Prepare uphold 1.25.0 - #297
Merged
Merged
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 19 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #297 +/- ##
==========================================
+ Coverage 94.04% 94.09% +0.04%
==========================================
Files 46 46
Lines 20868 20991 +123
==========================================
+ Hits 19626 19752 +126
+ Misses 1242 1239 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
HackingGate
force-pushed
the
prepare-1.25.0
branch
from
October 3, 2026 09:47
3d31ef0 to
3894eac
Compare
Three engine changes since 1.24.0. A rule whose `files.include` root is not on disk no longer selects nothing, prints one line on stderr and passes: the scan exits 2 naming the rule, the root and that the root does not exist. This holds for every rule, bundled sets included, so a repository that inherits `default-token-grant` and has no `.github/workflows` is now refused (#294). The relative-link check removes inline code spans from each line before it reads links, delimited as CommonMark does: a run of N backticks closes at the next run of exactly N, and an unmatched run stays literal. A regular expression in backticks such as `[2-9](\.\d+)` is no longer reported as a link to a missing file (#295). A remote counts as GitHub only when its host is github.com, www.github.com or raw.githubusercontent.com, the one definition private-names and the shim already used. A GitHub Enterprise remote is no longer asked about on github.com: unowned-push keeps the allow-list's refusal for it with exit 1, and the shim's visibility lookup reports could-not-tell. Any other unknown forge is refused as before (#296). encoding_rs is 0.8.42 (#281), and CI runs astral-sh/setup-uv 10.2.0 (#280). A consumer taking the pin to v1.25.0 must have every `files.include` root its rules name on disk, inherited sets included: a missing root now fails the scan with exit 2 where it warned, and the fix is to correct the root or remove it. A consumer pushing to a GitHub Enterprise remote that its allow-list does not name is now refused where github.com may have answered for it.
HackingGate
force-pushed
the
prepare-1.25.0
branch
from
October 3, 2026 10:00
3894eac to
084d44e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three engine changes since 1.24.0. A rule whose
files.includeroot is noton disk no longer selects nothing, prints one line on stderr and passes: the
scan exits 2 naming the rule, the root and that the root does not exist. This
holds for every rule, bundled sets included, so a repository that inherits
default-token-grantand has no.github/workflowsis now refused (#294).The relative-link check removes inline code spans from each line before it
reads links, delimited as CommonMark does: a run of N backticks closes at the
next run of exactly N, and an unmatched run stays literal. A regular
expression in backticks such as
[2-9](\.\d+)is no longer reported as alink to a missing file (#295).
A remote counts as GitHub only when its host is github.com, www.github.com or
raw.githubusercontent.com, the one definition private-names and the shim
already used. A GitHub Enterprise remote is no longer asked about on
github.com: unowned-push keeps the allow-list's refusal for it with exit 1,
and the shim's visibility lookup reports could-not-tell. Any other unknown
forge is refused as before. A remote URL's host now ends at the first
/,?or
#, and userinfo is stripped up to the last@, sohttps://evil.com#@github.com/acme/widget.gitis read as evil.com, which iswhere git pushes, and unowned-push no longer accepts it on the strength of
github.com ownership. Two spellings uphold cannot read the way git does now
name no host and no repository, so unowned-push refuses them as an unreadable
destination: a
%anywhere in ascheme://URL's authority and a[in ascp-like host. A
file://URL names no host, so it is never asked about on aforge, and its repository is read from the path like a plain local path, so
the allow-list judges it by its path (#296).
encoding_rs is 0.8.42 (#281), and CI runs astral-sh/setup-uv 10.2.0 (#280).
A consumer taking the pin to v1.25.0 must have every
files.includeroot itsrules name on disk, inherited sets included: a missing root now fails the scan
with exit 2 where it warned, and the fix is to correct the root or remove it.
A consumer pushing to a GitHub Enterprise remote that its allow-list does not
name is now refused where github.com may have answered for it. An ssh Host
alias such as
git@github-work:me/repo, orssh.github.com:443, is no longercounted as GitHub, so a push through one to a destination the allow-list does
not name is refused; name the destination in the allow-list, or use a
github.com URL. A push through a remote URL carrying a percent-encoded
credential is refused whatever the allow-list names; drop the encoded
credential from the URL.