Skip to content

fix(prerelease-check): skip the package's own version in package.json - #873

Merged
bedatty merged 4 commits into
developfrom
fix/prerelease-check-skip-own-package-version
Oct 9, 2026
Merged

bedatty merged 4 commits into
developfrom
fix/prerelease-check-skip-own-package-version

Conversation

@bedatty

@bedatty bedatty commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Description

The package.json scan in prerelease-check grepped the whole file, so a repository shipping a beta of itself had its top-level "version" reported as an unstable dependency pin. On a blocking branch that annotates as ::error:: and hard-fails the gate for the entire beta cycle, forcing callers to work around it by listing their own version in .prerelease-allow — a mechanism meant for dependency debt that cannot be remediated by upgrade (seen in matcher #538).

The package's own version identifies the artifact the repository produces, not a dependency it consumes. It is now resolved with jq and the line that declares it is dropped from the findings. Every dependency pin in the file is still scanned; an unparseable package.json leaves the exemption empty, which keeps the previous behaviour (fail towards reporting, never towards silence).

Affected: src/security/prerelease-check (consumed by the pr-security-scan reusable workflow).

Type of Change

  • feat: New workflow or new input/output/step in an existing workflow
  • fix: Bug fix in a workflow (incorrect behavior, broken step, wrong condition)
  • perf: Performance improvement (e.g. caching, parallelism, reduced steps)
  • refactor: Internal restructuring with no behavior change
  • docs: Documentation only (README, docs/, inline comments)
  • ci: Changes to self-CI (workflows under .github/workflows/ that run on this repo)
  • chore: Dependency bumps, config updates, maintenance
  • test: Adding or updating tests
  • BREAKING CHANGE: Callers must update their configuration after this PR

Breaking Changes

None. No inputs or outputs change. The action only stops emitting a false positive, so any caller that passed before keeps passing.

Testing

  • YAML syntax validated locally
  • Triggered a real workflow run on a caller repository using @this-branch or the beta tag
  • Verified all existing inputs still work with default values
  • Confirmed no secrets or tokens are printed in logs
  • Checked that unrelated workflows are not affected

src/security/prerelease-check/test.py extracts the shipped scan step from action.yml and runs it for real against a throwaway workspace. Four cases were added — own beta version alone is not a finding; own beta version alongside a beta dependency reports only the dependency; a dependency whose value equals the self-version still blocks; a stable self-version exempts nothing. 14/14 pass locally.

Caller repo / workflow run:

Related Issues

Closes #871

The package.json scan grepped the whole file, so a repo shipping a beta of
itself had its top-level "version" reported as an unstable dependency pin.
On a blocking branch that annotates as an error and hard-fails the gate for
the entire beta cycle, forcing callers to work around it by listing their own
version in .prerelease-allow — a mechanism meant for dependency debt.

Resolve the package's own version with jq and drop the line that declares it.
Every dependency pin in the file is still scanned; an unparseable package.json
leaves the exemption empty, keeping the previous behaviour.
@bedatty
bedatty requested a review from a team as a code owner October 9, 2026 15:11
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: LerianStudio/github-actions-shared-workflows/.coderabbit.yml
  • Review profile: ASSERTIVE
  • Plan: Essentials
  • Run ID: 92bb9514-e882-4e72-b758-69f96f585ce8

📥 Commits

Reviewing files that changed from the base of the PR and between 75db678 and a2b3978.


📒 Files selected for processing (2)
  • src/security/prerelease-check/action.yml
  • src/security/prerelease-check/test.py

Limit details: You’ve used the included review currently available. Your 66 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.



Walkthrough

The prerelease check now excludes a package’s own top-level version from findings when it can parse that version. Dependency pins remain scanned, including pins that match the package version. Tests and the README describe this behavior.

Changes

Package version filtering

Layer / File(s) Summary
Scan filtering and validation
src/security/prerelease-check/action.yml, src/security/prerelease-check/test.py, src/security/prerelease-check/README.md
The scan skips a match for the package’s top-level version when it can read that version. Tests cover dependency pins, including a pin that matches the package version and a dependency named version. The README documents the behavior.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Low

Suggested reviewers: fredcamaral

Merge Risk: 🔵 Low · up to a2b39

A prerelease dependency can go unreported if it shares a line with the package version. The case is format-dependent and can be avoided by placing the dependency on another line, but it remains worth fixing.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check Warning Issue #871 requires the package's own top-level version to be excluded while dependency pins remain findings. The action resolves .version with jq and preserves ordinary dependency findings. How… Restrict the exemption to the actual top-level version declaration. Keep a nested version dependency with the same value as a finding, but exclude the top-level line. Update the regression test to require that result.
✅ Passed checks (4 passed)
Check name Status Explanation
Description check Passed The description follows the repository template, explains the bug and behavior change, identifies affected workflows, documents testing, and states that there are no breaking changes. The caller workf…
Title check Passed The title is concise, specific, and accurately describes the primary change: excluding the package's own version from prerelease findings.
Out of Scope Changes check Passed The changes stay within src/security/prerelease-check. The action change, regression tests, and README update support the pre-release scan behavior and issue #871. No unrelated product or workflow c…
Docstring Coverage Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 1 files. (1 skipped: 1…

Full details: Linked Issues check

Explanation

Issue #871 requires the package's own top-level version to be excluded while dependency pins remain findings. The action resolves .version with jq and preserves ordinary dependency findings. However, when a nested version property has the same value, the guard clears SELF_VERSION and reports both lines. The top-level field is therefore still reported in that valid case. The test test_an_ambiguous_version_in... explicitly expects this behavior.



  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Usage-based review receipt

Note

This review was completed with usage-based billing: files reviewed beyond your plan's included limits are billed at $0.25/file. View usage-based billing.


Comment @coderabbitai help to get the list of available commands.

@lerian-studio lerian-studio added size/S PR changes 50–199 lines documentation Improvements or additions to documentation security Changes to security workflows or vulnerability reporting policy composite Changes to any composite action manifest (src/**/*.yml) labels Oct 9, 2026
@lerian-studio

lerian-studio commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ CodeQL Analysis Results

Languages analyzed: actions

✅ No security issues found.


🔍 View full scan logs | 🛡️ Security tab

@lerian-studio

lerian-studio commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🔍 Lint Analysis

Check Files Scanned Status
YAML Lint 1 file(s) ✅ success
Action Lint no changes ⏭️ skipped
Pinned Actions 1 file(s) ✅ success
Markdown Link Check 1 file(s) ✅ success
Spelling Check 3 file(s) ✅ success
Shell Check 1 file(s) ✅ success
README Check 1 file(s) ✅ success
Composite Schema 1 file(s) ✅ success
Deployment Matrix no changes ⏭️ skipped

🔍 View full scan logs

@lerian-studio

lerian-studio commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🔍 PR Validation Summary

✅ PR Mergeable — no blocking failures

Check Status Blocking
Source Branch ✅ success yes
PR Title ✅ success yes
PR Description ✅ success yes
Breaking Change Guard ✅ success yes
Commit Signatures ✅ success yes
PR Size ✅ success no
Auto Labels ✅ success no
PR Metadata ✅ success no

🔍 View workflow run

@bedatty

bedatty commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

This comment has been minimized.

@lerian-studio

This comment has been minimized.

@lerian-studio lerian-studio added the review-ready Required checks passed — CodeRabbit is cleared to review label Oct 9, 2026
@coderabbitai

This comment has been minimized.

coderabbitai[bot]

This comment was marked as resolved.

@lerian-studio

This comment has been minimized.

@coderabbitai

This comment has been minimized.

coderabbitai[bot]

This comment was marked as resolved.

@lerian-studio

Copy link
Copy Markdown
Contributor

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@bedatty
bedatty merged commit b91d725 into develop Oct 9, 2026
44 checks passed
@github-actions
github-actions Bot deleted the fix/prerelease-check-skip-own-package-version branch October 9, 2026 17:13
@bedatty bedatty linked an issue Oct 9, 2026 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

composite Changes to any composite action manifest (src/**/*.yml) documentation Improvements or additions to documentation review-ready Required checks passed — CodeRabbit is cleared to review security Changes to security workflows or vulnerability reporting policy size/S PR changes 50–199 lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

prerelease check flags a package.json's own top-level version field

2 participants