Skip to content

MOB-53942: Move vulnerability_history.md out of .claude/, fix jq buffering and Copilot reviewer fallback - #2030

Merged
henrychv merged 4 commits into
masterfrom
MOB-53942-fixes
Sep 23, 2026
Merged

henrychv merged 4 commits into
masterfrom
MOB-53942-fixes

Conversation

@henrychv

@henrychv henrychv commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Move vulnerability_history.md from .claude/skills/prisma-taurus/ to the repo root (git mv, content unchanged). Confirmed empirically — including with the exact pinned CLAUDE_CODE_VERSION=2.1.197 — that headless/dontAsk runs are denied all write access (Edit, Write, and Bash-based writes alike) to anything under .claude/, a hard, tool-agnostic guardrail no --allowed-tools/--add-dir combination changes. SKILL.md's path references, git add command, and the reference table updated to match.
  • Force line-buffered jq output (--unbuffered) in Jenkinsfile-vulnerability-ai — without it, jq fully buffers stdout when piped to a non-TTY (always true in a Jenkins sh step), so VERBOSE_OUTPUT rendered a long-running invocation as one silent gap followed by a burst of messages at the end, indistinguishable from a hang in the console.
  • Fix the Copilot reviewer request: gh pr edit --add-reviewer @copilot routes through GraphQL, a confirmed known no-op for bot logins — it can return exit 0 while silently attaching nothing. The previous ||-chained fallback to the REST requested_reviewers endpoint therefore never actually ran, since gh never reported failure. Only api call kept. Also notes not to verify attachment immediately afterward — even a successful REST call can show empty requested_reviewers for a long time, since Copilot's actual review can take far longer to start than any short check budgets for.

Test plan

  • Confirmed the .claude/ write denial directly: Edit, Write, and Bash-based writes (redirects, sed -i, etc.) against a .claude/ path were all denied identically under --permission-mode dontAsk, with both the current CLI and the pinned 2.1.197.
  • Confirmed the jq buffering fix locally with a synthetic slow producer: without --unbuffered, 5 messages spanning 10s of real time all land within 40ms of each other (fully buffered); with it, they land ~2s apart matching real time.
  • Confirmed the Copilot GraphQL no-op directly against a real PR (taurus-cloud PR Nose Request, echoString command #833): gh pr edit --add-reviewer @copilot exited 0 twice while requested_reviewers stayed empty both times; the REST fallback separately returned 201 Created while also showing empty moments later (Copilot's actual review landed ~2h after the request).

🤖 Generated with Claude Code

henrychv and others added 2 commits September 23, 2026 12:42
…uffering

vulnerability_history.md moved from .claude/skills/prisma-taurus/ to the
repo root. Confirmed empirically (Edit, Write, and Bash-based writes all
denied identically, with the pinned CLAUDE_CODE_VERSION=2.1.197 too) that
headless/dontAsk runs are denied all write access to anything under
.claude/ - a hard, tool-agnostic guardrail no --allowed-tools/--add-dir
combination changes. Step 14's path-relative references and git add
updated to match; content unchanged (git mv, not a rewrite).

Also forces line-buffered jq output in the Jenkinsfile (--unbuffered) -
same fix as blazect-asset-catalog and taurus-cloud's equivalent
Jenkinsfiles, for the same reason: jq fully buffers stdout when piped to a
non-TTY, making VERBOSE_OUTPUT render a long wait as one silent gap
followed by a burst at the end.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
gh pr edit --add-reviewer @copilot routes through GraphQL, a confirmed
known no-op for bot logins (Copilot is a bot, not a user) - verified
directly on a real PR: it exited 0 twice while requested_reviewers stayed
empty both times. An ||-chained fallback that only calls the REST
requested_reviewers endpoint when gh "fails" therefore never reaches it,
since gh never reports failure. Now runs both unconditionally.

Also notes not to verify attachment immediately after either call: a
successful REST call can still show empty requested_reviewers moments
later, since Copilot's actual review can take far longer to start than any
short check budgets for (observed ~2h from request to submitted review on
a sibling repo's PR) - only step 16a's existing bounded poll may conclude
anything about whether Copilot reviewed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…irely

Copilot review feedback caught a real risk in the previous fix: the
unconditional gh pr edit --add-reviewer @copilot call, followed by the REST
call, still runs both as separate statements in the same script - if the
shell has set -e (or similar) active and gh genuinely fails for an
unrelated reason (auth blip, rate limit), it aborts before the REST call
ever runs. Since gh's call is a confirmed no-op for bot logins and buys
nothing once REST is called unconditionally anyway, the fix is to just
not call it at all - one command, no ordering hazard.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Copilot fallback and stale path references still require correction.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

This PR relocates vulnerability history guidance, improves Jenkins output streaming, and updates Copilot reviewer requests.

Changes:

  • Moves vulnerability_history.md to the repository root.
  • Adds unbuffered jq output to vulnerability-pipeline stages.
  • Runs the Copilot REST reviewer request independently.
File Summary
vulnerability_history.md Relocated vulnerability guidance.
Jenkinsfile-vulnerability-ai Enables unbuffered progress output.
.claude/​skills/​prisma-taurus/​SKILL.md Updates paths and reviewer instructions. Findings include fallback handling under set -e, generic REST failure messaging, and three stale Dockerfile references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .claude/skills/prisma-taurus/SKILL.md Outdated
Comment thread .claude/skills/prisma-taurus/SKILL.md
…ents

Copilot review on PR #2030 caught 3 comments (lines 162, 168, 254) still
pointing at .claude/skills/prisma-taurus/vulnerability_history.md, the
file's old location before it moved to the repo root. Checked
taurus-cloud and blazect-asset-catalog for the same pattern (their
equivalent history/notes files and any mend-fix-notes.md/mend_fixes.md
variant) - both clean, no stale references found there.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Update the REST failure message to be cause-neutral and reconcile the documentation with the direct-REST flow.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
Resolved since last review (2)

Comment thread .claude/skills/prisma-taurus/SKILL.md
@codecov

codecov Bot commented Sep 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.24%. Comparing base (17294ff) to head (6952bac).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #2030   +/-   ##
=======================================
  Coverage   88.24%   88.24%           
=======================================
  Files          75       75           
  Lines       21247    21247           
=======================================
  Hits        18748    18748           
  Misses       2499     2499           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@henrychv
henrychv merged commit 3b1edb7 into master Sep 23, 2026
4 checks passed
@henrychv
henrychv deleted the MOB-53942-fixes branch September 23, 2026 11:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants