feat: show fixed version on issues - #60
Conversation
…-590 OD-784 Bump the API to 57.7.10, where CommitIssue carries fixedVersion, and pass it to the dependency chain helpers so SCA issues show the target version like findings do. Add fixedVersion to the JSON output of the three commands. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 4 |
| Duplication | 27 |
AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.
TIP This summary will be updated as you push new changes.
There was a problem hiding this comment.
Pull Request Overview
The API-derived fixedVersion value is interpolated into terminal output without demonstrated sanitization, creating a potential control-sequence injection risk. This should be addressed before merging.
Required finding-precedence behavior and API-version validation lack dedicated tests. Codacy reports the changes as up to standards; no uncovered complex files were identified.
About this PR
- Add regression coverage for both
SrmItem.fixedVersionprecedence and fallback to the linked issue'sfixedVersion. - Add an automated check that the API fetch script uses API version 57.7.10.
1 comment outside of the diff
src/commands/issue.test.ts
line 1🟡 MEDIUM RISK
Suggestion: This test file has grown beyond 500 lines and the new dependency-chain cases repeat substantial mock/setup code. Consider extracting shared fixtures and helpers or moving the dependency-chain scenarios into a focused test file.
Test suggestions
- issue detail renders a fixed version for a direct dependency
- issue detail renders a fixed version for a transitive dependency
- issue detail omits version text when fixedVersion is empty or absent
- issues list renders a fixed version in the dependency-chain card
- issue, issues, and pull-request --issue JSON output includes fixedVersion
- pull-request --issue renders a fixed version in the dependency-chain block
- finding linked-issue rendering prefers SrmItem.fixedVersion and falls back to issue.fixedVersion
- API fetch script uses version 57.7.10
- fixedVersion containing ANSI/control characters is safely rendered without emitting control sequences
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. finding linked-issue rendering prefers SrmItem.fixedVersion and falls back to issue.fixedVersion
2. API fetch script uses version 57.7.10
3. fixedVersion containing ANSI/control characters is safely rendered without emitting control sequences
TIP How was this review? Give us feedback
What
Surfaces the new
fixedVersionfield ofCommitIssue(API57.7.9+) on SCA issues, matching whatfinding/findingsalready show. Counterpart of codacy/codacy-spa#3145.issue,issuesandpull-request --issuepassissue.fixedVersionto the existing dependency chain helpers:Direct - Update <pkg> to <version>Transitive - a → b → c (Fixed in <version>)fixedVersion(no fix available) renders as before, with no version text.finding's linked-issue block still prefers theSrmItem.fixedVersionit already passes; the issue's own value is the fallback.--output jsongainsfixedVersionon all three commands.API bump
Pinned
57.6.4→57.7.10(57.7.9is the first version with the field; it and57.7.10bundle identical specs).Tests
792 pass (+8 new),
tsc --noEmitclean.Docs: command specs,
src/commands/AGENTS.md,SPECS/README.mdchangelog and a changeset are updated.🤖 Generated with Claude Code