Repository navigation
refactor(plugin): simplify artifact projections - #1227
Conversation
|
@codex review the current head SHA. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The refactors preserve observable behavior and are supported by comprehensive targeted and repository-wide tests.
Review effort: Balanced
Findings: None
What changed in this PR
Simplifies artifact projection internals while preserving compatibility, output formatting, size budgets, and SARIF hashing behavior.
Changes:
- Consolidates code-evidence merging, validation, deduplication, and bounding.
- Reuses JSON sizing and validation data structures.
- Simplifies Markdown formatting and UTF-16 iteration.
| File | Description |
|---|---|
plugins/codex-security/scripts/report_projection.py |
Simplifies Markdown escaping and title deduplication. |
plugins/codex-security/scripts/finding_preview.py |
Consolidates evidence projection and JSON-size calculations. |
plugins/codex-security/scripts/finalize_scan_contract.py |
Streamlines legacy validation and SARIF UTF-16 hashing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
alandelong-oai
left a comment
There was a problem hiding this comment.
Reviewed the actual PR contribution at b5579aeb77978c7c9adc04736f98d7082e30fd44 against 1fb0e5fbf8684c926cac2a36d08389b212d28d5a with three independent full-diff review passes and root synthesis, including every changed test and fixture. No actionable introduced issue was identified.
Read the full contribution. Shared evidence merge preserves ordering/first-wins and size constraints; shared JSON/Markdown output and validation order reveal no supported introduced discrepancy. No runtime or renderer execution.
Static source review only; tests and builds were not run locally. This approval does not establish whole-stack integration or deployment.
Summary
Artifact projection repeats evidence filtering, JSON sizing and report formatting work. Consolidate those operations while preserving saved-artifact compatibility and rendered output.
Changes
Testing
Passed on commit
b5579aeb7797:python -m pytest plugins/codex-security/tests/test_finalize_scan_contract.py plugins/codex-security/tests/test_finding_preview.py plugins/codex-security/tests/test_report_projection.py -q -n 4 --dist worksteal --max-worker-restart 0— 215 passed, 2 skipped, and 55 subtests passed.python -m pytest plugins/codex-security/tests -q -n 4 --dist worksteal --max-worker-restart 0— 1,587 passed, 6 skipped, and 162 subtests passed.All five portable plugin checks passed:
Three independent Codex reviews and separate verification completed without findings.
Risk and rollout
Compatibility depends on evidence order, exact truncation boundaries, Unicode handling and historical sealed artifacts. Preserve those behaviors, streaming reads and the supported Python recursion boundary; no artifact schema or output policy changes are intended.
Public disclosure review