feat: web: bump @protolabsai/design ^0.11.0 + @protolabsai/ui ^0.66.1; tokenNameGuard accepts _ token names (protoContent#525/#547 step 3, card 1 foundation) - #3888
Conversation
…; tokenNameGuard accepts `_` token names (protoContent#525/#547 step 3, card 1 foundation)
|
Warning Review limit reachedNext included review available in 24 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
QA panel review — WARN
code-review-structural · head 442178d4ea5c · formal
Low-risk dependency bump with a targeted regex widening; the real risk is the Python test file left behind. Fix first: update _VAR_REF and _TOKEN_DEF in tests/test_plugin_view_ds_tokens.py to include underscore in the character class, and remove --pl-radius-md from KNOWN_MISSPELLINGS — both are confirmed by the verifier against the snapshot and changelog. The panel was unanimous; no disagreements. Verification confirmed both majors and marked the protopatch minor as uncertain (pre-existing CI orchestration gap, not introduced by this PR). Coverage gap: no finder examined the plugin-kit.css snapshot for completeness against the full token set.
Findings
| Severity | Location | Finding | Verified | |
|---|---|---|---|---|
| 🟠 | major | tests/test_plugin_view_ds_tokens.py:53 |
The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-… | confirmed |
| 🟠 | major | tests/test_plugin_view_ds_tokens.py:44 |
KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file whi… | confirmed |
| 🟡 | minor | apps/web/package.json:10 |
Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks |
findings JSON (machine-readable)
[
{
"file": "tests/test_plugin_view_ds_tokens.py",
"line": 53,
"severity": "major",
"category": "cross-file",
"claim": "The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0; the equivalent TypeScript regexes in tokenNameGuard.test.ts were widened to [a-z0-9_-] in this PR but the Python test was not updated, causing test_the_token_snapshot_matches_the_real_kit to fail and test_every_referenced_token_is_defined to produce false positives.",
"evidence": "_VAR_REF = re.compile(r\"var\\(\\s*(--pl-[a-z0-9-]+)\")\n_TOKEN_DEF = re.compile(r\"^\\s*(--pl-[a-z0-9-]+)\\s*:\", re.M)",
"verdict": "confirmed",
"note": "Regexes verbatim in file at head; diff shows TS DECL/VAR_REF/NESTED_HEAD widened to [a-z0-9_-]; snapshot at head has no underscore tokens; changelog confirms --pl-space-0_5/-1_5/-2_5 added in 0.11.0."
},
{
"file": "tests/test_plugin_view_ds_tokens.py",
"line": 44,
"severity": "major",
"category": "cross-file",
"claim": "KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file which includes it and by the changelog); any plugin view using var(--pl-radius-md) will be flagged as a misspelling by test_no_known_misspelled_ds_tokens.",
"evidence": "\"--pl-radius-md\": \"--pl-radius\",",
"verdict": "confirmed",
"note": "Entry verbatim in KNOWN_MISSPELLINGS at head; snapshot file contains --pl-radius-md; TS test spot-checks it in defined set; changelog confirms radius scale added in 0.11.0."
},
{
"file": "apps/web/package.json",
"line": 10,
"severity": "minor",
"category": "build-release",
"claim": "Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks",
"evidence": "The detected project commands are `uv run ruff check .` / `uv run ruff format --check .` / `uv run pytest`, all Python-only. The TypeScript app's only tsc invocation lives in the `build` script (package.json line 10) and its tests run via `vitest run` (line 14). A CI or developer relying on the detected commands will not type-check or run tests for the owned .ts files, so type errors or regression Fix: Extend the root typecheck/lint/test orchestration to also run `npm --prefix apps/web run build` (or a dedicated tsc typecheck) and `npm --prefix apps/web run test`, or update the detected commands to (protopatch confidence: high)",
"source": "protopatch",
"verdict": "uncertain",
"note": "package.json confirms tsc in build and vitest in test, but the 'detected project commands' claim references CI orchestration config not visible in this PR diff; pre-existing condition, not a defect introduced by this dependency bump."
}
]2 finding(s) excluded from the verdict by in-diff confinement (file not among this PR's changed paths):
tests/test_plugin_view_ds_tokens.py(major) — The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0tests/test_plugin_view_ds_tokens.py(major) — KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file whic
There was a problem hiding this comment.
Promoting the WARN verdict for head 442178d4ea5c: all checks terminal-green, zero unresolved review threads. (approve-on-green)
Open findings carried by this approval — non-blocking, but they did not go away:
- major
tests/test_plugin_view_ds_tokens.py:53— The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0; the equivalent TypeScript regexes in t - major
tests/test_plugin_view_ds_tokens.py:44— KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file which includes it and by the changelog); any - minor
apps/web/package.json:10— Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks
Approving a WARN does not resolve its findings (issue #22).
Summary
Bumps
@protolabsai/designfrom^0.10.1to^0.11.0and@protolabsai/uifrom^0.63.0to^0.66.1inapps/web/package.json, regenerates the rootpackage-lock.json, and widens the token-name guard'sDECL/VAR_REF/NESTED_HEADcharacter classes from[a-z0-9-]to[a-z0-9_-]so the new underscore-keyed space tokens (--pl-space-0_5,--pl-space-1_5,--pl-space-2_5) are captured whole rather than truncated at the_. The new radius scale (--pl-radius-md/-lg/-xl/-pill) and spacing half-steps are added to the spot-check and a meta assertion confirms whole-name capture forvar(--pl-space-0_5). Two generated files were also refreshed to keep existing gates green:THIRD_PARTY_LICENSES.md(attribution, which the prior candidate forgot) andtests/data/ds-plugin-kit-tokens.txt(DS plugin-kit token snapshot, which gained 11 new entries from the bump).Refs protoLabsAI/protoContent#525
Refs protoLabsAI/protoContent#547