Skip to content

feat: updatecheck foundation package (PR-01 of 5) - #651

Merged
shivasurya merged 1 commit into
mainfrom
feat/updatecheck-foundation
Apr 12, 2026
Merged

shivasurya merged 1 commit into
mainfrom
feat/updatecheck-foundation

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

  • Adds sast-engine/updatecheck/ as a purely additive, zero-callers foundation package implementing the full version-check pipeline from the version-update-check tech spec.
  • No behavior change for users — the package is unimported until PR-02 (CLI) and PR-03 (MCP) land.
  • 100% statement coverage on all new files.

What's in this PR

File Purpose
manifest.go Wire types (Manifest, ManifestLatest, ManifestAnnouncement), public Result/UpgradeNotice/Announcement/Options, Fetch() with context-scoped timeout
semver.go Strict MAJOR.MINOR.PATCH parser, Compare(), Match() with < <= > >= = and space-separated AND
select.go selectUpgrade() (info/warn escalation via min_supported) and selectAnnouncement() with 6-tier priority, audience filter, time-window, dismissed-IDs, and version_range semver filter
check.go Check() orchestrator; opt-out via DisableCheck flag and PATHFINDER_NO_UPDATE_CHECK env var (build tag !noupdatecheck)
check_noop.go Stub returning nil for distros using -tags noupdatecheck

Stack

PR-01 (this) — updatecheck pkg, no callers
  ├── PR-02 — CLI integration (cmd/root.go + banner)
  │     └── PR-04 — analytics wiring
  └── PR-03 — MCP server integration
        └── PR-04 — analytics wiring
PR-05 — release/latest.json + publish workflow (parallel)

Verification

cd sast-engine
go test -coverprofile=cover.out ./updatecheck/...
go tool cover -func=cover.out | tail -1
# total: (statements) 100.0%

go build -tags noupdatecheck ./...
golangci-lint run ./updatecheck/...
# 0 issues

Test plan

  • go build ./... — zero issues
  • go test ./updatecheck/... — all tests pass
  • go tool cover — 100.0% statement coverage
  • golangci-lint run ./updatecheck/... — 0 issues
  • go build -tags noupdatecheck ./... — noop stub compiles
  • Zero callers outside updatecheck/ (grep -r "updatecheck" . --include="*.go" --exclude-dir=updatecheck returns empty)

🤖 Generated with Claude Code

Adds sast-engine/updatecheck/ — a purely additive, zero-callers package
that implements the full version-check pipeline described in the
version-update-check tech spec.

- manifest.go: wire types (Manifest, ManifestLatest, ManifestAnnouncement,
  etc.), public Result/UpgradeNotice/Announcement/Options types, and
  Fetch() with context-scoped 800ms/5s HTTP timeout.
- semver.go: strict MAJOR.MINOR.PATCH parser, Compare(), Match() with
  <, <=, >, >=, = and space-separated AND (up to 2 constraints).
- select.go: selectUpgrade() (info/warn escalation via min_supported)
  and selectAnnouncement() with the 6-tier priority rule, audience filter,
  time-window filter, dismissed-IDs filter, and version_range semver filter.
- check.go (!noupdatecheck): Check() orchestrator with opt-out via
  DisableCheck flag and PATHFINDER_NO_UPDATE_CHECK env var.
- check_noop.go (noupdatecheck): stub returning nil for distros that
  compile the feature out via -tags noupdatecheck.
- 100% statement coverage across all files.
- Zero callers anywhere in the binary tree (purely additive).

Part of: version-update-check stack (PR-01 of 5).
Next: PR-02 wires Check() into cmd/root.go PersistentPreRun.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@shivasurya shivasurya added enhancement New feature or request go Pull requests that update go code labels Apr 12, 2026
@shivasurya shivasurya self-assigned this Apr 12, 2026
@safedep

safedep Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

View complete scan results →

This report is generated by SafeDep Github App

@github-actions

Copy link
Copy Markdown

Code Pathfinder Security Scan

Pass Critical High Medium Low Info

No security issues detected.

Metric Value
Files Scanned 11
Rules 205

Powered by Code Pathfinder

@codecov

codecov Bot commented Apr 12, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.87%. Comparing base (0fbf2cd) to head (24b3fe9).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #651      +/-   ##
==========================================
+ Coverage   84.75%   84.87%   +0.11%     
==========================================
  Files         165      169       +4     
  Lines       24403    24594     +191     
==========================================
+ Hits        20682    20873     +191     
  Misses       2937     2937              
  Partials      784      784              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya commented Apr 12, 2026 •

Copy link
Copy Markdown
Owner Author

shivasurya commented Apr 12, 2026 •

Copy link
Copy Markdown
Owner Author

Merge activity

  • Apr 12, 2:24 PM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Apr 12, 2:24 PM UTC: @shivasurya merged this pull request with Graphite.

@shivasurya
shivasurya merged commit ad5f716 into main Apr 12, 2026
8 checks passed
@shivasurya
shivasurya deleted the feat/updatecheck-foundation branch April 12, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant