Skip to content

fix: disable integration tests badge for False Positive Report plugin - #51

Merged
azurit merged 3 commits into
coreruleset:mainfrom
azurit:lint
Sep 30, 2026
Merged

azurit merged 3 commits into
coreruleset:mainfrom
azurit:lint

Conversation

@azurit

@azurit azurit commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Integration tests are disabled for this plugin.

Summary by CodeRabbit

  • Chores
    • The false-positive-report-plugin registry entry no longer lists its CI status or integration tests badge.

Removed 'ci' field from the false-positive-report-plugin entry.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: f1ada3e8-e0b1-48e9-8c31-506f33583804

📥 Commits

Reviewing files that changed from the base of the PR and between 52a8d65 and 24c5a7b.

📒 Files selected for processing (1)
  • README.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Advanced

Run ID: 5019cab2-601d-4952-bbe6-fd824df9f2b2

📥 Commits

Reviewing files that changed from the base of the PR and between e16072e and 52a8d65.

📒 Files selected for processing (2)
  • registry.json
  • registry.yaml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

💤 Files with no reviewable changes (2)
  • registry.yaml
  • registry.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The ci field was removed from the false-positive-report-plugin entry in registry.json and registry.yaml.

Changes

Registry entry update

Layer / File(s) Summary
Remove CI field from registry entry
registry.json, registry.yaml
The ci: true field was removed from the false-positive-report-plugin entry in both files.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested labels: release:ignore, :jigsaw: plugin

Merge Risk: ⚪ Minimal · up to 52a8d

This change only turns off the integration tests badge for the False Positive Report plugin in the registry metadata. It has no apparent runtime impact and is low risk to merge.

🚥 Pre-merge checks | ✅ 16 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Ai Contribution Disclosure ⚠️ Warning ⚠️ The PR body is missing the required lowercase ## what, ## why, and ## refs sections. The reviewed diff confirms a real registry change in registry.yaml and registry.json (two ci field d… Update the PR body to include concrete ## what, ## why, and ## refs sections. If AI tools materially assisted with the change, also add ## ai disclosure with concrete **tools used**, **assisted with**, and **review performed**…
Renovate: Config Present And Valid ⚠️ Warning Renovate config is absent. The PR modifies root files (registry.json and registry.yaml), so the check applies. Neither the base nor head contains any allowed Renovate config path. Add a root renovate.json containing $schema set to https://docs.renovatebot.com/renovate-schema.json and an extends array that includes github>coreruleset/renovate-config.
✅ Passed checks (16 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: disabling the integration tests badge for the False Positive Report plugin by removing its ci registry field.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Regex Assembly Is The Source Of Truth ✅ Passed Passed — not applicable. The pull request changes only registry.json and registry.yaml. It does not modify an @rx pattern in rules/*.conf or any file under regex-assembly/.
Rule Change Requires Go-Ftw Test Coverage ✅ Passed Not applicable. The pull request only removes the ci field from registry.json and registry.yaml. It does not change a SecRule in rules/*.conf or plugins/*.conf, and it does not change `reg…
Redos Risk & Re2 Compatibility ✅ Passed Passed — not applicable. The pull request only removes the ci field from registry.json and registry.yaml; it does not add or modify a regular expression in rules/*.conf, regex-assembly/*.ra,…
False Positive Risk & Existing Coverage ✅ Passed Passed: not applicable. The pull request only removes the ci field from the false-positive-report-plugin entries in registry.yaml and registry.json. It does not add or widen a detection patter…
Crs Rule Metadata & Id Conventions ✅ Passed Passed: not applicable. The authoritative diff changes only registry.json and registry.yaml. It does not add or modify a SecRule in rules/.conf, plugins/.conf, or crs-setup.conf.example.
Rule & Config Breaking Changes ✅ Passed PASS — The PR removes only the optional ci metadata from the false-positive-report-plugin entries in registry.yaml and registry.json. The schema defines ci as an optional boolean with defaul…
Owasp Security (Web, Api & Llm) ✅ Passed PASS — The PR only removes the optional ci metadata from the false-positive-report-plugin entries in registry.yaml and registry.json. The registry schema defines ci as a boolean used to deri…
Unpinned Dependencies & Actions ✅ Passed Passed. Not applicable: the diff changes only registry.json and registry.yaml. It does not change a manifest, lockfile, Dockerfile, workflow, or pipeline file covered by this check.
Secrets, Payloads & Pii In Logs ✅ Passed PASS: The pull request changes only registry.yaml and registry.json. It removes ci: true from the false-positive-report-plugin registry entry. It adds no log, error, stack-trace, telemetry, pa…
New Dependency Scrutiny ✅ Passed The PR changes only registry.json and registry.yaml. Both diffs remove ci: true from the existing false-positive-report-plugin entry. The diff adds no package, Action, or Buildkite plugin depe…
Install & Build-Time Code Execution ✅ Passed PASS — The PR changes only registry.json and registry.yaml, removing the ci field for false-positive-report-plugin. It adds no installer, shell, CI, Docker, packaging, Go, npm, or Terraform ex…
Full details: Ai Contribution Disclosure

Explanation

⚠️ The PR body is missing the required lowercase ## what, ## why, and ## refs sections. The reviewed diff confirms a real registry change in registry.yaml and registry.json (two ci field deletions). No Co-Authored-By or AI-tool signature appears in the two commit messages. The small metadata diff provides no stated AI-assistance signal, so this finding is for the missing required sections, not for missing AI disclosure.

Resolution

Update the PR body to include concrete ## what, ## why, and ## refs sections. If AI tools materially assisted with the change, also add ## ai disclosure with concrete **tools used**, **assisted with**, and **review performed** fields.

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@azurit

azurit commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@fzipi Can you advise what is wrong here with checks? Thanks.

@fzipi

fzipi commented Sep 30, 2026

Copy link
Copy Markdown
Member

The `validate` check is failing: `registry.yaml`/`registry.json` were updated, but `README.md` wasn't regenerated, so its table row for false-positive-report-plugin still shows the old integration-tests badge. CI does `git diff --exit-code -- README.md registry.json` after running the generator, so it fails on that drift.

Fix: run `uv run scripts/generate_registry.py` and commit the resulting `README.md` change.


🤖 Generated with Claude Code

@fzipi

fzipi commented Sep 30, 2026

Copy link
Copy Markdown
Member

I'm adding that to the docs in #52

@azurit

azurit commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

Fix: run uv run scripts/generate_registry.py and commit the resulting README.md change.

Anything like uv does not seems to be part of Debian or Ubuntu.

@fzipi

fzipi commented Sep 30, 2026

Copy link
Copy Markdown
Member

pip install uv

@fzipi

fzipi commented Sep 30, 2026

Copy link
Copy Markdown
Member
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://deb.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | sudo gpg --dearmor --yes -o /etc/apt/keyrings/deb.griffo.io.gpg
echo "deb [signed-by=/etc/apt/keyrings/deb.griffo.io.gpg] https://deb.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | sudo tee /etc/apt/sources.list.d/deb.griffo.io.list > /dev/null
sudo apt update
sudo apt install uv

@azurit
azurit merged commit 655ac2b into coreruleset:main Sep 30, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants