeRabbit configuration file
web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.
Files:
web/src/data/releases.ts
|
@kevincodex1 please merge right away; it should resolve the broken smoke test on main,. |
Tell agents and contributors that the curated changelog is owned by the release/web process, and stop verify-dist from instructing unrelated PRs to patch it when npm publishes ahead of the site.
There was a problem hiding this comment.
Actionable comments posted: 6
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
web/scripts/verify-dist.test.ts (1)
63-78: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick winPreserve the first-entry invariant in this test.
web/src/data/releases.tsderiveslatestVersionfromreleases[0].versionon Line 146.releases.find(...)only verifies that0.27.0exists. It allows an older release to remain first, which makes the site version stale while this test still passes.Add this assertion, or compare the complete expected record at index zero:
Proposed test change
test('keeps the 0.27.0 release with its curated highlights', () => { + expect(releases[0]?.version).toBe('0.27.0') expect(releases.find(release => release.version === '0.27.0')).toEqual({Run
bun test web/scripts/verify-dist.test.ts.As per coding guidelines: “Add or update tests when a TypeScript or TSX change affects behavior.” As per path instructions: “Review tests for meaningful coverage of the changed behavior.”
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@web/scripts/verify-dist.test.ts` around lines 63 - 78, Update the 0.27.0 release test to also assert that the expected release is the first entry in the releases collection, preserving the latestVersion invariant derived from releases[0].version. Keep the existing complete-record assertion and run the targeted verify-dist test.Sources: Coding guidelines, Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 32-41: Update the “Check out Release Please PR branch”
actions/checkout step to set persist-credentials to false, preventing the token
from remaining in git configuration during installs, tests, and builds. Provide
authentication only immediately before or within the “Commit synced web release
entry” push step, using the existing GITHUB_TOKEN and preserving the final push
behavior.
- Around line 42-46: Disable Bun executable caching in the “Set up Bun for
release PR sync” step by configuring its setup-bun inputs with no-cache enabled.
Keep the existing bun-version-file configuration and conditional execution
unchanged.
In `@package.json`:
- Line 61: No code change is required for the sync:web-release script entry;
before merging, have a human confirm that bun run typecheck, bun test
scripts/sync-web-release-entry.test.ts, and all GitHub Checks pass.
In `@scripts/sync-web-release-entry.test.ts`:
- Around line 47-59: Add a test in the parseChangelogSection suite using a
changelog fixture containing more than five highlight bullets, and assert the
returned highlights array includes only the first five entries, directly
exercising the cap behavior.
- Around line 137-143: Extend the deriveTheme test suite with cases for an empty
highlights array returning “release highlights,” a highlight without a scope
prefix being preserved, and a highlight exceeding 72 characters being truncated
with an ellipsis. Keep the existing scope-prefix-stripping test unchanged.
- Around line 61-135: Add two tests in the syncWebReleaseEntry suite for its
validation errors: one using a changelog without the requested manifest version
section, and another using a matching section with no bullet highlights. Assert
that each syncWebReleaseEntry call throws the corresponding expected error
message.
---
Outside diff comments:
In `@web/scripts/verify-dist.test.ts`:
- Around line 63-78: Update the 0.27.0 release test to also assert that the
expected release is the first entry in the releases collection, preserving the
latestVersion invariant derived from releases[0].version. Keep the existing
complete-record assertion and run the targeted verify-dist test.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: d7a85729-0488-4e91-8956-1cbea266ce8f
📒 Files selected for processing (9)
.github/workflows/release.ymlAGENTS.mdCONTRIBUTING.mdpackage.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.tsweb/scripts/verify-dist.test.tsweb/scripts/verify-dist.tsweb/src/data/releases.ts
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: smoke-and-tests (22)
- GitHub Check: smoke-and-tests (24.11.x)
- GitHub Check: typecheck
🧰 Additional context used
📓 Path-based instructions (13)
**/*
📄 CodeRabbit inference engine (AGENTS.md)
**/*: Keep changes focused on one problem and avoid unrelated formatting, renames, dependency changes, or broad rewrites.
Prefer existing patterns in the file or nearby module over introducing new abstractions.
Update documentation when setup, commands, provider behavior, or user-facing behavior changes.
Use Bun for source builds, scripts, dependency management, and tests; the installed CLI must run on Node.js >=22.0.0.
For new features, larger refactors, dependency changes, or runtime changes, follow the issue-first guidance in CONTRIBUTING.md.
Run the narrowest useful validation checks for each change and list the exact commands in the PR.
Do not change the Node runtime or Bun development workflow without prior maintainer agreement.
Do not introduce dependencies without clear project benefit.
Do not skip tests for behavior changes.
Do not silently change provider tags; maintainers control them during review.
Address CodeRabbit or maintainer feedback before requesting more review.
**/*: Preserve existing repository patterns and architecture unless the change intentionally refactors them; avoid broad rewrites and unrelated cleanup.
Update documentation when setup instructions, commands, or user-facing behavior changes.
Review AI-assisted or generated code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Keep each pull request focused on one problem or clearly scoped feature, and do not mix unrelated fixes, features, refactors, or cleanup.
Dependency changes require a concrete project benefit, such as fixing a bug, addressing a security issue, or supporting an approved feature.
Run the relevant validation checks locally before submitting; pull requests that fail CI checks will not be merged.
Provider changes must explicitly identify affected providers, test the changed provider/model path when possible, and must not assign or use provider tags.
Do not change the project language, core runtime, o...
Files:
package.jsonweb/scripts/verify-dist.tsAGENTS.mdscripts/sync-web-release-entry.test.tsCONTRIBUTING.mdweb/src/data/releases.tsweb/scripts/verify-dist.test.tsscripts/sync-web-release-entry.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
package.jsonweb/scripts/verify-dist.tsAGENTS.mdscripts/sync-web-release-entry.test.tsCONTRIBUTING.mdweb/src/data/releases.tsweb/scripts/verify-dist.test.tsscripts/sync-web-release-entry.ts
**/package.json
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing JavaScript or TypeScript dependencies, explain the concrete project benefit rather than relying only on preference-based reasoning.
Files:
package.json
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
package.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
**/*.{ts,tsx}: Add or update tests when TypeScript or React behavior changes.
Use TypeScript strict mode and ESM imports.Maintain type correctness by running
bun run typecheckandbun run typecheck:type-testsfor relevant TypeScript changes.
Files:
web/scripts/verify-dist.tsscripts/sync-web-release-entry.test.tsweb/src/data/releases.tsweb/scripts/verify-dist.test.tsscripts/sync-web-release-entry.ts
web/**/*
📄 CodeRabbit inference engine (AGENTS.md)
When changing the web documentation site, run web:typecheck and web:build.
Files:
web/scripts/verify-dist.tsweb/src/data/releases.tsweb/scripts/verify-dist.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched JavaScript and TypeScript files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Add or update tests when a JavaScript or TypeScript change affects behavior.
Files:
web/scripts/verify-dist.tsscripts/sync-web-release-entry.test.tsweb/src/data/releases.tsweb/scripts/verify-dist.test.tsscripts/sync-web-release-entry.ts
**/web/**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing the web application, run the web typecheck and web build checks.
Files:
web/scripts/verify-dist.tsweb/src/data/releases.tsweb/scripts/verify-dist.test.ts
web/**
⚙️ CodeRabbit configuration file
web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.
Files:
web/scripts/verify-dist.tsweb/src/data/releases.tsweb/scripts/verify-dist.test.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Use focused tests for the affected behavior and run the narrowest meaningful test command for the touched area.
Files:
scripts/sync-web-release-entry.test.tsweb/scripts/verify-dist.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
scripts/sync-web-release-entry.test.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
web/src/data/releases.ts
📄 CodeRabbit inference engine (AGENTS.md)
Do not edit web/src/data/releases.ts in ordinary feature or bugfix PRs; release automation and dedicated web release PRs own it.
Do not edit
web/src/data/releases.tsduring ordinary feature or bug-fix work; modify it only in an explicit release/web changelog PR.
Files:
web/src/data/releases.ts
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🪛 ast-grep (0.45.0)
scripts/sync-web-release-entry.ts
[warning] 40-43: Regular expression constructed from variable input detected. This can lead to Regular Expression Denial of Service (ReDoS) attacks if the variable contains malicious patterns. Use libraries like 'recheck' to validate regex safety or use static patterns.
Context: new RegExp(
^## \\[${escapeRegExp(target)}\\][^\\n]*\\((\\d{4}-\\d{2}-\\d{2})\\)\\s*$,
'm',
)
Note: [CWE-1333] Inefficient Regular Expression Complexity
(regexp-from-variable)
🪛 LanguageTool
AGENTS.md
[uncategorized] ~77-~77: The official name of this software platform is spelled with a capital “H”.
Context: ...rift for the Release Please/web path in .github/workflows/release.yml. Diagnostics an...
(GITHUB)
[style] ~104-~104: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...ess it before requesting more review. - Do not edit web/src/data/releases.ts in ...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[uncategorized] ~104-~104: The official name of this software platform is spelled with a capital “H”.
Context: ...he Release Please workflow syncs it via .github/workflows/release.yml) and dedicated w...
(GITHUB)
CONTRIBUTING.md
[uncategorized] ~137-~137: The official name of this software platform is spelled with a capital “H”.
Context: ...hangelog PR. Release Please automation (.github/workflows/release.yml) and dedicated w...
(GITHUB)
🪛 zizmor (1.28.0)
.github/workflows/release.yml
[warning] 35-40: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 44-44: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
🔇 Additional comments (11)
web/src/data/releases.ts (1)
4-8: LGTM!Also applies to: 25-36
web/scripts/verify-dist.test.ts (1)
162-163: LGTM!web/scripts/verify-dist.ts (1)
116-116: LGTM!AGENTS.md (1)
77-78: LGTM!Also applies to: 104-104
CONTRIBUTING.md (1)
106-106: LGTM!Also applies to: 137-137, 155-156
scripts/sync-web-release-entry.ts (3)
1-84: LGTM!
165-187: LGTM!
86-91: 🗄️ Data Integrity & IntegrationNo formatter currently rewrites
web/src/data/releases.ts.The release workflow runs the sync script, tests, and the web build. The build runs
astro check,astro build, andverify-dist, not a formatter.readCurrentTopVersionandinsertReleaseEntrydo not require two-space indentation; onlyremoveReleasePleaseDraftdoes.> Likely an incorrect or invalid review comment.scripts/sync-web-release-entry.test.ts (1)
1-45: LGTM!Also applies to: 145-156
.github/workflows/release.yml (2)
48-55: LGTM!
57-69: LGTM!The scoped
git diff --quiet -- web/src/data/releases.tscheck andgit addtargeting only that path correctly avoid committing unrelated build artifacts frombun run --cwd web build.
|
still draft bro @jatmn |
a7b1f16 to
01e40a2
Compare
|
@kevincodex1 LGTM |
Summary
Impact
Validation
bun test ./web/scripts/verify-dist.test.ts— 16 passed, 0 failedbun run web:typecheck— 0 diagnosticsbun run web:build— 13 pages built;verify-distpassedbun run security:pr-scan -- --base b3735bedb3962b10a5735010ecd92d934fa80d6a— no suspicious additionsgit diff --checkScope
01e40a2728d57b0282bdf070bd12821fae33aea7