Prepare uphold 1.24.0 - #292
Conversation
One engine change since 1.23.0. supply-chain no longer hands an npm git dependency to guarddog, which asked npm for it and got a 404, so a repository depending on its own package by git exited 2 on every run. Each git dependency in a package.json's dependencies is held to the same first-party owner rule and git ls-remote check as a uv git source, against the commit bun.lock or package-lock.json records; a tag its #<ref> names must point at that commit. One with no recorded commit is refused by name, and guarddog reads the rest of the manifest (#290). A git remote spelled as an option (starting with -) is now refused for uv and npm alike, and git ls-remote takes the remote after --, so a manifest cannot hand git an --upload-pack command (#290). The tests assert every empty collection with a message that prints it, as Rust 1.99's clippy::assert_is_empty asks (#291). A consumer taking the pin to v1.24.0 needs no change. A repository whose package.json depends on a git source under another owner, or on one no lock pins, now fails the supply-chain section by name where it was could-not-look.
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 15 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #292 +/- ##
==========================================
+ Coverage 94.05% 94.07% +0.02%
==========================================
Files 46 46
Lines 20861 20861
==========================================
+ Hits 19620 19626 +6
+ Misses 1241 1235 -6 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
One engine change since 1.23.0. supply-chain no longer hands an npm git
dependency to guarddog, which asked npm for it and got a 404, so a repository
depending on its own package by git exited 2 on every run. Each git
dependency in a package.json's dependencies is held to the same first-party
owner rule and git ls-remote check as a uv git source, against the commit
bun.lock or package-lock.json records; a tag its # names must point at
that commit. One with no recorded commit is refused by name, and guarddog
reads the rest of the manifest (#290).
A git remote spelled as an option (starting with -) is now refused for uv
and npm alike, and git ls-remote takes the remote after --, so a manifest
cannot hand git an --upload-pack command (#290).
The tests assert every empty collection with a message that prints it, as
Rust 1.99's clippy::assert_is_empty asks (#291).
A consumer taking the pin to v1.24.0 needs no change. A repository whose
package.json depends on a git source under another owner, or on one no lock
pins, now fails the supply-chain section by name where it was could-not-look.