Repository navigation
fix(prerelease-check): skip the package's own version in package.json - #873
Conversation
The package.json scan grepped the whole file, so a repo shipping a beta of itself had its top-level "version" reported as an unstable dependency pin. On a blocking branch that annotates as an error and hard-fails the gate for the entire beta cycle, forcing callers to work around it by listing their own version in .prerelease-allow — a mechanism meant for dependency debt. Resolve the package's own version with jq and drop the line that declares it. Every dependency pin in the file is still scanned; an unparseable package.json leaves the exemption empty, keeping the previous behaviour.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Limit details: You’ve used the included review currently available. Your 66 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. WalkthroughThe prerelease check now excludes a package’s own top-level version from findings when it can parse that version. Dependency pins remain scanned, including pins that match the package version. Tests and the README describe this behavior. ChangesPackage version filtering
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Low Suggested reviewers: Merge Risk: 🔵 Low · up to A prerelease dependency can go unreported if it shares a line with the package version. The case is format-dependent and can be avoided by placing the dependency on another line, but it remains worth fixing. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)✅ Passed checks (4 passed)Full details: Linked Issues checkExplanation Issue
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Usage-based review receipt
Note This review was completed with usage-based billing: files reviewed beyond your plan's included limits are billed at $0.25/file. View usage-based billing. Comment |
🛡️ CodeQL Analysis ResultsLanguages analyzed: ✅ No security issues found. 🔍 View full scan logs | 🛡️ Security tab |
🔍 Lint Analysis
|
🔍 PR Validation Summary✅ PR Mergeable — no blocking failures
|
|
@coderabbitai review |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
@coderabbitai review |
✅ Action performedReview finished.
|
Description
The
package.jsonscan inprerelease-checkgrepped the whole file, so a repository shipping a beta of itself had its top-level"version"reported as an unstable dependency pin. On a blocking branch that annotates as::error::and hard-fails the gate for the entire beta cycle, forcing callers to work around it by listing their own version in.prerelease-allow— a mechanism meant for dependency debt that cannot be remediated by upgrade (seen in matcher #538).The package's own version identifies the artifact the repository produces, not a dependency it consumes. It is now resolved with
jqand the line that declares it is dropped from the findings. Every dependency pin in the file is still scanned; an unparseablepackage.jsonleaves the exemption empty, which keeps the previous behaviour (fail towards reporting, never towards silence).Affected:
src/security/prerelease-check(consumed by thepr-security-scanreusable workflow).Type of Change
feat: New workflow or new input/output/step in an existing workflowfix: Bug fix in a workflow (incorrect behavior, broken step, wrong condition)perf: Performance improvement (e.g. caching, parallelism, reduced steps)refactor: Internal restructuring with no behavior changedocs: Documentation only (README, docs/, inline comments)ci: Changes to self-CI (workflows under.github/workflows/that run on this repo)chore: Dependency bumps, config updates, maintenancetest: Adding or updating testsBREAKING CHANGE: Callers must update their configuration after this PRBreaking Changes
None. No inputs or outputs change. The action only stops emitting a false positive, so any caller that passed before keeps passing.
Testing
@this-branchor the beta tagsrc/security/prerelease-check/test.pyextracts the shipped scan step fromaction.ymland runs it for real against a throwaway workspace. Four cases were added — own beta version alone is not a finding; own beta version alongside a beta dependency reports only the dependency; a dependency whose value equals the self-version still blocks; a stable self-version exempts nothing. 14/14 pass locally.Caller repo / workflow run:
Related Issues
Closes #871