Skip to content

chore(release): merge v0.16.0 to main - #594

Merged
ajianaz merged 22 commits into
mainfrom
release/v0.16.0
Oct 8, 2026
Merged

ajianaz merged 22 commits into
mainfrom
release/v0.16.0

Conversation

@ajianaz

@ajianaz ajianaz commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

What

GitFlow release merge: develop → main for v0.16.0. Tag v0.16.0 will be pushed on main after this merges, triggering release.yml.

Why

Ship 0.16.0: security hardening of upgrade/installer, LLM parsing and project config (#563, #572, #573, #580); rule-scoped inline suppression cora-ignore: (#554); fixes for index/watch/secrets/findings/test isolation (#565, #578, #579, #586, #587); internal refactors (#574-#577, #582, #585).

Testing

Full suite green on develop (1091 tests, fmt, clippy -D warnings); cora-ignore also verified end-to-end with a locally built binary; CI validates this PR.

🤖 Generated with Claude Code

ajianaz and others added 22 commits September 11, 2026 12:13
The CLA gate relied on a manually POSTed commit status. Fork PRs run
workflows with a read-only GITHUB_TOKEN regardless of declared
permissions, so the status step always 403s on forks — every external
fork PR was permanently red even with a signed CLA. The bot comment
step also 403s on forks.

- Drop the commit-status step and statuses:write; the gate now rides
  on this job's own Actions check run (fork-safe by construction).
- Comment step becomes same-repo-only + continue-on-error (courtesy,
  never a gate). Unsigned path emits a ::error annotation with the
  portal link instead.
- github-script upgraded to v9.

Validated end-to-end on codecoradev/uteke (PR #1224 + E2E probe).

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
…r tests (#561)

Two develop-wide red gates, one unblock PR (both verified against CI):

- RUSTSEC-2026-0285: rustls 0.23.42 in Cargo.lock trips rustsec
  audit-check on every open PR. Pin 0.23.45 (same remediation as
  gaira 2026-10-03); rustls-webpki rides along to 0.103.15. Closes #560.
- 'use std::f32;' in the vector tests module resolves f32::EPSILON to
  the deprecated module-path constant: clippy -D warnings is red on
  rustc 1.99, now including CI's stable toolchain. Removing the import
  restores the associated-constant resolution. Closes #557.

Lockfile + one test-only line; no runtime code paths touched.

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
…es (#562)

Chunked review merged a contradictory report when chunks returned
issues with an empty summary field: the header counted the issues but
the fallback summary printed 'No issues found across all chunks.' (live:
gaira PR #108 run #1388 verdict comment). The fallback keyed only off
summaries/any_error and never consulted the collected issues.

Extract the decision into merged_chunk_summary() with an explicit
issue-count branch (issue_count > 0 and any_error now compose into one
honest message), unit-test all five outcomes. Gating is unchanged:
exit code still derives from should_block.

Fixes #556

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
…aml (#563)

- ignore provider.base_url from a discovered .cora.yaml unless CORA_TRUST_PROJECT_CONFIG=1
- require https base_url (http only for loopback)
- cap LLM error bodies echoed in LlmStatus via preview_raw
- cora-review workflow: require pinned CORA_BASE_URL secret

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
…dling (#564)

- Frame stdin as bytes and decode UTF-8 properly (no more byte-as-char),
  recover from stray '}'/garbage with a -32700 parse error, cap message size.
- Do not respond to notifications; notifications/cancelled no longer stops
  the server (only shutdown/EOF); tools/call without a name returns -32602.
- find_affected_tests: use file stem, escape LIKE wildcards, cap files.
- Clamp limit/depth/min_lines, cap review_diff size.
- cora.install requires confirm:true to write and validates agent names.
- Remove unused since/branch params from cora.get_debt schema.
- AGENT.md: tool count 15 -> 18.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…nor skip patterns (#565)

- schema v8: files keyed by (project_id, path) so projects sharing a relative
  path no longer overwrite each other's fingerprint (perpetual reindex).
- graph: find_callers/callees/trace use exact match instead of LIKE '%x%'
  (run no longer matches rerun; _ and % are not wildcards).
- index runs auto-prune stale files; pruning also clears edges.
- serve and watch use index_project_with_skip with resolved config patterns.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Exact-match checksum lookup, random 0700 temp dir, extract only the
regular-file binary entry (reject symlink/hardlink), request timeouts and
size caps, no-redirect version probe with tag validation, and require an
explicit ack to skip checksums. install.sh now fails closed on missing
checksums, falls back to shasum, and rejects link entries.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…#573)

String-aware JSON array extraction (brackets and ||| inside finding
bodies no longer truncate results), untrusted-data clause appended to all
system prompts, diff fence longer than any backtick run, SSE line and
total size caps, and high-confidence secret scanning for test/doc paths.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…he index (#574)

Evolve IndexBridge into the one module that resolves the project root
(via resolve_project_root), opens the index with shared PRAGMAs, and
ensures the project id. Tolerant mode for review, strict mode for CLI/MCP.
Index scanners and brain context take the bridge, so a review run from a
subdirectory resolves the same project_id as indexing from the root.

Closes #566

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
… and MCP (#575)

Add src/index/queries.rs as the single implementation. Fixes the CLI stem
bug (extension used as stem), adds LIKE ESCAPE, batches queries, and makes
MCP dead-code honor analysis.entry_point_patterns from project config.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…tup (#576)

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Extract engine::deterministic::run (rules, secrets, security, index scans,
claim flags) returning a structured DeterministicReport with context() and
merge_into(), testable without an LLM. The three index scanners share one
scan_changed_files preamble. All ignore/skip/include/exclude matching now goes
through engine::path_match (index, review scanners, scan, watch).

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
)

Covers security hardening (#563, #572, #573), fixes (#553, #561, #562,
#564, #565, #574-#576), and the ignore-pattern semantic changes from
#577 that can alter which files existing configs exclude.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
#582)

Review, streaming review and scan now share one findings step
(llm::findings) that owns empty-response recovery, parse, repair, partial
salvage and the single stricter-prompt retry. llm.rs is split into
transport / prompts / findings / repair modules; the LLM layer no longer
prints (LlmEvents sink), so tests drive the policy with a fake transport.

Closes #570

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
secrets_scanner skipped test/spec/fixture/mock/example paths entirely, so
real leaked credentials committed there were never reported. Extract the
high-confidence list from security_scanner into engine::secret_patterns
and run it in those paths from both scanners; generic rules stay
suppressed there.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…is indexed (#584)

detect_changes returned every source file on every tick and the whole
project was reindexed after a trigger, so --filter only gated whether a
cycle fired. The watch loop now keeps an (mtime, size) snapshot, diffs it
each tick (new/modified/deleted), applies the ext/git-only/--filter/skip
filters, and reindexes only the changed files via a new include predicate
(IndexSession::index_matching). Deletions are pruned by the same run; idle
ticks do no indexing work. Fixes both cora watch and index --watch.

Closes #578

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…585)

Move all SQL for reviews/findings/finding_events into engine::review_store
(replaces engine::db_writer). cora findings, debt tracker and review/scan
persistence call it and hold no SQL. Store takes a &Connection so it is
testable with in-memory SQLite; best-effort persistence policy is explicit
in persist_review_best_effort.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…tive (#588)

Severities are stored lowercase, but the filter upper-cased its argument
(never matching) and the renderer matched uppercase literals (no colour).
Lowercase the filter argument, colour via a pure case-insensitive helper,
and validate --severity (info|minor|major|critical, any case) in clap.

Closes #586

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…dex lock wait (#587) (#589)

Unit tests now resolve the CodeCora data root to a process-wide scratch
dir unless CODECORA_HOME is set, so index/watch tests no longer open the
developer's real global vector index or hang behind another cora process.
acquire_file_lock polls try_lock for 15s then errors naming the lock path.

Signed-off-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
#580) (#590)

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
…593)

* feat(review): rule-scoped inline suppression via cora-ignore (#554)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* fix(review): use ASCII lowercase when locating cora-ignore marker (#554)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* ci: retrigger checks for 247350c

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

---------

Co-authored-by: ajianaz <ajianaz@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
@ajianaz
ajianaz merged commit 7935353 into main Oct 8, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant