Repository navigation
MOB-53942: Move vulnerability_history.md out of .claude/, fix jq buffering and Copilot reviewer fallback - #2030
Conversation
…uffering vulnerability_history.md moved from .claude/skills/prisma-taurus/ to the repo root. Confirmed empirically (Edit, Write, and Bash-based writes all denied identically, with the pinned CLAUDE_CODE_VERSION=2.1.197 too) that headless/dontAsk runs are denied all write access to anything under .claude/ - a hard, tool-agnostic guardrail no --allowed-tools/--add-dir combination changes. Step 14's path-relative references and git add updated to match; content unchanged (git mv, not a rewrite). Also forces line-buffered jq output in the Jenkinsfile (--unbuffered) - same fix as blazect-asset-catalog and taurus-cloud's equivalent Jenkinsfiles, for the same reason: jq fully buffers stdout when piped to a non-TTY, making VERBOSE_OUTPUT render a long wait as one silent gap followed by a burst at the end. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
gh pr edit --add-reviewer @copilot routes through GraphQL, a confirmed known no-op for bot logins (Copilot is a bot, not a user) - verified directly on a real PR: it exited 0 twice while requested_reviewers stayed empty both times. An ||-chained fallback that only calls the REST requested_reviewers endpoint when gh "fails" therefore never reaches it, since gh never reports failure. Now runs both unconditionally. Also notes not to verify attachment immediately after either call: a successful REST call can still show empty requested_reviewers moments later, since Copilot's actual review can take far longer to start than any short check budgets for (observed ~2h from request to submitted review on a sibling repo's PR) - only step 16a's existing bounded poll may conclude anything about whether Copilot reviewed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…irely Copilot review feedback caught a real risk in the previous fix: the unconditional gh pr edit --add-reviewer @copilot call, followed by the REST call, still runs both as separate statements in the same script - if the shell has set -e (or similar) active and gh genuinely fails for an unrelated reason (auth blip, rate limit), it aborts before the REST call ever runs. Since gh's call is a confirmed no-op for bot logins and buys nothing once REST is called unconditionally anyway, the fix is to just not call it at all - one command, no ordering hazard. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The Copilot fallback and stale path references still require correction.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR relocates vulnerability history guidance, improves Jenkins output streaming, and updates Copilot reviewer requests.
Changes:
- Moves
vulnerability_history.mdto the repository root. - Adds unbuffered
jqoutput to vulnerability-pipeline stages. - Runs the Copilot REST reviewer request independently.
| File | Summary |
|---|---|
vulnerability_history.md |
Relocated vulnerability guidance. |
Jenkinsfile-vulnerability-ai |
Enables unbuffered progress output. |
.claude/skills/prisma-taurus/SKILL.md |
Updates paths and reviewer instructions. Findings include fallback handling under set -e, generic REST failure messaging, and three stale Dockerfile references. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…ents Copilot review on PR #2030 caught 3 comments (lines 162, 168, 254) still pointing at .claude/skills/prisma-taurus/vulnerability_history.md, the file's old location before it moved to the repo root. Checked taurus-cloud and blazect-asset-catalog for the same pattern (their equivalent history/notes files and any mend-fix-notes.md/mend_fixes.md variant) - both clean, no stale references found there. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Update the REST failure message to be cause-neutral and reconcile the documentation with the direct-REST flow.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Resolved since last review (2)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #2030 +/- ##
=======================================
Coverage 88.24% 88.24%
=======================================
Files 75 75
Lines 21247 21247
=======================================
Hits 18748 18748
Misses 2499 2499 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|


Summary
vulnerability_history.mdfrom.claude/skills/prisma-taurus/to the repo root (git mv, content unchanged). Confirmed empirically — including with the exact pinnedCLAUDE_CODE_VERSION=2.1.197— that headless/dontAskruns are denied all write access (Edit, Write, and Bash-based writes alike) to anything under.claude/, a hard, tool-agnostic guardrail no--allowed-tools/--add-dircombination changes.SKILL.md's path references,git addcommand, and the reference table updated to match.jqoutput (--unbuffered) inJenkinsfile-vulnerability-ai— without it,jqfully buffers stdout when piped to a non-TTY (always true in a Jenkinsshstep), soVERBOSE_OUTPUTrendered a long-running invocation as one silent gap followed by a burst of messages at the end, indistinguishable from a hang in the console.gh pr edit --add-reviewer @copilotroutes through GraphQL, a confirmed known no-op for bot logins — it can return exit0while silently attaching nothing. The previous||-chained fallback to the RESTrequested_reviewersendpoint therefore never actually ran, sinceghnever reported failure. Only api call kept. Also notes not to verify attachment immediately afterward — even a successful REST call can show emptyrequested_reviewersfor a long time, since Copilot's actual review can take far longer to start than any short check budgets for.Test plan
.claude/write denial directly: Edit, Write, and Bash-based writes (redirects,sed -i, etc.) against a.claude/path were all denied identically under--permission-mode dontAsk, with both the current CLI and the pinned2.1.197.jqbuffering fix locally with a synthetic slow producer: without--unbuffered, 5 messages spanning 10s of real time all land within 40ms of each other (fully buffered); with it, they land ~2s apart matching real time.gh pr edit --add-reviewer @copilotexited0twice whilerequested_reviewersstayed empty both times; the REST fallback separately returned201 Createdwhile also showing empty moments later (Copilot's actual review landed ~2h after the request).🤖 Generated with Claude Code