Wave 7: findings - #9
Conversation
🤖 CodeAnt AI — Review Status
|
|
Warning Review limit reached
Next review available in: 29 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (18)
Comment |
MergerNeeds Review The shipped code has concrete correctness and reliability defects despite resolved discussions: it ignores Commit |
There was a problem hiding this comment.
Review Summary
This PR introduces a standalone findings package with SARIF normalization, SHA-256 fingerprinting, baseline CRUD operations, and suppression filtering. The implementation is well-structured and thoroughly tested (88 passing tests).
Critical Issue Found (1)
- baseline.ts: Type validation bug that allows null/undefined values to bypass validation before type casting, potentially violating type safety guarantees
The rest of the implementation appears solid with proper error handling, comprehensive test coverage, and good documentation. Once the critical validation issue is addressed, this PR should be ready to merge.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
PR Summary by QodoWave 7: Add standalone findings package (SARIF normalize, fingerprint, baseline)
AI Description
Diagram
High-Level Assessment
Files changed (18)
|
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 82 |
| Duplication | 0 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
This pull request is currently not up to standards. The implementation contains a major logic bug in normalizeSarif where context.root is ignored; this prevents fingerprints from being stable across different file systems (e.g., local vs. CI), which is a core requirement of the package. Additionally, Codacy reports over 500 new issues, and the primary normalization function has a cyclomatic complexity of 32, far exceeding the threshold of 10. These issues must be addressed before merging to ensure maintainability and functional correctness.
About this PR
- The PR introduces 527 new quality issues according to static analysis. Please review the linting and formatting rules for the new
@sverka/findingspackage to ensure it aligns with project standards before merging.
Test suggestions
- SARIF normalization: verify mapping of levels to severities and rule resolution via ruleId or ruleIndex.
- Multi-location results: verify that one Finding is produced per location.
- Fingerprint computation: verify SHA-256 determinism and path normalization (Windows backslashes).
- Fingerprint validation: ensure empty file or non-positive lines throw INVALID_FINGERPRINT_INPUT while empty rule/checkId are accepted.
- Baseline CRUD: verify creating, updating (merging/pruning), and comparing (new/resolved/unchanged).
- Suppression: verify that findings matching non-expired baseline suppression entries are filtered out.
- Baseline I/O: verify loading/saving from JSON and error handling for missing or invalid files.
- Public API: verify all required types, functions, and error classes are exported from the index.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1. SARIF paths remain machine-specific
|
There was a problem hiding this comment.
All reported issues were addressed across 18 files
Tip: instead of fixing issues one by one fix them all with cubic
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
a665749 to
1bae0dd
Compare
1bae0dd to
3d14c00
Compare
3d14c00 to
65f1505
Compare
65f1505 to
8fe4702
Compare
8fe4702 to
5d1ad2a
Compare
5d1ad2a to
dcc00fa
Compare
e886641 to
650b365
Compare
650b365 to
274cb9d
Compare
274cb9d to
f6a43fc
Compare
f6a43fc to
cda0d0c
Compare
0272712 to
f9d995b
Compare
213ffb0 to
d43b68d
Compare
19a97a7 to
f2775b6
Compare
Standalone findings package: SARIF normalization, SHA-256 fingerprinting, baseline CRUD + diff, suppression filtering. No @Sverka deps, node stdlib only (crypto/fs/path). 88 tests pass. Spec 07 amended to resolve contradiction: empty rule/checkId are valid fingerprint inputs (SARIF edge case), only file and line range are validated. saveBaseline returns Promise<void> per spec. Reviewer APPROVED after rework (both rejections fixed: return type + spec amendment). <details> - 88 tests pass (errors 8, fingerprint 14, normalize 25, baseline 22, suppress 12, public-api 7) - typecheck clean - build green (findings 10.45kB index.mjs) - lint clean - reviewer approved (sv-fd9, second pass) </details> Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
f2775b6 to
d858065
Compare
Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
|



User description
Summary
Test plan
Stacked on #8
Generated with Devin
Summary by cubic
Adds standalone
@sverka/findingsfor SARIF 2.1.0 normalization, SHA-256 fingerprints, and baseline tracking with suppressions and only-new filtering. Ships pure ESM (.mjs+.d.mts), uses only Node stdlib, exports SARIF/baseline types, and updates spec 07 (allow emptyrule/checkId;saveBaselinereturnsPromise<void>).New Features
Finding.normalizeSarif,computeFingerprint, baseline ops, suppression utils; typed errors with codes.Refactors
overridefor errorcause.Written for commit 56e0be4. Summary will update on new commits.
CodeAnt-AI Description
Add SARIF findings normalization with stable baselines and suppressions
What Changed
Impact
✅ Consistent findings across SARIF-emitting tools✅ Stable issue tracking across repeated scans✅ Fewer repeated findings through baseline and suppression filtering🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.