Skip to content

feat: show fixed version on issues - #60

Merged
claudiacodacy merged 1 commit into
mainfrom
feat/issue-fixed-version
Oct 1, 2026
Merged

claudiacodacy merged 1 commit into
mainfrom
feat/issue-fixed-version

Conversation

@claudiacodacy

@claudiacodacy claudiacodacy commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

What

Surfaces the new fixedVersion field of CommitIssue (API 57.7.9+) on SCA issues, matching what finding/findings already show. Counterpart of codacy/codacy-spa#3145.

  • issue, issues and pull-request --issue pass issue.fixedVersion to the existing dependency chain helpers:
    • direct: Direct - Update <pkg> to <version>
    • transitive: Transitive - a → b → c (Fixed in <version>)
  • An empty fixedVersion (no fix available) renders as before, with no version text.
  • finding's linked-issue block still prefers the SrmItem.fixedVersion it already passes; the issue's own value is the fallback.
  • --output json gains fixedVersion on all three commands.

API bump

Pinned 57.6.4 → 57.7.10 (57.7.9 is the first version with the field; it and 57.7.10 bundle identical specs).

Tests

792 pass (+8 new), tsc --noEmit clean.
Docs: command specs, src/commands/AGENTS.md, SPECS/README.md changelog and a changeset are updated.

🤖 Generated with Claude Code

…-590 OD-784

Bump the API to 57.7.10, where CommitIssue carries fixedVersion, and pass it
to the dependency chain helpers so SCA issues show the target version like
findings do. Add fixedVersion to the JSON output of the three commands.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 4 complexity · 27 duplication

Metric Results
Complexity 4
Duplication 27

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

The API-derived fixedVersion value is interpolated into terminal output without demonstrated sanitization, creating a potential control-sequence injection risk. This should be addressed before merging.

Required finding-precedence behavior and API-version validation lack dedicated tests. Codacy reports the changes as up to standards; no uncovered complex files were identified.

About this PR

  • Add regression coverage for both SrmItem.fixedVersion precedence and fallback to the linked issue's fixedVersion.
  • Add an automated check that the API fetch script uses API version 57.7.10.
1 comment outside of the diff
src/commands/issue.test.ts

line 1 🟡 MEDIUM RISK
Suggestion: This test file has grown beyond 500 lines and the new dependency-chain cases repeat substantial mock/setup code. Consider extracting shared fixtures and helpers or moving the dependency-chain scenarios into a focused test file.

Test suggestions

  • issue detail renders a fixed version for a direct dependency
  • issue detail renders a fixed version for a transitive dependency
  • issue detail omits version text when fixedVersion is empty or absent
  • issues list renders a fixed version in the dependency-chain card
  • issue, issues, and pull-request --issue JSON output includes fixedVersion
  • pull-request --issue renders a fixed version in the dependency-chain block
  • finding linked-issue rendering prefers SrmItem.fixedVersion and falls back to issue.fixedVersion
  • API fetch script uses version 57.7.10
  • fixedVersion containing ANSI/control characters is safely rendered without emitting control sequences
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. finding linked-issue rendering prefers SrmItem.fixedVersion and falls back to issue.fixedVersion
2. API fetch script uses version 57.7.10
3. fixedVersion containing ANSI/control characters is safely rendered without emitting control sequences

TIP How was this review? Give us feedback

@claudiacodacy claudiacodacy changed the title feat: show fixed version on issues OD-590 OD-784 feat: show fixed version on issues Sep 30, 2026
@claudiacodacy
claudiacodacy merged commit a77c4a7 into main Oct 1, 2026
4 checks passed
@claudiacodacy
claudiacodacy deleted the feat/issue-fixed-version branch October 1, 2026 08:28
@github-actions github-actions Bot mentioned this pull request Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants