Skip to content

Prepare uphold 1.24.0 - #292

Merged
HackingGate merged 1 commit into
mainfrom
prepare-1.24.0
Oct 1, 2026
Merged

HackingGate merged 1 commit into
mainfrom
prepare-1.24.0

Conversation

@HackingGate

Copy link
Copy Markdown
Owner

One engine change since 1.23.0. supply-chain no longer hands an npm git
dependency to guarddog, which asked npm for it and got a 404, so a repository
depending on its own package by git exited 2 on every run. Each git
dependency in a package.json's dependencies is held to the same first-party
owner rule and git ls-remote check as a uv git source, against the commit
bun.lock or package-lock.json records; a tag its # names must point at
that commit. One with no recorded commit is refused by name, and guarddog
reads the rest of the manifest (#290).

A git remote spelled as an option (starting with -) is now refused for uv
and npm alike, and git ls-remote takes the remote after --, so a manifest
cannot hand git an --upload-pack command (#290).

The tests assert every empty collection with a message that prints it, as
Rust 1.99's clippy::assert_is_empty asks (#291).

A consumer taking the pin to v1.24.0 needs no change. A repository whose
package.json depends on a git source under another owner, or on one no lock
pins, now fails the supply-chain section by name where it was could-not-look.

One engine change since 1.23.0. supply-chain no longer hands an npm git
dependency to guarddog, which asked npm for it and got a 404, so a repository
depending on its own package by git exited 2 on every run. Each git
dependency in a package.json's dependencies is held to the same first-party
owner rule and git ls-remote check as a uv git source, against the commit
bun.lock or package-lock.json records; a tag its #<ref> names must point at
that commit. One with no recorded commit is refused by name, and guarddog
reads the rest of the manifest (#290).

A git remote spelled as an option (starting with -) is now refused for uv
and npm alike, and git ls-remote takes the remote after --, so a manifest
cannot hand git an --upload-pack command (#290).

The tests assert every empty collection with a message that prints it, as
Rust 1.99's clippy::assert_is_empty asks (#291).

A consumer taking the pin to v1.24.0 needs no change. A repository whose
package.json depends on a git source under another owner, or on one no lock
pins, now fails the supply-chain section by name where it was could-not-look.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 15 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c917d5f8-a6f6-4d98-ad62-0d07be74d519

📥 Commits

Reviewing files that changed from the base of the PR and between 42291c6 and 2c3629a.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • Cargo.toml
  • README.md
  • hooks/lefthook.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 94.07%. Comparing base (42291c6) to head (2c3629a).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #292      +/-   ##
==========================================
+ Coverage   94.05%   94.07%   +0.02%     
==========================================
  Files          46       46              
  Lines       20861    20861              
==========================================
+ Hits        19620    19626       +6     
+ Misses       1241     1235       -6     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@HackingGate
HackingGate merged commit c3113b4 into main Oct 1, 2026
12 checks passed
@HackingGate
HackingGate deleted the prepare-1.24.0 branch October 1, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants