fix(catalog): drop unpublished requests plugins; validate manifest in CI - #9
Conversation
- Remove prairie.requests.arr and prairie.requests.seerr from manifest.json. Their repos (prairie-server/prairie-plugins-requests-*) do not exist, so every download 404s. Also drop them from the update-manifest dispatch options. - Add scripts/validate-manifest.py and a CI job that checks manifest.json parses and that every download URL is a well-formed https GitHub release-asset URL in the entry's own repo, under its version tag, with one binary per supported platform. It makes no network requests. - Pin actions to SHAs, pin golangci-lint v2.14.0, bump grpc to v1.83.2, fix errcheck in cmd/update-catalog, and list the lint, coverage and manifest checks in CONTRIBUTING. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe changes remove two plugin entries, add offline manifest validation to CI, pin workflow actions and the lint version, update Go dependencies, and explicitly ignore response body close errors. ChangesCatalog manifest validation
Workflow and Go maintenance
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant GitHubActions
participant validate-manifest.py
participant manifest.json
GitHubActions->>validate-manifest.py: Run validator with manifest.json
validate-manifest.py->>manifest.json: Read and validate entries
validate-manifest.py-->>GitHubActions: Return status and validation output
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The catalog removals and offline validation are consistent and appear ready to merge after normal checks. Validation intentionally does not confirm that releases exist. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The changes remove two catalog entries and add checks for the remaining entries. No introduced security issue was established, but the new check does not verify that releases exist or prevent the separate catalog-update workflow from publishing before CI runs. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files. (5 skipped: 5 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Merging this publishes the catalog. The only change to
manifest.jsonis removing two entries.Catalog content (
manifest.json)prairie.requests.arrandprairie.requests.seerr. Theirrepo_urls (prairie-server/prairie-plugins-requests-arr/-seerr) don't exist, so every binary and checksum download 404s. This was CodeRabbit's finding on chore: sync upstream silo-plugins main + repair broken catalog JSON (2026-09-28) #8 (manifest.json:468). NeitherPrairie-Server/prairie-plugins-requests-*norprairie-plugin-requests-*exists.update-manifest.yml: dropped therequests-arr/requests-seerrdispatch options and their repo mappings, which pointed at the same missing repos.New CI check:
Validate catalog manifestA new job in
ci.ymlrunspython3 -m json.tool manifest.jsonand thenscripts/validate-manifest.py. The script needs only the Python standard library and makes no network requests. For each entry it checks:plugin_idis present and unique, andversionis semver.repo_urlishttps://github.com/<owner>/<repo>.checksums_urland everybinaries[*].urlare https GitHub release-asset URLs in the same repo asrepo_url, under tagv<version>, namedchecksums.txt/plugin-<os>-<arch>, with no credentials, query, fragment, or whitespace.binarieskeys matchsupported_platforms.*_urlfields are absolute https URLs.Tested locally against the current catalog (passes) and against mutated copies: an http URL, the wrong tag, another plugin's repo, a mismatched asset name, a duplicate id, a missing platform binary, whitespace, and unparsable JSON. Each mutation fails with a specific message. It can't detect a repo or release that was never published (the removed entries had well-formed URLs), because that needs a live request.
Other
# vX.Y.Zcomment. golangci-lint is pinned tov2.14.0.google.golang.org/grpcv1.82.1 → v1.83.2 (indirect).resp.Body.Close()calls incmd/update-catalognow explicitly discard their errors (behavior unchanged).go testnever had|| true, and there's no Makefile, so neither change applies here.update-catalog/update-manifestkeep persisted checkout credentials because they push tomain.Validation
AI disclosure
🤖 Generated with Claude Code
Summary by CodeRabbit