Skip to content

fix(catalog): drop unpublished requests plugins; validate manifest in CI - #9

Merged
JonahMMay merged 1 commit into
mainfrom
chore/catalog-cleanup
Sep 29, 2026
Merged

JonahMMay merged 1 commit into
mainfrom
chore/catalog-cleanup

Conversation

@JonahMMay

@JonahMMay JonahMMay commented Sep 29, 2026 •

Copy link
Copy Markdown

Summary

Merging this publishes the catalog. The only change to manifest.json is removing two entries.

Catalog content (manifest.json)

  • Removed prairie.requests.arr and prairie.requests.seerr. Their repo_urls (prairie-server/prairie-plugins-requests-arr / -seerr) don't exist, so every binary and checksum download 404s. This was CodeRabbit's finding on chore: sync upstream silo-plugins main + repair broken catalog JSON (2026-09-28) #8 (manifest.json:468). Neither Prairie-Server/prairie-plugins-requests-* nor prairie-plugin-requests-* exists.
  • Verified by parsing both files: the new catalog equals the old one with exactly those two entries filtered out. The other 10 entries are byte-for-byte unchanged, and the diff has 376 deletions and 0 additions.
  • Remaining entries: audiobook-metadata 0.1.5, autoscan.arr 0.1.3, ebook-metadata 0.1.2, manga-metadata 0.1.2, mdblist 0.4.1, sportarr 1.0.3, theintrodb 0.1.2, tmdb 1.2.21, tvdb 1.2.25, watchprovider.floppy 0.3.1.
  • update-manifest.yml: dropped the requests-arr / requests-seerr dispatch options and their repo mappings, which pointed at the same missing repos.

New CI check: Validate catalog manifest

A new job in ci.yml runs python3 -m json.tool manifest.json and then scripts/validate-manifest.py. The script needs only the Python standard library and makes no network requests. For each entry it checks:

  • plugin_id is present and unique, and version is semver.
  • repo_url is https://github.com/<owner>/<repo>.
  • checksums_url and every binaries[*].url are https GitHub release-asset URLs in the same repo as repo_url, under tag v<version>, named checksums.txt / plugin-<os>-<arch>, with no credentials, query, fragment, or whitespace.
  • binaries keys match supported_platforms.
  • Presentation *_url fields are absolute https URLs.

Tested locally against the current catalog (passes) and against mutated copies: an http URL, the wrong tag, another plugin's repo, a mismatched asset name, a duplicate id, a missing platform binary, whitespace, and unparsable JSON. Each mutation fails with a specific message. It can't detect a repo or release that was never published (the removed entries had well-formed URLs), because that needs a live request.

Other

  • Every action in all three workflows is pinned to a full commit SHA with a # vX.Y.Z comment. golangci-lint is pinned to v2.14.0.
  • google.golang.org/grpc v1.82.1 → v1.83.2 (indirect).
  • errcheck: the two deferred resp.Body.Close() calls in cmd/update-catalog now explicitly discard their errors (behavior unchanged).
  • CONTRIBUTING lists the lint, coverage, and manifest checks.
  • The catalog's go test never had || true, and there's no Makefile, so neither change applies here. update-catalog / update-manifest keep persisted checkout credentials because they push to main.

Validation

python3 -m json.tool manifest.json > /dev/null                        # ok
python3 scripts/validate-manifest.py manifest.json                    # manifest.json: 10 plugin(s) OK
go test $(go list ./... | grep -v '/cmd/') -covermode=atomic -coverprofile=coverage.out   # ok
./scripts/check-coverage.sh coverage.out                              # coverage 98.2% (min 95.0%)
golangci-lint run --max-issues-per-linter=0 --max-same-issues=0 ./... # 0 issues (was 2)
go build ./cmd/update-catalog                                         # ok

AI disclosure

  • Tool: Claude Code
  • Model: claude-opus-5-5
  • Involvement: AI-generated

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Plugin Availability
    • Requests Arr and Requests Seerr are no longer included in the plugin catalog or offered in the manifest update workflow.
  • Reliability
    • Catalog release information is now checked for valid download links and platform details, helping catch catalog issues before they reach users.

