Wave 12: compiler-github package - #14
Conversation
🤖 CodeAnt AI — Review Status
|
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe PR defines a synchronous GitHub workflow compiler, adds its public types and exports, implements deterministic YAML generation from ChangesGitHub workflow compilation
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant Plan
participant compileGithubWorkflow
participant yaml
participant GitHubActions
Plan->>compileGithubWorkflow: provide plan and compiler configuration
compileGithubWorkflow->>compileGithubWorkflow: construct workflow triggers, permissions, env, and steps
compileGithubWorkflow->>yaml: serialize workflow
yaml-->>compileGithubWorkflow: return YAML
compileGithubWorkflow-->>GitHubActions: consume generated workflow
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
MergerNeeds Review Generated credential mappings are not usable by operations: the SDK supplies empty credentials and the host executor forwards only its PATH allowlist, so GitHub secret environment variables are dropped before checks run. This concrete security/correctness issue needs human review, and no CI ran for the non-trivial change. Commit |
There was a problem hiding this comment.
Review Summary
This PR introduces the @sverka/compiler-github package that compiles Sverka Plan IR to GitHub Actions workflows. I've identified critical logic errors that prevent the code from functioning correctly and must be fixed before merge.
Critical Issues Found (4)
toKebab()function creates invalid output - Produces leading hyphens for capitalized strings (e.g., "Contents" → "-contents"), which will generate malformed GitHub Actions YAMLbuildTriggers()silently drops user push configurations - Creates push trigger structure but never assigns to result objectbuildTriggers()silently drops user pullRequest configurations - Creates pull_request trigger structure but never assigns to result object- Test validates incorrect YAML escaping - Tests expect escaped
${{ }}syntax that GitHub Actions cannot parse, masking the string escaping bug inbuildCredentialEnv()
Impact
These defects will cause:
- Invalid permission keys in generated workflows
- User-specified triggers being silently ignored
- Credentials incorrectly escaped, causing workflow failures
- Tests passing while masking broken functionality
All issues have specific fixes provided. Please address these before merging.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
PR Summary by QodoAdd @sverka/compiler-github to compile Plan IR into GitHub Actions YAML
AI Description
Diagram
High-Level Assessment
Files changed (11)
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 22 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
The PR introduces the @sverka/compiler-github package. While the implementation aligns with the architectural intent of ADR-004, the Codacy analysis indicates the code is not up to standards with 164 new issues.
There are several critical issues that should prevent merging:
- Broken Workflow Permissions: The current logic for custom permissions will unintentionally disable the default
contents: readpermission, causing repository checkout to fail. - Environment Incompatibility: The workflow targets the
ubuntu-latestrunner but relies onbun, which is not pre-installed, leading to inevitable CI failures. - Maintainability Risks: The core compilation logic in
compile.tshas been flagged for high cyclomatic complexity and lacks unit test coverage, posing a long-term stability risk.
About this PR
- The PR has introduced 164 new quality issues according to Codacy. Please review the linting and style guidelines for the workspace to ensure the new package meets the project's quality standards.
Test suggestions
- Default configuration produces expected workflow structure, steps, and default triggers (push on main, pull_request)
- Custom configuration overrides defaults for name, runner, sverka version, and node version
- Trigger mapping correctly handles custom branch lists and workflow_dispatch toggle
- Credential declarations from multiple operations are collected, deduplicated, and mapped to the env block
- Permission mapping correctly converts camelCase keys to kebab-case (e.g., security-events)
- Empty operations list results in a valid workflow that still executes the plan
- The compiler output is identical when given the same plan and configuration inputs
- Public API correctly exports the compiler function and necessary types without exposing internal logic
- Automate unit tests for compile.ts to address coverage gaps in complex logic
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Automate unit tests for compile.ts to address coverage gaps in complex logic
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1.
|
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
5c2a220 to
66da355
Compare
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
66da355 to
6e2a4e1
Compare
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
6e2a4e1 to
4f66797
Compare
a9a2614 to
4cb448e
Compare
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
63df124 to
da5a17b
Compare
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
specs/12-compiler-github/spec.md (1)
59-65: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick winRestrict
GithubPermissions.idTokento"write".GitHub Actions supports
"write"and"none"forid-token, but not"read". Align the specification with the public type by removing"read".🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@specs/12-compiler-github/spec.md` around lines 59 - 65, Update the GithubPermissions.idToken property type to allow only "write", removing "read" while leaving the other permission properties unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@engdocs/architecture/wave-12-compiler-github-plan.md`:
- Around line 73-83: Specify the `text` language on the fenced file-tree code
block in the architecture plan by changing its opening fence, while leaving the
tree content unchanged.
