Skip to content

chore: regenerate catalog from OpenAPI spec - #69

Merged
dangrondahl merged 1 commit into
mainfrom
chore/update-catalog
Sep 30, 2026
Merged

dangrondahl merged 1 commit into
mainfrom
chore/update-catalog

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated catalog update from the Kosli OpenAPI spec.

Please review the diff to verify the changes look correct before merging.

@github-actions
github-actions Bot force-pushed the chore/update-catalog branch from dd10213 to 3519fab Compare September 28, 2026 07:23
@claude

claude Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Claude finished @github-actions[bot]'s task in 4m 37s —— View job


Catalog diff review — PR #69

  • Read git diff origin/main...HEAD -- src/catalog.json
  • Enumerate actions added
  • Enumerate actions removed
  • Enumerate actions changed (params, schemas, deprecated)
  • Grep src/, test/, README.md for dangling references
  • Sanity checks (action count, surviving $ref)

Verdict: safe to merge. No actions added, none removed, no id/method/path line changed anywhere in the diff. This is a pure schema-refinement regeneration.


1. Actions added

None. Action count is 123 before → 123 after (grep -c '^ "id": '). Not a single "id":, "method":, or "path": line appears on either side of the diff.

2. Actions removed

None — so the "confirm each removal against the live spec" step does not apply to this run. The two historical failure modes (#16 stale-branch clobber, #18 genuine upstream retirement) are both ruled out by the unchanged count and the absence of any - "id": line.

3. Actions changed

No parameter was added or removed on any action. All changes are to schemas of existing parameters and request bodies.

a. New request-body field — create_evaluation (POST /evaluations/{org}, src/catalog.json:3089)

A nullable decision object, DecisionInput: required control (maxLength: 256), name, flow, trail; optional fingerprint (sha256 or null). Described as "Record the outcome as a decision against a control. Absent, the evaluation stands alone and writes nothing to a trail." This is the only genuinely new capability in the diff.

Checked against the CLAUDE.md body/param collision rule: create_evaluation's only parameter is org, and neither org nor any param name appears anywhere in its body schema — so test/catalog.test.ts:50 and :63 still hold.

b. New enum value — attest_system (src/catalog.json:2693)

-"type_name": {"type":"string","enum":["decision"],"title":"Type Name"},
+"type_name": {"type":"string","enum":["decision","sbom"],"title":"Type Name"},

c. Validation patterns added to path/query params (widest-reaching change, ~30 sites)

env_name gained ^[a-zA-Z0-9][a-zA-Z0-9\.\-_]*$; flow_name/trail_name/flow/trail gained ^[a-zA-Z0-9][a-zA-Z0-9\.\-_~]*$ — previously bare {"type":"string"}. Affects the attest_* family, assert_artifact, archive_*, create_trail, get_trail*, override_attestation, rename_*, the report_*_environment family, and others. Purely additive validation; a legal name still validates.

A handful of existing patterns were rewritten to an equivalent form (^[a-zA-Z0-9][a-zA-Z0-9\-_.~]*$ → ^[a-zA-Z0-9][a-zA-Z0-9\.\-_~]*$) — same character class, different escaping/ordering. No behaviour change.

d. Pagination constraints

Action Params Change
list_artifacts page, per_page minimum: 1 added
list_flow_attestations page, per_page anyOf [integer, null] → {"type":"integer","minimum":1}

The list_flow_attestations one is a real narrowing: those two params are no longer nullable. Low practical risk — execute_read_action omits params the caller doesn't supply rather than sending null — but an explicit "page": null that previously passed would now be a 422 from Kosli. Both keep their defaults (1 / 20).

e. 28 × "additionalProperties": false removed (schema loosening)

JiraItem, JUnitResult, FoundPullRequestV1, PullRequestApprover, SnykTool, ProjectScanResult, SnykResultsSummary, Jira Results, Results, and the notification/action targets SlackAppContext (×8), WebhookActionTarget/SlackActionTarget/EmailActionTarget (×4 each). These objects now accept extra keys. Strictly permissive — nothing that validated before stops validating.

f. Attachment-URL key pattern tightened + model renamed (11 sites, across the attest_* family and create_artifact/override_attestation)

-"^[^=.]+$": { … "title": "ExternalAttachmentUrl" }
+"^[^=.\x00]+$": { … "title": "ExternalAttachmentUrlInput" }

NUL is now excluded from attachment keys. The …Input suffix and the additionalProperties removals together look like an upstream Pydantic split into separate input/output models — consistent, not a generator regression.

g. Docs on environment/flow action triggers (4 sites: create_or_update_environment_action, create_or_update_environment_notification, create_or_update_flow_action, update_environment_notification)

A long per-value description for the trigger enum plus "examples": [["ON_STARTED_ARTIFACT","ON_NON_COMPLIANT_ENV"]]. Notably it documents that ON_SCALED_ARTIFACT "does not fire when an artifact starts, so it is not a deployment trigger" — a genuine LLM-facing clarification. This is most of the +8.5 KB.

h. deprecated

Unchanged: 4 occurrences before, 4 after, same locations. Nothing newly deprecated, nothing un-deprecated.

4. Dangling references

None. Grepped src/, test/, and README.md (excluding src/catalog.json) for every renamed/changed identifier — ExternalAttachmentUrl, JiraItem, JUnitResult, FoundPullRequestV1, SnykTool, ProjectScanResult, SnykResultsSummary, PullRequestApprover, SlackAppContext, type_name, create_evaluation, list_flow_attestations, list_trail_moments — zero hits outside the catalog.

  • src/hints.json keys on create_or_update_flow_with_template and create_or_update_policy, referencing template_file and policy_file. All four still present and unchanged by this diff.
  • test/fixtures/catalog-subset.json pins 11 action ids (list_environments, get_environment, list_flows, get_trail, search_artifacts, list_snapshots, create_control, create_or_update_policy, get_user_default_org, set_user_default_org, create_artifact). All still exist; the fixture is a hand-curated slice and does not need regenerating for this diff.
  • No "searchText" line changed, so search_actions relevance is untouched.

5. Sanity checks

Check Result
Action count 123 → 123 ✅
Actions removed 0 ✅
Surviving $ref 0 — generator inlined everything ✅
Blob size 367,706 → 376,198 bytes (+8.5 KB, +2.3%) — accounted for by the new trigger docs and decision ✅
org in a body schema none introduced ✅
Body field colliding with an action's own param none introduced ✅
Unexplained diff content none — every added line falls into one of (a)–(g) above ✅

One caveat on my verification: npm test and node were not in my allowed tools in this run, so I could not execute test/catalog.test.ts locally — the $ref, unique-id, org-in-body, and body/param-collision claims above were verified by direct inspection of the JSON, not by running the suite. CI runs the real thing; if it's green, those invariants are confirmed.
· branch chore/update-catalog

@dangrondahl
dangrondahl merged commit 07fe90b into main Sep 30, 2026
5 checks passed
@dangrondahl
dangrondahl deleted the chore/update-catalog branch September 30, 2026 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant