Skip to content

project inspect: stabilize the v1 report surface and redact URL secrets #81

Description

@Deicyde

Problem

The new project-inspection v1 surface has four small output-contract inconsistencies:

  • The release catalog uses mathlib_rev for the tag and mathlib_commit for the SHA, while inspection uses mathlib.input_rev for the tag and mathlib.rev for the SHA.
  • Errors in .lake/package-overrides.json reuse the invalid-lake-manifest and unsupported-lake-manifest codes; only path distinguishes them.
  • A Lake-valid lock with no optional inputRev prints Mathlib: None @ <sha> (...) in human output.
  • URL redaction covers authority userinfo only. A valid manifest or active override URL can expose query or fragment secrets in JSON and logs.

PR #79 removes other malformed-manifest None cases, but these four remain.

Impact

The first three make a young versioned API harder to consume consistently. The last can disclose credentials from a URL that Autoform reports.

Acceptance criteria

  • Give tag/input revision and resolved commit unambiguous names across both schemas, or document the mapping explicitly and preserve it intentionally.
  • Use override-specific diagnostic codes.
  • Never print the literal Python value None in human output.
  • Strip URL query/fragment secrets and redact authority credentials before values enter reports or diagnostics; test manifest and active-override paths in JSON and human output.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions