Skip to content

chore: add Yarn fullsend harness for plugin work - #4

Open
johnmcollier wants to merge 1 commit into
mainfrom
feat/yarn-fullsend-harness
Open

johnmcollier wants to merge 1 commit into
mainfrom
feat/yarn-fullsend-harness

Conversation

@johnmcollier

Copy link
Copy Markdown
Contributor

Summary

  • Point code/fix agents at the RHDH Yarn harness (wrapper, yarn-proxy.env, npm allow_encoded_slash policy)
  • Allow redhat-developer/rhdh-skill so the rhdh-coding URL skill can load
  • Keep parasol mint/WIF and create_issues targets unchanged

Vanilla scaffold is enough for markdown-only issues. /fs-code on a real plugin will fail without Yarn on PATH.

Test plan

  • Merge; confirm .fullsend/rhdh/ is on main
  • After the repo is scaffolded with Yarn Berry (yarnPath / .yarn/releases), run /fs-code on a plugin-shaped issue and check the sandbox log for yarn succeeding (not yarn: command not found or encoded-slash DENIED)
  • Markdown-only issues should still triage as before

Made with Cursor

Code and fix agents need the vendored Yarn wrapper, npm encoded-slash
policy, and rhdh-coding skill once this repo is a Backstage plugin.

Co-authored-by: Cursor <cursoragent@cursor.com>
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:41 PM UTC · Completed 7:59 PM UTC

Commit: 31609aa · View workflow run →

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

Low

  • [missing-authorization] — No linked issue authorizes this PR. The change adds agent harness configuration files (~530 lines) without a tracking issue documenting motivation and acceptance criteria. The PR body provides clear motivation and a concrete test plan, which mitigates the gap.
    Remediation: Create a tracking issue that documents the motivation and acceptance criteria. Link it from the PR.

  • [permission-expansion] .fullsend/rhdh/policies/code.yaml:32 — The vertex_ai network policy allows access to *.googleapis.com on port 443, which is a broad wildcard covering all Google Cloud API endpoints. While restricted to claude and node binaries, it grants broader network access than a more specific hostname would.
    Remediation: If only specific GCP services are needed (e.g., Vertex AI), consider narrowing the wildcard to specific regional endpoint(s) such as us-central1-aiplatform.googleapis.com.

- host: "*.googleapis.com"
port: 443
protocol: rest
enforcement: enforce

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] permission-expansion

The vertex_ai network policy allows access to '*.googleapis.com' on port 443, which is a broad wildcard covering all Google Cloud API endpoints. While restricted to 'claude' and 'node' binaries, it grants broader network access than a more specific hostname would.

Suggested fix: If only specific GCP services are needed (e.g., Vertex AI), consider narrowing the wildcard to specific regional endpoint(s) such as us-central1-aiplatform.googleapis.com.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant