docs: point the README at the code for required variables and collaborators #32
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/readme-set-pointers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The README listed two sets a second time: the forge and runner variables required on every path, and the collaborators
src/main.tshands the orchestrator. Each list now names the code that defines it.forgeCredentialsinsrc/credentials.ts,readWrapperInputsinsrc/wrapper/event-context.tsandsrc/main.ts, which read them before the fork gate. The environment table above the paragraph stays.WrapperDepsinsrc/contract/types.ts.This addresses review comment 122213 on #30 and the review's unadjudicated claim
01M44BTESXJKH5PCCHGSW3K4W5("README duplicates the required environment-variable set").Stacked on #30.
🤖 Generated with Claude Code
Review
01M45PCTE20F1BP8DW7MH3EAHG— headbc6feebb4c323e5de12f497db1b545598f82263aReview — j4k-oss/review-wrapper @
f5714bee59Scope: diff against base tree
211444be4c6dStatus: dispatched — coverage complete (5/5 slots terminal)
Facts: current review-wide projection
Computed under:
Findings (5)
medium — The action-input table duplicates the input manifest
01M45PKHG05A01JTKWN246515HREADME.md(snippet)01M45PRH1M2T7W5PV2GPNJAF2G· valid: The exact-grounded README table lists expected-service-origin and its behavior. The reviewer names action.yml as the runner-read source, reports that its input set contains the same sole member, and accounts for the origin-match and empty-value guidance there. This meets the restated-sets comparison requirement; agreement today leaves a separately maintained copy that can drift. Point to action.yml inputs, retaining distinct security rationale. Earlier matching claims and their rationales supply no concrete refutation; their valid verdicts are not the basis of this judgment.medium — The recovery table copies the diagnostic formatter’s message inventory
01M45PM88CFCMMRJB44VRSFMX0README.md(snippet)01M45PRH1M2T7W5PV2GPNJAF2G· valid: The exact-grounded table enumerates failure messages and recoveries. The reviewer supplies the four selected codes plus fallback in src/wrapper/remedies.ts, their corresponding display labels in committed dist/index.mjs, and reports that the job diagnostic emits the matching recovery. No case differs today, so this is a medium copied-set defect. The unavailable standalone j4k/review source does not leave an essential comparison missing: the reported shipped bundle provides the labels, and the local map defines the selected remedies. Point to the diagnostic and formatExecutionRecovery, preserving the subsequent retry distinction. Earlier accounts lacking dependency strings do not refute this current comparison.medium — The fork-gate explanation wrongly promises that no credential function runs before it
01M45PMWXHPY2VRZ1SRGRVV283README.md(snippet)01M45PRH1M2T7W5PV2GPNJAF2G· valid: The exact-grounded sentence promises that the fork gate precedes any call to the credentials module. The concrete reported trace instead has main.ts call forgeCredentials from that module before readWrapperInputs and runWrapper, while reviewCredentials is deferred through openSession until after the fork branch. The composition claim also grounds the entry point's credential-read role. The static import-isolation check does not prohibit the earlier forgeCredentials call, so it cannot rescue the broad wording. Specify reviewCredentials while preserving the capability-token isolation guarantee. Earlier matching claims contain no concrete refutation; this is a documentation precision defect, not evidence that the capability token leaks.medium — The security model copies counts of credential readers and internal imports
01M45PQCJ93QGRP4SQPB9CHW1RREADME.md(snippet)01M45PRH1M2T7W5PV2GPNJAF2G· valid: The exact-grounded security sentence copies counts of token-reading modules and internal imports. The reviewer identifies src/credentials.ts as the sole application reader and reports its node:process import and empty internal-import set, supplying both source sets and matching counts. These numbers describe inventory sizes, not a capacity argument, and naming the file does not exempt adjacent copied counts under the pointer exception. The proposed reference to reviewCredentials retains the token-flow constraint and points to the implementation where the reviewer says the isolation requirement remains. Remove the counts and use that pointer. With no present mismatch reported, medium is appropriate.low — Edited composition paragraph retains internal wiring prose in the README
01M45PMCC4EPZNY064T5AD50YFREADME.md(snippet)01M45PRH1M2T7W5PV2GPNJAF2G· valid: The exact-grounded paragraph narrates private startup wiring rather than defining a term or explaining a decision. The reviewer explicitly reports that the diff edits this paragraph and supplies the corresponding main.ts call sequence and WrapperDeps contract. Project-docs Division of labor and Consolidating stray documentation require deleting implementation narration from a touched stray passage; the README onboarding exception does not cover this private composition account. Keep any useful observable job-conclusion explanation. No contrary repository convention is evidenced. This is a low wrong-home defect.Other claims
Coverage
Coverage pass: 01M45PCTFWRATQ0C95YXRWAM8Z
Accounting: complete
Slot health: healthy
All four findings are summary-only, so I'm answering them here. Each one is about README text this PR doesn't change, so each fix targets
mainon its own.01M44DH0VFHYT6MWYWH96G8Z8Y("Security model says the fork gate precedes all credential reads") is valid.src/main.tscallsforgeCredentials(), which readsFORGEJO_TOKENandGITHUB_API_URL, before the fork gate. OnlyreviewCredentials()waits behind it. Tracked in #33, which says the gate guards only the review credentials and describes what the two tests actually check. It also covers the duplicate01M44DPZPHFRSW7SEY35PBGPJ6.01M44DMTYMV2XX9RFN5A2MCZCP(action input table) and01M44DNK5MWG0DWZ49QPQ50Q54(recovery table) are valid. Tracked in #34, which points atinputsinaction.ymland at the remedyformatExecutionRecoveryprints on the failure log line.01M44DRX5S6FCDZFDHJHVECRGJ("The introduction narrates where the HTTP contract was decided") is valid. Tracked in #35, which points the introduction at section 8 of the service'sdocs/SPEC.md. It also covers the duplicate01M44DTFZKA23QS4RKFKFE5E98.ab235f39c4bc6feebb4c@ -150,5 +150,5 @@`src/main.ts` is the only place the modules meet. It reads the forge credentials and`GITHUB_REPOSITORY`, builds the forge client, derives the run's inputs from the eventpayload, and hands the orchestrator its collaborators: the wait protocol, the clock, andthe three reconcilers (summary, inline, dispositions). The orchestrator's exit codebecomes the process exit code, so the job's conclusion follows the outcome's exit code.payload, and hands the orchestrator the collaborators that `WrapperDeps` in`src/contract/types.ts` names. The orchestrator's exit code becomes the process exitcode, so the job's conclusion follows the outcome's exit code.low — Edited composition paragraph retains internal wiring prose in the README
lens
project-docs· armdefault· tally 1 valid / 0 invalid / 0 uncertainclaim
01M45PMCC4EPZNY064T5AD50YFof review01M45PCTE20F1BP8DW7MH3EAHG