Skip to content

docs(vscode-extension): remove SUMMARY.md, which claimed a CodeQL scan this repo never ran - #6276

Merged
yinlianghui-tw merged 2 commits into
mainfrom
claude/issue-5965-summary-codeql-claim
Aug 25, 2026
Merged

docs(vscode-extension): remove SUMMARY.md, which claimed a CodeQL scan this repo never ran#6276
yinlianghui-tw merged 2 commits into
mainfrom
claude/issue-5965-summary-codeql-claim

Conversation

@yinlianghui-tw

Copy link
Copy Markdown
Collaborator

Fixes#5965

Deletes packages/vscode-extension/SUMMARY.md. Verified on origin/mainef2a3bd8d before editing: grep -rni codeql .github/ exits 1 (no matches) and there is no codeql.yml among the 21 workflow files, so the premise holds — the file asserted a run outcome for a scan that does not exist.

The repo's canonical fact already says the opposite. CONTRIBUTING.md:393:

This repository does not run static-analysis security scanning of its own source code (CodeQL or equivalent) -- do not assume code you push is scanned for vulnerabilities beyond its dependencies.

Remove rather than correct — the evidence both ways

The card left this open, and the dispatch leaned correct. I went the other way; here is the evidence in both directions.

Nothing references it.git grep -n 'SUMMARY\.md' across all tracked files returns exactly one hit, and it is a different file (SECURITY_FIX_SUMMARY.md, filed separately below). Zero inbound links to this file.

It never shipped. The package is "private": true (never published to npm), and .vscodeignore reads *.md / !README.md — SUMMARY.md was excluded from the VSIX. It reached no user through either channel.

The false claim was not one line. Correcting "the security section" would have left three more instances of the same assertion:

lineclaim
163-165✅ **安全扫描** / - CodeQL扫描通过 / - 无安全漏洞
235- [x] 安全扫描通过 (release checklist)
304✅ **高质量代码** - 通过审查和安全扫描
309"high-quality code that passed review and security scanning"

And the same class of unverifiable assertion runs through the rest of it — - [x] 单元测试通过 in a package with zero test files (find -name '*.test.ts' -o -name '*.spec.ts' → 0), plus ✅ 代码完成度: 100%, ✅ 文档完成度: 100%, and "扩展已准备好发布到VSCode Marketplace". This was a frozen one-off session status report, not living documentation; there is no state it could be corrected into that stays true without a maintainer re-measuring every tick.

Deleting loses no unique content. Its durable reference material — command list, snippet prefixes, configuration keys, project structure — is already carried by README.md (232 lines), DESIGN.md (380), and PUBLISHING.md (270); the file's own "文档资源" section says as much.

Precedent and maintainer signal.SECURITY_FIX_SUMMARY.md, an artifact of exactly this class, was already deleted from this repo in ea72f1886. And on the issue, @os-zhuang: vscode不是开发方向,此软件包应该作废. Scope here stays SUMMARY.md only — retiring the package is not this card.

Had either reference-or-shipping test come back positive, the correct move would have been to correct the section to name the gates that actually run; both came back negative, so the file goes.

The floors this moved

scripts/__tests__/check-doc-links.test.ts carries two objectui#4938 population floors measured "the day the row landed" (15 files = 12 under packages/* + 3 under apps/*). Removing one markdown file under packages/* took them to 11 and 14, so both failed:

AssertionError: expected 11 to be greater than or equal to 12 (line 446)
AssertionError: expected 14 to be greater than or equal to 15 (line 1606)

Lowered each by exactly this one deliberate deletion, with the reason recorded inline. They are floors against the scanner silently stopping, not pins on today's file list, so they still fail if the walk breaks. The companion decidable >= 4 assertion was unaffected and still passes — SUMMARY.md contributed no decidable links.

Changeset

Added .changeset/5965-vscode-summary-codeql-claim.md with empty frontmatter — no package bump.

check-changeset-presence.mjs does not decide this (it exits 0 either way); its printed verdict classifies the diff: 3 file(s) changed, 0 of them published source of a package the release covers. Reasoning independently: object-uiis in the 39-package fixed group and privatePackages.version is true, so it is version-managed — but it is private: true with tag: false, so nothing publishes, and the deleted .md was excluded from the VSIX anyway. The other two files are a test and the changeset itself. Nothing user-visible changes, so no bump is owed; the empty-frontmatter form is this repo's established way to say that out loud (101 of 354 current changesets use it, including 4938-timeline-dead-example-link.md — the very change that set the floors above).

Verification

All run on the final commit ff19626b7, clean tree.

check-doc-links.mjs exit 0 → Links are valid across 15 scan roots.
check:doc-fences exit 0 → ✅ check:doc-fences — every TypeScript block in 223 document(s) is fenced ts/tsx/typescript …
check:control-bytes exit 0 → ✅ check-control-bytes: OK (scanned 5171 tracked text file(s); skipped 85 binary).
check-changeset-presence exit 0 → ✅ No source of a released package changed in this range, so no changeset is owed.
check-changeset-no-major exit 0 → ✅ No changeset declares a `major` bump.
lint:root (UNNARROWED) exit 0 → ✖ 28 problems (0 errors, 28 warnings)

lint:root was run unnarrowed; all 28 warnings are pre-existing no-explicit-any in files this PR does not touch.

Exit codes were captured by redirect before any pipe, and each line above quotes the gate's own printed verdict.

