Promote dev to stable: update diagnostics cleanup - #2477
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughBump package and plugin versions to 4.260522.14, upgrade GitHub Actions checkout/upload steps to v5, add Biome ignores for docs and a symlink-cycle test path, and refactor genie diagnostics with helpers and tests for process-line filtering and pgserve-port extraction. ChangesRelease, CI, config, and diagnostics updates
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request updates the project version to 4.260522.12 across several configuration files and refactors the diagnostic process snapshot collection logic. The changes introduce a dedicated filtering function to exclude noise from database-related processes while retaining relevant Genie service lines. A review comment points out that the filter for ' serve start ' is fragile because a preceding trim operation might remove the trailing space, potentially causing the check to fail if no arguments follow the command.
| export function isGenieProcessSnapshotLine(line: string): boolean { | ||
| if (/pgserve|autopg|postgres-server\.js|postgres -D /.test(line)) return false; | ||
| return ( | ||
| line.includes(' serve start ') || |
There was a problem hiding this comment.
The trailing space in ' serve start ' makes the filter fragile. If the genie serve start command is invoked without additional arguments (like --daemon), the line.trim() call on line 1251 will remove any trailing whitespace from the ps output, causing this includes check to fail. Removing the trailing space ensures it matches both cases correctly.
| line.includes(' serve start ') || | |
| line.includes(' serve start') || |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release-orphan-alert.yml:
- Line 46: The workflow currently uses the mutable reference "uses:
actions/checkout@v5" and leaves credential persistence on; update that step to a
pinned reference (replace the mutable tag with a fixed version or full commit
SHA for actions/checkout) and add a with: block setting persist-credentials:
false so the job does not configure GITHUB_TOKEN for read-only operations;
target the checkout step that currently reads "uses: actions/checkout@v5" and
change it to a pinned ref and include persist-credentials: false.
In @.github/workflows/release-publish.yml:
- Line 97: Replace the mutable ref "uses: actions/checkout@v5" with the
immutable commit SHA for the actions/checkout v5 release (e.g. "uses:
actions/checkout@<commit-sha>") to mitigate supply-chain risk; fetch the exact
SHA from the actions/checkout repository tag for v5 and update the line, keeping
any existing "with:" inputs (such as persist-credentials or token) unchanged so
credentials/behavior remain identical.
In @.github/workflows/sign-attest.yml:
- Line 198: The checkout action in the sign job is unpinned and leaves
credentials persisted; update the checkout step (the uses: actions/checkout@v5
entry inside the sign job) to a pinned immutable commit (replace the tag with
the full commit SHA for the actions/checkout v5 release) and add a with: block
containing persist-credentials: false (and optionally fetch-depth: 0) so no
credentials are stored for a job that does not push commits.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 8019ed91-80eb-44a2-b5f3-4a88dd94dbd4
📒 Files selected for processing (14)
.claude-plugin/marketplace.json.github/workflows/audit-next-tag.yml.github/workflows/binary-sha-drift.yml.github/workflows/build-tarballs.yml.github/workflows/ci.yml.github/workflows/release-orphan-alert.yml.github/workflows/release-publish.yml.github/workflows/sign-attest.ymlbiome.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/package.jsonsrc/genie-commands/__tests__/update.test.tssrc/genie-commands/update.ts
| timeout-minutes: 5 | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v5 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/release-orphan-alert.yml"
echo "== File =="
wc -l "$FILE"
echo
echo "== Lines 1-120 =="
nl -ba "$FILE" | sed -n '1,140p'
echo
echo "== Find actions/checkout usage =="
rg -n "uses:\s*actions/checkout@" "$FILE" || true
echo
echo "== Find persist-credentials / token / git commands =="
rg -n "persist-credentials|with:\s*$|token:|git\s+(fetch|tag|log|push)" "$FILE" || trueRepository: automagik-dev/genie
Length of output: 202
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/release-orphan-alert.yml"
echo "== checkout usages =="
rg -n "uses:\s*actions/checkout@" "$FILE" || true
echo
echo "== persist-credentials / token / checkout inputs around checkout =="
sed -n '35,80p' "$FILE" | cat -n
echo
echo "== Find persist-credentials / token / git commands in whole file =="
rg -n "persist-credentials|token:|with:\s*|git\s+(fetch|tag|log|push)" "$FILE" || true
