Skip to content

Upgrade to Calcit 0.27 and deploy frontend with COS built-in verification - #12

Merged
tiye merged 1 commit into
mainfrom
codex/markup-calcit027-cos
Oct 1, 2026
Merged

tiye merged 1 commit into
mainfrom
codex/markup-calcit027-cos

Conversation

@tiye

@tiye tiye commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Changes

Upgrade Calcit/procs 0.23.1 to latest stable 0.27.0, using published Reel 0.6.33-alpha.2, Respo UI 0.7.32-alpha.3 and Respo 0.16.114-alpha.5. Canonical calcit.cirru/deps.cirru only, explicit browser/js entry and retired-snapshot CI guards. Source migration preview has no mechanical fixes; retain existing typed Store/Op/Reel contracts and implementation.

Add frontend COS action v1.1.1 pinned by SHA, with built-in public-base-url verification. Build uses absolute CDN base, production prefix Respo/markup/, isolated PR/run preview prefix. Serialize production uploads. Keep original server dist/* source and destination expression unchanged, only restrict server deploy to main pushes. No extra upload-validation script or defensive suite; preserve existing typed Reel rendering test, strict Caps --strict --ci, strict entry and zero dynamic-method gate. Add all application public definition coverage.

Verification

Commit 7f9ca30: official Linux Upload 36828982976 SUCCESS. Strict Caps dependencies, toolchain, canonical/source checks, strict entry and 16/16 public definitions pass; zero dynamic-method findings. Actual typed Reel rendering regression 1/1 passes, with code generation/Vite build. COS action internally verified HTML (702 bytes), JS (356664 bytes), CSS (345 bytes) at https://cos-sh.tiye.me/Respo/markup/pr/12/36828982976/.

Local strict Caps installation of 5 modules passed without conflicts; toolchain verify, immutable Yarn install, canonical format and git diff --check passed. Local pinned macOS 0.27.0 still reports 5 upstream Respo ToString-bound diagnostics in 4 definitions; no app-local diagnostic/suppression. Strict acceptance comes from current-commit official Linux run, not local output. No real browser, production deployment or merge claimed. Build-blocking review replied with current Linux success and resolved. PR secret exposure review remains unresolved: repository has multiple write collaborators and no protected COS environment. Maintainer choice requested (protected preview environment/separate preview credentials, or main-only uploads); no permissions/secrets changed without that choice.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 07:12
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e2cd5329-bbae-44f5-94f1-7db7112f52f0

📥 Commits

Reviewing files that changed from the base of the PR and between 3cfb399 and 7f9ca30.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (7)
  • .github/workflows/upload.yaml
  • .gitignore
  • .yarnrc.yml
  • README.md
  • calcit.cirru
  • deps.cirru
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The project now targets browser JavaScript and uses updated Calcit and Respo versions. The CI workflow validates and builds the project with event-specific asset paths, handles conditional COS uploads, and limits server deployment to pushes to main.

Changes

Browser Build and Deployment

Layer / File(s) Summary
Browser target and toolchain configuration
calcit.cirru, deps.cirru, package.json, .yarnrc.yml, .gitignore, README.md
The default entry targets browser JavaScript. Calcit and Respo dependencies are updated, generated files are ignored, and the README documents commands, validation, and deployment configuration.
CI setup, validation, and build
.github/workflows/upload.yaml
The workflow configures its runner and tools, checks project files and namespaces, and builds with an event-specific CDN base URL.
Asset publishing and server deployment
.github/workflows/upload.yaml
The workflow handles COS credentials and asset verification. Server deployment and deploy-status output run only on pushes to main.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Workflow as GitHub Actions workflow
  participant Calcit as Calcit tools
  participant Vite
  participant COS as COS upload action
  participant Server as Production server
  Workflow->>Calcit: Validate project files and namespaces
  Workflow->>Vite: Build with event-specific base URL
  Vite-->>Workflow: dist assets
  opt COS credentials are available
    Workflow->>COS: Upload assets to the CDN prefix
    COS-->>Workflow: Verify public-base-url
  end
  opt Event is a push to main
    Workflow->>Server: Deploy with rsync
  end
Loading

Merge Risk: ⚪ Minimal · up to 7f9ca

No actionable merge-blocking defect is established. Merge after normal CI checks pass; Linux validation, the typed Reel test, and COS verification remain pending.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 7f9ca

Preview and production publishing use the same COS credentials. A contributor who controls a same-repository PR branch can therefore reach credentials intended for production publishing; choosing a preview path does not independently restrict that authority. Fork PRs are excluded, and the configured server deployment is now main-only. Actual cloud permissions and recovery behavior remain unverified.

Retained concerns

  • Medium · security · inferred: Same-repository PR publishing receives the COS credentials also used for production. PR-specific prefixes separate normal destinations, but do not independently authorize preview-only writes. When the credentials can publish production assets, PR-controlled execution can potentially use that authority outside the intended preview prefix.
Security review details

Security Blast Radius

  • inferred — The demonstrated attacker prerequisite is control of a same-repository PR branch, not merely the ability to submit a fork PR. The new authority path reaches credentials intended to publish production assets in the configured COS bucket. Permissions over sibling prefixes, other buckets, or other services cannot be established.

Security Findings and Attack Paths

  • inferred — A same-repository branch contributor can alter PR-executed workflow code to consume COS credentials or select a production destination rather than the normal preview prefix. If those credentials support main publishing, this permits production asset modification without merging that PR. This is an inferred authority path, not an observed exploit or proof of bucket-wide access.
  • observed — The base already supplied the rsync private key to its PR-triggered deployment step. The head removes that normal PR deployment path. That pre-existing secret exposure is counterevidence against describing all PR-to-deployment authority as newly introduced, but it does not establish isolation for the new COS integration.

Trust Boundaries and Controls

  • inferred — Fork exclusion, unique preview prefixes, action pinning, and read-only repository-token permissions constrain normal execution. They do not independently restrict the shared COS credential to preview writes or protect it from a contributor who can modify the credential-bearing PR workflow. No separate protected publishing environment is declared in this workflow.

Resilience and Maintainability Implications

  • inferred — Run-specific preview paths contain ordinary cross-run overwrites, but reruns retain the same run identity and publication is not proven atomic. The workflow delegates verification to the external action and declares no compensation after partial upload, failed verification, or failed server deployment. Provider recovery and preview retention remain coverage gaps rather than verified insecure outcomes.

Hardening Proposals

  • proposed — Separate preview and production credential identities, enforce preview-only cloud permissions, and place production credentials behind independently protected publishing approval. These controls would make destination separation an authorization boundary rather than a workflow convention.
  • proposed — Establish the publishing provider's interruption, retry, and rollback guarantees, plus an owner for preview expiry. If publication is non-atomic, consider immutable release prefixes and controlled promotion or restoration instead of relying only on post-upload verification.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the two main changes: upgrading Calcit to 0.27 and deploying the frontend with COS built-in verification.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Known dependency diagnostics block compilation, while PR deployment exposes long-lived COS credentials to modifiable workflow code.

Review effort: Balanced
Findings: 2 High severity

Open (2)
What changed in this PR

Upgrades the Calcit toolchain and adds verified COS frontend deployments.

Changes:

  • Upgrades Calcit/procs and Respo dependencies.
  • Configures an explicit browser/JavaScript entry with stricter CI validation.
  • Adds isolated COS preview uploads and serialized production deployment.
File Description
yarn.lock Locks Calcit/procs 0.27.0.
README.md Documents setup, CI, and deployment.
package.json Updates the Calcit/procs dependency.
deps.cirru Updates Calcit and Respo versions.
calcit.cirru Configures the browser JavaScript entry.
.yarnrc.yml Preapproves the updated package version.
.gitignore Ignores retired snapshots and generated state.
.github/​workflows/​upload.yaml Adds strict validation and verified COS deployment.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +89 to +93
if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository
env:
COS_BUCKET: ${{ secrets.COS_BUCKET }}
COS_SECRET_ID: ${{ secrets.COS_SECRET_ID }}
COS_SECRET_KEY: ${{ secrets.COS_SECRET_KEY }}

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

已检查仓库:存在多位 write 协作者,目前唯一环境 copilot 没有保护规则,因此这条风险成立。已向维护者请求选择:配置有审批保护且使用独立预览密钥的部署环境,或暂时把 COS 上传限制到 main。不会仅添加空 environment 名称就宣称已受保护,也不会在没有维护者决定时擅自修改协作者权限或密钥配置。此线程保持未解决。

Comment thread deps.cirru
@tiye
tiye merged commit 221ef4c into main Oct 1, 2026
2 checks passed
@tiye
tiye deleted the codex/markup-calcit027-cos branch October 1, 2026 08:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants