feat: add plugin upgrade command for dynamic plugin dependency management - #177
Conversation
4f3a541 to
7ed3578
Compare
|
🤖 Finished Review · ✅ Success · Started 12:42 PM UTC · Completed 12:57 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $5.53 |
|
Risk Assessment: moderate (2/5) DetailsTier 1 signals unchanged from prior run (large blast radius from 924-line addition, zero protected paths, no security-sensitive or CI changes, one dependency file, 0.11 test ratio, known contributor); Tier 2 shows moderate churn on package.json and CHANGELOG but all recent (<7d), keeping the composite at 2.10 — consistent with prior score of 2 (moderate). Previous runRisk Assessment: moderate (2/5) DetailsComposite of 0.62x2.13 + 0.38x1.33 = 1.82 rounds to 2; the large blast radius and 890-line addition drive Tier 1 change-size to 5 but are offset by zero protected paths, no security-sensitive or CI changes, one dependency file, partial test coverage (ratio 0.11), and a known contributor — Tier 2 confirms low churn on the new core files — yielding moderate risk consistent with the prior score of 2. Previous run (2)Risk Assessment: moderate (2/5) DetailsLarge blast radius from 883 lines and 8 files but no protected paths, security-sensitive files, CI workflow changes, or dependency modifications; test coverage present (ratio 0.12) and known contributor; low Tier 2 churn on core new files yields composite ~1.9, rounding to 2, consistent with the prior moderate rating across all review runs. Previous run (3)Risk Assessment: moderate (2/5) DetailsTier 1 signals unchanged from prior assessment — large blast radius from 871 lines and 8 files but no protected paths, security-sensitive files, CI workflow changes, or dependency modifications, with test coverage present and a known contributor; Tier 2 history is stable with low churn, yielding a composite of 1.73 (62%×1.875 + 38%×1.5), which rounds to 2, consistent with the prior moderate rating. Previous run (4)Risk Assessment: moderate (2/5) DetailsTier 1 signals unchanged from prior assessment: large blast radius from 854 lines and 4 new source files, but no protected paths, security-sensitive files, CI workflow changes, or dependency modifications, and test coverage is present with a known contributor, yielding a composite of 1.81 rounded to 2. Previous run (5)Risk Assessment: moderate (2/5) DetailsTier 1 signals unchanged from prior assessment; blast radius large but mitigated by most files being new. No protected paths, security-sensitive files, CI workflows, or dependency files touched. Test coverage present (0.12 ratio). Known contributor. Composite 2.0 preserves prior moderate rating. Previous run (6)Risk Assessment: moderate (2/5) DetailsNew feature adding a plugin upgrade command across 5 files (714 lines). Blast radius is large but mitigated by 3 of 5 files being entirely new with no impact on existing code paths. No protected paths, security-sensitive files, CI workflows, or dependency files touched. Test coverage present (0.20 file ratio). Known contributor. Moderate churn on existing files follows expected patterns. |
|
Looks good to me Previous runReviewFindingsMedium
Low
Next steps:
Previous run (2)ReviewFindingsLow
Info
Previous run (3)ReviewFindingsLow
Next steps:
Previous run (4)ReviewFindingsLow
Next steps:
Previous run (5)ReviewFindingsMedium
Low
Next steps:
Previous run (6)ReviewFindingsHigh
Medium
Low
Next steps:
|
|
Hmm, looks like the |
|
🤖 Finished Review · ✅ Success · Started 1:24 PM UTC · Completed 1:42 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $6.10 |
|
🤖 Review · Commit: |
|
🤖 Finished Review · ✅ Success · Started 2:09 PM UTC · Completed 2:26 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.03 |
|
🤖 Review · Commit: |
|
🤖 Review · Commit: |
1b54744 to
f0787d3
Compare
|
🤖 Finished Review · ✅ Success · Started 3:10 PM UTC · Completed 3:29 PM UTC Commit: Runtime: claude · Model: sonnet → claude-sonnet-4-6 · Effort: high · Cost: $4.63 |
|
🤖 Finished Review · ✅ Success · Started 4:03 PM UTC · Completed 4:18 PM UTC Commit: Runtime: claude · Model: sonnet → claude-sonnet-4-6 · Effort: high · Cost: $3.35 |
Superseded by updated review
…ment (RHIDP-16666) Assisted-by: opencode rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
…veLength in test Assisted-by: opencode rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
Assisted-By: openai/gpt-5.6-terra Signed-off-by: Stan Lewis <gashcrumb@gmail.com> rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
99ac494 to
eb67054
Compare
|
🤖 Finished Review · ✅ Success · Started 11:57 AM UTC · Completed 12:13 PM UTC Commit: Runtime: claude · Model: sonnet → claude-sonnet-4-6 · Effort: high · Cost: $3.69 |
Assisted-By: OpenCode rh-pre-commit.version: 2.4.0 rh-pre-commit.check-secrets: ENABLED
|
|
🤖 Finished Review · ✅ Success · Started 5:32 PM UTC · Completed 5:48 PM UTC Commit: Runtime: claude · Model: sonnet → claude-sonnet-4-6 · Effort: high · Cost: $3.13 |
Superseded by updated review
|
🤖 Finished Retro · ✅ Success · Started 12:19 PM UTC · Completed 12:32 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.69 |
Retro: PR #177 —
|



Description
Implements RHIDP-16666 (
rhdh-cli plugin upgradecommand) under epic RHIDP-13609 / RHDHPLAN-985.Key Features:
Plugin Upgrade Command (
src/commands/upgrade/):rhdh-cli plugin upgrade [rhdhVersion]and aliasrhdh-cli plugin versions:bump.@backstage/*dependencies acrossdependencies,devDependencies, andpeerDependenciesinpackage.jsonto match the target release manifest.^,~) and exact version pins, while leaving third-party / non-manifest dependencies untouched.backstage.jsonversion when present.@backstage/*packages.yarn.lock) or npm and runs install to synchronize lockfiles (unless--skip-installis passed).Command Flags:
--dry-run: Displays planned package updates in a formatted table without writing to disk.--skip-install: Skips running package manager install after updatingpackage.json.--manifest-file <path>: Path to local Backstage manifest for offline/air-gapped environments.--json: Machine-readable output for automation scripts.Jira Issues:
Verification:
yarn test).yarn tsc), linting (yarn lint:check), and formatting (yarn prettier:check) passing.