echo
echo "== Show full file with line numbers (small enough) =="
cat -n "$FILE"Repository: automagik-dev/genie
Length of output: 8105
🌐 Web query:
GitHub actions/checkout persist-credentials default value true/false documentation
💡 Result:
The persist-credentials input in actions/checkout defaults to true. The action’s README states: “Whether to configure the token or SSH key with the local git config” and shows “# Default: true” for persist-credentials. [1][2][3] If you set persist-credentials: false, the token is not persisted in the local git config (and is intended to be opted out of); otherwise the token/credentials are persisted for subsequent steps and are removed during post-job cleanup. [1][3]
Citations:
- 1: https://github.com/actions/checkout/?tab=readme-ov-file
- 2: https://github.com/actions/checkout/tree/refs/heads/main
- 3: https://github.com/actions/checkout
Pin actions/checkout and disable credential persistence in this read-only job
.github/workflows/release-orphan-alert.yml line 46 uses the mutable actions/checkout@v5, and actions/checkout defaults persist-credentials to true, so it configures GITHUB_TOKEN credentials for git even though the workflow only does read-only git operations (git fetch/git tag/git log) and never pushes.
Suggested patch
- - uses: actions/checkout@v5
+ - uses: actions/checkout@<full-commit-sha-for-v5>
+ with:
+ persist-credentials: false🧰 Tools
🪛 zizmor (1.25.2)
[warning] 46-46: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 46-46: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/release-orphan-alert.yml at line 46, The workflow
currently uses the mutable reference "uses: actions/checkout@v5" and leaves
credential persistence on; update that step to a pinned reference (replace the
mutable tag with a fixed version or full commit SHA for actions/checkout) and
add a with: block setting persist-credentials: false so the job does not
configure GITHUB_TOKEN for read-only operations; target the checkout step that
currently reads "uses: actions/checkout@v5" and change it to a pinned ref and
include persist-credentials: false.
| timeout-minutes: 10 | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v5 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/release-publish.yml"
echo "== File = $FILE =="
test -f "$FILE" || { echo "Missing $FILE"; exit 1; }
echo "== Checkout occurrences =="
rg -n "uses:\s*actions/checkout@" "$FILE" || true
echo "== Lines around checkout@v5 =="
# Print a tight window around first occurrence(s)
rg -n "uses:\s*actions/checkout@v5" "$FILE" | cut -d: -f1 | head -n 20 | while read -r ln; do
start=$((ln-10)); end=$((ln+10));
echo "--- around line $ln ($start-$end) ---"
sed -n "${start},${end}p" "$FILE" | nl -ba -w2 -s' | '
done
echo "== persist-credentials / git push presence =="
rg -n "persist-credentials|git push|push origin|checkout@v" "$FILE" || true
echo "== timeout-minutes presence =="
rg -n "timeout-minutes" "$FILE" || true
echo "== caching keys presence =="
rg -n "actions/cache|cache" "$FILE" || trueRepository: automagik-dev/genie
Length of output: 303
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/release-publish.yml"
echo "== Checkout occurrences =="
rg -n "uses:\s*actions/checkout@" "$FILE" || true
echo "== Context around actions/checkout@v5 (line(s) found) =="
rg -n "uses:\s*actions/checkout@v5" "$FILE" | cut -d: -f1 | head -n 20 | while read -r ln; do
start=$((ln-15)); end=$((ln+15));
echo "--- around line $ln (${start}-${end}) ---"
sed -n "${start},${end}p" "$FILE"
done
echo "== persist-credentials / git push presence =="
rg -n "persist-credentials|git push|push origin|checkout@" "$FILE" || true
echo "== timeout-minutes presence =="
rg -n "timeout-minutes" "$FILE" || true
echo "== caching keys presence =="
rg -n "actions/cache|cache" "$FILE" || trueRepository: automagik-dev/genie
Length of output: 1631
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/release-publish.yml"
echo "== persist-credentials occurrences =="
rg -n "persist-credentials" "$FILE" || true
echo "== git push occurrences =="
rg -n "git push" "$FILE" || true
rg -n "push origin" "$FILE" || true
echo "== checkout step options near line 97 =="
sed -n '90,110p' "$FILE" | nl -ba -w2 -s' | ' || sed -n '90,110p' "$FILE"
echo "== Context around git push (around first match) =="
first=$(rg -n "git push" "$FILE" | head -n1 | cut -d: -f1 || true)
if [[ -n "${first:-}" ]]; then
start=$((first-25)); end=$((first+25));
sed -n "${start},${end}p" "$FILE"
fi
echo "== Any other actions/checkout uses (including non-v5) =="
rg -n "uses:\s*actions/checkout@" "$FILE" || trueRepository: automagik-dev/genie
Length of output: 2584
Pin actions/checkout to an immutable commit SHA (don’t use mutable @v5) in the release publish workflow.