In `@packages/compiler-github/src/__tests__/compile.test.ts`:
- Around line 48-57: Update the workflow trigger test around the pullRequest
configuration to use a non-default branch such as "release" instead of "main",
and assert that the generated pull_request trigger includes "release". Preserve
the existing assertions for workflow_dispatch and the other configured branch.
- Around line 130-135: Update the empty-plan test in the “compileGithubWorkflow
— empty operations” suite to parse the generated yaml before asserting it.
Validate the parsed workflow structure, including the required jobs entry and
sverka execute command, rather than relying only on substring checks.
In `@specs/12-compiler-github/spec.md`:
- Around line 9-11: The v1 GitHub workflow specification currently invokes the
unsupported plan-file form of the CLI. Update the documented workflow, ADR-004,
architecture plan, and related tests to invoke `sverka execute` without
`.sverka/plan.json`, preserving SDK config loading or auto-discovery and the
single-job wrapper behavior.
---
Outside diff comments:
In `@specs/12-compiler-github/spec.md`:
- Around line 59-65: Update the GithubPermissions.idToken property type to allow
only "write", removing "read" while leaving the other permission properties
unchanged.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 3ab74e1b-5658-4c87-90a9-4588802e5971
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (10)
engdocs/architecture/wave-12-compiler-github-plan.mdpackages/compiler-github/package.jsonpackages/compiler-github/project.jsonpackages/compiler-github/src/__tests__/compile.test.tspackages/compiler-github/src/__tests__/helpers/fixtures.tspackages/compiler-github/src/__tests__/public-api.test.tspackages/compiler-github/src/compile.tspackages/compiler-github/src/index.tspackages/compiler-github/src/types.tsspecs/12-compiler-github/spec.md
📜 Review details
🧰 Additional context used
🪛 LanguageTool
engdocs/architecture/wave-12-compiler-github-plan.md
[uncategorized] ~49-~49: The official name of this software platform is spelled with a capital “H”.
Context: ...DK uses temp dir for artifacts). The github/codeql-action/upload-sarif@v3 step ...
(GITHUB)
🪛 markdownlint-cli2 (0.23.2)
engdocs/architecture/wave-12-compiler-github-plan.md
[warning] 73-73: Fenced code blocks should have a language specified
(MD040, fenced-code-language)
🔇 Additional comments (8)
packages/compiler-github/package.json (1)
5-11: LGTM!Also applies to: 21-24
packages/compiler-github/project.json (1)
18-23: LGTM!packages/compiler-github/src/types.ts (1)
1-29: LGTM!packages/compiler-github/src/compile.ts (1)
1-140: LGTM!packages/compiler-github/src/index.ts (1)
3-8: LGTM!packages/compiler-github/src/__tests__/compile.test.ts (1)
5-43: LGTM!Also applies to: 60-128
packages/compiler-github/src/__tests__/helpers/fixtures.ts (1)
1-58: LGTM!packages/compiler-github/src/__tests__/public-api.test.ts (1)
1-18: LGTM!
da5a17b to
a423ab0
Compare
a423ab0 to
0c84f73
Compare
|
0c84f73 to
5a115ba
Compare
|
❌ The last analysis has failed. |
There was a problem hiding this comment.
Actionable comments posted: 7
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@engdocs/architecture/wave-12-compiler-github-plan.md`:
- Line 388: Remove the hardcoded /home/pepl/projects/sverka directory change
from the verification block and replace it with a checkout-independent root
transition using cd ../.. after the package-level commands or git rev-parse
--show-toplevel.
- Line 166: Update the documented command examples and acceptance criteria at
the referenced architecture-plan sections and in the compiler GitHub
specification to use `sverka execute` without the `.sverka/plan.json` argument,
matching the compiler and package tests.
- Around line 253-256: Update the YAML test around the parsed workflow output to
assert the structured values at on.push.branches, on.pull_request.branches, and
on.workflow_dispatch rather than relying only on string containment. Explicitly
map pullRequest to pull_request and workflowDispatch to workflow_dispatch when
building or reading the expected trigger structure; do not use generic
camelCase-to-kebab-case conversion.
- Around line 289-302: Update the GithubPermissions definition to add optional
idToken with only the "write" value, and update buildPermissions to emit it as
the kebab-case YAML key id-token. Preserve the existing camelCase-to-kebab-case
mapping and reject or avoid supporting idToken: "read".
In `@packages/compiler-github/src/__tests__/compile.test.ts`:
- Around line 114-121: Update the permissions tests around compileGithubWorkflow
so the default workflow permissions are parsed and explicitly verified not to
include id-token. Preserve the existing custom-permission assertion for
securityEvents kebab-case conversion, while ensuring the default-permission
coverage rejects id-token: write.
- Around line 64-111: Update the credential tests around compileGithubWorkflow
to parse the serialized workflow and assert the expected mappings are located
specifically at jobs.sverka.env. Replace substring-based checks in the
declared-credentials test with an exact environment-object assertion, and in the
deduplication test assert jobs.sverka.env contains exactly one TOKEN key.