- Remove prairie.requests.arr and prairie.requests.seerr from
  manifest.json. Their repos (prairie-server/prairie-plugins-requests-*)
  do not exist, so every download 404s. Also drop them from the
  update-manifest dispatch options.
- Add scripts/validate-manifest.py and a CI job that checks manifest.json
  parses and that every download URL is a well-formed https GitHub
  release-asset URL in the entry's own repo, under its version tag, with
  one binary per supported platform. It makes no network requests.
- Pin actions to SHAs, pin golangci-lint v2.14.0, bump grpc to v1.83.2,
  fix errcheck in cmd/update-catalog, and list the lint, coverage and
  manifest checks in CONTRIBUTING.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9871240c-cdb9-4f83-86a6-a6bfcc8780c4

📥 Commits

Reviewing files that changed from the base of the PR and between b081647 and fbc270c.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (8)
  • .github/workflows/ci.yml
  • .github/workflows/update-catalog.yml
  • .github/workflows/update-manifest.yml
  • CONTRIBUTING.md
  • cmd/update-catalog/main.go
  • go.mod
  • manifest.json
  • scripts/validate-manifest.py
💤 Files with no reviewable changes (1)
  • manifest.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The changes remove two plugin entries, add offline manifest validation to CI, pin workflow actions and the lint version, update Go dependencies, and explicitly ignore response body close errors.

Changes

Catalog manifest validation

Layer / File(s) Summary
Remove plugin entries
manifest.json, .github/workflows/update-manifest.yml
The manifest and manual workflow mapping no longer include prairie.requests.arr or prairie.requests.seerr.
Add manifest validator
scripts/validate-manifest.py
The new script checks manifest structure, plugin IDs and versions, HTTPS URLs, GitHub release asset paths, and platform declarations. It reports errors to stderr and returns a nonzero status.
Run and document validation
.github/workflows/ci.yml, CONTRIBUTING.md
CI runs the validator. Contributor instructions add lint, coverage, and manifest-validation commands and describe the checks. The validator does not check whether a release exists.

Workflow and Go maintenance

Layer / File(s) Summary
Pin workflow actions and lint version
.github/workflows/ci.yml, .github/workflows/update-catalog.yml, .github/workflows/update-manifest.yml
Workflow actions use commit SHAs. The CI lint tool uses a pinned action revision and golangci-lint v2.14.0 instead of latest.
Update Go dependencies and response cleanup
go.mod, cmd/update-catalog/main.go
Five indirect dependency versions are updated. Both HTTP response handlers explicitly ignore errors from Body.Close().

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant validate-manifest.py
  participant manifest.json
  GitHubActions->>validate-manifest.py: Run validator with manifest.json
  validate-manifest.py->>manifest.json: Read and validate entries
  validate-manifest.py-->>GitHubActions: Return status and validation output
Loading

Suggested reviewers: quick104

Merge Risk: ⚪ Minimal · up to fbc27

The catalog removals and offline validation are consistent and appear ready to merge after normal checks. Validation intentionally does not confirm that releases exist.

Security Architecture Review

Security architecture risk: 🔵 Low · up to fbc27

The changes remove two catalog entries and add checks for the remaining entries. No introduced security issue was established, but the new check does not verify that releases exist or prevent the separate catalog-update workflow from publishing before CI runs.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — Manifest changes can affect the repository’s published catalog; the available evidence does not establish how downstream installations authenticate publishers or consume its download URLs.

Trust Boundaries and Controls

  • observed — Repository-supplied URLs are parsed and compared, not fetched, by the new validator. Its checks allow any syntactically valid GitHub owner and repository, provided an entry’s asset URLs match that repository.

Resilience and Maintainability Implications

  • inferred — The CI check is not a pre-publication control for the existing direct-push catalog updater; whether other publication or consumer controls close that gap is unknown.

Hardening Proposals

  • proposed — If validation is intended to block all catalog publication, run it before the catalog updater pushes, and separately define how publisher ownership and asset existence are verified.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files. (5 skipped: 5… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the two main changes: removing unpublished requests plugins and adding manifest validation in CI.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files. (5 skipped: 5 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@JonahMMay
JonahMMay merged commit b1d6eb6 into main Sep 29, 2026
4 checks passed
@JonahMMay
JonahMMay deleted the chore/catalog-cleanup branch September 29, 2026 03:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant