docs(#6578): add vendored dependency checklist - #7267
shairevivo wants to merge 6 commits into
Conversation
Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Shai Revivo <srevivo@redhat.com>
E2E tests did not runE2E tests run automatically for org/repo members and collaborators on pull requests. For other contributors, a maintainer must add the See E2E testing guide for details. |
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can start a comment with 'qodo' or '@qodo' to chat about any finding |
PR Summary by QodoDocument sandbox vendored dependency verification checklist
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Site previewPreview: https://ccb99fee-site.fullsend-ai.workers.dev Commit: |
|
/fs-review |
|
🤖 Finished Review · ✅ Success · Started 8:53 AM UTC · Completed 9:09 AM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $3.25 |
|
Risk Assessment: moderate (2/5) DetailsAnchored to the prior score of 2 (moderate): Tier 1 signals are unchanged from the prior run (single-file, ~16-line docs-only diff, no protected/security/CI/dependency touches, non-bot non-first-time author); Tier 2 reconfirms this doc is a known high-churn, fix/revert-heavy hotspot already priced into the prior score, while Tier 3 shows the PR scope cleanly matches its linked issue with no risk labels, weighting the composite down to a rounded 2 (moderate). Previous runRisk Assessment: moderate (2/5) DetailsScore unchanged from the prior review (2/moderate): independent re-verification confirms Tier 1 signals are identical (single-file, 16-line docs-only diff, no protected/security/CI/dependency touches, non-bot author) and the file under review is byte-identical to the prior-reviewed revision — the only intervening commits are an unrelated main merge (ADR 0106/coalescing docs from PR #6909). Tier 2 reconfirms the same known high-churn, fix/revert-heavy documentation hotspot already priced into the prior score, with no new risk signal introduced. Previous run (2)Risk Assessment: moderate (2/5) DetailsScore unchanged from the prior review (2/moderate): Tier 1 signals are identical in shape (single-file, 16-line docs-only diff, no protected/security/CI/dependency touches, returning non-bot author), and Tier 2 confirms the same high-churn/fix-revert documentation hotspot already reflected in the prior score, with the amendment being a minor wording/placement refinement to the same file rather than a scope or risk-signal change. Previous run (3)Risk Assessment: moderate (2/5) DetailsSmall (1 file, 15 lines), docs-only, additive checklist addition by a returning contributor that closely satisfies its linked, unlabeled issue, with no protected/security/CI/dependency touches; the only elevating signal is that the target file is a high-churn documentation hotspot, nudging the score from low to moderate. |
|
Looks good to me Previous runReviewFindingsLow
Previous run (2)ReviewRe-review: both prior findings (imprecise FindingsLow
Info
Next steps:
Previous run (3)ReviewFindingsLow
Next steps:
|
Keep the pin table adjacent to its lead-in and document permission modes. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Shai Revivo <srevivo@redhat.com>
|
🤖 Finished Review · ✅ Success · Started 3:28 AM UTC · Completed 3:41 AM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $2.47 |
|
🤖 Finished Review · ✅ Success · Started 8:16 AM UTC · Completed 8:30 AM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $2.22 |
Superseded by updated review
|
🤖 Finished Review · ✅ Success · Started 9:10 PM UTC · Completed 9:21 PM UTC Commit: Runtime: pi · Model: sonnet → claude-sonnet-5 · Effort: high · Cost: $2.10 |
Superseded by updated review
Summary
Adds a contributor-facing checklist for adding or bumping sandbox-vendored dependencies. It consolidates the auth, artifact integrity, supply-chain, permissions, environment, egress, and runtime evidence that #6572 established after an OAuth-based extension failed in a fresh sandbox.
Closes #6578
Validation
make lint(staged documentation change)make lint-md-linksVendored-dependency checklist evidence
This PR changes documentation only; no dependency is added or bumped.
The checklist's requirement to record each applicable item as
verified,blocked, ornot applicabledeliberately operationalizes #6578's validation criteria: future vendoring PRs should reference the checklist and flag anything they cannot verify. This PR keeps that evidence requirement in the contributor runtime guide; it does not add broader PR-template or repository-wide enforcement.Re-review changes: required evidence