Validation: SARIF gates and merge (#1483) - #36
Closed
joaodinissf wants to merge 1 commit into
Closed
joaodinissf wants to merge 1 commit into
joaodinissf wants to merge 1 commit into
Conversation
Run PMD/Checkstyle/CPD and SpotBugs in separate analysis lanes. Preserve Maven failure status with --fail-at-end and validate every expected raw and merged report before counting findings. Require successful invocation metadata for PMD and SpotBugs; Checkstyle omits it, so retain its valid format while preserving the producer process status. Parse CPD XML and reject processing errors instead of counting lines that resemble findings. Resolve each run's URI base chains and emit repository-relative artifact URIs, including secondary locations. A real GitHub upload accepted preserved base IDs but recorded package-relative paths that did not match the source tree. Explicit relative URIs remove that consumer dependency. Resolve rule indices before combining descriptors, preserve SpotBugs taxonomies, and reject conflicting or unsupported metadata instead of discarding it. Exercise extracted workflow blocks with real producer reports and negative fixtures, and run targeted mutation checks in a fast CI job. Cover absent reports, malformed input, incomplete analysis, notification errors, merged output corruption, source locations, descriptors and producer exit status. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
joaodinissf
force-pushed
the
codex/validation-20260926-1483
branch
from
September 26, 2026 11:31
949b75a to
230afc4
Compare
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fork-only validation of upstream stack dsldevkit#1483
Final candidate:
230afc4d11902623937c0752a8f2f91367056688. The complete verification workflow passed.Before publication, this exact head passed 112 local report/merge/process cases, eight mutation checks, and its applicable signed Git scope scenarios. The reusable suites also run in the fast
analysis-regressionjob.The changes preserve Maven failures, reject incomplete SARIF, parse CPD XML, retain rule/taxonomy metadata, and emit repository-relative source locations. The separate deliberate finding probe verified two actual annotations at the expected source line; its failing SpotBugs check is intentional.
This draft is a validation resource in the owner's fork. It does not modify the upstream PR and is not a request to merge or publish. No snapshot, release, or deployment workflow was triggered. Any upstream publication requires separate approval.