fix(release): reconcile published npm package name and harden packaging gate - #40
Conversation
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Hacktron Security Check - SkippedReason: Billing required for Code Review seats
|
|
Warning Review limit reachedNext included review available in 47 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| echo "npm package name: $NPM_NAME" | ||
| grep -Fq "npx ${NPM_NAME}" README.md || { echo "ERROR: README missing 'npx ${NPM_NAME}'"; exit 1; } | ||
| grep -Fq "npm install -g ${NPM_NAME}" README.md || { echo "ERROR: README missing 'npm install -g ${NPM_NAME}'"; exit 1; } | ||
| BAD=$(grep -rhoE "@[A-Za-z0-9._-]+/skill-doctor" \ |
There was a problem hiding this comment.
Suggestion: The unanchored pattern also matches names such as @security.kalarislabs/skill-doctor-old, then filters that match as canonical, allowing a non-canonical package name through. [logic error]
Assessment: 🟠 Major · 🔁 Occurrence: Sometimes
Prompt for AI Agent 🤖
This is a comment left during a code review.
**Path:** .github/workflows/ci.yml
**Line:** 86:86
**Comment:**
*Logic Error: The unanchored pattern also matches names such as `@security.kalarislabs/skill-doctor-old`, then filters that match as canonical, allowing a non-canonical package name through.
Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix| ``` | ||
|
|
||
| The npm package is a thin installer that verifies SHA-256 digests against official release checksums and places the prebuilt static binary; there is no Node runtime dependency at scan time. Prebuilt standalone binaries are also downloadable directly from [GitHub Releases](https://github.com/KalarisLabs/Skill-Doctor/releases). | ||
| To build the npm package from source without downloading prebuilt binaries, set `SKILL_DOCTOR_SKIP_DOWNLOAD=1`. |
There was a problem hiding this comment.
Suggestion: This only skips downloading; it does not build or install a binary, so the npm command fails unless target/release already contains one. [api mismatch]
Assessment: 🟠 Major · 🔁 Occurrence: Sometimes
Prompt for AI Agent 🤖
This is a comment left during a code review.
**Path:** README.md
**Line:** 39:39
**Comment:**
*Api Mismatch: This only skips downloading; it does not build or install a binary, so the npm command fails unless `target/release` already contains one.
Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix| if echo "$out" | grep -Fq "no matching package"; then | ||
| echo "::warning::$c dry-run deferred: workspace dep not yet on crates.io for this version" |
There was a problem hiding this comment.
Missing Dependencies Are Ignored
The advisory publish check converts every Cargo failure containing no matching package into a warning without confirming that the missing package is an unpublished workspace dependency. A stale or misspelled external dependency produces the same message, so an unpublishable downstream crate can pass verification and fail only during manual publication. Restrict this exception to explicitly expected workspace dependencies and keep all other publish dry-run failures fatal.
Artifacts
- Creates a disposable external-dependency crate, runs a real Cargo dry run, and evaluates the extracted workflow branch; it demonstrates the unsafe classification condition.
- Captured real `cargo publish --dry-run` command, working directory, exit code 101, and Cargo diagnostic containing `no matching package`; it proves an external failure has the matched phrase.
- Captured execution of the extracted release workflow decision branch using the real Cargo output; it emits the warning and exits 0 without workspace dependency verification, confirming suppression.
Ran code and verified through T-Rex
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/release.yml
Line: 147-148
Comment:
**Missing Dependencies Are Ignored**
The advisory publish check converts every Cargo failure containing `no matching package` into a warning without confirming that the missing package is an unpublished workspace dependency. A stale or misspelled external dependency produces the same message, so an unpublishable downstream crate can pass verification and fail only during manual publication. Restrict this exception to explicitly expected workspace dependencies and keep all other publish dry-run failures fatal.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
User description
Overview
This PR addresses release-pipeline defects, reconciles the published npm package name to
@security.kalarislabs/skill-doctoracross all tracked files, hardens the release packaging gate, and aligns repository documentation with production truth.Key Changes
Canonical npm Scope Reconciliation:
@security.kalarislabs/skill-doctoris the sole scope in tracked files (0 occurrences of stale@kalarislabs/or@kalarislabsai/scopes)..github/workflows/install-verify.yml,docs/RELEASE.md,docs/PAPER-RECONCILIATION.md, andskills/release-publish/SKILL.md.CI Name-Drift Protection (
ci.yml):version-syncensuringpackage.jsonname matchesREADME.md(npx ${NPM_NAME}andnpm install -g ${NPM_NAME}).@.../skill-doctorscope appears in repository markdown, JSON, or YAML files.Release Pipeline Hardening (
release.yml):packaging-dry-runjob running on a clean checkout in parallel withbuild-release, gated ongit status --porcelain.skill-doctor-neutralize,skill-doctor-rules,skill-doctor-sandbox) and tolerant advisory loop for downstream crates (skill-doctor-core,skill-doctor-mcp,skill-doctor).rm -f crates/*/*.jsontorm -f crates/*/*.cdx.json crates/*/bom.json, followed by clean tree check.provenance-and-release.Install & Post-Release Verification Hardening (
install-verify.yml):@security.kalarislabs/skill-doctor.Documentation Alignment (
README.md&docs/RELEASE.md):version-sync(cargo install --path crates/skill-doctor-cli --locked --features mcp,Requires Rust 1.93.0+ (MSRV),uses: KalarisLabs/Skill-Doctor@v0.1.0).SKILL_DOCTOR_SKIP_DOWNLOAD=1and--features mcprequirement.SD_L3_REQUIRE_INTERPRETER=1 cargo test --workspace --all-features --locked).docs/RELEASE.mdpackaging architecture explanation and correctedskill-doctor-sandboxtiering.Verifiable Evidence Table
@kalarislabs/,@kalarislabsai/,@security.kalarislabs/)@security.kalarislabs/skill-doctornpm view @security.kalarislabs/skill-doctor version dist-tags->0.1.0,latest: 0.1.0(other scopes 404)@kalarislabs/, 7@kalarislabsai/, 7@security.kalarislabs/@security.kalarislabs/skill-doctor, 0 stale scopesgrep -rhoE "@[A-Za-z0-9._-]+/skill-doctor" ... | sort | uniq -cversion-syncexit 1), passed when restored (exit 0)--allow-dirtyused; downstreams skippedpackaging-dry-run), no--allow-dirty, Tier 1 hard + downstream advisory loopnpm pack --dry-runpassed with exit code 0rm -f crates/*/*.jsonrm -f crates/*/*.cdx.json crates/*/bom.json+git status --porcelaincheckrelease.ymlisDraft=false,isLatest=true, install lines verified#issuecomment-5651121107), branch deletedgit log origin/main..origin/fix/pre-release-auditempty; comment livenpx @security.kalarislabs/skill-doctor@0.1.0CodeAnt-AI Description
Align the published npm package name and strengthen release verification
What Changed
@security.kalarislabs/skill-doctoracross installation checks, release guidance, and documentationImpact
✅ Fewer failed npm installations from package name drift✅ Earlier detection of invalid release packages✅ Verified malicious-skill detection after release💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Not safe to merge until unexpected missing dependencies cause release verification to fail.
Fix with agent prompt
Summary
Reviews (1) · Last reviewed commit: "fix(release): reconcile published npm pa..."