Skip to content

chore: reuse shared Rust lint config from ai-shared - #374

Merged
jan-kubica merged 4 commits into
mainfrom
feat/reuse-shared-rust-config
Jul 23, 2026
Merged

jan-kubica merged 4 commits into
mainfrom
feat/reuse-shared-rust-config

Conversation

@jan-kubica

@jan-kubica jan-kubica commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • consume rustfmt.toml and deny.toml from ai-shared via .ai/manifest.json sharedRootFiles instead of local copies
  • bump the .ai/shared submodule (also refreshes AGENTS.md with newer shared modules — additive only)

Notes

  • The shared cargo-deny policy is identical to the previous local one (only comments differ); cargo deny check passes.
  • clippy.toml intentionally stays local: this repo additionally bans wall-clock/RNG access for deterministic output, which is stricter than the shared baseline, so it is not listed in sharedRootFiles.

Depends on

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Documentation

    • Added guidance for identifying, assessing and manually updating prerelease-pinned dependencies.
    • Refined development guidance covering TypeScript, Rust rule systems, testing and collaboration practices.
    • Updated configuration comments and shared tooling documentation.
  • Chores

    • Improved dependency skill synchronisation when optional arguments are provided.
    • Updated shared tooling references and included additional shared configuration files.
  • Configuration

    • Draft pull requests are no longer automatically reviewed.
    • Review exclusions now include draft titles.

@coderabbitai

coderabbitai Bot commented Jul 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@jan-kubica, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 21 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 2e970304-515d-40af-ac44-4efa4176997c

📥 Commits

Reviewing files that changed from the base of the PR and between b4652d3 and 4b1ce30.

📒 Files selected for processing (13)
  • .agents/skills/plan/SKILL.md
  • .agents/skills/product-think/SKILL.md
  • .agents/skills/rabbit-round/SKILL.md
  • .agents/skills/regression-hunt/SKILL.md
  • .agents/skills/security-audit/SKILL.md
  • .agents/skills/update-deps/SKILL.md
  • .ai/shared
  • .claude/commands/plan.md
  • .claude/commands/rabbit-round.md
  • .claude/commands/regression-hunt.md
  • .claude/commands/security-audit.md
  • .claude/commands/update-deps.md
  • AGENTS.md
📝 Walkthrough

Walkthrough

The pull request updates prerelease dependency procedures, contributor guidance, shared tooling metadata, review configuration, cargo-deny documentation, a subproject reference, and AI skill synchronisation argument handling.

Changes

Prerelease dependency guidance

Layer / File(s) Summary
Prerelease dependency update workflow
.agents/skills/update-deps/SKILL.md, .claude/commands/update-deps.md
Adds prerelease pin detection, dist-tag validation, risk classification, and manual pin updates followed by bun install.

Repository engineering guidance

Layer / File(s) Summary
Engineering and testing conventions
AGENTS.md
Adds collaboration, TypeScript, Rust rule-system, and insta snapshot-testing guidance.

Tooling configuration and synchronisation

Layer / File(s) Summary
Shared tooling configuration
.ai/manifest.json, .ai/shared, .coderabbit.yaml
Adds shared root files, advances the shared subproject reference, and changes draft-review and guideline-pattern settings.
Policy documentation and skill synchronisation
deny.toml, scripts/sync-ai-skills.sh
Revises cargo-deny comments and conditionally forwards synchronisation arguments based on whether arguments are present.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and aligned with the main change: consuming shared Rust configuration from ai-shared.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/reuse-shared-rust-config

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@jan-kubica
jan-kubica force-pushed the feat/reuse-shared-rust-config branch from 4e7b6f1 to 292e407 Compare July 23, 2026 09:06

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 292e407df0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .ai/shared Outdated
jan-kubica and others added 3 commits July 23, 2026 21:40
Consume rustfmt.toml and deny.toml from ai-shared via the new
`.ai/manifest.json` "sharedRootFiles" mechanism instead of holding local
copies. The shared deny policy is identical to the previous local one (only
comments differ).

clippy.toml intentionally stays local: this repo additionally bans wall-clock
and RNG access for deterministic output, which is stricter than the shared
baseline, so it is not listed in sharedRootFiles.

Bumping the .ai/shared submodule also refreshes the generated AGENTS.md with
the newer shared modules (additive only).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@jan-kubica
jan-kubica force-pushed the feat/reuse-shared-rust-config branch from 292e407 to b4652d3 Compare July 23, 2026 19:44

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.agents/skills/update-deps/SKILL.md:
- Around line 66-75: Update the prerelease guidance in
.agents/skills/update-deps/SKILL.md lines 66-75 and
.claude/commands/update-deps.md lines 61-70 to distinguish exact prerelease pins
from ranges that exclude newer prereleases, limiting the inventory claim
accordingly. Update .agents/skills/update-deps/SKILL.md lines 151-154 and
.claude/commands/update-deps.md lines 146-149 to state that bun update --latest
can replace prerelease pins or dist-tags with the registry latest release, and
advise avoiding it unless that replacement is intended.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 40804ea0-d53f-41cf-82ab-3676160936b3

📥 Commits

Reviewing files that changed from the base of the PR and between 8bb15b6 and b4652d3.

📒 Files selected for processing (8)
  • .agents/skills/update-deps/SKILL.md
  • .ai/manifest.json
  • .ai/shared
  • .claude/commands/update-deps.md
  • .coderabbit.yaml
  • AGENTS.md
  • deny.toml
  • scripts/sync-ai-skills.sh
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: validate
🧰 Additional context used
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Treat legal data, personal data, repository secrets, and private business or security context as sensitive; keep public artifacts limited to implementation-visible engineering context.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Prefer designs with least privilege, data minimization, workspace isolation, explicit access checks, encryption-aware handling, and structured audit trails.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Use Conventional Commits with `feat:`, `chore:`, `fix:`, or `docs:` and rebase feature branches onto main for linear history.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Enable `git rerere` and `rerere.autoupdate` to record and replay conflict resolutions.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Fail fast at boundaries, minimize brace nesting with early returns, use named constants for domain values, and batch operations to minimize round-trips.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Do not manually reformat unchanged code; formatter output is acceptable when included with semantic changes.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Use standard formats and keep self-hosting first-class; avoid lock-in.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Prefer vertical end-to-end feature slices over horizontal layers; new capabilities should have their own routes, components, and handlers.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Preserve native benchmark task semantics, report unsupported tasks as unsupported rather than zero, and keep document-level holdout predictions and failure analysis local and uncommitted.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: Keep prepared-package schema versions for payload schema only; represent compression and digest choices with explicit tagged fields, and rebuild after unreleased wire-format breaks.
Learnt from: CR
Repo: stella/anonymize

Timestamp: 2026-07-23T19:44:40.793Z
Learning: International-facing output must not assume English language or typography; identify competing date, quotation, citation, and legal terminology standards when relevant.
🪛 LanguageTool
AGENTS.md

[formatting] ~38-~38: If the ‘because’ clause is essential to the meaning, do not use a comma before the clause.
Context: ...r prefix it with @ or link the account, because the attribution must not trigger a Gi...

(COMMA_BEFORE_BECAUSE)


[misspelling] ~245-~245: This word is normally spelled as one.
Context: ...s. Prefer YAML or JSON snapshots over hand-written assertion lists when the important cont...

(EN_COMPOUNDS_HAND_WRITTEN)

🔇 Additional comments (8)
AGENTS.md (1)

36-39: LGTM!

Also applies to: 62-77, 105-111, 136-138, 206-218, 243-249

.ai/manifest.json (1)

14-18: LGTM!

.ai/shared (1)

1-1: 🗄️ Data Integrity & Integration

Confirm the submodule pin contains the merged ai-shared main commit.

The tracked entry points to d06174098a0792b61404c24aa13e582f182d15f1, but the repository is unable to reach that object from the fetch/promisor remote. Ensure the pinned commit is available and reachable from origin/main so consumers can fetch the dependency and run scripts/sync-ai-skills.sh.

.coderabbit.yaml (1)

15-20: LGTM!

Also applies to: 60-61

deny.toml (1)

1-8: LGTM!

Also applies to: 18-18, 38-52

scripts/sync-ai-skills.sh (1)

28-32: LGTM!

.agents/skills/update-deps/SKILL.md (1)

95-97: LGTM!

.claude/commands/update-deps.md (1)

90-92: LGTM!

Comment thread .agents/skills/update-deps/SKILL.md Outdated
@jan-kubica
jan-kubica merged commit 383184b into main Jul 23, 2026
6 checks passed
@jan-kubica
jan-kubica deleted the feat/reuse-shared-rust-config branch July 23, 2026 20:41
@github-actions github-actions Bot locked and limited conversation to collaborators Jul 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant