Problem
The new project-inspection v1 surface has four small output-contract inconsistencies:
- The release catalog uses
mathlib_rev for the tag and mathlib_commit for the SHA, while inspection uses mathlib.input_rev for the tag and mathlib.rev for the SHA.
- Errors in
.lake/package-overrides.json reuse the invalid-lake-manifest and unsupported-lake-manifest codes; only path distinguishes them.
- A Lake-valid lock with no optional
inputRev prints Mathlib: None @ <sha> (...) in human output.
- URL redaction covers authority userinfo only. A valid manifest or active override URL can expose query or fragment secrets in JSON and logs.
PR #79 removes other malformed-manifest None cases, but these four remain.
Impact
The first three make a young versioned API harder to consume consistently. The last can disclose credentials from a URL that Autoform reports.
Acceptance criteria
- Give tag/input revision and resolved commit unambiguous names across both schemas, or document the mapping explicitly and preserve it intentionally.
- Use override-specific diagnostic codes.
- Never print the literal Python value
None in human output.
- Strip URL query/fragment secrets and redact authority credentials before values enter reports or diagnostics; test manifest and active-override paths in JSON and human output.
Problem
The new project-inspection v1 surface has four small output-contract inconsistencies:
mathlib_revfor the tag andmathlib_commitfor the SHA, while inspection usesmathlib.input_revfor the tag andmathlib.revfor the SHA..lake/package-overrides.jsonreuse theinvalid-lake-manifestandunsupported-lake-manifestcodes; onlypathdistinguishes them.inputRevprintsMathlib: None @ <sha> (...)in human output.PR #79 removes other malformed-manifest
Nonecases, but these four remain.Impact
The first three make a young versioned API harder to consume consistently. The last can disclose credentials from a URL that Autoform reports.
Acceptance criteria
Nonein human output.