fix(docs): send scopes with the flag the CLI documents - #12455
Conversation
|
This pull request is part of a Mergify stack:
|
Merge Protections🟢 All 7 merge protections satisfied — ready to merge. Show 7 satisfied protections🟢 ⛓️ Depends-On RequirementsRequirement based on the presence of
🟢 🤖 Continuous Integration
🟢 👀 Review Requirements
🟢 Enforce conventional commitMake sure that we follow https://www.conventionalcommits.org/en/v1.0.0/
🟢 🔎 Reviews
🟢 📕 PR description
🟢 🚦 Auto-queueWhen all merge protections are satisfied, this pull request will be queued automatically. |
|
Two notes that belong with this stack rather than in either commit. The One thing I found on the way is out of scope here and is not filed as an issue. The four judgment proofreaders only ever review changed lines, so an old violation survives indefinitely — which is exactly why the em dash in that |
There was a problem hiding this comment.
Pull request overview
Updates the shared “Any CI (Mergify CLI)” snippet used by the monorepo scopes docs pages so it matches the current CLI contract (no deprecated flags) and uses a stable, script-friendly output format for git refs.
Changes:
- Switch
mergify ci scopes-sendfrom deprecated--fileto--scopes-json. - Parse base/head refs from
mergify ci git-refs --format jsonviajqinstead of scraping the humantextoutput. - Document the rationale for
--scopes-jsonvs--scopes-fileand for preferring--format json.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
`pnpm check:internal-leaks` only ever saw a ticket as a *link*: its `internal-tracker` rule matches tracker hosts. A bare issue key in prose, in a code block or in an example value passed cleanly — and one did. The `mergify tests quarantines add` example on the quarantine page shipped with a `--reason` string naming an internal ticket, so it has been live on docs.mergify.com since #11681 and sits in this repository's public history. The scan reported that exact file clean, before and after. A bare key is also the case a reviewer is least likely to stop on: inside an example value it reads as a plausible sample rather than as a leak. What changed: - A `ticket-ref` rule for bare issue keys — the two live prefixes, plus the lowercase form a branch name carries. - Prefixes are listed explicitly instead of matching a generic `[A-Z]{3,}-\d+`. The generic shape fires on `AES-256`, `WCAG-2` and on a reader's own issue keys in a sample config, and that cost lands on every docs contributor; the miss cost of an explicit list falls only on a prefix somebody introduces deliberately, which is a deliberate act. - The allow directive now accepts several rule ids. One line can trip two rules — a tracker URL carries the key inside it — and such a line previously could not be allowed at all. - The corpus is swept: across the 143 scanned pages that example was the only occurrence. Its reason string is now "flaky under load, fix in progress", the same wording #12411 uses for the same line, so the two changes do not fight. That also removes the prose em dash the example carried inside a CLI string. - `AGENTS.md` and the `proofread-leaks` skill now list bare keys as well. The judgment layer had the same blind spot as the regex, which is why the line survived review too. Verified: the scan exits 1 against the pre-fix file and 0 against the tree, the full `pnpm test` suite and `pnpm check` are green, and the commit is green on its own as well as on top of the stack. One decision is deliberately left open: whether the already-published value needs scrubbing beyond this branch. It is a ticket prefix rather than a credential, and it is in the git history of a public repository as well as on the site, so removing it from the page is all this change claims to do. Reported as Mergifyio/ci-bot#368. MRGFY-8721 Change-Id: I847b80676f560fb73f319e2524be6d94207591e8
The "Any CI (Mergify CLI)" block on the four monorepo scopes pages ends in
`mergify ci scopes-send --file scopes.json`. `--file` is a deprecated alias, kept
hidden from `--help` and from `public/cli-schema.json` since the CLI was ported
to Rust: it still works, and prints `Warning: --file is deprecated, use
--scopes-json instead.` on every run. So a reader copying the block gets a
deprecation warning for a flag they cannot look up.
`--scopes-json` is the right one, not `--scopes-file`: it reads the
`{"scopes": [...]}` object, which is exactly the shape every page's `jq` filter
writes, while `--scopes-file` expects one scope per line. Confirmed against the
CLI's own reader — it deserializes `scopes` plus an optional `all_scopes`, so the
examples need no change, and `--all` documented on the scopes page stays
consistent with it.
While in the block, the base and head refs now come from `--format json` piped
through `jq` instead of `awk '/^Base:/ {print $2}'` on the default output. The
text format is the human one with no stability promise; `json` and `shell` are
the two contracts meant for scripts. `jq` is already required by all four pages,
so this adds no dependency, and the variables the pages interpolate (`$BASE`,
`$HEAD`) are unchanged.
Checked the rest of the corpus: no other page repeats `--file`, and the scopes
page already documents `--scopes-json`. Nothing outside this repository generates
the snippet — the dashboard and the engine never emit this command.
Reported as Mergifyio/ci-bot#371.
MRGFY-8721
Change-Id: I7691b7156a88b4c43487a2b41f61216c92b5a6a5
ccec4b4 to
f67a34b
Compare
Revision history
|
|
Re-pushed to address the review thread on What changed: the two jq filters in the shared snippet are now single-quoted, and the JSON is piped with
The base #12454 also has a new head ( Both PRs are green and the stack has no open threads. |
Merge Queue Status
This pull request spent 3 minutes 34 seconds in the queue, including 2 minutes 42 seconds running CI. Required conditions to merge
|
The "Any CI (Mergify CLI)" block on the four monorepo scopes pages ends in
mergify ci scopes-send --file scopes.json.--fileis a deprecated alias, kepthidden from
--helpand frompublic/cli-schema.jsonsince the CLI was portedto Rust: it still works, and prints
Warning: --file is deprecated, use --scopes-json instead.on every run. So a reader copying the block gets adeprecation warning for a flag they cannot look up.
--scopes-jsonis the right one, not--scopes-file: it reads the{"scopes": [...]}object, which is exactly the shape every page'sjqfilterwrites, while
--scopes-fileexpects one scope per line. Confirmed against theCLI's own reader — it deserializes
scopesplus an optionalall_scopes, so theexamples need no change, and
--alldocumented on the scopes page staysconsistent with it.
While in the block, the base and head refs now come from
--format jsonpipedthrough
jqinstead ofawk '/^Base:/ {print $2}'on the default output. Thetext format is the human one with no stability promise;
jsonandshellarethe two contracts meant for scripts.
jqis already required by all four pages,so this adds no dependency, and the variables the pages interpolate (
$BASE,$HEAD) are unchanged.Checked the rest of the corpus: no other page repeats
--file, and the scopespage already documents
--scopes-json. Nothing outside this repository generatesthe snippet — the dashboard and the engine never emit this command.
Reported as Mergifyio/ci-bot#371.
MRGFY-8721
Depends-On: #12454