The workflow uses actions/checkout@v5 at the checkout step; since it later runs git push origin main, keep credentials behavior as-is and address the supply-chain risk by SHA-pinning.
Suggested patch
- - uses: actions/checkout@v5
+ - uses: actions/checkout@<full-commit-sha-for-v5>🧰 Tools
🪛 zizmor (1.25.2)
[warning] 97-97: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 97-97: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/release-publish.yml at line 97, Replace the mutable ref
"uses: actions/checkout@v5" with the immutable commit SHA for the
actions/checkout v5 release (e.g. "uses: actions/checkout@<commit-sha>") to
mitigate supply-chain risk; fetch the exact SHA from the actions/checkout
repository tag for v5 and update the line, keeping any existing "with:" inputs
(such as persist-credentials or token) unchanged so credentials/behavior remain
identical.
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v5 |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/sign-attest.yml"
echo "== File: $FILE =="
ls -l "$FILE"
echo "== Lines around 198 =="
nl -ba "$FILE" | sed -n '160,230p'Repository: automagik-dev/genie
Length of output: 277
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/sign-attest.yml"
echo "== Lines around 198 =="
awk 'NR>=175 && NR<=215 {printf "%4d: %s\n", NR, $0}' "$FILE"Repository: automagik-dev/genie
Length of output: 1921
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/sign-attest.yml"
echo "== Matching persist-credentials =="
rg -n "persist-credentials" "$FILE" || true
echo "== Matching actions/checkout@ =="
rg -n "uses:\s*actions/checkout@" "$FILE" || true
echo "== Matching secrets usage =="
rg -n "secrets\." "$FILE" || true
echo "== Matching caches =="
rg -n "cache|actions/cache" "$FILE" || true
echo "== Print sign job steps (approx) =="
# Print from start of sign job through a bit further so we can see checkout's `with:` block if present.
awk 'NR>=160 && NR<=280 {print NR ":" $0}' "$FILE"Repository: automagik-dev/genie
Length of output: 6082
🏁 Script executed:
#!/bin/bash
set -euo pipefail
FILE=".github/workflows/sign-attest.yml"
echo "== Any git push/commit/config usage =="
rg -n "git (push|commit|config|add)" "$FILE" || true
echo "== Any actions/checkout usage count =="
rg -n "uses:\s*actions/checkout@" "$FILE" || trueRepository: automagik-dev/genie
Length of output: 179
Harden checkout in the signing job (pin immutable SHA + disable persisted credentials).
In .github/workflows/sign-attest.yml line 198 the job uses actions/checkout@v5 unpinned, and there’s no persist-credentials: false. Since this sign job doesn’t commit/push anything, disabling credential persistence is appropriate.
