Repository navigation
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…iately Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Claude Code Review
This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.
Tip: disable this comment in your organization's Code Review settings.
✅ Deploy Preview for ohif-dev ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThis change adds a weekday and manually triggered workflow that builds a selected branch’s viewer, inventories packages in the build, and audits npm advisories. The lockfile report also gains a package-version changes table. ChangesDependency audit
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Workflow as GitHub Actions workflow
participant Build as Rsbuild viewer build
participant Extractor as dist-packages.mjs
participant Audit as daily.mjs
participant Registry as npm bulk advisory endpoint
Workflow->>Build: Build viewer and write audit record
Workflow->>Extractor: Pass audit record and target lockfile
Extractor-->>Workflow: Write package inventory
Workflow->>Audit: Pass lockfile, workspace, inventory, and branch label
Audit->>Registry: Query advisories for package versions
Registry-->>Audit: Return advisory findings
Audit-->>Workflow: Write summary and set exit status
Merge Risk: ⚪ Minimal · up to The reviewed dependency check is mergeable after normal checks; no actionable issue remains from this review. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)✅ Passed checks (3 passed)Full details: Description checkExplanation The description provides detailed context, implementation details, failure behavior, limitations, and testing results. However, it does not use the required template sections and omits the required checklist confirmations and tested-environment details. Resolution Update the description to include the required Context, Changes & Results, Testing, Checklist, and Tested Environment sections. Complete every checklist item, and provide the actual OS, Node.js version, and browser values. Confirm documentation and code-documentation requirements explicitly. Full details: Docstring CoverageExplanation Docstring coverage is 70.37% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 27 functions across 8 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
🛠️ Fix failing CI checks 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Viewers
|
||||||||||||||||||||||||||||
| Project |
Viewers
|
| Branch Review |
chore/daily-security-check
|
| Run status |
|
| Run duration | 01m 54s |
| Commit |
|
| Committer | Joe Boccanfuso |
| View all properties for this run ↗︎ | |
| Test results | |
|---|---|
|
|
0
|
|
|
0
|
|
|
0
|
|
|
0
|
|
|
28
|
| View all changes introduced in this branch ↗︎ | |
What
A weekday workflow that checks
master's dependencies for high and critical advisories, and flags the ones that are in the viewer build. It can also be run by hand on any branch.How it works
build:viewer:ci. A small wrapper config loadsrsbuild.config.tsunchanged.dist:distwhole (todayonnxruntime-webanddicom-microscopy-viewer), with their dependencies from the lockfile.pnpm-lock.yamlwith npm's advisory endpoint (the onepnpm audituses), and writes a run summary with four lists:The summary is public, so each row shows only the advisory link and the package name. The log shows counts only.
When the run fails
Other findings never fail the run.
Also in this PR
build:viewer:cichanges and the workflow's build step no longer matches it.Limits
pnpm auditfinds, no more. Code that a library bundles inside itself is only seen at the lockfile's version.distsome other way thanoutput.copyisn't seen as "in the build". Its findings show under "promptly" or "soon" instead of "immediately".release/3.13) use that branch'srsbuild.config.ts, so the list may differ from that branch's real build.Testing
npm testin.scripts/dependency-audit(run by CircleCIUNIT_TESTS).master: 318 packages in the build; 0 to review immediately, 4 promptly, 3 soon, 1 ignored with an updatemomentpinned to 2.29.3: listed under "Review immediately", and the run failed🤖 Generated with Claude Code
Summary by CodeRabbit