Gate Babysitter catalog activation on deployed dependencies - #119
Conversation
Session-Id: 01a0d4a0-59f8-7c60-8d5d-59261379b03c
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Devin Review found 2 potential issues.
1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7a9ea53150
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0d4a0-59f8-7c60-8d5d-59261379b03c
|
Preview deployed!
This is a Cloudflare Workers preview version of this PR's build. |
There was a problem hiding this comment.
All reported issues were addressed
You’re at about 99% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 12 files
You’re at about 99% of the monthly reviewed-line limit. You may want to disable incremental reviews to conserve quota. Reviews will continue until that limit is exceeded. If you need help avoiding interruptions, please contact contact@cubic.dev.
Requires human review: Auto-approval blocked because this review re-detected 2 unresolved issues already reported by Cubic.
Re-trigger cubic
|
@codex review |
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Session-Id: 01a0d616-0dc2-71c1-97ca-cb5beaa61ccc
|
@codex review Please review exact head This revision addresses all eight open threads: exact evidence keys and string types in runtime and CI, code-owned dependency ID/repository binding, direct null-evidence and complete install-URL assertions, data-driven blocked copy, docs punctuation, and live immutable artifact verification. Independent authenticated GitHub contents and git checks confirm Activation remains blocked, both evidence records remain null, and no install link is emitted. No merge or deployment performed. |
|
To use Codex here, create a Codex account and connect to github. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 123eb7e64d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0d616-0dc2-71c1-97ca-cb5beaa61ccc
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 62e38a4e2c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0d616-0dc2-71c1-97ca-cb5beaa61ccc
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d9c6d7fcae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0d616-0dc2-71c1-97ca-cb5beaa61ccc
|
@codex review |
|
@cursor review |
|
To use Codex here, create a Codex account and connect to github. |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit c6ba28c. Configure here.
kjgbot
left a comment
There was a problem hiding this comment.
Independent exact-head review: GO at c6ba28c. Every recommended extension is now matched to a supported plugin contract and validated for base compatibility, artifact coordinates, runtime provenance, activation parity, and deployment evidence. Unsupported, duplicate, malformed, or drifted entries fail closed. Exact-head CI and preview are terminal green; targeted catalog/receipt tests pass 21/21 and verify:recommended-flows passes.
Summary
@relayflows/sdk2.0.31 runtime provenance to Software Garden as metadata onlyCurrent rollout state
The entry is intentionally
blocked. Both dependency evidence values arenullbecause neither dependency is merged and deployed. This PR does not publish, deploy, or enable Babysitter.Cloud additionally validates server-owned rollout state for both dependency IDs, so catalog evidence alone cannot activate the extension.
Verification
npm --workspaces run test -- --testTimeout=30000 --maxWorkers=2— 31 web files / 302 tests and 5 router files / 72 tests passed; defaultnpm testhit the 5-second timeout in existing shell/git tests on this hostnpx tsc --noEmit— web and router passednpm run verify:recommended-flows— deterministic gate validation passed; Software Garden v2.0.26 source ref/digest and the actual Babysitter artifact directory, payload digest, and manifest hash verifiednpm run build— Next.js 16.3.5 production build passed, including TypeScript and 459 static pagesv2.0.31audit —extensions/babysitteris byte-identical to reviewed ref8b33ebab8347514f80d9da5a81206a087f641714Dependencies
cloud-babysitter-capability-adapter: not yet merged/deployedrelay-native-existing-session-delivery: not yet merged/deployedNote
Medium Risk
Changes public catalog JSON (v3), API responses, and install URLs for a first-party plugin; incorrect gate logic could block legitimate installs or accept bad evidence, though Babysitter remains blocked and server-side Cloud authorization is still required.
Overview
Babysitter is promoted to catalog v3 as pinned metadata only until two named runtime dependencies (Cloud capability adapter and Relay native existing-session delivery) each carry merge-and-deploy evidence. Both the flow-plugin and recommended-flow catalogs gain
runtimeandactivationfields; Babysitter staysblockedwithevidence: nullin this PR, so nothing is enabled yet.Install surfaces are fail-closed:
flowPluginInstallHref()now requiresflowPluginIsActivatable()(gateready, full dependency set, shaped evidence, and PR URLs bound to code-owned implementations Cloud #3989 and Relay #1851). The plugin gallery hides install/badge controls and shows blocked dependency IDs; docs and page metadata describe catalog/release status instead of open install.CI gains
verify:catalog-gates(wired before existing recommended-flow verification), plusverify-deployment-receipts(live GitHub PR + production deployment receipts forreadyentries) andverify-plugin-artifacts(immutable commit directory + digest/manifest checks). Cross-catalog drift between Software Gardenextensions[]and the plugin catalog is validated in script and tests.Reviewed by Cursor Bugbot for commit c6ba28c. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Gates Babysitter's catalog entry on merge-and-deployment evidence for its two runtime dependencies. Previously the gallery advertised an install badge; now the entry is inert catalog metadata, and
flowPluginInstallHref()returnsnulluntil both dependencies carry valid merge and deployment proof. The entry staysblocked— neither dependency is merged or deployed — so Babysitter cannot be installed or activated.Activation gate
@relayflows/sdk2.0.31 runtime provenance.verify-catalog-gates, a deterministic validator covering evidence shape, every recommended-flow extension contract, cross-catalog drift, and the invariant thatreadyrequires both dependencies proven.pullRequestUrlto a code-owned implementation PR (Cloud #3989, Relay #1851); a replacement implementation requires a code change, not a catalog edit.mainwith a matching commit and timestamp, the deployment must targetproductionat that commit, and its latest status must besuccess.Artifact verification
verify-plugin-artifacts, which fetches the pinned commit, enumerates the artifact directory, and hashes every file to confirm the digest and manifest checksum.verify:recommended-flowsand covers it with ordering, tampering, and manifest tests.Written for commit c6ba28c. Summary will update on new commits.