Skip to content

Wave 1: core package - #1

Merged
ThePlenkov merged 20 commits into
mainfrom
wave-1-core
Aug 11, 2026
Merged

ThePlenkov merged 20 commits into
mainfrom
wave-1-core

Conversation

@ThePlenkov

@ThePlenkov ThePlenkov commented Aug 9, 2026 •

Copy link
Copy Markdown
Contributor

User description

Summary

  • Core package: workflow graph, composables (pipeline/run), operations, outputs
  • 79 vitest tests pass
  • typecheck clean, build green
  • public API exported from src/index.ts, no any

Test plan

  • bun run test (vitest) — 79 tests pass
  • bun run typecheck
  • bun run build

Generated with Devin


CodeAnt-AI Description

Add the core workflow graph API for composing, planning, and executing workflows

What Changed

  • Added lazy workflow operations for commands, sequential pipelines, parallel groups, conditions, matrix combinations, and named workflows.
  • Workflows now produce ordered plans for planning, execution, or compilation, including skipped, cancelled, failed, and successful operation outcomes.
  • Added validation for cycles, duplicate IDs, unknown dependencies, invalid conditions, and invalid matrix dimensions with structured errors.
  • Matrix workflows expand into Cartesian combinations with distinct IDs and MATRIX_* environment values.
  • Exported the core workflow types, composables, runtime contracts, and package-specific error classes.
  • Added package error classes for the CLI, runtime, and policy packages, along with broad behavior and public API test coverage.
  • Updated project guidance and test configuration so packages without tests pass repository-wide checks.

Impact

✅ Lazy workflow definitions without setup-time side effects
✅ Reliable sequential, parallel, conditional, and matrix plans
✅ Clear skipped and cancelled operation outcomes

🔄 Retrigger CodeAnt AI Review

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@ThePlenkov ThePlenkov mentioned this pull request Aug 9, 2026
3 tasks done
@codacy-production

codacy-production Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 299 complexity · 0 duplication

Metric Results
Complexity 299
Duplication 0

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The PR establishes the core package and monorepo structure but contains several critical issues that should prevent merging in its current state. Most significantly, the Codacy analysis is 'not up to standards' due to 1,242 new issues and missing coverage data.

The implementation contains a major architectural divergence from ADR-006: operation IDs are currently generated using counters and name-concatenation instead of the required SHA-256 content-addressing. This breaks cache stability and plan reproducibility. Additionally, the condition evaluator contains a security risk related to unsafe property access and high cyclomatic complexity (34). Several implementation plan steps (6.2.7) and required files (canonical.ts) are also missing.

About this PR

  • The planned file 'packages/core/src/internal/canonical.ts' is missing despite being listed as a requirement for stable ID generation in the Wave 1 plan.
  • The PR scope significantly exceeds the 'core package' summary, including project-wide monorepo bootstrapping, website scaffolding, and extensive documentation tree setup.

Test suggestions

  • run() composable creates a node with 'run' kind and preserves all spec fields
  • pipeline() wires a linear dependency chain via predecessor references
  • parallel() creates a synthetic join node with input operations as siblings
  • matrix() produces a Cartesian product expansion of nodes with MATRIX_ env vars
  • Safe condition evaluator handles operator precedence (NOT > AND > OR)
  • Condition evaluator operates without eval() or Function constructor
  • Planning process performs zero I/O during discovery and walk (verified via spies)
  • Cycle detection identifies and rejects cyclic graphs with CompositionError
  • Operation IDs are generated using SHA-256 content hashes as specified in ADR-006
  • Planner identifies and rejects true duplicate operations sharing the same content
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Operation IDs are generated using SHA-256 content hashes as specified in ADR-006
2. Planner identifies and rejects true duplicate operations sharing the same content

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread packages/core/src/internal/ids.ts
Comment thread packages/core/src/internal/plan.ts Outdated
Comment thread packages/core/src/internal/conditions.ts
Comment thread packages/core/src/internal/conditions.ts
Comment thread packages/core/src/internal/ids.ts Outdated
Comment thread AGENTS.md
@ThePlenkov ThePlenkov mentioned this pull request Aug 10, 2026
9 tasks done
ThePlenkov added a commit that referenced this pull request Aug 10, 2026
The merge order was bottom-up (#1 first). This is wrong — stacks should
be merged TOP-DOWN:

1. Rebase the TOP PR onto main (its diff now includes ALL stack changes)
2. /act --loop on the TOP PR until convergence
3. Squash merge the TOP PR → main gets everything in one commit
4. Close all lower PRs (their changes are included in the top PR's squash)
5. Retrospect, advance to next stack

This is faster: one merge per stack (not N), one /act convergence per
stack (on the top PR only), lower PRs are closed not merged.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@baz-reviewer

baz-reviewer Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Merger

⚠️ Re-evaluating...

Commit e6cb772 · Updated 2026-08-11 10:44 UTC

Review this PR on Baz | Customize your next review

@codeant-ai

codeant-ai Bot commented Aug 10, 2026

Copy link
Copy Markdown

Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters.

If you still want a review, comment @codeant-ai : review. For better signal, consider splitting the PR into smaller chunks.

@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔄 Running review...
📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added workflow composition for sequential, parallel, conditional, and matrix-based operations.
    • Added planning, execution, and compilation modes with dependency validation, deterministic ordering, outcomes, artifacts, and context support.
    • Added structured error handling across core, CLI, policy, and runtime functionality.
    • Added comprehensive project orchestration workflows and agent guidance.
  • Documentation

    • Updated architecture, project structure, testing guidance, specifications, and architecture decision records.
  • Tests

    • Expanded coverage for workflows, conditions, matrices, validation, runtime modes, public APIs, and error handling.

Walkthrough

The PR establishes Sverka’s workflow foundation. It adds immutable operation composition, matrix expansion, conditional planning, DAG validation, runtime modes, public APIs, package tooling, agent orchestration, specifications, and documentation.

Changes

Sverka foundation

Layer / File(s) Summary
Orchestration and repository setup
AGENTS.md, agents/..., city.toml, formulas/..., .gitignore, .eslintrc.json, CLAUDE.md, README.md
Adds workspace instructions, agent prompts and scopes, daemon configuration, workflow stages, ignore rules, lint configuration, and Bun-based development commands.
Package targets and error APIs
packages/*/project.json, packages/core/package.json, packages/{cli,policy,runtime}/src/index.ts, packages/*/src/__tests__/public-api.test.ts
Adds Nx build, test, lint, and typecheck targets. Adds public CLI, policy, runtime, and core error contracts with tests.
Operation model and composable graph
packages/core/src/operation.ts, runtime.ts, internal/node.ts, internal/merge.ts, composables/*, errors.ts, index.ts
Adds operation and runtime types, immutable graph composition, specification merging, workflow construction, composables, and public exports.
Planning, IDs, conditions, and runtime execution
packages/core/src/internal/{plan,ids,conditions,canonical}.ts
Adds graph discovery, matrix expansion, dependency resolution, deterministic IDs, cycle detection, topological ordering, condition parsing, canonical serialization, runtime evaluation, and finalization.
Core behavior validation
packages/core/src/__tests__/*
Adds coverage for composition, workflow planning, matrices, conditions, DAG validation, runtime modes, laziness, canonical serialization, public exports, and error behavior.
Core specification and engineering records
specs/01-core/*, engdocs/adr/*, engdocs/README.md, engdocs/architecture/*, specs/00-overview/*, specs/15-documentation/*
Documents implementation order, planning semantics, predecessor resolution, operation ID design, runtime contracts, test coverage, and repository structure.
Estimated code review effort: 5 (Critical) ~120 minutes

Possibly related PRs

  • sverka-dev/sverka#19: Shares direct changes to the core composables, planner, runtime APIs, tests, agent configuration, and documentation.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 57.45% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the main change: adding the core package in Wave 1.
Description check ✅ Passed The description directly explains the core workflow API, validation, runtime modes, tests, and verification results.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch wave-1-core

Comment @coderabbitai help to get the list of available commands.

ThePlenkov added a commit that referenced this pull request Aug 10, 2026
The merge order was bottom-up (#1 first). This is wrong — stacks should
be merged TOP-DOWN:

1. Rebase the TOP PR onto main (its diff now includes ALL stack changes)
2. /act --loop on the TOP PR until convergence
3. Squash merge the TOP PR → main gets everything in one commit
4. Close all lower PRs (their changes are included in the top PR's squash)
5. Retrospect, advance to next stack

This is faster: one merge per stack (not N), one /act convergence per
stack (on the top PR only), lower PRs are closed not merged.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 102

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
specs/14-website/spec.md (1)

244-244: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Remove the extra Markdown fence.

This fence starts an unintended code block at end of file.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@specs/14-website/spec.md` at line 244, Remove the stray Markdown fence at the
end of specs/14-website/spec.md so it does not start an unintended code block.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.agents/skills/beads/SKILL.md:
- Line 38: Update the ordered-list markers in SKILL.md around “Inspect before
editing” and the other affected items, replacing each explicit 2., 3., 4., and
5. marker with 1. while preserving the existing item text and list structure.

In @.codacy.yml:
- Around line 36-40: Update the Codacy configuration for the ESLint 9 and
Markdownlint engines to remove their unsupported engines.*.enabled: true
settings, and activate both engines through Codacy Code patterns instead. Also
remove the markdown disablement from languages.markdown.enabled and the Markdown
exclusion from exclude_paths so Markdown analysis is enabled.

In @.gitignore:
- Around line 157-165: Update the .gitignore entries near website/dist/ and
website/node_modules/ to include website/.astro/. Remove any currently tracked
files under website/.astro/ from version control while leaving them locally
available.

In `@AGENTS.md`:
- Line 22: Fix the Markdown fence lint errors in the directory-tree and command
examples: specify a language such as text on the directory-tree fence to satisfy
MD040, and add blank lines before and after the command fence to satisfy MD031.

In `@agents/architect/prompt.template.md`:
- Around line 24-32: Update the skill-invocation instructions in the prompt
template so every mandatory skill is explicitly invoked, including deepwiki and
sourcegraph alongside spec-driven-development, minimalist, and
critical-thinking. Ensure the corresponding workflow section lists concrete
steps to use deepwiki for external-library research and sourcegraph for codebase
searches via the src CLI, preserving the existing invocation of the first three
skills.

In `@agents/builder/prompt.template.md`:
- Around line 23-34: Update the testing instruction in the Mandatory skills
section of prompt.template.md to require running the configured Vitest suite
with “bun run test” rather than “bun test”. Keep the existing skill list and
other testing guidance unchanged.
- Around line 57-59: Update the testing instructions in the prompt template to
replace the `bun test` command with the configured Vitest command, using `bun
run test` or the relevant Nx test target. Keep the requirement to confirm
failing tests for the correct reason before implementing.

In `@agents/mayor/prompt.template.md`:
- Around line 85-115: Update the “Stacked PRs to GitHub” procedure to require
explicit authorization under the active workflow profile before any git or
GitHub mutation, including checkout, add, commit, push, gh pr create, or
Git/Dolt synchronization. When authorization is absent, skip those commands and
report the completed wave without modifying repositories or GitHub; retain the
existing branch and commit steps only for authorized workflows.
- Around line 60-73: Update the wave progression instructions around “keep going
until the project is done” to require checking for an explicit user or
orchestrator stop request or scope change before closing, creating, or
dispatching subsequent wave work. Ensure that this human-control gate takes
precedence over the automatic continue-until-complete behavior, while preserving
monitoring and re-gating for active work when no stop or scope change is
requested.

In `@agents/reviewer/prompt.template.md`:
- Around line 52-64: Replace the markdown checkbox review checklist under
“Review checklist” with instructions to track each review task using bd.
Explicitly prohibit TodoWrite, TaskCreate, and markdown TODO lists, while
preserving the existing review requirements as bd-tracked tasks.
- Around line 43-57: Update the test command in the review instructions and
checklist from “bun test” to “bun run test” so the reviewer invokes the
configured root test script through the workspace Vitest and Nx target.

In `@CLAUDE.md`:
- Around line 43-51: Update the Markdown command fence in CLAUDE.md by adding
blank lines immediately before and after the indented fenced block containing
git status, git pull --rebase, and git push, resolving MD031 without changing
the commands or surrounding content.
- Around line 61-77: Replace the placeholder sections in CLAUDE.md with the
project’s actual Bun/Nx build, test, lint, and typecheck commands, using
AGENTS.md and the existing bun run test Vitest command as the source of truth.
Add a concise architecture overview and project-specific conventions so agents
can execute and modify the repository consistently, and remove the npm example
and placeholder text.

In `@engdocs/architecture/overview.md`:
- Around line 8-15: Label the system-flow code fence in the architecture
overview as text by updating its opening fence, while leaving the diagram
content unchanged.
- Around line 29-43: Update the architecture graph code fence to use text syntax
and match the dependency direction defined in dependencies.md: keep core
independent from ir, show dependencies pointing from executors such as
runtime-docker toward runtime, and correct the remaining package relationships
accordingly.

In `@engdocs/contributing/development-setup.md`:
- Around line 12-29: Update the development setup commands to invoke Vitest
through Nx: replace the top-level `bun test` command with `bun run test`, and
change the filtered `bun test --filter=`@sverka/core`` command to `bunx nx test
core`, preserving the surrounding build and test guidance.

In `@engdocs/contributing/guide.md`:
- Around line 5-10: Update the testing step in the contributing guide to use the
workspace script command bun run test instead of bun test, while leaving the
other setup, build, lint, and typecheck commands unchanged.

In `@engdocs/contributing/waves.md`:
- Around line 22-25: Update the Wave 1 row in the wave status table so the core
package reflects its post-merge status rather than remaining Pending, while
leaving the Wave 0 row unchanged.

In `@engdocs/README.md`:
- Around line 10-16: Label the directory-tree code fence in the README with the
text language by updating its opening fence, while leaving the documented
directory tree unchanged.
- Line 34: Add the missing engdocs ADR-006 document at the path referenced by
the README and the other linked document, or update both references to point to
the correct existing ADR. Ensure all links consistently resolve to the intended
SHA-256 content-addressed Plan and Operation IDs documentation.

In `@eslint.config.mjs`:
- Around line 7-24: Update the ignores array in the ESLint configuration to stop
excluding source-bearing TypeScript paths, including website files, test files,
__tests__ directories, and *.config.ts files. Retain ignores only for generated
or intentionally non-source output, ensuring all *.ts and *.tsx files remain
covered by the project’s ESLint and formatting checks.
- Around line 27-35: Add `@typescript-eslint/parser` as a development dependency
and configure it as languageOptions.parser in the TypeScript file configuration
block. Update the existing files: ["**/*.ts"] entry without changing its other
parser or ECMAScript settings.

In `@formulas/sverka-bootstrap.toml`:
- Around line 73-76: Update the finalize step identified by id "finalize" so it
requires explicit authorization before any Git or Dolt write operation,
including commit, push, or synchronization. Revise its description or
prerequisites to make this authorization gate explicit while preserving the
existing review dependency.
- Around line 64-67: Update the review instructions in the description block to
replace “bun test” with “bun run test”, ensuring the project’s root test script
is invoked instead of Bun’s native test runner.

In `@formulas/sverka-wave.toml`:
- Around line 27-43: Update the wave dependency flow around the review and
finalize steps so reviewer rejection cannot lead to finalize execution: add an
explicit approval gate or route rejection from reviewer back to implement, and
ensure finalize only runs after approval. Preserve the existing reviewer and
mayor roles, and verify the rejection path leaves the wave incomplete.

In `@nx.json`:
- Around line 22-24: Update the lint target’s inputs in the nx configuration to
track eslint.config.mjs instead of .eslintrc.json, preserving the existing
default input and caching behavior.
- Around line 13-17: Update the build target defaults in nx.json to declare the
generated output by adding an outputs entry for {projectRoot}/dist before
retaining build caching. Keep the existing dependsOn, inputs, and cache settings
unchanged.

In `@pack.toml`:
- Around line 5-11: Remove the packs.lock ignore rule from .gitignore, run gc
import install to generate the Pack V2 lockfile, and commit the resulting
packs.lock file. Do not create or use packs.lock.toml.

In `@packages/cli/src/index.ts`:
- Line 1: Define and export a package-specific CliError class from the public
API entry point marked by the existing `@sverka/cli` declaration. Make it extend
the standard Error type and preserve normal error behavior so consumers can
identify CLI-specific failures.

In `@packages/core/src/__tests__/conditions.test.ts`:
- Around line 87-95: Align the test name and assertion in the “malformed error
has code INVALID_CONDITION” case: use the required public error code
consistently, either renaming the test to COMPOSITION_ERROR or updating the
implementation and assertion to emit INVALID_CONDITION. Keep the existing
CompositionError and context checks unchanged.

In `@packages/core/src/__tests__/dag.test.ts`:
- Around line 20-23: Update both catch blocks in the DAG tests to narrow caught
errors with err instanceof CompositionError before accessing context; retain the
existing context assertions for matching errors and re-throw unexpected errors
instead of casting them.

In `@packages/core/src/__tests__/laziness.test.ts`:
- Line 40: Update the fetch spy setup in the laziness test to reject immediately
with an “Unexpected network call” error instead of preserving the real global
fetch implementation. Apply this mock rejection configuration to both fetch
spies.

In `@packages/core/src/__tests__/matrix.test.ts`:
- Around line 19-30: Update the “multi-dimension cartesian product with joined
id suffix” test to provide two values for both node and os, then assert four
operations covering every node/os combination in the expected IDs. Extend the
environment assertions to verify each operation’s MATRIX_NODE and MATRIX_OS
values match its corresponding Cartesian-product combination.

In `@packages/core/src/internal/ids.ts`:
- Around line 44-45: Update the matrix ID generation around formatMatrixValue
and the dims mapping to use a canonical, type-preserving encoding that escapes
delimiters, ensuring distinct values such as 1 and "1" produce different IDs.
After assigning IDs to matrix children, detect and reject duplicate IDs before
returning the planned children.

In `@packages/core/src/internal/node.ts`:
- Around line 33-45: Update the after and with methods to validate every added
Operation is a genuine private-branded OperationNode before storing it,
rejecting structurally valid public Operations without the required node fields.
Remove the unchecked casts and preserve existing predecessor and sibling
accumulation for valid nodes.

In `@packages/core/src/internal/plan.ts`:
- Around line 139-147: Update the matrix expansion logic around the child
creation loop and resolveEdges() to track each matrix template’s expanded child
nodes. Rewrite downstream predecessor references from the removed template to
all corresponding matrix children before resolving edges, so dependent
operations reference every expanded child and no unresolved template IDs remain.
- Around line 194-205: Update the node-rewriting flow around rewritten and idMap
to build an old-to-new mapping for every rebuilt node, then rewrite all
predecessor and sibling references through that mapping before filtering
artifacts and returning the graph. Ensure references to unchanged nodes remain
intact and later edge resolution can no longer target replaced node identities.

In `@packages/core/src/operation.ts`:
- Around line 18-31: Define a shared JSON-serializable scalar type and apply it
to both OperationSpec.matrix and the matrix() API. During planning, validate
every matrix value before String(v) is used for MATRIX_* environment variables
or matrix IDs, rejecting undefined, BigInt, and other non-scalar values to
prevent collisions and serialization failures.

In `@packages/core/src/runtime.ts`:
- Around line 12-19: Extend RuntimeResult with a required readonly outcomes
collection, then update planWorkflow to retain both evaluated OperationOutcome
values and synthetic skipped outcomes instead of discarding them. Propagate the
aggregate through every runtime implementation and test helper, preserving
existing outcome order and behavior.

In `@packages/ir/project.json`:
- Around line 11-16: Update the test target in packages/ir project.json to pass
Vitest’s empty-suite option, or add a valid IR test file; ensure nx test ir
succeeds when no tests are present.

In `@packages/policy/src/index.ts`:
- Line 1: Define a package-specific PolicyError class in the packages/policy
entry point and export it as part of the public API. Ensure it extends the
standard Error type and is available to consumers through the existing package
export surface.

In `@packages/runtime-podman/package.json`:
- Around line 18-24: Add eslint to the devDependencies of packages that invoke
it, including runtime-podman, so the package-local Nx lint target works with Bun
isolated installs. Keep the existing lint script unchanged and use the
workspace’s established eslint version.

In `@packages/runtime/project.json`:
- Around line 4-9: Update the build target in project.json to declare
packages/runtime/dist as its Nx output, unless nx.json already defines an
equivalent global build output. Ensure the target metadata identifies the
tsdown-generated dist directory so cached builds restore the package artifact.
- Around line 11-16: Update the runtime test configuration in the Nx "test"
target and the package test script to pass Vitest's --passWithNoTests option,
ensuring both invocation paths succeed when packages/runtime has no matching
test files.

In `@packages/runtime/src/index.ts`:
- Line 1: Define a package-specific `RuntimeError` class in the
`packages/runtime` public API entry point and export it alongside the existing
API. Make it an error type suitable for runtime-specific failures, preserving
standard Error behavior and package-level accessibility.

In `@README.md`:
- Around line 84-111: Add the `text` language identifier to the fenced Markdown
blocks containing the architecture diagram and project-structure block, ensuring
both fences satisfy Markdownlint MD040.
- Around line 1-5: Update the README’s opening structure so it begins with a
valid top-level heading recognized by Markdownlint: move the “# Sverka” heading
before the opening HTML div, or replace it with an HTML h1 and change the
tagline from “###” to a paragraph. Preserve the existing title and tagline
content while satisfying MD041 and MD001.
- Around line 139-143: Update the test command in the README quality-check
command list from bun test to bun run test, preserving the documented Vitest/Nx
test workflow and the surrounding commands unchanged.

In `@specs/00-overview/spec.md`:
- Around line 34-61: Add the text language tag to the fenced ASCII diagrams in
the overview specification, including the architecture and package-structure
fences, while preserving their existing diagram content unchanged.
- Around line 110-115: Update the “Test plan” section in spec.md to use “bun run
test” instead of “bun test,” and update contributing documentation and any other
instructions still referencing the old command so all test-running guidance
consistently invokes Nx and Vitest.

In `@specs/01-core/plan.md`:
- Around line 132-144: Resolve the error-code mismatch between the condition
parser and CompositionError: update the plan and conditions-related tests to
require the existing COMPOSITION_ERROR code, or introduce a separate
condition-specific error type that exposes INVALID_CONDITION and use it from
evaluateCondition. Keep malformed expressions mapped consistently to the chosen
contract.
- Around line 293-299: Update the root test command in the documented
verification commands to use “bun run test” instead of “bun test”, preserving
the existing typecheck, lint, and build commands.

In `@specs/01-core/spec.md`:
- Line 318: Update the Markdown fences in the data-model, ID-format, and
expression-grammar sections to specify the text language, resolving MD040.
Insert a blank line immediately before the commands fence to resolve MD031,
including the additionally referenced ranges.
- Around line 279-289: Update the matrix documentation around the matrix
operation description and related examples to use the content-addressed op- ID
contract instead of deterministic ID suffixes. Remove or revise any suffix-based
wording so it matches the later matrix rules, and ensure all affected examples
consistently demonstrate the same ID behavior.
- Around line 185-192: Align the PlanContext interface with its documented value
domain by either narrowing the comment to string arrays or expanding the index
signature to support readonly number and boolean arrays. Ensure the chosen type
and prose consistently describe the supported context values.
- Around line 342-345: Update the composition specification and corresponding
test plan to state that dependsOn and tags list merges concatenate values,
remove duplicates, and preserve their original order, matching concatDedupe in
merge.ts.
- Around line 514-522: Update the Test plan command references in the
documentation: replace `bun test` with `bun run test`, and specify `bunx nx run
core:test` for the core-specific test command. Keep the existing test coverage
descriptions unchanged.
- Around line 407-418: Resolve the operation-identity contract across the
specification, core, IR, and tests by deciding whether discovery index
participates in the computed ID; ensure the documented `{ kind, name, context }`
duplicate behavior matches that decision. Update core’s `computeOperationId`
implementation and remove any conflicting `kind:name/command/index` or
collision-suffix behavior, add the corresponding IR implementation, and revise
tests to validate identical operations and distinct indexed operations according
to the chosen contract.
- Around line 376-398: Define the complete operation identity projection,
explicitly deciding whether env, image, imageDigest, workingDir, timeoutSeconds,
retries, cache, network, credentials, artifacts, and condition affect identity;
include every identity-affecting field with deterministic canonicalization.
Update the operation-id implementation in computeOperationId and the `@sverka/ir`
package to use the same SHA-256 content-addressed projection, avoiding direct
spec.id or `${kind}:${name}` ids, and expose computeOperationId from the IR
package so both consumers remain consistent.

In `@specs/02-ir/spec.md`:
- Around line 125-126: Restrict the compiler metadata fields near compiler and
the corresponding metadata definition to a recursive JsonValue type instead of
unknown. Define JsonValue to allow only JSON primitives, arrays, and object
records whose values are JsonValue, and update validation to reject functions,
bigint, undefined, and cyclic structures so metadata can round-trip through
canonical JSON.
- Around line 339-376: Update the test execution instructions in the testing
section to use the workspace’s Vitest command with the IR package selector
instead of Bun’s test runner. Replace the `bun test packages/ir` entry while
leaving the typecheck and lint commands unchanged.

In `@specs/03-runtime/spec.md`:
- Around line 355-411: Update the test commands in the runtime specification to
use the project’s Vitest workspace command with the runtime package selector
instead of Bun’s built-in test runner. Keep the existing typecheck and lint
commands unchanged.
- Around line 191-199: Update the ExecutionState.outcomes representation to use
a JSON-serializable structure, such as a string-keyed record or entry array, so
StateStore persistence retains all operation outcomes. Ensure readers and
writers consistently use the new representation while preserving outcome lookup
semantics.
- Around line 73-106: Extend ExecuteRequest and the Executor contract with a
cancellation mechanism that the scheduler can invoke for in-progress operations.
Update the scheduler’s cancel() flow to propagate cancellation to the selected
executor and await its completion, ensuring ExecuteResult reports the cancelled
status while preserving existing state transitions.

In `@specs/04-runtime-docker/spec.md`:
- Around line 224-227: Update ContainerPolicyError and its call sites so each
policy violation preserves its rule-specific code: MISSING_TIMEOUT,
MISSING_DIGEST, UNDECLARED_SECRET, or DOCKER_SOCKET_DENIED. Either accept the
code in ContainerPolicyError’s constructor or introduce dedicated subclasses,
and ensure callers observe the required code instead of the generic
CONTAINER_POLICY_VIOLATION.
- Around line 259-261: Update the test plan in specs/04-runtime-docker/spec.md
to document the runtime-docker package or Nx test target that runs Vitest via
vitest run, replacing the bun test command in both referenced test-plan
sections.
- Around line 64-77: Align DockerExecutorConfig.runAs with its documented
default by making the property optional and normalizing omitted values to
"1000:1000" in the Docker executor constructor. Preserve explicitly supplied
runAs values.
- Around line 186-195: Validate or normalize the key at the start of
CacheManager.prepare before constructing any cache paths, rejecting absolute
paths and traversal segments; alternatively derive a safe hash/identifier from
the key. Ensure the same safe key is used consistently for /cache and persistent
cacheDir paths, preventing escape or collisions.
- Around line 143-159: Remove --timeout from the documented docker run
invocation and update the policy table and timeout rules to state that
timeoutSeconds is enforced by the parent process. In the parent execution flow,
track the container ID, monitor the deadline, stop then kill the container when
it expires, collect its output, and return a timeout failure.

In `@specs/05-runtime-host/spec.md`:
- Around line 51-55: Update the public entry point export block in src/index.ts
to re-export createAllowlist from the allowlist module, alongside
CommandAllowlist, so consumers can construct the documented allowlist through
the package root.
- Around line 61-63: Update HostExecutorConfig.enabled so its type and
documentation agree: either make enabled optional and normalize omitted values
to false, or keep it required and remove the statement that it defaults to
false. Apply the chosen contract consistently wherever HostExecutorConfig is
consumed.
- Around line 250-253: Update the test plan to document the runtime-host package
or Nx test target command that invokes vitest run instead of bun test. Preserve
the existing test location and Docker-daemon requirements, and apply the same
command correction to the additional test-plan section.
- Around line 145-148: Update the timeout handling requirements in the “Apply
timeout” execution flow to terminate the entire process tree, using
process-group termination on POSIX or job-object termination on Windows as
appropriate. Ensure descendants are cleaned up, then record the timeout failure
result and return only after termination cleanup completes.
- Around line 76-77: Update the runtime host construction and related validation
paths around runAsUid so an omitted value resolves to the current UID, but
rejects the configuration when that effective UID is 0; alternatively require an
explicitly configured non-root UID. Preserve the existing non-root behavior and
apply the same validation to the additional runAsUid handling paths.
- Around line 152-153: Update the artifact collection step to canonicalize each
declared artifact path and verify it remains contained within config.workspace
before copying. Reject traversal and symlink-resolved paths that escape the
workspace, while preserving copying for valid in-workspace artifacts.
- Around line 202-216: Align HostTimeoutError and the timeout execution path
with a single observable contract: either return an ExecuteResult with status
"failure" or consistently raise HostTimeoutError. Update the public API
documentation and all affected tests, including the timeout behavior around the
referenced execution flow, so they assert the chosen contract consistently.
- Around line 131-144: Update the operation validation and spawn flow to resolve
the allowlisted command to its approved absolute executable before applying
environment overrides. Reject loader/interpreter-related variables from
operation.env and the final environment, and explicitly spawn the executable
with shell: false while preserving the existing allowlist and environment merge
behavior.
- Around line 307-310: Expand the “Retry policy” section to state that Scheduler
owns retries and HostExecutor models one process attempt, using
retry.maxAttempts, retry.backoffSeconds, and retry.retryOn. Define how logs,
duration, exit data, errors, and artifacts are combined across attempts,
including artifact staging, cleanup, overwrite behavior, and repeated
non-idempotent workspace side effects. Update the success test to configure
retry.maxAttempts instead of an unscoped maxAttempts.

In `@specs/06-planner/spec.md`:
- Around line 406-459: Update the test execution instruction for planner tests
to use the project’s Vitest workspace command with the appropriate package
selector, replacing the `bun test` command while retaining the existing test
location and coverage scope.
- Around line 119-121: Update the ProjectContext contract and its construction
to remove raw provider tokens from the returned context, replacing credentials
with availability metadata only. Keep actual secrets in the private runtime
credential provider, and ensure PlanResult and the CLI inspect output cannot
expose them; apply the same change to the additional credential-handling
section.

In `@specs/07-findings/spec.md`:
- Around line 160-170: Align the Baseline model and resolved comparison result
so resolved findings are representable: either persist complete Finding
snapshots alongside fingerprints and use them in the compare operation, or
change resolvedFindings to return fingerprint values. Update the Baseline
interface and all affected compare/result definitions and serialization paths
consistently, including the referenced resolved-entry handling.
- Around line 450-506: Update the test execution instruction at the start of the
findings test plan to use the project’s Vitest workspace command with the
appropriate package selector instead of Bun’s built-in runner. Keep the
referenced test directory and all listed test scenarios unchanged.

In `@specs/08-policy/spec.md`:
- Around line 309-359: Update the test execution instruction to use the
project’s Vitest workspace command with the appropriate package selector instead
of Bun’s built-in runner. Preserve the existing test location and coverage list.
- Around line 64-67: Extend the policy evaluation input, using Finding or
PolicyContext, to carry suppression state or the set of suppressed fingerprints.
Propagate this state into the evaluator so excludeSuppressed filters matching
findings when true and retains them when false, including custom-rule evaluation
and all related policy specification sections.

In `@specs/09-sdk/spec.md`:
- Around line 216-229: Update the SDK workflow example’s test task in the
defineWorkflow configuration to invoke the project script with “bun run test”
instead of “bun test”, matching the existing lint and typecheck task
conventions.
- Around line 367-417: Update the test-running instruction in the SDK test plan
to use the workspace’s Vitest command with the appropriate package selector
instead of Bun’s built-in runner, while keeping the referenced test directory
and coverage unchanged.
- Around line 136-144: Update the ExecutionResult interface to preserve the
complete runtime execution result, including operations, artifacts, logs,
errors, and duration, in addition to the existing findings, policyResult,
verdict, and output fields. Prefer nesting the runtime result when an existing
runtime-result type is available, or otherwise expose all required fields
directly so SDK callers can inspect delegated execution details.

In `@specs/10-cli/spec.md`:
- Around line 183-185: Resolve the CLI contract inconsistency for inspect by
either defining inspect --json as an alias for the global --format json option,
including matching behavior and tests, or removing --json from the inspect
command documentation and related tests. Keep the command reference and option
definitions consistent.
- Around line 359-439: Update the test execution instruction in the CLI test
plan to use the project’s Vitest workspace command with the appropriate package
selector instead of “bun test.” Leave the listed CLI behavior and test location
unchanged.

In `@specs/11-checks/spec.md`:
- Line 384: Remove the stray Markdown code fence at the end of the specification
so the document does not start an unterminated code block.
- Around line 221-227: Update PluginProposeRule.image and the associated
resolve() flow so plugin images cannot remain mutable tags: either validate that
provided images use an `@sha256`: digest or resolve every image to a digest-pinned
ResolvedCheck.image before execution. Preserve optional image behavior while
ensuring any configured image is immutable.

In `@specs/12-compiler-github/spec.md`:
- Line 259: Remove the trailing Markdown fence at the end of the specification
so it no longer starts an unintended code block. Leave the preceding document
content unchanged.
- Around line 141-142: Update the workflow generation represented by the install
and execute steps to use the configured concrete Sverka version from
GithubCompilerConfig.sverkaVersion or PlanMetadata.sverkaVersion instead of
sverka@latest; if neither provides a version, fail compilation rather than
emitting an unpinned workflow.
- Around line 137-142: Add a pinned oven-sh/setup-bun action step before the bun
install command in the generated workflow, ensuring Bun is available regardless
of the runner label accepted by GithubCompilerConfig.runner.

In `@specs/13-compiler-gitlab/spec.md`:
- Around line 195-197: Update the custom config.stages handling to validate it
against all stages generated from plan check categories; when a derived stage is
missing, reject the configuration or deterministically append the required
stage, unless an explicit category-to-stage override defines the mapping. Ensure
native output never contains a job stage absent from the configured stages list.
- Around line 120-127: The generated GitLab job configuration around the image
and before_script must provide Bun for every thin and native output mode.
Replace node:24 with a Bun-capable image, or add Bun installation before the
existing global sverka installation, and validate both generated modes use the
declared image while retaining the bun-based commands.

In `@specs/14-website/spec.md`:
- Around line 137-161: The website navigation structure must not reference
undeclared routes. Update the links in the User Documentation and Agentic
Documentation sections to use declared or rendered documentation routes, or add
matching route declarations for each target such as /docs/workflow-api and
/docs/cli before publishing these links.

In `@specs/15-documentation/spec.md`:
- Line 348: Update the repository tree code fence in the documentation
specification to declare the text language by adding the text fence annotation,
while preserving the existing tree content.
- Around line 248-254: Update the taxonomy entries around “Package Map” and the
additional affected entries to use the repository’s actual documentation paths:
engdocs/architecture/dependencies.md, engdocs/adr/ADR-003-canonical-plan-ir.md,
and engdocs/contributing/development-setup.md. Keep each entry’s slug and
metadata consistent with its corrected path so the taxonomy builder resolves
every referenced page.

In `@website/src/layouts/Base.astro`:
- Line 28: Update the og:url meta tag in the Base layout to derive its value
from the configured site URL and current route, rather than using the hardcoded
https://sverka.dev value. Preserve the canonical origin while appending the
active route path.

In `@website/src/pages/getting-started.astro`:
- Around line 4-13: Ensure the documented install and commands are backed by an
implemented CLI contract: add a `bin` entry for `sverka` in the `@sverka/cli`
package and implement the documented `init`, `run`, `plan --explain`, and
`compile --target github|gitlab` commands in `packages/cli/src/index.ts`;
alternatively remove these examples from both pages if the CLI will not be
implemented.

In `@website/src/styles/global.css`:
- Line 8: Update the --font-sans declaration to use lowercase, unquoted
font-family keywords for BlinkMacSystemFont and Roboto, while preserving the
existing font stack order and fallback values.

---

Outside diff comments:
In `@specs/14-website/spec.md`:
- Line 244: Remove the stray Markdown fence at the end of
specs/14-website/spec.md so it does not start an unintended code block.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5393097b-4378-4911-8cb3-fde93f5703c5

📥 Commits

Reviewing files that changed from the base of the PR and between 5ba5461 and d6449b9.

⛔ Files ignored due to path filters (3)
  • bun.lock is excluded by !**/*.lock
  • website/bun.lock is excluded by !**/*.lock
  • website/public/favicon.svg is excluded by !**/*.svg
📒 Files selected for processing (179)
  • .agents/skills/beads/SKILL.md
  • .agents/skills/beads/agents/openai.yaml
  • .claude/settings.json
  • .codacy.yml
  • .codex/config.toml
  • .codex/hooks.json
  • .gitignore
  • AGENTS.md
  • CLAUDE.md
  • LICENSE
  • README.md
  • agents/architect/agent.toml
  • agents/architect/prompt.template.md
  • agents/builder/agent.toml
  • agents/builder/prompt.template.md
  • agents/control-dispatcher/agent.toml
  • agents/mayor/agent.toml
  • agents/mayor/prompt.template.md
  • agents/reviewer/agent.toml
  • agents/reviewer/prompt.template.md
  • bunfig.toml
  • city.toml
  • engdocs/README.md
  • engdocs/adr/ADR-000-typescript-nx-monorepo.md
  • engdocs/adr/ADR-001-bun-package-manager.md
  • engdocs/adr/ADR-002-tsdown-build.md
  • engdocs/adr/ADR-003-canonical-plan-ir.md
  • engdocs/adr/ADR-004-thin-wrapper-ci-compiler.md
  • engdocs/adr/ADR-005-predecessor-reference-resolution.md
  • engdocs/architecture/dependencies.md
  • engdocs/architecture/overview.md
  • engdocs/contributing/development-setup.md
  • engdocs/contributing/guide.md
  • engdocs/contributing/waves.md
  • eslint.config.mjs
  • formulas/sverka-bootstrap.toml
  • formulas/sverka-wave.toml
  • nx.json
  • pack.toml
  • package.json
  • packages/checks/package.json
  • packages/checks/project.json
  • packages/checks/src/index.ts
  • packages/checks/tsconfig.json
  • packages/checks/tsdown.config.ts
  • packages/cli/package.json
  • packages/cli/project.json
  • packages/cli/src/index.ts
  • packages/cli/tsconfig.json
  • packages/cli/tsdown.config.ts
  • packages/compiler-earthly/package.json
  • packages/compiler-earthly/project.json
  • packages/compiler-earthly/src/index.ts
  • packages/compiler-earthly/tsconfig.json
  • packages/compiler-earthly/tsdown.config.ts
  • packages/compiler-github/package.json
  • packages/compiler-github/project.json
  • packages/compiler-github/src/index.ts
  • packages/compiler-github/tsconfig.json
  • packages/compiler-github/tsdown.config.ts
  • packages/compiler-gitlab/package.json
  • packages/compiler-gitlab/project.json
  • packages/compiler-gitlab/src/index.ts
  • packages/compiler-gitlab/tsconfig.json
  • packages/compiler-gitlab/tsdown.config.ts
  • packages/core/package.json
  • packages/core/project.json
  • packages/core/src/__tests__/composables/parallel.test.ts
  • packages/core/src/__tests__/composables/pipeline.test.ts
  • packages/core/src/__tests__/composables/run.test.ts
  • packages/core/src/__tests__/composables/when.test.ts
  • packages/core/src/__tests__/composables/workflow.test.ts
  • packages/core/src/__tests__/composition.test.ts
  • packages/core/src/__tests__/conditions.test.ts
  • packages/core/src/__tests__/dag.test.ts
  • packages/core/src/__tests__/errors.test.ts
  • packages/core/src/__tests__/helpers/runtime.ts
  • packages/core/src/__tests__/laziness.test.ts
  • packages/core/src/__tests__/matrix.test.ts
  • packages/core/src/__tests__/public-api.test.ts
  • packages/core/src/__tests__/runtime-modes.test.ts
  • packages/core/src/composables/matrix.ts
  • packages/core/src/composables/parallel.ts
  • packages/core/src/composables/pipeline.ts
  • packages/core/src/composables/run.ts
  • packages/core/src/composables/when.ts
  • packages/core/src/composables/workflow.ts
  • packages/core/src/errors.ts
  • packages/core/src/index.ts
  • packages/core/src/internal/conditions.ts
  • packages/core/src/internal/ids.ts
  • packages/core/src/internal/merge.ts
  • packages/core/src/internal/node.ts
  • packages/core/src/internal/plan.ts
  • packages/core/src/operation.ts
  • packages/core/src/runtime.ts
  • packages/core/tsconfig.json
  • packages/core/tsdown.config.ts
  • packages/findings/package.json
  • packages/findings/project.json
  • packages/findings/src/index.ts
  • packages/findings/tsconfig.json
  • packages/findings/tsdown.config.ts
  • packages/ir/package.json
  • packages/ir/project.json
  • packages/ir/src/index.ts
  • packages/ir/tsconfig.json
  • packages/ir/tsdown.config.ts
  • packages/planner/package.json
  • packages/planner/project.json
  • packages/planner/src/index.ts
  • packages/planner/tsconfig.json
  • packages/planner/tsdown.config.ts
  • packages/policy/package.json
  • packages/policy/project.json
  • packages/policy/src/index.ts
  • packages/policy/tsconfig.json
  • packages/policy/tsdown.config.ts
  • packages/runtime-docker/package.json
  • packages/runtime-docker/project.json
  • packages/runtime-docker/src/index.ts
  • packages/runtime-docker/tsconfig.json
  • packages/runtime-docker/tsdown.config.ts
  • packages/runtime-host/package.json
  • packages/runtime-host/project.json
  • packages/runtime-host/src/index.ts
  • packages/runtime-host/tsconfig.json
  • packages/runtime-host/tsdown.config.ts
  • packages/runtime-podman/package.json
  • packages/runtime-podman/project.json
  • packages/runtime-podman/src/index.ts
  • packages/runtime-podman/tsconfig.json
  • packages/runtime-podman/tsdown.config.ts
  • packages/runtime-remote/package.json
  • packages/runtime-remote/project.json
  • packages/runtime-remote/src/index.ts
  • packages/runtime-remote/tsconfig.json
  • packages/runtime-remote/tsdown.config.ts
  • packages/runtime/package.json
  • packages/runtime/project.json
  • packages/runtime/src/index.ts
  • packages/runtime/tsconfig.json
  • packages/runtime/tsdown.config.ts
  • packages/sdk/package.json
  • packages/sdk/project.json
  • packages/sdk/src/index.ts
  • packages/sdk/tsconfig.json
  • packages/sdk/tsdown.config.ts
  • specs/00-overview/spec.md
  • specs/01-core/plan.md
  • specs/01-core/spec.md
  • specs/02-ir/spec.md
  • specs/03-runtime/spec.md
  • specs/04-runtime-docker/spec.md
  • specs/05-runtime-host/spec.md
  • specs/06-planner/spec.md
  • specs/07-findings/spec.md
  • specs/08-policy/spec.md
  • specs/09-sdk/spec.md
  • specs/10-cli/spec.md
  • specs/11-checks/spec.md
  • specs/12-compiler-github/spec.md
  • specs/13-compiler-gitlab/spec.md
  • specs/14-website/spec.md
  • specs/15-documentation/spec.md
  • tsconfig.base.json
  • tsconfig.json
  • website/.astro/content-assets.mjs
  • website/.astro/content-modules.mjs
  • website/.astro/content.d.ts
  • website/.astro/types.d.ts
  • website/astro.config.mjs
  • website/package.json
  • website/src/layouts/Base.astro
  • website/src/pages/docs.astro
  • website/src/pages/getting-started.astro
  • website/src/pages/index.astro
  • website/src/styles/global.css
  • website/tsconfig.json

Comment thread engdocs/architecture/overview.md Outdated
Comment thread engdocs/architecture/overview.md
Comment thread engdocs/contributing/development-setup.md
Comment thread engdocs/README.md Outdated
Comment thread engdocs/README.md
Comment thread specs/12-compiler-github/spec.md
Comment thread specs/15-documentation/spec.md Outdated
Comment thread website/src/layouts/Base.astro
Comment thread website/src/pages/getting-started.astro
Comment thread website/src/styles/global.css

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review continued from previous batch...

Comment thread .agents/skills/beads/SKILL.md
Comment thread .codacy.yml Outdated
Comment thread .gitignore
Comment thread AGENTS.md
Comment thread agents/builder/prompt.template.md
Comment thread specs/12-compiler-github/spec.md
Comment thread specs/13-compiler-gitlab/spec.md
Comment thread specs/13-compiler-gitlab/spec.md
Comment thread specs/14-website/spec.md
Comment thread specs/15-documentation/spec.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review continued from previous batch...

Comment thread agents/architect/prompt.template.md
Comment thread agents/mayor/prompt.template.md
Comment thread agents/mayor/prompt.template.md
Comment thread agents/reviewer/prompt.template.md
Comment thread engdocs/contributing/guide.md
Comment thread specs/05-runtime-host/spec.md
Comment thread specs/05-runtime-host/spec.md
Comment thread specs/05-runtime-host/spec.md
Comment thread specs/05-runtime-host/spec.md
Comment thread specs/05-runtime-host/spec.md
@codeant-ai

codeant-ai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed bc9349d Aug 11, 2026 · 10:32 10:33
✅ Incremental review completed c1dbec0 Aug 11, 2026 · 07:25 07:25
✅ Incremental review completed a09ab0a Aug 11, 2026 · 06:22 06:23
✅ Incremental review completed 0c34266 Aug 10, 2026 · 22:48 22:49
✅ Incremental review completed 2193d13 Aug 10, 2026 · 21:28 21:31

@codeant-ai codeant-ai Bot added the size:XXL This PR changes 1000+ lines, ignoring generated files label Aug 10, 2026
Comment thread packages/core/src/__tests__/conditions.test.ts
Comment thread packages/core/src/internal/ids.ts Outdated
Comment thread packages/core/src/internal/ids.ts
Comment thread packages/core/src/runtime.ts Outdated
Comment thread packages/core/src/internal/plan.ts Outdated
Comment thread packages/core/src/internal/plan.ts Outdated
Comment thread packages/core/src/internal/plan.ts Outdated
Comment thread packages/core/src/internal/plan.ts
Comment thread packages/core/src/internal/plan.ts Outdated
@ThePlenkov
ThePlenkov marked this pull request as draft August 10, 2026 21:33
@ThePlenkov
ThePlenkov marked this pull request as ready for review August 10, 2026 22:42
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Wave 1: Add @sverka/core workflow graph, planner, and runtime modes

✨ Enhancement 🧪 Tests 📝 Documentation ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Introduce @sverka/core workflow DSL (run/pipeline/parallel/when/matrix/workflow).
• Add planner to expand matrices, resolve dependencies, topo-sort, and evaluate conditions.
• Add comprehensive Vitest coverage and tighten repo tooling/docs for Bun + Nx workflows.
Diagram

graph TD
  A["User workflow code"] --> B["Composables"] --> C["Workflow"] --> D["Planner (planWorkflow)"] --> E["Runtime.evaluate/finalize"] --> F["RuntimeResult (ops+outcomes)"]
  D --> G["Condition evaluator"]
  D --> H["ID + DAG validation"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Use a small expression parser library for conditions
  • ➕ Less custom parsing code to maintain
  • ➕ Potentially richer grammar with well-tested edge cases
  • ➖ Adds dependency surface area and supply-chain risk
  • ➖ Harder to strictly constrain to a safe subset
2. Represent graph purely as IDs (no predecessor object refs)
  • ➕ Simplifies planning by avoiding identity-based node maps
  • ➕ Easier serialization/debugging at composition time
  • ➖ Requires assigning IDs early, conflicting with strict laziness/matrix expansion
  • ➖ More user-facing complexity (managing IDs) during composition
3. Adopt a dedicated DAG library for topo-sort/cycle detection
  • ➕ Battle-tested algorithms and clearer complexity bounds
  • ➕ Less bespoke validation logic
  • ➖ Extra dependency for relatively small, straightforward logic
  • ➖ May not align with custom semantics (artifact flattening, matrix expansion)

Recommendation: The PR’s approach (small, explicit planner with a safe hand-rolled condition parser and deterministic IDs) is appropriate for a foundational core package: it keeps the runtime contract clean, preserves laziness, and avoids bringing in heavyweight dependencies too early. The main tradeoff—maintaining bespoke parsing/DAG logic—seems acceptable at this stage given the constrained grammar and strong test coverage.

Files changed (72) +3159 / -187

Enhancement (18) +1240 / -0
index.tsAdd CliError base error class to @sverka/cli +15/-0

Add CliError base error class to @sverka/cli

• Introduces a package-scoped error base class with code and optional context for consistent error handling.

packages/cli/src/index.ts

matrix.tsImplement matrix() composable with planning-time expansion marker +27/-0

Implement matrix() composable with planning-time expansion marker

• Adds matrix() to attach matrix dimensions to an operation and mark it as a template for planner expansion.

packages/core/src/composables/matrix.ts

parallel.tsImplement parallel() as a synthetic join node with siblings +23/-0

Implement parallel() as a synthetic join node with siblings

• Creates a custom join artifact node that groups siblings without introducing dependency edges between them.

packages/core/src/composables/parallel.ts

pipeline.tsImplement pipeline() sequential composition +28/-0

Implement pipeline() sequential composition

• Chains operations via predecessor references and returns the tail; introduces an explicit empty-pipeline artifact node.

packages/core/src/composables/pipeline.ts

run.tsImplement run() operation constructor +12/-0

Implement run() operation constructor

• Creates a new operation node from a partial spec, defaulting kind to run and preserving laziness.

packages/core/src/composables/run.ts

when.tsImplement when() conditional wrapper +16/-0

Implement when() conditional wrapper

• Attaches a condition expression string to an operation spec while keeping composition lazy and immutable.

packages/core/src/composables/when.ts

workflow.tsImplement workflow() and Workflow interface +28/-0

Implement workflow() and Workflow interface

• Defines a frozen workflow wrapper over root operations that delegates planning/execution/compile behavior to the internal planner via plan(runtime).

packages/core/src/composables/workflow.ts

errors.tsAdd core error hierarchy +30/-0

Add core error hierarchy

• Introduces CoreError plus PlanningError and CompositionError subclasses with stable code and context fields.

packages/core/src/errors.ts

index.tsDefine @sverka/core public API exports +25/-0

Define @sverka/core public API exports

• Exports operation/runtime types, composables, workflow type, and error classes while keeping internal modules private.

packages/core/src/index.ts

conditions.tsAdd safe condition tokenizer/parser and evaluator +250/-0

Add safe condition tokenizer/parser and evaluator

• Implements a hand-rolled tokenizer and recursive descent parser for boolean expressions over PlanContext, throwing CompositionError on invalid syntax.

packages/core/src/internal/conditions.ts

ids.tsAdd deterministic ID assignment and matrix child ID formatting +71/-0

Add deterministic ID assignment and matrix child ID formatting

• Implements derived IDs based on kind and name/command/index, collision suffixing, and type-prefixed matrix value formatting to avoid collisions.

packages/core/src/internal/ids.ts

merge.tsAdd spec merge utilities for composable operations +37/-0

Add spec merge utilities for composable operations

• Provides concatDedupe and mergeSpecs to combine partial operation specs, concatenating tags/dependsOn while replacing scalar and nested object fields.

packages/core/src/internal/merge.ts

node.tsImplement internal OperationNode graph structure and immutable methods +92/-0

Implement internal OperationNode graph structure and immutable methods

• Defines internal node fields for predecessors/siblings and implements after/with/named/tagged as immutable transformations.

packages/core/src/internal/node.ts

plan.tsImplement workflow planner: discovery, matrix expansion, DAG validation +399/-0

Implement workflow planner: discovery, matrix expansion, DAG validation

• Plans workflows by discovering nodes, expanding matrices, flattening planning artifacts, assigning IDs, resolving edges, detecting cycles, topo-sorting, and driving runtime evaluation with skipped outcomes for false conditions.

packages/core/src/internal/plan.ts

operation.tsDefine Operation/OperationSpec data model for the core DSL +82/-0

Define Operation/OperationSpec data model for the core DSL

• Introduces the OperationKind union, serializable OperationSpec, and the lazy Operation interface for composable workflow definitions.

packages/core/src/operation.ts

runtime.tsDefine Runtime contract and result/outcome types +75/-0

Define Runtime contract and result/outcome types

• Introduces runtime modes, plan context typing, operation outcomes, and the Runtime interface used by planner/executors/compilers.

packages/core/src/runtime.ts

index.tsAdd PolicyError base error class to @sverka/policy +15/-0

Add PolicyError base error class to @sverka/policy

• Introduces a package-scoped error base class with code and optional context for consistent error handling.

packages/policy/src/index.ts

index.tsAdd RuntimeError base error class to @sverka/runtime +15/-0

Add RuntimeError base error class to @sverka/runtime

• Introduces a package-scoped error base class with code and optional context for consistent error handling.

packages/runtime/src/index.ts

Tests (14) +909 / -0
parallel.test.tsAdd tests for parallel() join-node and immutability behavior +37/-0

Add tests for parallel() join-node and immutability behavior

• Verifies parallel() produces a synthetic join node with siblings, adds no inter-sibling edges, and does not mutate inputs.

packages/core/src/tests/composables/parallel.test.ts

pipeline.test.tsAdd tests for pipeline() chaining and no-mutation semantics +42/-0

Add tests for pipeline() chaining and no-mutation semantics

• Covers linear predecessor wiring, single/empty pipeline behavior, and immutability of source operations.

packages/core/src/tests/composables/pipeline.test.ts

run.test.tsAdd tests for run() node creation and spec preservation +39/-0

Add tests for run() node creation and spec preservation

• Checks default kind behavior, honoring explicit kind, laziness, and round-tripping of spec fields.

packages/core/src/tests/composables/run.test.ts

when.test.tsAdd tests for when() condition attachment and laziness +25/-0

Add tests for when() condition attachment and laziness

• Ensures when() adds condition to the returned operation without mutating the input and never throws at call time.

packages/core/src/tests/composables/when.test.ts

workflow.test.tsAdd tests for workflow() freezing and planning output +51/-0

Add tests for workflow() freezing and planning output

• Verifies Workflow is frozen, plan() returns expected operations, and supports mixed parallel + pipeline roots.

packages/core/src/tests/composables/workflow.test.ts

composition.test.tsTest spec merging and immutable Operation method semantics +121/-0

Test spec merging and immutable Operation method semantics

• Covers concat/dedupe semantics, mergeSpecs behavior, node creation defaults, and ensures after/with/named/tagged are immutable.

packages/core/src/tests/composition.test.ts

conditions.test.tsAdd tests for safe condition parsing/evaluation semantics +97/-0

Add tests for safe condition parsing/evaluation semantics

• Validates boolean logic precedence, identifier lookup (including dotted keys), coercive equality, array truthiness, and malformed-expression errors.

packages/core/src/tests/conditions.test.ts

dag.test.tsAdd tests for DAG validation and matrix deferred validation +97/-0

Add tests for DAG validation and matrix deferred validation

• Tests cycle detection, duplicate IDs, topo ordering, and that matrix validation is deferred to plan time (not composition time).

packages/core/src/tests/dag.test.ts

errors.test.tsAdd tests for CoreError/PlanningError/CompositionError contract +40/-0

Add tests for CoreError/PlanningError/CompositionError contract

• Asserts error class hierarchy, code fields, and optional context behavior.

packages/core/src/tests/errors.test.ts

runtime.tsAdd test Runtime helpers for plan/execute/compile modes +73/-0

Add test Runtime helpers for plan/execute/compile modes

• Provides Runtime doubles that record evaluated operations, return outcomes, and optionally emit compile artifacts.

packages/core/src/tests/helpers/runtime.ts

laziness.test.tsAdd tests ensuring composables and planning do not perform I/O +65/-0

Add tests ensuring composables and planning do not perform I/O

• Mocks fs/process and spies on fetch to ensure defining workflows and plan() never touch I/O surfaces.

packages/core/src/tests/laziness.test.ts

matrix.test.tsAdd tests for matrix expansion semantics and env injection +65/-0

Add tests for matrix expansion semantics and env injection

• Checks cartesian expansion, deterministic child IDs, MATRIX_* env injection, predecessor inheritance, and removal of template markers.

packages/core/src/tests/matrix.test.ts

public-api.test.tsAdd tests for @sverka/core public export surface +50/-0

Add tests for @sverka/core public export surface

• Verifies key composables and error classes are exported and ensures known internal helpers are not re-exported.

packages/core/src/tests/public-api.test.ts

runtime-modes.test.tsAdd tests for plan/execute/compile runtime mode behavior +107/-0

Add tests for plan/execute/compile runtime mode behavior

• Ensures plan mode records operations, execute mode calls evaluate for included ops, compile mode emits artifacts, and false conditions skip evaluation.

packages/core/src/tests/runtime-modes.test.ts

Documentation (14) +835 / -52
AGENTS.mdClarify test command and pin Devin model guidance +5/-1

Clarify test command and pin Devin model guidance

• Updates instructions to use 'bun run test' via Nx (not Bun’s built-in runner) and documents the required DEVIN_MODEL setting for agents.

AGENTS.md

CLAUDE.mdReplace placeholder content with project-specific guidance +14/-7

Replace placeholder content with project-specific guidance

• Adds concrete build/test commands and documents Sverka architecture and conventions (SDD/TDD, no any, public API/export rules, error class conventions).

CLAUDE.md

README.mdFix markdown fences and update test command docs +3/-3

Fix markdown fences and update test command docs

• Marks ASCII diagrams as 'text' blocks and switches references from 'bun test' to 'bun run test' for Vitest via Nx.

README.md

prompt.template.mdExpand architect agent prompt with skills/personality and process +37/-5

Expand architect agent prompt with skills/personality and process

• Adds explicit spec-first and minimalist/critical-thinking requirements plus mandatory skills and clearer workflow steps for producing implementation plans.

agents/architect/prompt.template.md

prompt.template.mdExpand builder agent prompt with TDD/drill-first requirements +40/-6

Expand builder agent prompt with TDD/drill-first requirements

• Adds explicit TDD discipline, drill-first debugging process, mandatory skills, and a more detailed step-by-step workflow.

agents/builder/prompt.template.md

prompt.template.mdStrengthen mayor orchestration prompt and stacked-PR procedure +132/-3

Strengthen mayor orchestration prompt and stacked-PR procedure

• Adds drill-first escalation, wave progression rules, reporting expectations, and a detailed stacked PR workflow for wave-by-wave delivery.

agents/mayor/prompt.template.md

prompt.template.mdExpand reviewer prompt with evidence-driven gating checklist +43/-9

Expand reviewer prompt with evidence-driven gating checklist

• Adds stricter review methodology, mandatory skills, and explicit instructions to run tests/build/lint/typecheck rather than trusting claims.

agents/reviewer/prompt.template.md

README.mdAdd ADR links and fix markdown fence language tags +3/-1

Add ADR links and fix markdown fence language tags

• Marks structure diagrams as 'text' blocks and adds ADR references related to predecessor resolution and ID strategy.

engdocs/README.md

ADR-005-predecessor-reference-resolution.mdDocument predecessor-reference resolution decision +63/-0

Document predecessor-reference resolution decision

• Adds an ADR describing why composition stores predecessor references (Operation objects) and resolves to string IDs during planning.

engdocs/adr/ADR-005-predecessor-reference-resolution.md

overview.mdFix markdown fence language tags for diagrams +1/-1

Fix markdown fence language tags for diagrams

• Updates the system flow diagram fence to use 'text' for correct rendering.

engdocs/architecture/overview.md

spec.mdFix markdown fence language tags in overview spec +1/-1

Fix markdown fence language tags in overview spec

• Marks directory-tree blocks as 'text' fences for correct formatting.

specs/00-overview/spec.md

plan.mdAdd Wave 1 implementation plan for core package +311/-0

Add Wave 1 implementation plan for core package

• Introduces a detailed file-by-file, TDD-oriented build plan covering errors, types, composables, planner semantics, and verification gates.

specs/01-core/plan.md

spec.mdRefine core spec exports and planning semantics documentation +181/-14

Refine core spec exports and planning semantics documentation

• Expands the documented public exports and adds detailed semantics for predecessor resolution, ID assignment, matrix expansion, and condition evaluation.

specs/01-core/spec.md

spec.mdFix markdown fence language tags in documentation spec +1/-1

Fix markdown fence language tags in documentation spec

• Marks documentation layout blocks as 'text' fences for consistent rendering.

specs/15-documentation/spec.md

Other (26) +175 / -135
.codacy.ymlRework Codacy config to avoid ESLint es-x false positives +28/-110

Rework Codacy config to avoid ESLint es-x false positives

• Adds documentation notes about unsupported keys and excludes all JS/TS sources from Codacy ESLint engines (eslint-8 and eslint-9). This avoids es-x rules incorrectly flagging modern TypeScript/Node syntax.

.codacy.yml

.eslintrc.jsonAdd ESLint config disabling es-x rules for modern TS/Node +107/-0

Add ESLint config disabling es-x rules for modern TS/Node

• Introduces a repo ESLint config that turns off es-x rules and a few other noisy rules to match the project’s Node 24 + TypeScript expectations.

.eslintrc.json

.gitignoreIgnore tmp/ directory +3/-0

Ignore tmp/ directory

• Adds tmp/ to gitignore for temporary workspace artifacts.

.gitignore

agent.tomlSwitch architect agent session behavior to wake_mode resume +1/-1

Switch architect agent session behavior to wake_mode resume

• Replaces the session field with wake_mode configuration for agent lifecycle control.

agents/architect/agent.toml

agent.tomlSwitch builder agent session behavior to wake_mode resume +1/-1

Switch builder agent session behavior to wake_mode resume

• Replaces the session field with wake_mode configuration for agent lifecycle control.

agents/builder/agent.toml

agent.tomlAdd control-dispatcher agent configuration +2/-0

Add control-dispatcher agent configuration

• Introduces a city-scoped dispatcher config limiting concurrent active sessions.

agents/control-dispatcher/agent.toml

agent.tomlSwitch mayor agent session behavior to wake_mode resume +1/-1

Switch mayor agent session behavior to wake_mode resume

• Replaces the session field with wake_mode configuration for agent lifecycle control.

agents/mayor/agent.toml

agent.tomlSwitch reviewer agent session behavior to wake_mode resume +1/-1

Switch reviewer agent session behavior to wake_mode resume

• Replaces the session field with wake_mode configuration for agent lifecycle control.

agents/reviewer/agent.toml

bun.lockWire workspace dependencies between packages +6/-0

Wire workspace dependencies between packages

• Adds workspace dependency links (@sverka/ir → @sverka/core, @sverka/runtime → @sverka/ir) to reflect package layering.

bun.lock

city.tomlConfigure Devin environment and daemon dispatch settings +5/-2

Configure Devin environment and daemon dispatch settings

• Sets DEVIN_MODEL/permission mode at workspace level and tunes daemon scheduling knobs (dispatcher, concurrency, debounce).

city.toml

sverka-wave.tomlAssign finalize step to mayor agent +1/-0

Assign finalize step to mayor agent

• Updates the wave formula so the finalize step runs under the mayor agent.

formulas/sverka-wave.toml

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/checks/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/cli/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/compiler-earthly/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/compiler-github/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/compiler-gitlab/project.json

package.jsonSwitch core package exports to .mjs/.mts outputs +5/-5

Switch core package exports to .mjs/.mts outputs

• Updates package entrypoints and export map to use 'index.mjs' and 'index.d.mts', aligning with ESM output expectations.

packages/core/package.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/core/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/findings/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/planner/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/policy/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/runtime-docker/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/runtime-host/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/runtime-podman/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/runtime-remote/project.json

project.jsonAllow empty Vitest projects to pass in Nx test target +1/-1

Allow empty Vitest projects to pass in Nx test target

• Adds '--passWithNoTests' to the Nx test command to avoid failing packages without tests yet.

packages/sdk/project.json

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The current implementation fails to meet the core architectural requirements defined in ADR-006. Specifically, the ID generation logic uses non-deterministic strings instead of the required content-addressed SHA-256 hashes, which compromises cache stability and plan reproducibility. Additionally, the PR is missing the internal/canonical.ts module required for stable serialization, as outlined in the implementation plan. Codacy analysis indicates this PR is not up to standards due to high cyclomatic complexity in the expression lexer and planning logic. While the functional requirements for workflow composition and execution planning (run, pipeline, matrix, etc.) are implemented, these architectural and quality issues must be resolved before merging.

About this PR

  • ID generation significantly diverges from ADR-006 and the core specification. The use of human-readable strings with monotonic counters instead of content-addressed SHA-256 hashes breaks reproducibility and the distributed caching model.
  • The implementation of packages/core/src/internal/canonical.ts is missing from this PR. This module is essential for deterministic serialization of operations, which is a prerequisite for valid content-addressed ID generation.

Test suggestions

  • Cyclic dependency detection in the workflow graph
  • Matrix expansion into cartesian product nodes with injected environment variables
  • Condition expression parsing and evaluation with operator precedence (NOT > AND > OR)
  • Verification of laziness: no side effects (I/O) during workflow definition or planning
  • Immutability of operations: composition methods return new instances and do not mutate originals
  • Topological sorting respects dependency edges (predecessors before successors)

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread packages/core/src/internal/ids.ts
Comment thread packages/core/src/internal/conditions.ts
Comment thread specs/01-core/plan.md
Comment thread packages/core/src/internal/plan.ts
Comment thread packages/core/src/internal/plan.ts Outdated
@codeant-ai codeant-ai Bot added size:XXL This PR changes 1000+ lines, ignoring generated files and removed size:XXL This PR changes 1000+ lines, ignoring generated files labels Aug 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 17

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/core/src/__tests__/conditions.test.ts`:
- Around line 87-96: Restructure the test around evaluateCondition so the
sentinel failure cannot be caught by the assertion block. Narrow the caught
value from unknown with an appropriate instanceof CompositionError check, then
assert its code and context without type casts; ensure the test fails clearly
when evaluateCondition does not throw.

In `@packages/core/src/__tests__/dag.test.ts`:
- Around line 19-25: Replace the unsafe CompositionError casts in both catch
blocks of the DAG tests with explicit narrowing from unknown, using an
appropriate CompositionError type guard or validated instanceof check before
accessing context. Ensure the tests fail for unrelated error types while
preserving the existing cycle-context assertions.
- Around line 9-40: Add a test in the “DAG validation” suite, before the cycle
or duplicate-ID cases, covering a workflow whose operation uses dependsOn with
an unresolved ID such as “ghost”; assert that wf.plan(makePlanRuntime()) rejects
with CompositionError and an error message containing the unknown dependency ID.

In `@packages/core/src/__tests__/matrix.test.ts`:
- Around line 31-34: Update the assertions in the matrix operations test to
verify each spec’s MATRIX_NODE and MATRIX_OS values match the expected pairing
encoded by its operation ID suffix, rather than only checking that they are
defined. Preserve the existing product-size assertions and ensure incorrect or
duplicated environment mappings fail.
- Around line 43-47: Update the test iterating over result.operations to first
collect entries whose IDs start with "run:test[" and assert that at least one
matching operation exists, then verify each matching operation depends on
["run:build"].

In `@packages/core/src/internal/ids.ts`:
- Around line 40-53: Update matrixChildId and formatMatrixValue so delimiter
characters in matrix keys and values are escaped before constructing the ID,
preventing commas and equals signs from changing component boundaries. Ensure
objects and null are serialized distinctly rather than both relying on ambiguous
String(v) output, while preserving existing IDs for values without delimiters.
- Around line 30-34: Update derivedBase() and its collision-suffix handling so
unnamed operations derive IDs from stable node content rather than the discovery
index, preserving IDs when unrelated roots alter traversal order; alternatively,
document this discovery-order limitation in the assignId documentation if
reproducibility is not required.

In `@packages/core/src/internal/plan.ts`:
- Around line 349-357: Remove the duplicated unknown-dependency validation from
topoSort, preserving the single CompositionError check in detectCycles. Update
the planner pipeline to validate dependencies once before cycle detection, using
a separate validateDeps(specs) step if needed, while keeping topological sorting
focused on ordering.
- Around line 160-174: Update cartesianProduct to enforce a configurable maximum
combination count before materializing combinations, throwing CompositionError
when the limit is exceeded. Reuse the existing configuration/error-context
mechanisms and include each dimension’s key and size in the error context;
preserve the current product behavior when within the limit.
- Around line 121-158: Reduce expandMatrices() cognitive complexity by
extracting dimension checks into validateDims(dims) and matrix child creation
into buildMatrixChild(node, combo). Update expandMatrices() to call these
helpers while preserving the existing validation errors, environment variables,
marker removal, and __matrixCombo metadata.
- Around line 330-362: Replace the recursive visit function in detectCycles with
an iterative depth-first traversal using an explicit stack of operation frames,
preserving gray/black coloring, cycle-path reporting, unknown-dependency
validation, and stack cleanup. Ensure chains of arbitrary supported length do
not use the JavaScript call stack and all graph validation failures remain
CompositionError instances.
- Around line 146-155: Remove the __matrixCombo mutation in expandMatrices and
have it return the expanded nodes together with a Map<OperationNode, readonly
[string, unknown][]> keyed by each child and its combo. Update assignIds and its
callers to accept and read this map instead of using the double-cast hidden
property, preserving matrix-specific ID assignment.
- Around line 47-64: Update the operation loop around runtime.evaluate to stop
after a "failure" or "cancelled" outcome unless the failed OperationSpec has
continueOnError enabled. For each unreached operation, append a cancelled
OperationOutcome rather than evaluating it, while preserving condition-based
"skipped" outcomes and normal execution for permitted continuation.
- Around line 62-73: Ensure planWorkflow always invokes runtime.finalize() when
any runtime.evaluate() call rejects. Wrap the evaluation loop and finalization
flow in try/finally, preserving rejection propagation while guaranteeing
cleanup; keep successful outcome collection and finalized return behavior
unchanged.
- Around line 294-324: Refactor buildSpec() to eliminate the repeated
conditional spreads for optional fields by copying those keys through a shared
list or equivalent iteration. Preserve all existing field names, omission
behavior for undefined values, and required fields; adding a new optional field
should require only one list entry.

In `@packages/core/src/runtime.ts`:
- Around line 12-20: Make outcomes required on the RuntimeResult interface, then
update every Runtime.finalize() implementation to always return an outcomes
array, using an empty array when there are no outcomes so planWorkflow() can
overwrite it.
- Around line 63-64: Define and export a dedicated type for the runtime-supplied
portion of RuntimeResult, excluding operations, outcomes, and durationMs. Update
the Runtime.finalize() method to return this narrower type, adjust
planWorkflow() to compose the final RuntimeResult from it, and re-export the new
public type through the package src/index.ts entry point.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 0d9b1e07-1638-4eb9-b822-eb62e880b275

📥 Commits

Reviewing files that changed from the base of the PR and between d6449b9 and 8e63c00.

📒 Files selected for processing (19)
  • .codacy.yml
  • .eslintrc.json
  • .gitignore
  • CLAUDE.md
  • README.md
  • engdocs/README.md
  • engdocs/architecture/overview.md
  • packages/cli/src/index.ts
  • packages/core/src/__tests__/conditions.test.ts
  • packages/core/src/__tests__/dag.test.ts
  • packages/core/src/__tests__/matrix.test.ts
  • packages/core/src/internal/ids.ts
  • packages/core/src/internal/plan.ts
  • packages/core/src/runtime.ts
  • packages/policy/src/index.ts
  • packages/runtime/src/index.ts
  • specs/00-overview/spec.md
  • specs/01-core/spec.md
  • specs/15-documentation/spec.md
📜 Review details
🧰 Additional context used
📓 Path-based instructions (9)
specs/**/*.{md,mdx}

📄 CodeRabbit inference engine (AGENTS.md)

Write numbered, structured specifications before implementation as part of spec-driven development.

Files:

  • specs/00-overview/spec.md
  • specs/15-documentation/spec.md
  • specs/01-core/spec.md
**/*.{ts,tsx,js,jsx,json,md,mdx}

📄 CodeRabbit inference engine (AGENTS.md)

Use Prettier for formatting.

Files:

  • specs/00-overview/spec.md
  • packages/core/src/__tests__/conditions.test.ts
  • packages/policy/src/index.ts
  • packages/core/src/__tests__/dag.test.ts
  • packages/core/src/internal/ids.ts
  • engdocs/architecture/overview.md
  • engdocs/README.md
  • packages/core/src/__tests__/matrix.test.ts
  • packages/cli/src/index.ts
  • CLAUDE.md
  • packages/runtime/src/index.ts
  • specs/15-documentation/spec.md
  • packages/core/src/runtime.ts
  • packages/core/src/internal/plan.ts
  • README.md
  • specs/01-core/spec.md
specs/**/*.md

📄 CodeRabbit inference engine (CLAUDE.md)

Write specifications first in the specs/ directory using numbered, structured documents (SDD).

Files:

  • specs/00-overview/spec.md
  • specs/15-documentation/spec.md
  • specs/01-core/spec.md
**/*.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

**/*.{ts,tsx}: Use strict TypeScript and never use any; use unknown with appropriate narrowing instead.
Use TypeScript with ESM-compatible module conventions.

**/*.{ts,tsx}: Do not use any in TypeScript; use unknown and narrow it. Maintain strict TypeScript practices.
Use custom error classes for package-specific error handling.

Files:

  • packages/core/src/__tests__/conditions.test.ts
  • packages/policy/src/index.ts
  • packages/core/src/__tests__/dag.test.ts
  • packages/core/src/internal/ids.ts
  • packages/core/src/__tests__/matrix.test.ts
  • packages/cli/src/index.ts
  • packages/runtime/src/index.ts
  • packages/core/src/runtime.ts
  • packages/core/src/internal/plan.ts
**/*.{test,spec}.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

**/*.{test,spec}.{ts,tsx}: Write tests before implementation and use Vitest for testing.
Run tests with Vitest via the project's bun run test command; do not confuse it with Bun's built-in bun test runner.

Files:

  • packages/core/src/__tests__/conditions.test.ts
  • packages/core/src/__tests__/dag.test.ts
  • packages/core/src/__tests__/matrix.test.ts
**/src/index.{ts,tsx}

📄 CodeRabbit inference engine (AGENTS.md)

Export everything that is public from the package's src/index.ts entry point.

Files:

  • packages/policy/src/index.ts
  • packages/cli/src/index.ts
  • packages/runtime/src/index.ts
**/src/index.ts

📄 CodeRabbit inference engine (CLAUDE.md)

Export everything public from each package's src/index.ts entry point.

Files:

  • packages/policy/src/index.ts
  • packages/cli/src/index.ts
  • packages/runtime/src/index.ts
engdocs/**/*.{md,mdx}

📄 CodeRabbit inference engine (AGENTS.md)

Create engineering documentation before implementing code when the work requires engineering documentation.

Files:

  • engdocs/architecture/overview.md
  • engdocs/README.md
engdocs/**/*.md

📄 CodeRabbit inference engine (CLAUDE.md)

Create engineering documentation in engdocs/ before implementing code (document-first development).

Files:

  • engdocs/architecture/overview.md
  • engdocs/README.md
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Use Nx to orchestrate monorepo builds, tests, linting, and type-checking.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Organize work in waves using the architect, builder, and reviewer roles.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: All work flows through the mayor agent, with multi-step orchestration defined in `formulas/`.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Use `bd` (Beads) for all task tracking; do not use TodoWrite, TaskCreate, markdown TODO lists, or ad hoc memory files.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Do not override the configured `DEVIN_MODEL=glm-5-2` with a paid model.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Run relevant quality gates after code changes, update issue status, and report changed files, validation, and blocked sync or commit steps at handoff.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:09.173Z
Learning: Do not commit or push changes without explicit authority from the active profile or user request.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:15.729Z
Learning: Use `bd` for all task tracking; do not use TodoWrite, TaskCreate, markdown TODO lists, or `MEMORY.md` files. Run `bd prime` for workflow details.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:15.729Z
Learning: At session completion, file follow-up issues, run applicable quality gates, update issue status, and report changes, validation, and blocked sync steps. Do not commit or push without explicit authority.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:15.729Z
Learning: Use the documented build and test commands: `bun install`, `bun run build`, `bun run test`, `bun run lint`, and `bun run typecheck` as applicable.
Learnt from: CR
Repo: sverka-dev/sverka

Timestamp: 2026-08-10T22:43:15.729Z
Learning: Write tests before implementation (TDD).
🪛 GitHub Check: SonarCloud Code Analysis
packages/core/src/internal/plan.ts

[warning] 285-285: Use .includes() instead of .some() when checking value existence.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_s8kOKBTR_KTfKo2sn&open=AZ_s8kOKBTR_KTfKo2sn&pullRequest=1


[warning] 147-147: The empty object is useless.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_s8kOKBTR_KTfKo2sm&open=AZ_s8kOKBTR_KTfKo2sm&pullRequest=1


[failure] 121-121: Refactor this function to reduce its Cognitive Complexity from 18 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_s8kOKBTR_KTfKo2sl&open=AZ_s8kOKBTR_KTfKo2sl&pullRequest=1


[failure] 294-294: Refactor this function to reduce its Cognitive Complexity from 18 to the 15 allowed.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_s8kOKBTR_KTfKo2so&open=AZ_s8kOKBTR_KTfKo2so&pullRequest=1

🪛 markdownlint-cli2 (0.23.2)
specs/01-core/spec.md

[warning] 380-380: Fenced code blocks should have a language specified

(MD040, fenced-code-language)


[warning] 441-441: Fenced code blocks should have a language specified

(MD040, fenced-code-language)

🔇 Additional comments (28)
packages/policy/src/index.ts (1)

2-16: LGTM!

packages/cli/src/index.ts (1)

2-16: LGTM!

packages/runtime/src/index.ts (1)

2-16: LGTM!

packages/core/src/internal/plan.ts (2)

187-213: 🗄️ Data Integrity & Integration

Verify predecessor identity after flattenArtifacts() rebuilds a node.

Line 209 returns a replacement node. Any other node that still holds the original node in its predecessors array keeps the old identity, and idMap at line 36 contains only the replacement. resolveEdges() at line 284 then fails with unresolved predecessor reference. The previous review raised this and the author deferred the fix. The same concern applies to matrix templates removed at line 146.

Run the script to confirm whether any current test reaches this path, so the deferral stays intentional and covered.

#!/bin/bash
# Description: Find tests that chain operations after a join or a matrix template.
set -eu

rg -n -C 6 --type=ts 'join\(|parallel\(|matrix\(' packages/core/src/__tests__ | rg -n -C 6 '\.after\('

84-114: LGTM!

Also applies to: 236-292

packages/core/src/runtime.ts (1)

26-30: LGTM!

Also applies to: 38-46, 67-75

packages/core/src/internal/ids.ts (1)

14-28: LGTM!

Also applies to: 56-71

packages/core/src/__tests__/conditions.test.ts (1)

6-85: LGTM!

packages/core/src/__tests__/dag.test.ts (1)

42-72: LGTM!

Also applies to: 74-97

packages/core/src/__tests__/matrix.test.ts (1)

8-17: LGTM!

Also applies to: 50-65

specs/01-core/spec.md (7)

184-192: Align PlanContext with its documented value domain.

The prose permits arrays of primitives, but PlanContext permits only readonly string[]. A number[] or boolean[] context is rejected by the public type. Narrow the prose or expand the index signature. Keep the type and prose consistent.


369-372: Document list-merge deduplication.

The composition section says arrays only concatenate, while predecessor resolution and packages/core/src/internal/merge.ts remove duplicates. State concatenation, deduplication, and order preservation in both sections.

Also applies to: 535-536


374-419: Resolve the operation identity contract.

context includes discovery index, so otherwise identical operations at different positions cannot produce the same { kind, name, context } ID. The documented duplicate check cannot detect repeated operations across positions. The projection also omits fields such as env, image, imageDigest, workingDir, timeoutSeconds, retries, cache, network, credentials, artifacts, and condition. Define index participation and the complete projection, then align core, IR, and tests.

Also applies to: 538-552


376-376: Resolve the ADR-006 link.

The link at Line [376] targets ../../engdocs/adr/ADR-006-sha256-content-addressed-plan-ids.md, but the supplied stack does not contain that file. Add the ADR or update the link.


380-380: Add language tags to the remaining Markdown fences.

Add text to the ID-format fence at Line [380] and the expression-grammar fence at Line [441]. Static analysis still reports MD040.

Also applies to: 441-441

Source: Linters/SAST tools


516-516: Use the configured Vitest commands.

Replace bun test at Lines [516] and [576] with bun run test. Use bunx nx run core:test for the core-only command. bun test invokes Bun’s built-in runner, not the repository’s Nx/Vitest command.

Based on learnings, repository tests use bun run test and Nx/Vitest commands.

Also applies to: 574-579

Source: Learnings


49-62: LGTM!

Also applies to: 168-182, 205-206, 318-318, 347-368, 420-433, 434-440, 442-462, 527-534, 554-568

engdocs/README.md (2)

33-34: Resolve the ADR-006 link before merging.

The new entry at Line [34] points to ./adr/ADR-006-sha256-content-addressed-plan-ids.md, but the supplied stack does not contain that file. Add the ADR or update the link.


10-10: LGTM!

.gitignore (2)

157-165: Verify the Astro metadata exclusion.

The previous review found that website/.astro/ was still tracked. Confirm that the website exclusions now include website/.astro/ and that no files under that directory remain tracked.

Verification
#!/usr/bin/env bash
set -euo pipefail

rg -n 'website/\.astro' .gitignore
git ls-files -- 'website/.astro/**'

166-168: LGTM!

specs/15-documentation/spec.md (1)

348-348: LGTM!

specs/00-overview/spec.md (1)

65-65: LGTM!

engdocs/architecture/overview.md (1)

8-8: LGTM!

.codacy.yml (1)

1-70: LGTM!

CLAUDE.md (1)

63-69: LGTM!

Also applies to: 71-84

README.md (1)

84-84: LGTM!

Also applies to: 141-141, 158-158

.eslintrc.json (1)

1-105: 🎯 Functional Correctness

No change is required in .eslintrc.json. The active ESLint 9 runner uses eslint.config.mjs, and Codacy excludes JavaScript and TypeScript source files. The rules in .eslintrc.json cannot cause an undefined-rule failure in these runners.

			> Likely an incorrect or invalid review comment.

Comment thread packages/core/src/__tests__/conditions.test.ts
Comment thread packages/core/src/__tests__/dag.test.ts
Comment thread packages/core/src/__tests__/dag.test.ts
Comment thread packages/core/src/__tests__/matrix.test.ts Outdated
Comment thread packages/core/src/__tests__/matrix.test.ts Outdated
Comment thread packages/core/src/internal/plan.ts
Comment thread packages/core/src/internal/plan.ts
Comment thread packages/core/src/internal/plan.ts
Comment thread packages/core/src/runtime.ts
Comment thread packages/core/src/runtime.ts Outdated
@codeant-ai codeant-ai Bot added the size:XXL This PR changes 1000+ lines, ignoring generated files label Aug 11, 2026
… NaN/Infinity

Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot mentioned this pull request Aug 11, 2026
5 tasks done
@ThePlenkov
ThePlenkov merged commit f9f233b into main Aug 11, 2026
4 checks passed
@ThePlenkov
ThePlenkov deleted the wave-1-core branch September 23, 2026 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

baz: needs review size:XXL This PR changes 1000+ lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant