Upgrade to Calcit 0.27 and deploy frontend with COS built-in verification - #12
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (7)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe project now targets browser JavaScript and uses updated Calcit and Respo versions. The CI workflow validates and builds the project with event-specific asset paths, handles conditional COS uploads, and limits server deployment to pushes to ChangesBrowser Build and Deployment
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Workflow as GitHub Actions workflow
participant Calcit as Calcit tools
participant Vite
participant COS as COS upload action
participant Server as Production server
Workflow->>Calcit: Validate project files and namespaces
Workflow->>Vite: Build with event-specific base URL
Vite-->>Workflow: dist assets
opt COS credentials are available
Workflow->>COS: Upload assets to the CDN prefix
COS-->>Workflow: Verify public-base-url
end
opt Event is a push to main
Workflow->>Server: Deploy with rsync
end
Merge Risk: ⚪ Minimal · up to No actionable merge-blocking defect is established. Merge after normal CI checks pass; Linux validation, the typed Reel test, and COS verification remain pending. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Preview and production publishing use the same COS credentials. A contributor who controls a same-repository PR branch can therefore reach credentials intended for production publishing; choosing a preview path does not independently restrict that authority. Fork PRs are excluded, and the configured server deployment is now main-only. Actual cloud permissions and recovery behavior remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Known dependency diagnostics block compilation, while PR deployment exposes long-lived COS credentials to modifiable workflow code.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Upgrades the Calcit toolchain and adds verified COS frontend deployments.
Changes:
- Upgrades Calcit/procs and Respo dependencies.
- Configures an explicit browser/JavaScript entry with stricter CI validation.
- Adds isolated COS preview uploads and serialized production deployment.
| File | Description |
|---|---|
yarn.lock |
Locks Calcit/procs 0.27.0. |
README.md |
Documents setup, CI, and deployment. |
package.json |
Updates the Calcit/procs dependency. |
deps.cirru |
Updates Calcit and Respo versions. |
calcit.cirru |
Configures the browser JavaScript entry. |
.yarnrc.yml |
Preapproves the updated package version. |
.gitignore |
Ignores retired snapshots and generated state. |
.github/workflows/upload.yaml |
Adds strict validation and verified COS deployment. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository | ||
| env: | ||
| COS_BUCKET: ${{ secrets.COS_BUCKET }} | ||
| COS_SECRET_ID: ${{ secrets.COS_SECRET_ID }} | ||
| COS_SECRET_KEY: ${{ secrets.COS_SECRET_KEY }} |
There was a problem hiding this comment.
已检查仓库:存在多位 write 协作者,目前唯一环境 copilot 没有保护规则,因此这条风险成立。已向维护者请求选择:配置有审批保护且使用独立预览密钥的部署环境,或暂时把 COS 上传限制到 main。不会仅添加空 environment 名称就宣称已受保护,也不会在没有维护者决定时擅自修改协作者权限或密钥配置。此线程保持未解决。

Changes
Upgrade Calcit/procs 0.23.1 to latest stable 0.27.0, using published Reel 0.6.33-alpha.2, Respo UI 0.7.32-alpha.3 and Respo 0.16.114-alpha.5. Canonical calcit.cirru/deps.cirru only, explicit browser/js entry and retired-snapshot CI guards. Source migration preview has no mechanical fixes; retain existing typed Store/Op/Reel contracts and implementation.
Add frontend COS action v1.1.1 pinned by SHA, with built-in public-base-url verification. Build uses absolute CDN base, production prefix Respo/markup/, isolated PR/run preview prefix. Serialize production uploads. Keep original server dist/* source and destination expression unchanged, only restrict server deploy to main pushes. No extra upload-validation script or defensive suite; preserve existing typed Reel rendering test, strict Caps --strict --ci, strict entry and zero dynamic-method gate. Add all application public definition coverage.
Verification
Commit 7f9ca30: official Linux Upload 36828982976 SUCCESS. Strict Caps dependencies, toolchain, canonical/source checks, strict entry and 16/16 public definitions pass; zero dynamic-method findings. Actual typed Reel rendering regression 1/1 passes, with code generation/Vite build. COS action internally verified HTML (702 bytes), JS (356664 bytes), CSS (345 bytes) at https://cos-sh.tiye.me/Respo/markup/pr/12/36828982976/.
Local strict Caps installation of 5 modules passed without conflicts; toolchain verify, immutable Yarn install, canonical format and git diff --check passed. Local pinned macOS 0.27.0 still reports 5 upstream Respo ToString-bound diagnostics in 4 definitions; no app-local diagnostic/suppression. Strict acceptance comes from current-commit official Linux run, not local output. No real browser, production deployment or merge claimed. Build-blocking review replied with current Linux success and resolved. PR secret exposure review remains unresolved: repository has multiple write collaborators and no protected COS environment. Maintainer choice requested (protected preview environment/separate preview credentials, or main-only uploads); no permissions/secrets changed without that choice.