Repository navigation
Wave 11: checks - #13
ThePlenkov wants to merge 0 commit into
Conversation
🤖 CodeAnt AI — Review Status
|
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
MergerNeeds Review The shipped Commit |
There was a problem hiding this comment.
Summary
This PR introduces the @sverka/checks package with check resolution and findings extraction. The implementation is well-structured with comprehensive test coverage (32 passing tests). However, there are critical security issues that must be addressed before merge.
Critical Issues
Path Traversal Vulnerability (extract.ts): The file path handling in extractFindings allows arbitrary file access outside the artifact directory through path traversal attacks. This enables reading sensitive files anywhere on the filesystem.
Missing Imports (extract.ts): The path traversal fix requires additional imports (resolve, sep) from "node:path" that are currently missing.
Test Coverage
The PR demonstrates solid test coverage including edge cases (missing files, invalid SARIF, multiple package managers). All 32 tests pass and the implementation correctly handles the documented 6 check types across 4 languages.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
PR Summary by QodoWave 11: add checks resolver, SARIF findings extraction, and SDK wiring
AI Description
Diagram
High-Level Assessment
Files changed (20)
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 20 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
a9292a1 to
3aed5d4
Compare
Code Review by Qodo
1. Docker checks cannot validate
|
3aed5d4 to
d232c4b
Compare
be47308 to
1abd403
Compare
|
Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters. If you still want a review, comment |
1abd403 to
c8382c9
Compare
e5d8655 to
9f0469a
Compare
c8382c9 to
9c8272f
Compare
9f0469a to
e0cbd1d
Compare
9c8272f to
35a00ca
Compare
e0cbd1d to
3f4702c
Compare
35a00ca to
12edc45
Compare
3f4702c to
257ecc7
Compare
12edc45 to
464b3cb
Compare
257ecc7 to
0ce578f
Compare
0ce578f to
944fceb
Compare
066a0a1 to
1786a3f
Compare
535e2ea to
3b2803d
Compare
1786a3f to
7e38213
Compare
3b2803d to
7e38213
Compare
|



User description
Summary
@sverka/checkspackage:CheckResolver.resolve()mapsProposedCheck+ProjectContext→ResolvedCheck(OperationSpec + CheckOutput[]).createBuiltinResolver()covers 6 checkIds (typecheck, lint, test, clippy, vet, fmt-check) across Node/Python/Rust/Go.extractFindings()reads SARIF artifacts via@sverka/findings.normalizeSarif.CheckErrorwith 2 codes (RESOLUTION_FAILED, EXTRACTION_FAILED),override readonly cause: unknownpernoImplicitOverride.doPlan/doExecuteresolve proposed checks into operations, extract findings from SARIF output artifacts after execution. Re-exports added to@sverka/sdk.Test plan
anytypes (impl or tests)Generated with Devin
Summary by cubic
Adds
@sverka/checksto turn discovered checks into IR operations and extract SARIF findings. Integrates with@sverka/sdkso auto‑discoveryplan()returns check ops andexecute()loads findings.New Features
@sverka/checks:CheckResolver.resolve()→ResolvedCheck(IROperationSpec+CheckOutput[]);createBuiltinResolver()mapstypecheck,lint,test,clippy,vet,fmt-checkacross Node (bun/npm/yarn/pnpm), Python (ruff/pytest), Rust (cargo), and Go (go).extractFindings()reads SARIF via@sverka/findings.normalizeSarif; skips missing files; invalid SARIF throwsCheckError("EXTRACTION_FAILED").plan()resolves proposed checks into ops;execute()extracts findings from the artifact dir; throwsCONFIG_NOT_FOUNDwhen no resolvable checks; re‑exportscreateBuiltinResolver,extractFindings,CheckError, and types from@sverka/checks.Refactors
RESOLUTION_FAILEDandEXTRACTION_FAILED.@sverka/checksships ESM (.mjs/.d.mts); added deps@sverka/core,@sverka/planner,@sverka/findings;@sverka/sdknow depends on@sverka/checks.Written for commit 7e38213. Summary will update on new commits.
CodeAnt-AI Description
Resolve discovered checks into executable operations and extract SARIF findings
What Changed
Impact
✅ Runnable checks in auto-discovered plans✅ SARIF findings available after check execution✅ Clearer errors for invalid check results🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.