Skip to content

refactor(sdk): simplify publication preparation - #1211

Merged
mldangelo-oai merged 24 commits into
mainfrom
refactor/pr1185-followup-11-publication
Oct 4, 2026
Merged

mldangelo-oai merged 24 commits into
mainfrom
refactor/pr1185-followup-11-publication

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Publication preparation and receipt handling repeat transformations and fixture setup. Reuse the finding and workbench owners and consolidate equivalent publication operations.

Changes

  • Simplify cloud preparation, event mapping and receipt persistence.
  • Introduce the publication inspection fixture helper with its tests.
  • Keep publication claims, ordering, cancellation and recovery assertions.

Testing

  • Fresh publication run: 188 passed across 8 test modules.
  • The five portable source checks passed. SDK changes passed types and normal formatting; MCP changes passed MCP typecheck and relevant formatting checks.
  • The combined integration tree is byte-identical to the previously validated combined tree: both full SDK runs (3,566 passed, 53 skipped each), 209 MCP checks and installed-package checks remain applicable. These full suites were not rerun for this history-only integration.
  • Three fresh native reviews and an independent verifier passed for this exact base/head. Hosted CI and Codex/Copilot reviews run on the updated head.

Risk and rollout

Publication targets, defaults and receipt behavior remain unchanged. This patch requires the persisted-finding helpers; actual publication is outside local validation.

Stacked on #1210, with its current head merged. This diff contains only the publication changes. After the parent lands, integrate current main, preserve the publication contribution, rerun checks and retarget this PR to main before merging.

Public disclosure review

  • No customer, partner, prospect, or user identities, data, or identifying details are included.
  • No credentials, personal data, private source, scan findings, or nonpublic links or tickets are included.
  • I reviewed the branch name, title, description, commits, changes, comments, logs, screenshots, attachments, and links for public disclosure.

codex added 2 commits October 3, 2026 19:14
Repository fixtures and hydration tools duplicate Git process setup. Share the existing invocation patterns with their actual consumers.
SDK entrypoints and tests repeat runtime, authentication and option setup. Share the setup at existing owners and introduce internal helpers with their first consumers.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T08:14:14.668421Z 782ccff New commits
🔒 Security Review ✅ Completed 2026-10-04T08:14:47.567826Z 782ccff New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head 5f9dfd4.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 5f9dfd46f3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The refactors preserve existing behavior and maintain comprehensive publication coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Simplifies publication preparation and receipt tests by reusing shared helpers while preserving publication behavior.

Changes:

  • Consolidates finding mapping, claim resolution, hashing, and workbench runtime setup.
  • Reuses publication fixtures, mocks, JSONL utilities, and cancellation helpers.
  • Retains ordering, recovery, cancellation, and receipt assertions.
File Description
sdk/​typescript/​src/​cloud-publish.ts Reuses shared SHA-256 helper.
sdk/​typescript/​src/​publication-events.ts Simplifies claim normalization and conflict detection.
sdk/​typescript/​src/​publication-store.ts Reuses finding and workbench runtime helpers.
sdk/​typescript/​src/​publication.ts Simplifies publication issue preparation and evidence rendering.
sdk/​typescript/​src/​publish.ts Consolidates finding maps, prompt construction, and handoff records.
sdk/​typescript/​tests-ts/​cloud-publish.test.ts Reuses fixtures and mock helpers.
sdk/​typescript/​tests-ts/​custom-publish.test.ts Simplifies fixture and request assertions.
sdk/​typescript/​tests-ts/​finding-workflow-publication.test.ts Reuses reviewer, error, and mock helpers.
sdk/​typescript/​tests-ts/​publication-check.test.ts Reuses cancellation and failure fixtures.
sdk/​typescript/​tests-ts/​publication-integration.test.ts Consolidates integration fixtures and JSONL handling.
sdk/​typescript/​tests-ts/​publication-store.test.ts Simplifies fixture copying and cancellation synchronization.
sdk/​typescript/​tests-ts/​publication.test.ts Reuses completed-scan and temporary-directory fixtures.
sdk/​typescript/​tests-ts/​publish.test.ts Consolidates publication mocks, receipts, and JSONL assertions.
sdk/​typescript/​tests-ts/​support/​workbench-fakes.ts Adds a reusable canceled-inspection fixture.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

codex added 3 commits October 3, 2026 20:31
Persisted finding workflows and recovery tests repeat owner calls and data preparation. Consolidate those paths while retaining current recovery and validation behavior.
Publication preparation and receipt handling repeat transformations and fixture setup. Reuse the finding and workbench owners and consolidate equivalent publication operations.

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 5f9dfd46f3429a6a5dbe18be64dce623c0517e3f against its own base a8a76bab5dc1b0d76b80b9d10d780128b0f5da2e with exactly three independent high-reasoning full-diff reviews, including every test diff, plus root verification. No serious introduced code defect identified.

188 distinct focused SDK tests passed across the initial run and one targeted permission control. The initial run had 187 passes and a sandbox-denied read-only ps check; that unchanged test passed with permission. Fresh native host build, plugin/SDK builds, types and formatting passed.

Local validation was on macOS arm64. No model execution, local Windows run or full installed-package smoke. Reviewed sources remained unchanged. This review covers this exact head; it does not establish combined-stack validation against current main.

@mldangelo-oai
mldangelo-oai force-pushed the refactor/pr1185-followup-10-findings branch from a8a76ba to 3bfbd7e Compare October 3, 2026 21:09
@mldangelo-oai
mldangelo-oai force-pushed the refactor/pr1185-followup-11-publication branch from 5f9dfd4 to 32493da Compare October 3, 2026 21:09
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head 32493da.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: 32493da23e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It broadly refactors behavior-critical publication and recovery paths whose live external publication flow was not exercised.

Review effort: Balanced
Findings: None

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified the current own contribution and all touched source/test files are identical to the previously approved revision. The entire head differs only in an inherited test-helper invocation from the reviewed parent. Retained exactly three independent review passes and prior source validation with root verification; no actionable introduced findings remain.

Local evidence is macOS arm64 without model execution or a local Windows run. Hosted CI and merge readiness are separate.

At the prepublication check, current-head CI was still running with no reported failures. Approval is not a claim of completed CI or merge readiness.

codex added 9 commits October 3, 2026 21:34
# Conflicts:
#	sdk/typescript/src/security-policy.ts
#	sdk/typescript/tests-ts/api-policy.test.ts
#	sdk/typescript/tests-ts/api-post-scan.test.ts
#	sdk/typescript/tests-ts/component-scan.test.ts
#	sdk/typescript/tests-ts/security-policy.test.ts
# Conflicts:
#	sdk/typescript/tests-ts/multiscan.test.ts
@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head b52c309.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: b52c30905d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The stacked parent and required post-merge restacking mean the final main-targeted diff still requires human verification.

Review effort: Balanced
Findings: None

@alandelong-oai alandelong-oai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head b52c30905d49416f95ecc0a9b1242a6679e5e73a against 030d6b382fb1a9c7a6a9d9aeb2d52a018e5742d5. The contribution and all14 touched base/head blobs match the previously reviewed versions. Retained the prior three independent HIGH full-diff/test reviews after root identity verification; no duplicate full review. No serious introduced product finding remains.

Approval is withheld while inherited installed-package/container checks fail on the cleanup assertion described in #1207 (package-behavior.mjs:202). This is a base fixture/cleanup-contract failure at this head, not a new finding in this PR contribution. Correct it upstream and rerun hosted checks.

Local validation: 188 distinct runnable SDK tests verified:187 passed initially,one read-only ps sandbox denial; the unchanged named test passed with permission. Fresh macOS arm64 native host, plugin and SDK builds, types and formatting passed. Reviewed sources are unchanged. No model execution, local Windows run or full installed-package smoke. Source review is complete; merge readiness is not established.

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head 71fbbec.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 71fbbecd9c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The production publication paths are broadly refactored and the stacked branch still requires restacking before merge.

Review effort: Balanced
Findings: None

@mldangelo-oai

Copy link
Copy Markdown
Collaborator Author

@codex review the current head 41895ea.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 41895eaaf0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The production refactors preserve existing semantics, and the corresponding tests retain their behavioral assertions.

Review effort: Balanced
Findings: None

Base automatically changed from refactor/pr1185-followup-10-findings to main October 4, 2026 08:12
@mldangelo-oai
mldangelo-oai merged commit 9c415a8 into main Oct 4, 2026
14 checks passed
@mldangelo-oai
mldangelo-oai deleted the refactor/pr1185-followup-11-publication branch October 4, 2026 08:13
@github-actions github-actions Bot mentioned this pull request Oct 4, 2026
3 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants