Harden migration and Nx cache validation contracts - #889
Conversation
📝 WalkthroughWalkthroughMigration validation now tracks SQL content in an append-only ledger, verifies trusted Git history, and documents CI/base-selection rules. Worker test cache inputs include additional dependencies with contract tests confirming cache invalidation. ChangesMigration validation
Worker cache contracts
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant CI
participant checkMigrations
participant Git
participant MigrationLedger
CI->>checkMigrations: set MIGRATION_VALIDATION_BASE and run checker
checkMigrations->>Git: resolve base and read trusted migration history
Git-->>checkMigrations: trusted SQL files and ledger
checkMigrations->>MigrationLedger: compare checkout filenames and SHA-256 digests
MigrationLedger-->>CI: validation result
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-889.kody-a99.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/validate.yml:
- Around line 37-40: Update the checkout action configuration containing
fetch-depth: 0 to set persist-credentials to false, ensuring the workflow does
not retain the Actions token in Git configuration while leaving the full-history
checkout behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 50ef6e0f-4d8f-4151-8466-5b16959c22c2
📒 Files selected for processing (8)
.gitattributes.github/workflows/validate.ymldocs/contributing/setup.mdnx.jsontools/check-migrations.node.test.tstools/check-migrations.tstools/migration-ledger.jsontools/nx-cache-contract.node.test.ts
Summary
HEADas a trust base; CI supplies PR-base/push-before SHAs, local branches use their merge base, and main/detached checkouts fall back to the first parent.gitattributesTests
npm run validate: passed (format, lint, typecheck, 1,091 unit/worker tests, 17 Playwright tests, 2 MCP E2E tests, primitives, migrations)280ce219: Validate, preview deployment, Cursor Bugbot, and CodeRabbit passedSystem recap — composes existing primitives (low risk)
Mode: recap · Base:
main@ac6b9736· Head:280ce219Classification: composes — repository validation behavior changes without adding or changing a runtime system primitive.
Primitives touched
None. The diff is limited to repository tooling, CI/Nx metadata, regression tests, checkout attributes, and contributor documentation.
Before / after
HEADitself as trusted historyHEADand selects PR base, push-before SHA, merge base, or first parentcore.autocrlf=truetestandwrangler-env.tsfortest-mcpInvariants
Applied migration filenames and contents are immutable. Migration and ledger digest co-edits fail against pre-change history, including on main pushes. The grandfathered duplicate-prefix pairs, including both
0009files, remain exact and mandatory.Summary by CodeRabbit