Suggested patch
- - uses: actions/checkout@v5
+ - uses: actions/checkout@<full-commit-sha-for-v5>
+ with:
+ persist-credentials: false🧰 Tools
🪛 zizmor (1.25.2)
[warning] 198-198: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 198-198: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/sign-attest.yml at line 198, The checkout action in the
sign job is unpinned and leaves credentials persisted; update the checkout step
(the uses: actions/checkout@v5 entry inside the sign job) to a pinned immutable
commit (replace the tag with the full commit SHA for the actions/checkout v5
release) and add a with: block containing persist-credentials: false (and
optionally fetch-depth: 0) so no credentials are stored for a job that does not
push commits.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/genie-commands/update.ts`:
- Around line 1288-1290: Normalize the port-file value and avoid always invoking
`pgserve status`: call `safeRead` and `trim()` its result, treat
empty/whitespace as undefined (e.g., set `pgservePortFromFile = safeRead(...
)?.trim() || undefined`), then only call `runCommandSilent('pgserve', ['status',
'--json'], ...)` when `pgservePortFromFile` is undefined; finally set
`pgservePort = pgservePortFromFile ??
extractPgservePortFromStatus(pgserveStatusJson)`. Apply the same change to the
other identical occurrence that uses `pgservePortFromFile`, `runCommandSilent`,
and `extractPgservePortFromStatus`.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: b0860295-c0cd-4cb2-8949-305b04890731
📒 Files selected for processing (6)
.claude-plugin/marketplace.jsonpackage.jsonplugins/genie/.claude-plugin/plugin.jsonplugins/genie/package.jsonsrc/genie-commands/__tests__/update.test.tssrc/genie-commands/update.ts
| const pgservePortFromFile = safeRead(join(GENIE_HOME, 'pgserve.port'), 200); | ||
| const pgserveStatusJson = (await runCommandSilent('pgserve', ['status', '--json'], undefined, 2000)).output.trim(); | ||
| const pgservePort = pgservePortFromFile ?? extractPgservePortFromStatus(pgserveStatusJson); |
There was a problem hiding this comment.
Avoid unconditional pgserve status call and normalize file value first.
At Line 1289, diagnostics always spawn pgserve status --json even when Line 1288 already has a port file value. Also, Line 1290 treats empty/whitespace file content as present, so fallback never runs. This adds avoidable latency and can emit a useless pgservePort.
Proposed fix
- const pgservePortFromFile = safeRead(join(GENIE_HOME, 'pgserve.port'), 200);
- const pgserveStatusJson = (await runCommandSilent('pgserve', ['status', '--json'], undefined, 2000)).output.trim();
- const pgservePort = pgservePortFromFile ?? extractPgservePortFromStatus(pgserveStatusJson);
+ const pgservePortFromFile = safeRead(join(GENIE_HOME, 'pgserve.port'), 200)?.trim() || null;
+ let pgservePort = pgservePortFromFile;
+ if (!pgservePort) {
+ const pgserveStatus = await runCommandSilent('pgserve', ['status', '--json'], undefined, 2000);
+ pgservePort = extractPgservePortFromStatus(pgserveStatus.output.trim());
+ }Also applies to: 1330-1330
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@src/genie-commands/update.ts` around lines 1288 - 1290, Normalize the
port-file value and avoid always invoking `pgserve status`: call `safeRead` and
`trim()` its result, treat empty/whitespace as undefined (e.g., set
`pgservePortFromFile = safeRead(... )?.trim() || undefined`), then only call
`runCommandSilent('pgserve', ['status', '--json'], ...)` when
`pgservePortFromFile` is undefined; finally set `pgservePort =
pgservePortFromFile ?? extractPgservePortFromStatus(pgserveStatusJson)`. Apply
the same change to the other identical occurrence that uses
`pgservePortFromFile`, `runCommandSilent`, and `extractPgservePortFromStatus`.
Summary
processSnapshot.genieno longer captures pgserve/autopg/postgres noise.Verification
bun run typecheckbun run lintbun test src/genie-commands/__tests__/install.test.ts src/genie-commands/__tests__/update.test.tstypecheck && lint && dead-code && skills:lint && wishes:lint && lint:emit9af2e31: CI ✅, Commitlint ✅Summary by CodeRabbit
Chores
Tests