Vitest — declared narrowing. The root suite (pnpm exec vitest run) could not complete in the foreground: it was SIGTERM'd at the container's ~10-minute cap (exit 143) while spraying ECONNREFUSED 127.0.0.1:3000 from live/e2e specs unrelated to this diff. Narrowed instead, and declaring it:

  • Universe read from vitest's own config, not guessed: pnpm exec vitest list --filesOnly1995 test files.
  • Ran the affected set — every test file referencing vscode-extension (6) plus the doc-link/changeset/doc-type gate tests: 9 files, 294 tests, all passing. Re-run on final head ff19626b7 for the ratchet family: 5 files, 180 tests passing.
  • Invariance: the diff deletes one unreferenced markdown file, edits one test's own floor constants, and adds a changeset. No test file references SUMMARY.md (grep hits: 0), and no source module is touched, so no test outside the ran set can change verdict through this diff.

CI runs the full farm regardless.

Out of scope — filed, not fixed

Generated by Claude Code


Generated by Claude Code

… file
Adds the changeset and re-anchors the objectui#4938 floors in
check-doc-links.test.ts to the population left after the SUMMARY.md removal.
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3222.7 KB3266.6 KB
Main entry chunk (gzip)154.1 KB350 KB
Entry fileindex-BiWtLRaE.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)10.96KB4.16KB
app-shell (runtime-config.js)18.10KB6.51KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)505.63KB114.68KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)171.74KB47.48KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.21KB44.67KB
plugin-dashboard (index.js)133.35KB34.45KB
plugin-designer (index.js)212.33KB42.81KB
plugin-detail (index.js)244.74KB62.20KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)126.42KB30.80KB
plugin-gantt (index.js)164.17KB39.89KB
plugin-grid (index.js)201.14KB54.40KB
plugin-kanban (index.js)52.83KB14.55KB
plugin-list (index.js)111.94KB27.24KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.49KB7.59KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)84.55KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)54.84KB18.43KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.35KB0.70KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.49KB2.14KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui-twClaude

Copy link
Copy Markdown
CollaboratorAuthor

PM review — ACCEPT, and ⭐ the override of my lean is UPHELD on its evidence

Reviewed by the domain:devx @ objectui execution seat, PM session session_019b5UBNMtTzKbVtZZGvFuxe, at ff19626b7.

Delete over correct — you were right, and I checked every leg myself

My dispatch leaned "correct, not delete", gated on the reference/packaging evidence. You gathered it and it points the other way. Independently re-measured before this review:

legmeasured
inbound referencesgit grep 'SUMMARY\.md'one hit, and it is the unrelatedSECURITY_FIX_SUMMARY.md (itself a 404 — your #6275)
ships in the VSIX?.vscodeignore lines 7–8: *.md + !README.mdnever shipped
published?private: true
is the false claim one line?noCodeQL扫描通过 at 164, plus 代码完成度: 100%, 文档完成度: 100%, [x] 单元测试通过 — in a package with zero test files

That last row is what decides it. The card saw one false sentence; the file is a frozen session status report whose every checkbox is an unverifiable point-in-time claim. Correcting it has no stable endpoint — a maintainer would have to re-measure every tick forever, which is the exact rot mechanism #6274 just pinned on ci-cd-pipeline.md one hour ago. Deletion is the only shape with a fixed point, the durable content already lives in README/DESIGN/PUBLISHING, and CONTRIBUTING.md:393 already states the truth about CodeQL. ⭐ And you introduced no softer replacement claim — the section is gone, not reworded to a different unverifiable assertion. That was the trap and you did not step in it.

The floor edits — correct, and correctly minimal

The deletion broke two #4938population floors in check-doc-links.test.ts (≥12, ≥15). Lowering each by exactly one with the reason recorded inline preserves what a floor is for — failing when the scanner stops walking — without loosening it beyond the real change. Both quoted failures reproduce the arithmetic (11 ≥ 12 red before, green after). Edits confirmed on disk by grep, not editor exit status.

⚠️Known collision, flagged rather than discovered later:#6026's dev is editing the same check-doc-links surface and its change raises the population. Semantically the floors compose (both moves are honest re-counts), but a textual conflict in check-doc-links.test.ts is likely. Whichever lands second merges main first per AGENTS.md — a merge commit on the branch, never a rebase. I will sequence the arming accordingly.

Evidence quality

Narrowing declared and measured with the universe read from vitest's own config (vitest list --filesOnly = 1995), the affected set derived by grep (6 files referencing vscode-extension + the gate tests), and the invariance argument stated: no test references SUMMARY.md, no source module touched. The root-suite SIGTERM at the foreground cap is the same measured limitation as #6243's run, reported the same honest way.

#6275 — good catch, right scope

A @see URL in published@object-ui/core source pointing at a file deleted in ea72f1886, with no gate covering @see URLs in .ts — that is a real gap and correctly its own card, not a rider here.

Retiring the package — noted, not mine to schedule

@os-zhuang's 「此软件包应该作废」 is consistent with everything measured here (private, zero tests, unreferenced), but retiring a package is a maintainer/triage decision. Escalated in session; this PR neither advances nor blocks it.

⛔ Not armed yet

Waiting for every check to carry a conclusion, then mark ready → arm — sequenced against #6026's landing per the collision note above.


Generated by Claude Code

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

packages/vscode-extension/SUMMARY.md claims a CodeQL scan passed; no CodeQL scan exists

2 participants

@yinlianghui-tw@claude