Skip to content

Store app: disclose llm listings before install - #233

Merged
HereLiesAz merged 2 commits into
mainfrom
claude/amazing-fermi-3o92qn-cmp-llm
Sep 27, 2026
Merged

HereLiesAz merged 2 commits into
mainfrom
claude/amazing-fermi-3o92qn-cmp-llm

Conversation

@HereLiesAz

@HereLiesAz HereLiesAz commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

This brings the web store's llm disclosure (#232) to the Compose store app, storefront-cmp.

  • models/PackageSummary.kt: PackageSummary gains llm: LlmDto?. It's parsed from the block /api/packages already serves.

  • models/LlmDisclosure.kt: llmDisclosureLines builds the key/value lines that spec/llm.md § Discovery requires before install:

    • where the model runs and where prompts go;
    • data handling, operator, and whether the model can change without notice;
    • the model;
    • the weights' licence and download size;
    • what the runner needs;
    • the setup token's permissions.

    A prompts value it doesn't recognise reads as "unknown", never as safe.

  • components/LlmDisclosure.kt: shows those lines as a "Before you install" record on the detail screen, with an "Operator terms" link. The header also gets a tier pill.

  • components/Cascade.kt: catalogue entries end in "hosted llm" or "sandbox llm" instead of just "llm".

Verification

  • The new LlmDisclosureTest passes 4/4, covering endpoint, sandbox-weights, unknown handling and non-llm listings.
  • ./gradlew desktopTest compileKotlinDesktop passes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv


Generated by Claude Code

Summary by Sourcery

Expose the required LLM discovery information before installation in the Compose store.

New Features:

  • Add LLM listing support to the Compose store with pre-install disclosures covering hosting, prompt handling, model details, licensing, requirements, and setup permissions.

Enhancements:

  • Differentiate hosted and sandbox LLM listings in catalogue cards and detail headers.
  • Parse LLM metadata from package summaries and present operator terms alongside the disclosure.
  • Treat unrecognised prompt-handling values as unknown rather than safe.

Tests:

  • Add coverage for hosted and sandbox disclosures, unknown prompt handling, and non-LLM listings.

Parses the llm block from /api/packages, labels catalogue entries by
tier, and shows the spec/llm.md pre-install record on the detail screen.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QwYWVPse8spRrfMMcuTJPv
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
azphalt Error Error Sep 27, 2026 10:20pm UTC

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Reviewer's Guide

The Compose store now parses LLM metadata from package listings, presents tier-specific catalogue labels and a spec-aligned “Before you install” disclosure on detail pages, and verifies the formatting and unknown prompt-handling behavior with focused tests.

Sequence diagram for LLM listing disclosure before install

sequenceDiagram
    participant API as Package API
    participant Store as Compose Store
    participant Detail as Detail Screen
    participant User

    Store->>API: GET /api/packages
    API-->>Store: PackageSummary with LlmDto
    User->>Store: Open LLM listing
    Store->>Detail: Render tierLabel and LlmDisclosure
    Detail->>Detail: llmDisclosureLines(llm)
    Detail-->>User: Before you install record
    User->>Detail: Select Operator terms
    Detail->>Detail: openExternal(terms)
Loading

Flow diagram for LLM disclosure rendering

flowchart TD
    A[Package listing received] --> B{llm block present?}
    B -- No --> C[Render standard listing]
    B -- Yes --> D[Use tierLabel: hosted llm or sandbox llm]
    D --> E[Render Before you install]
    E --> F["llmDisclosureLines(llm)"]
    F --> G[Show runs, prompts, model, licence, size, runner needs, and setup token]
    G --> H{Operator terms present?}
    H -- Yes --> I[Show Operator terms link]
    H -- No --> J[Show disclosure without terms link]
Loading

File-Level Changes

Change Details Files
Added typed LLM metadata parsing and disclosure formatting for pre-install review.
  • Parse tier, setup token requirements, endpoint, weights, requirements, licensing, and data-handling fields from package summaries.
  • Generate testable key/value disclosure lines covering execution location, prompt handling, operator/model information, licensing, size, runner requirements, and token permissions.
  • Treat unrecognized prompt-handling values as unknown rather than safe.
apps/storefront-cmp/src/commonMain/kotlin/models/PackageSummary.kt
apps/storefront-cmp/src/commonMain/kotlin/models/LlmDisclosure.kt
apps/storefront-cmp/src/desktopTest/kotlin/models/LlmDisclosureTest.kt
Integrated LLM disclosures and tier identification into catalogue and detail-screen UI.
  • Show hosted or sandbox LLM labels in catalogue entry pills and detail headers.
  • Render a Before you install record with operator terms and setup context for LLM listings.
  • Leave non-LLM listings unchanged.
apps/storefront-cmp/src/commonMain/kotlin/components/Cascade.kt
apps/storefront-cmp/src/commonMain/kotlin/components/DetailScreen.kt
apps/storefront-cmp/src/commonMain/kotlin/components/LlmDisclosure.kt
Documented the storefront package behavior change.
  • Added a minor changeset describing LLM tier labels and pre-install disclosures.
.changeset/cmp-llm-disclosure.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@cloudflare-workers-and-pages

Copy link
Copy Markdown

🚀 Deploying Preview to Cloudflare 🚀

Preview Deployments by commit

Status Deployment URL Commit Updated (UTC) See this deployment's details
  • Build: Failed ❌

View logs ↗
422f607 2026-09-27T21:25:13.812Z View logs ↗

@HereLiesAz

Copy link
Copy Markdown
Owner Author

OpenCode security review

⚠️ Review unavailable. Neither model answered; see the shared workflow run. This is not a finding about the pull request.

Copy link
Copy Markdown
Owner Author

No validate_* test actually ran on this head. Every one of those checks reports cancelled: the shared CI run was triggered twice for the same commit (once for the push, once for the PR) and the second run cancelled the first. HereLiesAz/workflows#87, now merged, stops that, but only for runs started after it. I can't re-run from here (403), so the next push to this branch, or Re-run failed jobs in the Actions tab, will give a real result.

The other red checks aren't from this PR either: Vercel (a leftover project), Workers Builds (the Cloudflare preview), and github-advanced-security (Copilot). The OpenCode review reports "unavailable" because GEMINI_API_KEY isn't set.

Locally, ./gradlew desktopTest compileKotlinDesktop passes, including the 4 new LlmDisclosureTest cases.


Generated by Claude Code

@HereLiesAz
HereLiesAz marked this pull request as ready for review September 27, 2026 22:19

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @HereLiesAz, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 23 hours and 7 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@HereLiesAz
HereLiesAz merged commit 2933f77 into main Sep 27, 2026
1 of 2 checks passed
@HereLiesAz
HereLiesAz deleted the claude/amazing-fermi-3o92qn-cmp-llm branch September 27, 2026 22:19

This branch had an error being deployed

1 failed deployment
Preview — 66fd3625 Deployed Sep 27, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants