docs(privacy): disclose package codemods as the one qualified admin exception - #1058
Conversation
…xception The privacy policy promised that private packages and their source never appear in any admin endpoint or payload, not even in redacted form. The package-codemod fleet surface (#1049) made that sentence inaccurate: scan/apply results expose package identity, affected file paths, and finding messages, and apply writes reviewed migrations into user source. Qualify the promise honestly on /privacy and docs/use/privacy.md with a new Platform maintenance section (reviewed in-repo transforms, dry-run gating, audit log, revert snapshots, codemod commits, applied/reverted events, no source contents in results), add the user-facing note to docs/use/packages.md, and make no-source-in-findings an explicit codemod authoring invariant in docs/contributing/package-codemods.md. Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
|
Warning Review limit reached
Next review available in: 2 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-1058.kody-a99.workers.dev Worker: Mocks:
|
Summary
Follow-up to the package-codemod framework (#1049) and Kent's review question: the privacy policy currently promises that private packages and their source never appear in any admin endpoint, page, or API payload — "not even in redacted or count form." The fleet codemod surface makes that sentence inaccurate:
admin_package_codemod_scan/applyresults expose package identity (user/package ids), affected file paths, and finding messages, andapplywrites reviewed migrations into user package source. This PR amends the policy honestly rather than leaving a promise the deployed product contradicts.Changes
/privacypage (privacy.tsx) +docs/use/privacy.md(kept in sync): the absolute "never… not even in redacted or count form" sentence gains a pointer to one qualified exception, and a new Platform maintenance (package codemods) section explains the model: versioned, deterministic, code-reviewed in-repo transforms; admins choose when a published codemod runs (dry-run gated) and cannot author ad hoc transforms; applies republish through normal checks, leave acodemod(<id>)commit in the package's own history, keep revert snapshots, dispatchpackage.codemod.applied/.revertedevents, and are audit-logged; results expose paths and fixed messages, never file contents.docs/use/packages.md: user-facing "Platform maintenance migrations (codemods)" note under Save and edit packages, linking to the privacy section.docs/contributing/package-codemods.md: new authoring invariant Explore @kody/sandbox stdlib for codemode (execute tool) #5 — never put source contents in findings (fixed, codemod-authored messages only; interpolating matched snippets/identifiers would surface private source to the operator and break the policy). Both shipped codemods already comply; this pins it as a review requirement.Review notes
Policy wording is Kent's call — this PR should not merge without his sign-off on the text. The technical claims were verified against the shipped framework: findings are
{ path, message }with constant messages in0001and0002; apply/revert paths, KV revert snapshots, audit logging, and subscription events per #1049.Program report