- Around line 7-28: Update the tests around compileGithubWorkflow to parse the
generated YAML and assert workflow fields at their required paths: jobs.sverka
for runner, tool versions, and steps/actions; on for default triggers; and
permissions for contents access. Apply the same structured assertions to the
default and custom workflow cases, while retaining validation that each
generated document is valid YAML.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: f47e49bf-b2e5-4907-8d02-3b79e0bd9f4a
📒 Files selected for processing (2)
engdocs/architecture/wave-12-compiler-github-plan.mdpackages/compiler-github/src/__tests__/compile.test.ts
📜 Review details
🧰 Additional context used
🪛 LanguageTool
engdocs/architecture/wave-12-compiler-github-plan.md
[uncategorized] ~49-~49: The official name of this software platform is spelled with a capital “H”.
Context: ...DK uses temp dir for artifacts). The github/codeql-action/upload-sarif@v3 step ...
(GITHUB)
🔇 Additional comments (4)
packages/compiler-github/src/__tests__/compile.test.ts (3)
1-4: LGTM!
46-60: LGTM!
124-147: LGTM!engdocs/architecture/wave-12-compiler-github-plan.md (1)
159-171: 🩺 Stability & AvailabilityNo Bun setup change is required. The workflow already adds
oven-sh/setup-bun@v2beforebun install, and the default test asserts it.> Likely an incorrect or invalid review comment.
|
Pure function compileGithubWorkflow(plan, config?) that compiles a canonical
Sverka Plan to a GitHub Actions workflow YAML string. Thin wrapper per
ADR-004: single job runs `sverka execute .sverka/plan.json`. Maps plan
credentials to job-level env block with ${{ secrets.VAR }} references.
camelCase→kebab-case conversion for permissions and triggers. Deterministic
output. No custom errors (pure function on validated Plan). 13 tests pass.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…-bun, execute cmd, interface order Address PR #14 review feedback: 1. toKebab leading hyphen: regex added offset check so capitalized first chars don't get a leading hyphen (amazon-q). 2. idToken permission: removed "read" — GitHub Actions only supports "write" for id-token (codeant-ai). 3. sverka execute: removed .sverka/plan.json positional arg — CLI uses strict yargs and rejects unknown args (codeant-ai, critical). 4. setup-bun: added oven-sh/setup-bun@v2 step — ubuntu-latest doesn't include bun (codacy). 5. Interface ordering: moved GithubTriggers and GithubPermissions before GithubCompilerConfig (codacy). Tests: 13 pass. Full monorepo 16 projects green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…mplexity Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
- Mark file-tree fence as in architecture plan - Test pullRequest trigger with a non-default branch and parse the YAML - Parse empty-plan YAML output and assert required workflow structure Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|



User description
Summary
@sverka/compiler-githubpackage: pure functioncompileGithubWorkflow(plan, config?)that compiles a canonical Sverka Plan IR to a GitHub Actions workflow YAML stringsverka execute .sverka/plan.jsonCredentialDeclaration.envVar) to job-levelenv:block with${{ secrets.VAR }}referencessecurityEvents→security-events) and triggers (pullRequest→pull_request,workflowDispatch→workflow_dispatch)Errorpropagates)Stack:
main→ #1 → #2 → #3 → #5 → #6 → #7 → #8 → #9 → #10 → #11 → #13 (wave-11-checks) → this PRTest plan
anytypes in implementationGenerated with Devin
Summary by cubic
Adds
@sverka/compiler-github, a purecompileGithubWorkflow(plan, config?)that compiles a Sverka Plan into a deterministic GitHub Actions workflow. Generates one job that checks out, sets up Node 24 and Bun, installs Sverka, runssverka execute, and uploads.sverka/output/artifacts.New Features
actions/checkout@v4,actions/setup-node@v4(Node "24"),oven-sh/setup-bun@v2,bun install -g sverka@<version>,sverka execute, upload.sverka/output/viaactions/upload-artifact@v4(if: always()).env:with${{ secrets.VAR }}(deduped); omitsenv:when none.ubuntu-latest,permissions: { contents: "read" }, triggerspush: [main]+pull_request; optionalworkflow_dispatch.Bug Fixes
id-tokento"write"..sverka/plan.jsonarg fromsverka execute; added explicit Bun setup viaoven-sh/setup-bun@v2.Written for commit 095dc11. Summary will update on new commits.
CodeAnt-AI Description
Generate configurable GitHub Actions workflows from Sverka plans
What Changed
sverka execute, and upload output artifacts even when execution failsImpact
✅ Faster setup for GitHub Actions workflows✅ Credentials available from GitHub Secrets✅ Artifacts preserved after failed checks🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.