Wave 9: sdk - #11
Wave 9: sdk#11
Conversation
🤖 CodeAnt AI — Review Status
|
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe PR adds the Wave 09 TypeScript SDK. It supports workflow discovery, plan mode, host or Docker execution, IR plan conversion, policy and baseline processing, structured results, typed errors, public exports, and comprehensive tests. ChangesSDK facade implementation
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant Sverka
participant ConfigLoader
participant PlanRuntime
participant PlanConverter
participant Scheduler
participant PolicyEvaluator
Sverka->>ConfigLoader: discover and load workflow
Sverka->>PlanRuntime: evaluate workflow operations
Sverka->>PlanConverter: convert operations into validated plan
Sverka->>Scheduler: execute plan with selected executor
Scheduler-->>Sverka: return status and outcomes
Sverka->>PolicyEvaluator: evaluate findings and baseline result
PolicyEvaluator-->>Sverka: return policy result and verdict
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
This PR implements the SDK layer with comprehensive re-exports, high-level APIs, and config discovery. The implementation is generally well-structured, but several critical issues must be addressed before merge:
Critical Issues (5 findings):
- Security: Unrestricted command allowlist creates code execution risk when loading untrusted configs
- Security: Path traversal vulnerability in config loading without path validation
- Security: Truncated hash in cache key generation increases collision risk
- Logic: Missing cleanup of temporary directories in failure scenarios
- Logic: Unsafe type assertion bypasses TypeScript's type safety
Strengths:
- Clean API design with createSverka factory pattern
- Comprehensive re-exports from core packages
- Good separation of plan vs execute modes
- Extensive test coverage (60 tests passing)
All findings require fixes as they either create security vulnerabilities or logic errors that could cause incorrect behavior or resource leaks.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 111 |
| Duplication | 4 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
MergerNeeds Review PR exceeds the merge-gate context budget (72597 tokens); escalating to a human reviewer. Commit |
MergerNeeds Review This non-trivial public SDK/runtime change has no CI verification. The SDK tests dynamically import Commit |
PR Summary by QodoAdd @sverka/sdk public API with config discovery, plan(), and execute()
AI Description
Diagram
High-Level Assessment
Files changed (23)
|
Code Review by Qodo
1. False conditions still execute
|
There was a problem hiding this comment.
All reported issues were addressed across 23 files
Tip: instead of fixing issues one by one fix them all with cubic
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
|
❌ The last analysis has failed. |
SDK composition root: re-exports from core, ir, runtime, runtime-host, runtime-docker, findings, policy. High-level API: createSverka(), discover(), plan(), execute(), evaluate(). Config file discovery (sverka.config.ts). 60 tests pass. Reviewer APPROVED with 5 non-blocking nits (untested execute+baseline, EXECUTION_FAILED wrapper, generatedBy hardcoded, WorkflowDefinition type broadening, validatePlan skip for empty ops). <details> - 60 tests pass (10 files: re-exports, public-api, task, define-workflow, find-config, load-workflow, convert, plan-mode, execute-mode, errors) - typecheck clean - build green (dist index.mjs + index.d.mts) - lint clean - reviewer approved (sv-3yy) </details> Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
…tionalPropertyTypes Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
- Derive sverkaVersion from package.json at runtime.
- Clamp spec.retries to maxAttempts >= 1.
- Replace cast-based resolveDefaults with explicit field mapping.
- Use canonicalStringify + sorted paths for sourceContextHash.
- Merge duplicate imports; remove unused root param from createExecutor.
- Clean up temp artifact/cache dirs in executePlan finally.
- Pass baseline fingerprints whenever baselinePath is set.
- Simplify mergeOptions by removing unnecessary ?? {} fallbacks.
- Derive Docker runAs from current process uid/gid.
- Improve tests: consolidate execute-mode assertions, meaningful find-config
bound test, and marker-based plan-mode side-effect assertion.
- Add spec clarity for config lookup, zero-config execute, executor image
behavior, and canonical source context hash.
- Fix markdown lint in wave-09-sdk-plan.md.
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
…sourceContextHash changedFiles sort Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
- Increase cache key hash to 32 hex chars (128 bits) to reduce collision risk. - Validate configPath is inside project root before dynamic import. - Wrap executePlan temp dirs cleanup in a top-level try/finally. - Document trust requirement for the allow-all command allowlist. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Use a dedicated valueOrDefault helper so resolveDefaults no longer contains multiple ?? operators. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|



User description
Summary
Test plan
Stacked on #10
Generated with Devin
Summary by cubic
Adds
@sverka/sdkas a single entry point to define, plan, and run workflows end-to-end. Includes config discovery, deterministic plan generation, host-first execution (Docker opt-in), baseline filtering, policy evaluation, and a typedSdkError. Findings are stubbed to[]until check providers land.New Features
createSverka(),plan(),execute(),defineWorkflow(),task(); config viafindConfig()andloadWorkflow()(safe dynamic import with project-root guard).convertToPlan()sets metadata (apiVersion,sverkaVersionfrom package.json,generatedBy, canonicalsourceContextHash); deterministiccomputePlanId; zero-configplan()returns a proposal when no config is found.loadBaseline/filterOnlyNew; evaluates policy; findings stay empty for now.validatePlan,computePlanId), planner, runtime (Scheduler,@sverka/runtime-host,@sverka/runtime-docker), findings, policy.Bug Fixes and Refactors
sourceContextHash; canonical stringify with sorted paths (explicit comparator).maxAttempts >= 1; 128-bit cache key; validateconfigPathis inside the project root; clean temp artifact/cache dirs with top-leveltry/finally; pass baseline fingerprints whenbaselinePathis set; derive DockerrunAsfrom current uid/gid; forwardPATHto the host executor.resolveDefaults, explicit field mapping).index.mjs,index.d.mts); derivesverkaVersionat runtime from package.json.Written for commit c47f227. Summary will update on new commits.
CodeAnt-AI Description
Add a single SDK entry point for defining, planning, and running workflows
What Changed
@sverka/sdkas a unified import for workflow building, project discovery, planning, execution, findings, and policy evaluationplan()andexecute()APIs, pluscreateSverka()for reusable defaults; planning records workflows without running commandssverka.config.tsand.jsdiscovery, workflow loading, validation, and clear typed errors for missing, invalid, or unloadable configurationImpact
✅ One import for end-to-end workflow use✅ No command execution during planning✅ Clear configuration failure errors🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.