Repository navigation
chore: add Yarn fullsend harness for plugin work - #4
johnmcollier wants to merge 1 commit into
Conversation
Code and fix agents need the vendored Yarn wrapper, npm encoded-slash policy, and rhdh-coding skill once this repo is a Backstage plugin. Co-authored-by: Cursor <cursoragent@cursor.com>
|
🤖 Finished Review · ✅ Success · Started 7:41 PM UTC · Completed 7:59 PM UTC Commit: |
ReviewFindingsLow
|
| - host: "*.googleapis.com" | ||
| port: 443 | ||
| protocol: rest | ||
| enforcement: enforce |
There was a problem hiding this comment.
[low] permission-expansion
The vertex_ai network policy allows access to '*.googleapis.com' on port 443, which is a broad wildcard covering all Google Cloud API endpoints. While restricted to 'claude' and 'node' binaries, it grants broader network access than a more specific hostname would.
Suggested fix: If only specific GCP services are needed (e.g., Vertex AI), consider narrowing the wildcard to specific regional endpoint(s) such as us-central1-aiplatform.googleapis.com.
Summary
yarn-proxy.env, npmallow_encoded_slashpolicy)redhat-developer/rhdh-skillso therhdh-codingURL skill can loadcreate_issuestargets unchangedVanilla scaffold is enough for markdown-only issues.
/fs-codeon a real plugin will fail without Yarn on PATH.Test plan
.fullsend/rhdh/is onmainyarnPath/.yarn/releases), run/fs-codeon a plugin-shaped issue and check the sandbox log foryarnsucceeding (notyarn: command not foundor encoded-slash DENIED)Made with Cursor