Repository navigation
chore: close AI-readiness gaps (AGENTS.md, CI checks, hermetic specs, RuboCop) - #29
Bhargavi Kamble (bhargavikamblepattern) wants to merge 9 commits into
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ense scan in Static Checks Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kill Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
| crack (1.0.1) | ||
| bigdecimal | ||
| rexml | ||
| diff-lcs (1.6.2) |
There was a problem hiding this comment.
Code library with Restrictive license
More Details
Code library diff-lcs version 1.6.2 has GPL-2.0-or-later license, categorized as Restrictive, its use may cause a supply chain licensing issue.
Remediation guidance
- Review the license terms to understand its specific rules.
- If needed, Replace this component immediately with an alternative using a permissive license (e.g., MIT, Apache 2.0).
- Consult your legal team if the component is business-critical or the terms are unclear.
To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason
If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).
To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Agent documentation contains incorrect HTTP and exception-hierarchy guidance, and the RuboCop baseline contradicts the stated exclude-only configuration.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Adds AI-readiness documentation, reproducible tooling, CI checks, and hermetic tests without changing runtime behavior.
Changes:
- Adds agent guidance, ADRs, release documentation, and changelog history.
- Introduces RuboCop, pre-commit, locked tooling, and PR workflows.
- Separates hermetic unit tests from opt-in live API tests.
| File | Description |
|---|---|
.agents/pattern-agents.json |
Adds agent dispatch metadata. |
.claude/skills/change-and-verify/SKILL.md |
Documents Ruby change and release flow. |
.claude/skills/change-github-workflows/SKILL.md |
Documents workflow-change guidance. |
.devcontainer/devcontainer.json |
Adds a Ruby development container. |
.github/CODEOWNERS |
Routes repository reviews. |
.github/workflows/ci.yml |
Removes trailing whitespace. |
.github/workflows/pr-hygiene.yml |
Validates PR titles. |
.github/workflows/static-checks.yml |
Runs linting, tests, and license scanning. |
.gitignore |
Tracks the lockfile and ignores outputs. |
.pre-commit-config.yaml |
Adds hygiene and RuboCop hooks. |
.rubocop.yml |
Configures Ruby linting and metrics. |
.rubocop_todo.yml |
Baselines existing offenses. |
.ruby-version |
Pins Ruby 2.7.8. |
.tool-versions |
Pins Ruby for tool managers. |
.trivyignore.yaml |
Documents the diff-lcs license exception. |
AGENTS.md |
Adds repository guidance. |
CHANGELOG.md |
Reconstructs release history. |
CLAUDE.md |
Links Claude guidance to AGENTS.md. |
Gemfile.lock |
Locks development dependencies and platforms. |
Makefile |
Adds setup, lint, and test commands. |
blurb.gemspec |
Adds test and lint dependencies. |
docs/adr/0000-template.md |
Adds an ADR template. |
docs/adr/0001-record-architecture-decisions.md |
Establishes ADR usage. |
docs/adr/0002-single-request-path-with-key-case-conversion.md |
Documents request behavior. |
docs/adr/0003-campaign-type-codes-in-resource-urls.md |
Documents campaign URL construction. |
docs/adr/README.md |
Indexes ADRs. |
docs/runbooks/README.md |
Indexes runbooks. |
docs/runbooks/release-gem.md |
Documents gem releases. |
lib/blurb/base_class.rb |
Applies whitespace formatting. |
lib/blurb/errors/request_throttled.rb |
Applies whitespace formatting. |
lib/blurb/request.rb |
Applies whitespace formatting. |
spec/blurb/product_ad_requests_spec.rb |
Removes trailing whitespace. |
spec/fixtures/create_response.json |
Adds a create-response fixture. |
spec/fixtures/error_bad_request.json |
Adds a bad-request fixture. |
spec/fixtures/error_invalid_report.json |
Adds a report-error fixture. |
spec/fixtures/error_throttled.json |
Adds a throttling fixture. |
spec/fixtures/profiles.json |
Adds profile fixtures. |
spec/fixtures/sp_campaigns.json |
Adds campaign fixtures. |
spec/fixtures/token.json |
Adds a fake OAuth fixture. |
spec/spec_helper.rb |
Separates hermetic and live suites. |
spec/support/fixtures.rb |
Adds fixture loading support. |
spec/unit/account_spec.rb |
Tests OAuth and profile behavior. |
spec/unit/request_collection_spec.rb |
Tests URL and bulk-request behavior. |
spec/unit/request_spec.rb |
Tests request conversion and errors. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| Style/RaiseArgs: | ||
| EnforcedStyle: compact | ||
|
|
| # Changing code in blurb | ||
|
|
||
| 1. Read `AGENTS.md` (layout, what must not change) and `docs/adr/` before touching `lib/blurb/request.rb`, `lib/blurb/base_class.rb` or `lib/blurb/request_collection*.rb`. | ||
| 2. Make the change. Every HTTP call goes through `Blurb::Request` (ADR 0002); don't call `RestClient` elsewhere. |
| - `lib/blurb/request.rb` — the single HTTP path (`rest-client`). Camel-cases request keys, snake-cases response keys, maps HTTP errors to `lib/blurb/errors/*`. See `docs/adr/0002-*`. | ||
| - `lib/blurb/request_collection*.rb` — generic list/retrieve/create/update/delete over a resource URL; `RequestCollectionWithCampaignType` adds the `sp`/`hsa`/`sd` path segment. See `docs/adr/0003-*`. | ||
| - `lib/blurb/*_requests.rb` — endpoint-specific collections (reports, snapshots, history, suggested keywords). | ||
| - `lib/blurb/errors/` — `FailedRequest`, `RequestThrottled`, `InvalidReportRequest` (all inherit `BaseException`). |
| `lib/blurb/request.rb` is the only code that talks HTTP: | ||
|
|
||
| - Request payloads and query params are camel-cased (`camelcase_keys`), except keys that are already all upper case, which pass through. `Date`/`Time`/`ActiveSupport::TimeWithZone` values are formatted as `YYYYMMDD`. | ||
| - Responses are JSON-parsed and every key becomes a snake_case **symbol** (`underscore_keys`). | ||
| - `429` raises `Blurb::RequestThrottled`; `406` on a report URL raises `Blurb::InvalidReportRequest`; any other error response raises `Blurb::FailedRequest` with the parsed body. A `307` is followed with a plain `GET` and returned **unparsed** — that is how report and snapshot downloads work. | ||
| - `GET` requests set `max_redirects: 0` so the `307` reaches the rescue above. | ||
|
|
||
| `RequestCollection`, `Account` and the `*_requests.rb` classes only build URLs, headers and payloads and call `Request#make_request`. |
The gem failed to load outside Rails with ActiveSupport >= 7.1 (core_ext loaded before active_support) and Request#make_request called present? without requiring object/blank. The spec helper worked around both; the requires now live in lib/blurb/request.rb and the workaround is gone. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Pins the exact JSON body sent for sp/hsa/sd report creates and history retrieve under spec/fixtures/golden/ (UPDATE_GOLDEN=1 regenerates). Raises the SimpleCov gate to 82% (current 82.66%). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sig/blurb.rbs types Blurb, Account, Profile, the request collections and error classes; sig/vendor.rbs stubs rest-client, oauth2 and ActiveSupport. steep check runs as a pre-commit hook (so in make lint and Static Checks) and as make typecheck. lib/ only gains '# @type var' comments and one whitespace fix; no runtime change. The positional-hash call in RequestCollection#execute_bulk_request is reported as information, not an error, pending a Ruby 3 follow-up. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>


Summary
Raises blurb's AI-readiness score (ClickUp SRE-3689, INFRA batch 5/13) by closing gaps from
docs/engineering-best-practices-audit.md. This PR adds tooling, docs and tests. The only runtime change is a require-only fix in its ownfix:commit (see below); otherwiselib/gains whitespace fixes and# @typecomments, and the gem's runtime dependencies and the existing.github/workflows/ci.ymlare untouched (apart from a whitespace-only formatter fix). It leavesREADME.mdalone so it doesn't conflict with #26..claude/skills/change-and-verify(Ruby change/verify/release flow) andchange-github-workflowsAGENTS.md(layout, commands, do-not-touch);CLAUDE.mdis a symlink to itdocs/adr/0002(single request path: key casing and error mapping),0003(campaign-type URL codes, no/v2for SD). Both are Proposed — owner to confirmdocs/runbooks/release-gem.md(the audit's one recurring task)CHANGELOG.md, rebuilt from tags v0.5.2–v0.5.9 plus a note on upgrading to 0.2.0* @patterninc/sre(backstageOwner: sre-comm).rubocop.yml, metrics cops on). Existing offenses are listed by file in.rubocop_todo.yml(exclude-only, no raisedMax), so new code has to meet the defaultssig/blurb.rbs(+sig/vendor.rbsstubs), checked by Steep 1.4 (Steepfile) as a pre-commit hook, so inmake lintand Static Checks;make typecheck.pre-commit-config.yaml(hygiene hooks, RuboCop, Conventional Commits on commit-msg);PR Hygienechecks PR titlesStatic ChecksandPR HygienePR workflows. Making them required is a separate admin step, not done here (see below).trivyignore.yaml: diff-lcs, a dev-only gem that is also MIT-licensedspec/unit/has 19 hermetic specs using WebMock stubs and JSON fixtures inspec/fixtures/. They pin request/response key casing, error mapping, 307 report download, URL shapes and bulk splittingspec/unit/golden_payloads_spec.rbpins the exact JSON body of sp/hsa/sd report creates and history retrieve againstspec/fixtures/golden/(UPDATE_GOLDEN=1regenerates)spec/blurb/are tagged:liveand left out of the default run;make test-live(BLURB_LIVE=1) runs themmake testwritesrspec-junit.xml, uploaded by Static Checks.ruby-version/.tool-versionsset to Ruby 2.7.8;.devcontainer/Makefile:bootstrap,fmt,lint,test,test-live,allGemfile.lockis now committed (removed from.gitignore), locked for linux and darwin on x86_64 and arm64.agents/pattern-agents.jsonDev-only additions to
blurb.gemspec:webmock ~> 3.18,simplecov ~> 0.22,rubocop ~> 1.50.2,steep ~> 1.4.0.Runtime fix (own commit)
fix: require active_support and object/blank in request.rb: the gem failed to load outside Rails with ActiveSupport >= 7.1 (core_extloaded beforeactive_support), andRequest#make_requestcalledpresent?without requiringobject/blank. Both requires now live inlib/blurb/request.rband the workaround inspec/spec_helper.rbis gone. No effect where Rails has already loaded them.Verification
make allpasses locally: every pre-commit hook including RuboCop and Steep, then 24 examples with 0 failures and 82.66% coverage.gauge-repo audit (
docs/engineering-best-practices-audit.md, re-run on this branch):master(before)Remaining: 16 Partial (make the checks required), 49 Partial (
clickup_list_id), 30 Gap (mutation testing, blocked on Ruby 3), 43 Gap (logging, runtime change).check.sh: before, 2 Met / 1 Partial / 10 Gap / 5 N/A; after, 12 Met / 1 Partial (16, an admin setting) / 0 Gap / 5 N/A. Its N/A rows 10, 11, 23 and 48 appear because the script doesn't detect Ruby; the audit counts them, and this PR addresses them.Defaults used
.agents/pattern-agents.json:datadog.service=blurb,datadog.env=productionare the script's defaults. This gem has no runtime of its own, so the owner may want to drop them.clickup_list_idis not set.ci.ymlstill pins 2.7.2.#sre-comm, from backstageOwner.Follow-ups (not done here; they change behaviour or existing workflows)
RequestCollection#execute_bulk_requestcallsexecute_request(execute_request_params)with a positional hash; Ruby 3 raisesArgumentError. Fix with**execute_request_params, then remove the two downgraded diagnostics inSteepfile.SnapshotRequests#downloadbuildsheaders = @headers.dup["Content-Encoding"] = "gzip"and then sends@headers, so the gzip header is never sent.mutantneeds Ruby >= 3.0; the last 2.7-compatible release (0.11.25) needsparser ~> 3.2.2, which conflicts with RuboCop 1.50. Addmutant-rspecafter the Ruby 3 move.FailedRequest,RequestThrottledandInvalidReportRequestinherit fromStandardError, notBlurb::BaseException, even though the 0.5.4 commit says they should.activesupportdependency (audit item 48). Left out because it changes consumers' dependency resolution.puts-basedloginlib/blurb/request.rbwith an injectableLogger..github/workflows/ci.ymlruns on every push, installs gems only, and passes unrelatedRUBY_GEM_BUNDLE_TOKEN/SIDEKIQ_ENTERPRISE_TOKENsecrets. Delete it, or align it to.ruby-version, now that Static Checks runs the suite. Delete the stale.travis.ymltoo.README.md: the TravisCI badge,iserve-productslinks and the.envvariable names in "Development" are stale (the code readsBLURB_*). Left alone to avoid conflicting with Update README.md #26. The gemspechomepageis stale as well..rubocop_todo.ymlin small PRs (about 860 existing offenses, about 816 auto-correctable).ai-readiness-branch-rulesruleset (the dry run is ready) to requireStatic ChecksandPR Hygieneonmaster.Open questions for the owner
clickup_list_idin.agents/pattern-agents.json)?@patterninc/sreright for backstage ownersre-comm?🤖 Generated with Claude Code